2023-04-21 13:25:09 +00:00
{
2023-06-14 17:31:25 +00:00
"type" : "bundle" ,
"id" : "bundle--56eac220-9900-4d35-bb22-461b950d210f" ,
"objects" : [
{
"type" : "identity" ,
"spec_version" : "2.1" ,
"id" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:21.000Z" ,
"modified" : "2016-03-17T15:47:21.000Z" ,
"name" : "CIRCL" ,
"identity_class" : "organization"
} ,
{
"type" : "report" ,
"spec_version" : "2.1" ,
"id" : "report--56eac220-9900-4d35-bb22-461b950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:21.000Z" ,
"modified" : "2016-03-17T15:47:21.000Z" ,
"name" : "Malspam (2016-03-17) - Dridex (122), Locky" ,
"published" : "2016-03-17T15:48:15Z" ,
"object_refs" : [
"indicator--56eac23a-7cd0-476d-934b-4044950d210f" ,
"indicator--56eac23b-14dc-45b6-a6b1-42db950d210f" ,
"indicator--56eac23b-e2e8-4690-965c-4cb4950d210f" ,
"indicator--56eac23b-8e80-4a02-b69f-4b5b950d210f" ,
"indicator--56eac23b-1900-4947-a394-4c1a950d210f" ,
"indicator--56eac23c-9058-4173-a240-4d5a950d210f" ,
"indicator--56eac23c-8c94-4ee8-8fab-47fa950d210f" ,
"indicator--56eac23c-c808-4c30-80ab-41c6950d210f" ,
"indicator--56eac23d-67d4-4934-983b-473e950d210f" ,
"indicator--56eac23d-9b54-47b3-b3db-4869950d210f" ,
"indicator--56eac23d-0908-4b02-b7f3-4e6c950d210f" ,
"indicator--56eac23d-0f88-4c60-8033-46dd950d210f" ,
"indicator--56eac23e-4514-4fe0-ad0c-4721950d210f" ,
"indicator--56eac23e-db88-4caf-bc6e-4990950d210f" ,
"indicator--56eac23e-e064-47a3-9092-4a16950d210f" ,
"indicator--56eac23f-4a48-440b-b3a4-4e85950d210f" ,
"indicator--56eac23f-d114-4346-a633-4652950d210f" ,
"indicator--56eac23f-7ee4-4c62-9b42-4048950d210f" ,
"indicator--56eac23f-c1f8-4883-a3d3-429c950d210f" ,
"indicator--56eac240-2fcc-49ab-83bb-4c3e950d210f" ,
"indicator--56eac240-39b0-4cd2-98aa-4879950d210f" ,
"indicator--56eac240-12c0-408f-a0ea-4eb7950d210f" ,
"indicator--56eac240-00e0-4c53-b7a4-47c1950d210f" ,
"indicator--56eac241-8110-4e88-8757-480e950d210f" ,
"indicator--56eac241-8b78-4488-8f5e-410f950d210f" ,
"indicator--56eac241-dadc-40b1-adc9-4b7c950d210f" ,
"indicator--56eac242-27a0-482b-9819-4f2e950d210f" ,
"indicator--56eac242-4b10-4ebe-a04b-4cef950d210f" ,
"indicator--56eac242-285c-4bb8-840b-4dbb950d210f" ,
"indicator--56eac243-0460-4ef4-86ed-4b6c950d210f" ,
"indicator--56eac243-e110-4a66-93ba-4a03950d210f" ,
"indicator--56eac243-a244-4c25-b5d0-455d950d210f" ,
"indicator--56eac244-8940-45e4-b222-4229950d210f" ,
"indicator--56eac244-f58c-4e9e-8222-4993950d210f" ,
"indicator--56eac244-df84-4be6-a71f-4811950d210f" ,
"indicator--56eac245-ca84-44fe-85d5-4fb3950d210f" ,
"indicator--56eac245-d9bc-409b-8545-409f950d210f" ,
"indicator--56eac246-e374-4388-b84d-4551950d210f" ,
"indicator--56eac246-c998-45c0-adab-48c5950d210f" ,
"indicator--56eac246-3508-40b2-886f-4349950d210f" ,
"indicator--56eac247-0c94-4f1b-bd4b-481a950d210f" ,
"indicator--56eac293-b124-4554-9cbc-45f9950d210f" ,
"indicator--56eac294-029c-45cf-bc16-4acd950d210f" ,
"indicator--56eac295-c148-4f3d-ad50-40e5950d210f" ,
"indicator--56eac296-46c8-46d8-b363-424f950d210f" ,
"indicator--56eac296-e140-4372-ae61-429e950d210f" ,
"indicator--56eac297-54ac-46c4-ad8c-42d5950d210f" ,
"indicator--56eac298-0f1c-4dc8-b1c5-4838950d210f" ,
"indicator--56eac298-a4e0-4d6f-87ef-46de950d210f" ,
"indicator--56eac299-212c-4323-aa33-4241950d210f" ,
"indicator--56eac29a-1fcc-423d-9e72-4a19950d210f" ,
"indicator--56eac29a-5fe4-4e69-adf4-4287950d210f" ,
"indicator--56eac29b-f2ec-4b5f-9a51-4457950d210f" ,
"indicator--56eac29c-b000-420e-8968-4026950d210f" ,
"indicator--56eac29d-f0d0-4ed7-aa0f-4c82950d210f" ,
"indicator--56eac29d-e0d0-49c5-a44d-452a950d210f" ,
"indicator--56eac29e-e5c0-4433-b226-4002950d210f" ,
"indicator--56eac29f-0e14-4ccd-b6a9-41c6950d210f" ,
"indicator--56eac29f-7d2c-4f1d-bfde-467a950d210f" ,
"indicator--56eac2a0-d1cc-432b-b643-4d1f950d210f" ,
"indicator--56eac2a1-d650-44eb-b596-4a8e950d210f" ,
"indicator--56eac2a1-2258-42a0-9f37-4339950d210f" ,
"indicator--56eac2a2-e338-48f6-a82f-41f5950d210f" ,
"indicator--56eac2a3-3cc4-40f3-bd58-46c2950d210f" ,
"indicator--56eac2a4-61d8-4299-af23-4e6d950d210f" ,
"indicator--56eac2a4-8698-445b-b528-4c36950d210f" ,
"indicator--56eac2a5-5068-4743-a642-4dbd950d210f" ,
"indicator--56eac2a6-99d8-4015-b2c5-4ed7950d210f" ,
"indicator--56eac2a6-8120-4542-804f-4d17950d210f" ,
"indicator--56eac2a7-6bb8-4cc1-9591-4685950d210f" ,
"indicator--56eac2a8-3d88-47ac-abb2-47c6950d210f" ,
"indicator--56eac2a8-04b8-4ebb-96ff-4156950d210f" ,
"indicator--56eac2a9-5420-4193-adf9-4a60950d210f" ,
"indicator--56eac2aa-7220-46f1-99af-4444950d210f" ,
"indicator--56eac2aa-abdc-440b-a717-472c950d210f" ,
"indicator--56eac2ab-0550-4439-aab1-45ae950d210f" ,
"indicator--56eac2ab-689c-4b2e-b3f2-48df950d210f" ,
"indicator--56eac2ac-4030-45e3-ab10-4231950d210f" ,
"indicator--56eac2ac-b168-4c5e-b21f-471d950d210f" ,
"indicator--56eac2ad-895c-4319-9f3b-429d950d210f" ,
"indicator--56eac2ae-a38c-492a-9745-4437950d210f" ,
"indicator--56eac2ae-3310-4539-9b4f-4994950d210f" ,
"indicator--56eac2af-fe60-4b72-8d9d-415c950d210f" ,
"indicator--56eac2af-9540-4f68-905f-402e950d210f" ,
"indicator--56eac2b0-b874-41e2-a4f4-418c950d210f" ,
"indicator--56eac2b1-7840-4548-85f6-4e87950d210f" ,
"indicator--56eac2b1-7fe4-4e90-adf9-4403950d210f" ,
"indicator--56eac2b2-f520-4ed0-b00f-4383950d210f" ,
"indicator--56eac2b2-16c0-4ac4-bdd3-4ad6950d210f" ,
"indicator--56eac2b3-e874-4844-aa76-4ed1950d210f" ,
"indicator--56eac2b4-f9ec-46f1-a42a-44d5950d210f" ,
"indicator--56eac2b4-9864-4fad-9d46-4884950d210f" ,
"indicator--56eac2b5-0940-477c-bceb-48bc950d210f" ,
"indicator--56eac2b6-26fc-4e41-8dc7-444c950d210f" ,
"indicator--56eac2b6-b19c-4ad1-b647-47e4950d210f" ,
"indicator--56eac2b7-a288-4668-8a74-457b950d210f" ,
"indicator--56eac2b7-3cc8-4a79-af65-4531950d210f" ,
"indicator--56eac2b8-21fc-4990-bc52-4764950d210f" ,
"indicator--56eac2b8-de40-4816-9d5f-4258950d210f" ,
"indicator--56eac2b9-d520-4976-8625-4660950d210f" ,
"indicator--56eac2ba-0dc0-40b2-b5e3-4595950d210f" ,
"observed-data--56eac362-3b08-465e-b1a9-4dca950d210f" ,
"file--56eac362-3b08-465e-b1a9-4dca950d210f" ,
"artifact--56eac362-3b08-465e-b1a9-4dca950d210f" ,
"observed-data--56eac3ba-bcd8-497b-aea0-4c0a02de0b81" ,
"url--56eac3ba-bcd8-497b-aea0-4c0a02de0b81" ,
"observed-data--56eac3ba-34f0-4332-b943-4bf102de0b81" ,
"url--56eac3ba-34f0-4332-b943-4bf102de0b81" ,
"observed-data--56eac3bb-1c40-4a77-92a4-4fd402de0b81" ,
"url--56eac3bb-1c40-4a77-92a4-4fd402de0b81" ,
"observed-data--56eac3bb-e854-4895-ab44-4c5c02de0b81" ,
"url--56eac3bb-e854-4895-ab44-4c5c02de0b81" ,
"observed-data--56eac3bb-4b48-4f7d-8bac-4a1402de0b81" ,
"url--56eac3bb-4b48-4f7d-8bac-4a1402de0b81" ,
"observed-data--56eac3bc-a7ec-4fef-876f-4dbb02de0b81" ,
"url--56eac3bc-a7ec-4fef-876f-4dbb02de0b81" ,
"observed-data--56eac3bc-f4f0-4364-b50c-410602de0b81" ,
"url--56eac3bc-f4f0-4364-b50c-410602de0b81" ,
"observed-data--56eac3bd-31cc-4257-915c-446702de0b81" ,
"url--56eac3bd-31cc-4257-915c-446702de0b81" ,
"observed-data--56eac3bd-5778-4e85-acae-49dc02de0b81" ,
"url--56eac3bd-5778-4e85-acae-49dc02de0b81" ,
"observed-data--56eac3bd-f844-4519-851c-490102de0b81" ,
"url--56eac3bd-f844-4519-851c-490102de0b81" ,
"observed-data--56eac3be-7d50-4c59-a0f0-492402de0b81" ,
"url--56eac3be-7d50-4c59-a0f0-492402de0b81" ,
"observed-data--56eac3be-5674-457e-9a66-424f02de0b81" ,
"url--56eac3be-5674-457e-9a66-424f02de0b81" ,
"observed-data--56eac3be-75bc-4d5e-a326-4eba02de0b81" ,
"url--56eac3be-75bc-4d5e-a326-4eba02de0b81" ,
"indicator--56eac9f2-f6c8-4ac8-a41d-47f7950d210f" ,
"indicator--56eac9f2-8c28-47bb-8c21-4e0b950d210f" ,
"indicator--56eac9f2-7d9c-40ef-8095-47ff950d210f" ,
"indicator--56eac9f3-a41c-4e36-8f5e-4873950d210f" ,
"indicator--56eac9f3-4068-453c-83db-43d0950d210f" ,
"indicator--56eaca0b-89a8-48c5-800c-4c43950d210f" ,
"indicator--56eaca0b-0dc0-4e7f-b549-41bc950d210f" ,
"indicator--56eaca0c-10c4-4c06-9e71-4009950d210f" ,
"indicator--56eaca0d-1c44-43f8-84fe-453f950d210f" ,
"indicator--56eaca0d-5910-4bca-b0b7-4489950d210f" ,
"indicator--56eaca0e-81d4-475b-8938-4ab4950d210f" ,
"indicator--56eaca0f-17b4-4ec8-964d-4f92950d210f" ,
"indicator--56eaca0f-67fc-4f1b-a31a-4926950d210f" ,
"indicator--56eaca10-c984-4c93-b93e-4090950d210f" ,
"indicator--56eaca11-0a9c-40c8-bf8b-4790950d210f" ,
"indicator--56eaca11-56ec-4629-bd44-4c61950d210f" ,
"indicator--56eaca12-0e58-48b2-bc37-4bea950d210f" ,
"indicator--56eaca13-1e78-4210-8bc5-4958950d210f" ,
"indicator--56eaca13-834c-43b1-ae71-4b87950d210f" ,
"indicator--56eaca14-5428-45de-8e32-4ac5950d210f" ,
"indicator--56eaca15-e998-4373-820b-4348950d210f" ,
"indicator--56eaca15-afb4-4ae1-9b52-4eee950d210f" ,
"indicator--56eaca16-e284-4b97-bcac-4011950d210f" ,
"indicator--56eaca16-bfac-42e4-9f55-44fe950d210f" ,
"indicator--56eaca17-e698-4672-a607-486a950d210f" ,
"indicator--56eaca18-2190-4e09-a5d9-4652950d210f" ,
"indicator--56eaca18-cf98-4d8c-a0a9-492f950d210f" ,
"indicator--56eaca19-43b4-423f-b097-489e950d210f" ,
"indicator--56eaca19-45e8-4e0e-a3e9-445b950d210f" ,
"indicator--56eaca1a-1ff8-4a6c-a14f-4fd7950d210f" ,
"indicator--56eaca1b-1174-47a2-bee3-44fb950d210f" ,
"indicator--56eaca1b-72a8-44c8-a6b4-435b950d210f" ,
"indicator--56eaca1c-ba5c-4060-b2f3-448f950d210f" ,
"indicator--56eaca1d-2550-4f52-a4eb-4013950d210f" ,
"indicator--56eaca1d-4798-4db2-a91c-43df950d210f" ,
"indicator--56eaca1e-0274-4089-a96a-4589950d210f" ,
"indicator--56eaca1f-1784-4b13-952d-40b8950d210f" ,
"indicator--56eaca20-c958-4301-81fd-4cc8950d210f" ,
"indicator--56eaca20-2438-4c88-9f55-416c950d210f" ,
"indicator--56eaca21-e514-43db-bbb4-49b5950d210f" ,
"indicator--56eaca22-8fe8-45e6-8895-4814950d210f" ,
"indicator--56eaca22-468c-4311-b4b9-4d02950d210f" ,
"indicator--56eaca23-6fd8-46b6-a10b-4520950d210f" ,
"indicator--56eaca24-09cc-43d2-a67a-42ab950d210f" ,
"indicator--56eaca25-105c-4a4e-844c-4da0950d210f" ,
"indicator--56eaca25-efd4-4887-93c8-49d5950d210f" ,
"indicator--56eaca26-3d50-48f4-a3c8-4181950d210f" ,
"indicator--56eaca26-0d60-4105-96b4-4368950d210f" ,
"indicator--56eaca27-1a14-4e5b-8ce8-4fb7950d210f" ,
"indicator--56eaca28-0588-447f-baf8-4ca1950d210f" ,
"indicator--56eaca29-6008-4dde-93d6-4aff950d210f" ,
"indicator--56eaca29-07cc-4848-a68b-4c65950d210f" ,
"indicator--56eaca2a-7644-4ab8-8097-4022950d210f" ,
"indicator--56eaca2b-7b10-40f7-a0b1-4ce2950d210f" ,
"indicator--56eaca2c-1c48-4194-8f3d-4c59950d210f" ,
"indicator--56eaca2c-4bec-4afa-904d-4df7950d210f" ,
"indicator--56eaca2d-cff4-4840-a3df-478c950d210f" ,
"indicator--56eaca2e-2dbc-4698-89fa-47b1950d210f" ,
"indicator--56eaca2e-7b08-4ac8-965c-427a950d210f" ,
"indicator--56eacae6-cb28-44ab-931b-4723950d210f" ,
"indicator--56eacae6-5444-420e-bc08-43d5950d210f" ,
"indicator--56eacae7-ada0-4266-b01e-44b0950d210f" ,
"indicator--56eacb16-5800-4c75-8da3-4a7a950d210f" ,
"indicator--56eacb16-b578-4e27-9e7a-4a3f950d210f" ,
"indicator--56eacb16-457c-4333-86cf-48ad950d210f" ,
"indicator--56eacbf1-5038-4c64-8b52-45d4950d210f" ,
"indicator--56eacbf1-f69c-4b5f-9733-4398950d210f" ,
"indicator--56eacbf1-af44-4b79-83c4-4cdc950d210f" ,
"indicator--56eacbf2-5564-4bc6-80be-41a7950d210f" ,
"indicator--56eacbf2-02b4-42d4-b5e0-4e95950d210f" ,
"indicator--56eacbf2-e230-40b3-a942-4eaa950d210f" ,
"indicator--56eacbf3-0e2c-46d5-b7c3-411a950d210f" ,
"indicator--56eacbf3-8378-45a3-81a0-4971950d210f" ,
"indicator--56eacbf3-54cc-46d6-bed0-4b55950d210f" ,
"indicator--56eacbf4-b95c-4cbe-bf8f-4c36950d210f" ,
"indicator--56eacbf4-45bc-446a-b25f-48fe950d210f" ,
"indicator--56eacbf4-0278-4f1b-9c03-4b66950d210f" ,
"indicator--56eacbf5-06ac-4f04-ad0c-4651950d210f" ,
"indicator--56eacbf5-048c-4ef7-ab55-40d9950d210f" ,
"indicator--56eacbf5-8b94-4108-b026-4ada950d210f" ,
"indicator--56eacbf6-1334-47d1-a6cd-4bf4950d210f" ,
"indicator--56eacbf6-cec8-4a87-9e40-4144950d210f" ,
"indicator--56eacbf6-0bc0-46ff-ba56-4626950d210f" ,
"indicator--56eacbf7-22b8-479d-8187-41f8950d210f" ,
"indicator--56eacbf7-7a7c-4b29-87bf-448c950d210f" ,
"indicator--56eacbf7-ff24-4944-bff9-4925950d210f" ,
"indicator--56eacbf7-8850-446d-a496-4145950d210f" ,
"indicator--56eacbf8-d8e4-43d8-a92c-43a9950d210f" ,
"indicator--56eacbf8-6d48-4568-a565-49d8950d210f" ,
"indicator--56eacbf8-c164-4f4a-9d9b-4468950d210f" ,
"indicator--56eacbf9-352c-44a8-b8af-4ef0950d210f" ,
"indicator--56eacbf9-7070-4b9c-b80d-4226950d210f" ,
"indicator--56eacbfa-e8c0-4f55-bdce-48fb950d210f" ,
"indicator--56eacbfa-461c-4334-bd48-45b5950d210f" ,
"indicator--56eacbfa-8ef8-4f2c-b096-4bda950d210f" ,
"indicator--56eacbfb-b644-4b58-9fcc-4a16950d210f" ,
"indicator--56eacbfb-d958-4ab6-98c3-4121950d210f" ,
"indicator--56eacbfb-1a38-4f40-8663-454d950d210f" ,
"indicator--56eacbfc-b850-462f-9f45-4e74950d210f" ,
"indicator--56eacbfc-3f1c-4f7b-b440-43e5950d210f" ,
"indicator--56eacbfc-9ca4-4acf-9049-44ee950d210f" ,
"indicator--56eacbfd-0e3c-4d94-9198-4a02950d210f" ,
"indicator--56eacbfd-3788-438b-83b1-4078950d210f" ,
"indicator--56eacbfd-171c-4a08-9bb8-4bdc950d210f" ,
"indicator--56eacbfe-9e04-4ad2-b51f-4540950d210f" ,
"indicator--56eacbfe-457c-4d76-8fd1-43c5950d210f" ,
"indicator--56eacbff-3594-4fb3-9f99-4d97950d210f" ,
"indicator--56eacbff-f278-495d-a353-4bd8950d210f" ,
"indicator--56eacbff-2ea8-41c5-9a3c-4a35950d210f" ,
"indicator--56eacc00-a528-4c51-a370-470b950d210f" ,
"indicator--56eacc00-29f8-497c-b84d-4bb7950d210f" ,
"indicator--56eacc00-d89c-41dd-8716-4651950d210f" ,
"indicator--56eacc01-cb4c-489c-b715-4f99950d210f" ,
"observed-data--56eacc9e-211c-4173-ac60-4cff02de0b81" ,
"url--56eacc9e-211c-4173-ac60-4cff02de0b81" ,
"observed-data--56eacc9f-44cc-48b6-a055-43ba02de0b81" ,
"url--56eacc9f-44cc-48b6-a055-43ba02de0b81" ,
"observed-data--56eacc9f-3328-41a1-835c-41ba02de0b81" ,
"url--56eacc9f-3328-41a1-835c-41ba02de0b81" ,
"observed-data--56eacc9f-f430-4697-a779-40b002de0b81" ,
"url--56eacc9f-f430-4697-a779-40b002de0b81" ,
"observed-data--56eacca0-a27c-4958-9f41-4e4702de0b81" ,
"url--56eacca0-a27c-4958-9f41-4e4702de0b81" ,
"observed-data--56eacca0-3f44-415c-ad20-460402de0b81" ,
"url--56eacca0-3f44-415c-ad20-460402de0b81" ,
"observed-data--56eacca0-e128-4dde-a09c-4d6102de0b81" ,
"url--56eacca0-e128-4dde-a09c-4d6102de0b81" ,
"observed-data--56eacca1-6f44-4dde-b2e8-4e5b02de0b81" ,
"url--56eacca1-6f44-4dde-b2e8-4e5b02de0b81" ,
"observed-data--56eacca1-b4a8-4cee-a226-494d02de0b81" ,
"url--56eacca1-b4a8-4cee-a226-494d02de0b81" ,
"observed-data--56eacca1-e5c4-4f49-a818-433202de0b81" ,
"url--56eacca1-e5c4-4f49-a818-433202de0b81" ,
"observed-data--56eacca2-b798-434c-ad87-4f1d02de0b81" ,
"url--56eacca2-b798-434c-ad87-4f1d02de0b81" ,
"observed-data--56eacca2-671c-4ece-87bb-414b02de0b81" ,
"url--56eacca2-671c-4ece-87bb-414b02de0b81" ,
"observed-data--56eacca2-6138-4661-a545-429f02de0b81" ,
"url--56eacca2-6138-4661-a545-429f02de0b81" ,
"observed-data--56eacca3-a7c8-4de4-93f2-461c02de0b81" ,
"url--56eacca3-a7c8-4de4-93f2-461c02de0b81" ,
"observed-data--56eacca3-2104-42a0-8075-4c9102de0b81" ,
"url--56eacca3-2104-42a0-8075-4c9102de0b81" ,
"observed-data--56eacca3-2120-449d-a48e-46b102de0b81" ,
"url--56eacca3-2120-449d-a48e-46b102de0b81" ,
"observed-data--56eacca4-7624-4223-a99d-47f802de0b81" ,
"url--56eacca4-7624-4223-a99d-47f802de0b81" ,
"observed-data--56eacca4-69a4-43c3-9974-4f4002de0b81" ,
"url--56eacca4-69a4-43c3-9974-4f4002de0b81" ,
"observed-data--56eacca4-2c64-4571-b1bf-404d02de0b81" ,
"url--56eacca4-2c64-4571-b1bf-404d02de0b81" ,
"observed-data--56eacd5d-ba48-4ecc-be53-489b02de0b81" ,
"url--56eacd5d-ba48-4ecc-be53-489b02de0b81" ,
"indicator--56ead0a0-2f84-4b87-9215-4295950d210f" ,
"indicator--56ead0a0-e120-40cf-b3ce-4971950d210f" ,
"indicator--56ead0a1-e968-47ea-8d0c-4995950d210f" ,
"indicator--56ead0a2-23e0-4e9e-8f19-4b45950d210f" ,
"indicator--56ead0a2-b034-45e5-8dd8-4358950d210f" ,
"indicator--56ead0a3-8b74-4610-a21a-40b8950d210f" ,
"indicator--56ead0a4-cbe0-45af-a755-4183950d210f" ,
"indicator--56ead0a4-6868-4a21-8b76-4e6a950d210f" ,
"indicator--56ead0a5-5468-48cd-8c83-47ca950d210f" ,
"indicator--56ead0a6-63b4-4e00-a61e-4849950d210f" ,
"indicator--56ead0a7-e6b0-4969-ac04-4c4c950d210f" ,
"indicator--56ead0a7-3c74-40a3-8210-4cc4950d210f" ,
"indicator--56ead0a8-a450-4141-b8bb-40bb950d210f" ,
"indicator--56ead0a9-e568-4064-92dd-47af950d210f" ,
"indicator--56ead0a9-23fc-43c8-985e-4b9f950d210f" ,
"indicator--56ead0aa-4ea8-4931-bc7e-4de3950d210f" ,
"indicator--56ead0ab-a334-486e-b6f4-47eb950d210f" ,
"indicator--56ead0ac-e5a8-41b9-823f-4c1f950d210f" ,
"indicator--56ead0ac-f0bc-4f41-9b92-40ac950d210f" ,
"indicator--56ead0ad-3160-498f-aa22-4650950d210f" ,
"indicator--56ead0ae-dd64-4773-86ce-4a7a950d210f" ,
"indicator--56ead0ae-8ce0-4943-ac04-4b07950d210f" ,
"indicator--56ead0af-7554-44eb-9e27-4d18950d210f" ,
"indicator--56ead0b0-3a24-4c2d-b865-4391950d210f" ,
"indicator--56ead11b-2b20-4b0e-a60f-45ab950d210f" ,
"indicator--56ead11c-b0ec-46e3-a6f7-44c5950d210f" ,
"indicator--56ead11c-8058-4c0c-b2de-4c83950d210f" ,
"indicator--56ead11c-9f9c-4e80-b5f9-4f85950d210f" ,
"observed-data--56ead189-705c-45b0-882b-470f02de0b81" ,
"url--56ead189-705c-45b0-882b-470f02de0b81" ,
"observed-data--56ead189-a5c4-4cf1-8f73-4c9702de0b81" ,
"url--56ead189-a5c4-4cf1-8f73-4c9702de0b81" ,
"observed-data--56ead189-8ddc-4de0-afea-4f6c02de0b81" ,
"url--56ead189-8ddc-4de0-afea-4f6c02de0b81" ,
"observed-data--56ead18a-c850-49d4-aef8-439e02de0b81" ,
"url--56ead18a-c850-49d4-aef8-439e02de0b81" ,
"observed-data--56ead18a-354c-4fbd-b912-4c1a02de0b81" ,
"url--56ead18a-354c-4fbd-b912-4c1a02de0b81" ,
"observed-data--56ead18b-62e4-4a0d-8e2e-465002de0b81" ,
"url--56ead18b-62e4-4a0d-8e2e-465002de0b81" ,
"observed-data--56ead18b-853c-495f-9780-4f3902de0b81" ,
"url--56ead18b-853c-495f-9780-4f3902de0b81" ,
"observed-data--56ead18b-40f0-4969-9c51-4e4402de0b81" ,
"url--56ead18b-40f0-4969-9c51-4e4402de0b81" ,
"observed-data--56ead18c-ba10-4d24-bdf3-4a1b02de0b81" ,
"url--56ead18c-ba10-4d24-bdf3-4a1b02de0b81" ,
"observed-data--56ead18c-b6f0-4d96-804a-421b02de0b81" ,
"url--56ead18c-b6f0-4d96-804a-421b02de0b81" ,
"observed-data--56ead18c-0f5c-4205-9e46-4b6902de0b81" ,
"url--56ead18c-0f5c-4205-9e46-4b6902de0b81" ,
"observed-data--56ead18d-2520-4f06-a728-4bdd02de0b81" ,
"url--56ead18d-2520-4f06-a728-4bdd02de0b81" ,
"observed-data--56ead18d-6c48-443f-8f8f-4d5402de0b81" ,
"url--56ead18d-6c48-443f-8f8f-4d5402de0b81" ,
"observed-data--56ead18d-9ae8-41d7-b6d0-43bf02de0b81" ,
"url--56ead18d-9ae8-41d7-b6d0-43bf02de0b81"
] ,
"labels" : [
"Threat-Report" ,
"misp:tool=\"MISP-STIX-Converter\"" ,
"circl:incident-classification=\"malware\""
] ,
"object_marking_refs" : [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23a-7cd0-476d-934b-4044950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:02.000Z" ,
"modified" : "2016-03-17T14:42:02.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://bartoszosamochodach.pl/r9ks1lc4n']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:02Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23b-14dc-45b6-a6b1-42db950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:03.000Z" ,
"modified" : "2016-03-17T14:42:03.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'bartoszosamochodach.pl']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:03Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23b-e2e8-4690-965c-4cb4950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:03.000Z" ,
"modified" : "2016-03-17T14:42:03.000Z" ,
"description" : "Download location" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '136.243.147.67']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:03Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23b-8e80-4a02-b69f-4b5b950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:03.000Z" ,
"modified" : "2016-03-17T14:42:03.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://blog.couponndeal.us/wp-content/plugins/hello123/89h8btyfde445.exe']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:03Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23b-1900-4947-a394-4c1a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:03.000Z" ,
"modified" : "2016-03-17T14:42:03.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'blog.couponndeal.us']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:03Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"hostname\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23c-9058-4173-a240-4d5a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:04.000Z" ,
"modified" : "2016-03-17T14:42:04.000Z" ,
"description" : "Download location" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '103.30.12.10']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:04Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23c-8c94-4ee8-8fab-47fa950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:04.000Z" ,
"modified" : "2016-03-17T14:42:04.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://blog.jackintheboxworldwide.com/old5gs']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:04Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23c-c808-4c30-80ab-41c6950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:04.000Z" ,
"modified" : "2016-03-17T14:42:04.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'blog.jackintheboxworldwide.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:04Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"hostname\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23d-67d4-4934-983b-473e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:05.000Z" ,
"modified" : "2016-03-17T14:42:05.000Z" ,
"description" : "Download location" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '198.154.254.194']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:05Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23d-9b54-47b3-b3db-4869950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:05.000Z" ,
"modified" : "2016-03-17T14:42:05.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://br4ndfor.com/5ud9sk']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:05Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23d-0908-4b02-b7f3-4e6c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:05.000Z" ,
"modified" : "2016-03-17T14:42:05.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'br4ndfor.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:05Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23d-0f88-4c60-8033-46dd950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:05.000Z" ,
"modified" : "2016-03-17T14:42:05.000Z" ,
"description" : "Download location" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '208.91.198.130']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:05Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23e-4514-4fe0-ad0c-4721950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:06.000Z" ,
"modified" : "2016-03-17T14:42:06.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://crossfat.pl/3ikd5r']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:06Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23e-db88-4caf-bc6e-4990950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:06.000Z" ,
"modified" : "2016-03-17T14:42:06.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'crossfat.pl']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:06Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23e-e064-47a3-9092-4a16950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:06.000Z" ,
"modified" : "2016-03-17T14:42:06.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://dogtrainclub.com/fik3n5as']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:06Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23f-4a48-440b-b3a4-4e85950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:07.000Z" ,
"modified" : "2016-03-17T14:42:07.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'dogtrainclub.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:07Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23f-d114-4346-a633-4652950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:07.000Z" ,
"modified" : "2016-03-17T14:42:07.000Z" ,
"description" : "Download location" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '173.236.74.28']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:07Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23f-7ee4-4c62-9b42-4048950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:07.000Z" ,
"modified" : "2016-03-17T14:42:07.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://heavenlybhutan.com/wp-content/plugins/hello123/89h8btyfde445.exe']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:07Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac23f-c1f8-4883-a3d3-429c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:07.000Z" ,
"modified" : "2016-03-17T14:42:07.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'heavenlybhutan.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:07Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac240-2fcc-49ab-83bb-4c3e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:08.000Z" ,
"modified" : "2016-03-17T14:42:08.000Z" ,
"description" : "Download location" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '67.222.134.12']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:08Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac240-39b0-4cd2-98aa-4879950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:08.000Z" ,
"modified" : "2016-03-17T14:42:08.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://immidia.tk/d4fj2sd']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:08Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac240-12c0-408f-a0ea-4eb7950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:08.000Z" ,
"modified" : "2016-03-17T14:42:08.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'immidia.tk']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:08Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac240-00e0-4c53-b7a4-47c1950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:08.000Z" ,
"modified" : "2016-03-17T14:42:08.000Z" ,
"description" : "Download location" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '192.185.189.62']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:08Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac241-8110-4e88-8757-480e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:09.000Z" ,
"modified" : "2016-03-17T14:42:09.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://jaksprawdzicsamochodprzedzakupem.pl/o1pc9vx']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:09Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac241-8b78-4488-8f5e-410f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:09.000Z" ,
"modified" : "2016-03-17T14:42:09.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'jaksprawdzicsamochodprzedzakupem.pl']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:09Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac241-dadc-40b1-adc9-4b7c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:09.000Z" ,
"modified" : "2016-03-17T14:42:09.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://mockup.asia/x5ief']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:09Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac242-27a0-482b-9819-4f2e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:10.000Z" ,
"modified" : "2016-03-17T14:42:10.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'mockup.asia']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:10Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac242-4b10-4ebe-a04b-4cef950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:10.000Z" ,
"modified" : "2016-03-17T14:42:10.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://myprimeminister.in/ne7ue8k']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:10Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac242-285c-4bb8-840b-4dbb950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:10.000Z" ,
"modified" : "2016-03-17T14:42:10.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'myprimeminister.in']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:10Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac243-0460-4ef4-86ed-4b6c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:11.000Z" ,
"modified" : "2016-03-17T14:42:11.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://polscyspecjalisci.pl/x8bn3d5vs']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:11Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac243-e110-4a66-93ba-4a03950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:11.000Z" ,
"modified" : "2016-03-17T14:42:11.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'polscyspecjalisci.pl']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:11Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac243-a244-4c25-b5d0-455d950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:11.000Z" ,
"modified" : "2016-03-17T14:42:11.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://projektantstyluzycia.pl/7a3kd4sf']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:11Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac244-8940-45e4-b222-4229950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:12.000Z" ,
"modified" : "2016-03-17T14:42:12.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'projektantstyluzycia.pl']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac244-f58c-4e9e-8222-4993950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:12.000Z" ,
"modified" : "2016-03-17T14:42:12.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://sharvaripriya.com/hd6as']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac244-df84-4be6-a71f-4811950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:12.000Z" ,
"modified" : "2016-03-17T14:42:12.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'sharvaripriya.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:12Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac245-ca84-44fe-85d5-4fb3950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:13.000Z" ,
"modified" : "2016-03-17T14:42:13.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://sprawdzonywarsztat.pl/l6jkx1']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:13Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac245-d9bc-409b-8545-409f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:13.000Z" ,
"modified" : "2016-03-17T14:42:13.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'sprawdzonywarsztat.pl']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:13Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac246-e374-4388-b84d-4551950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:13.000Z" ,
"modified" : "2016-03-17T14:42:13.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://studio-lipinska.pl/ji2pk4']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:13Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac246-c998-45c0-adab-48c5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:14.000Z" ,
"modified" : "2016-03-17T14:42:14.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'studio-lipinska.pl']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:14Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac246-3508-40b2-886f-4349950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:14.000Z" ,
"modified" : "2016-03-17T14:42:14.000Z" ,
"description" : "Download location" ,
"pattern" : "[url:value = 'http://wszystkocopotrzebne.pl/5h4fg8']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:14Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac247-0c94-4f1b-bd4b-481a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:42:15.000Z" ,
"modified" : "2016-03-17T14:42:15.000Z" ,
"description" : "Download location" ,
"pattern" : "[domain-name:value = 'wszystkocopotrzebne.pl']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:42:15Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"domain\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac293-b124-4554-9cbc-45f9950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:31.000Z" ,
"modified" : "2016-03-17T14:43:31.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAHB1cUgf+U2VcQcAAG8RAAAgABwANGM3NjFlMGI0MTA0ZjY0ZjZjZTA0NWY5ZjFjNDYyNWNVVAkAA5PC6laTwupWdXgLAAEEIQAAAAQhAAAAlXEPX35+sgEqnnSJVWmA1G2tqJi0A2bIa3Nc1ANDJGCykvB219riOQ1B0Sw3G/NrbzdDQg4jNoOAmUDCkPpOPF6+a/ENqM391WpeVLaQS+hAMczpTVoqRCzUa6bKTf9OEgREcRHauwTR8rO37X+xHGQo8m84mSueccIl2IbQha8gnicxZPmxGv8mypQYY/gdzWkesOiLUIuYpvb/dkFw6C4IoRT/++aWocGgiYC0Y/OKC5K0KMDKZ7++yG9SmlRoUZLXpaoy36XX0jyUMpxAmVQf0Cgol1hc1dQix8Al7ie0sBQ8E+LZdHA3yvdDNVAa0AI9dXJT/gPWL1FekTH+4N74zf7x71NTHMsiqPmwVCpk1pYyK0GTDOVVbAsSx6XD3QC+6JpSJpGWLXrVjLpGQE224mev7FU+aABW0lLf/JICsM7Jy45UwQZv2lscMVHlzWyWlmbFD9KJEqbbkzcHcu1rU8zmw0SGMC/O9ns+V2sV4vFBViFS1KhSnbrOxO1R4yGW7+caFuy1MBbYpySRY2UyZh4a1NLrYUhKNQLVLNeoO7h7+WoIq5fsZYe9p6Z/Zi6ZSamuShTUBzavx6vRt3g7Hb3UL3etHHVsllagIv6d/Zy0rthVuGCmmm1F0e4LQ7NFXeNzmVIzowczP7q1c2d0z9+xsFHYo35XgDIP65DQfZYmfFSD5xJDSPck1PUPZBm53+P+2NERXyPKHh2H2PBq9cN4QP+RAWIcSoi1SObwP0FBa7gRGMxdOirZyqKq5wMqeMWcH1cpfG9fXtBNN0HbYYUZ9eqr0OL0Sx1Xo5RZSZ/OUWrwtRYdRIDUY9uhnb4FbhHdYTMGe+VsQdm5sPA+HZQZcCdK1fBkmmR6Dpzpf8KY8RJksGUvTP+8f76w1H/3adEIcJ8iOOl88IbkV7BeDYphFMC0RbeCDbjVaVhw7cfUvDTvNApkUeVscV8oBFm6RAQ+Q3cy6dBsC3b96mT+oR8sT1t6+ICzddqTqD1lgiE4fnW4XXgXCgsZ9ikBAAyPwZdXYSbqWAhG3gqZq06dvbIFfs6IwRhpDjEwfmgplwDStKy4isKDh559NeWPL1/Yt49h8vBA0THbsYEAAkYy3kGmZYX2RCOn/6jfAlQxtcVSNnIPpPUKYMscNvSqGwVVyEBjnAjXnkxc2v1wgi/M6AfFfDeh5FKFVY+cDVO88AYCq1CrncAoDbRUJoJKvlya8Nlqi0EiOVQCyeh1Euw7ZyKoLHncwvppXMftc+iujJm0r48GDtOc4eNNPc/43Ucm/lDbqIpK5JsixZ0YxAavNjrlszTMI7PAf1WJ3Z7VeHg2cemDwE4LJyuiyRpEep6yUApALILbNzA39dDnKdK39je/ucTZ/pdWFdZSzgPYGuTwDspkU935DkDB2B2RBxnoH0YgGrp23y6ZC9AJpTARyunihafmaVUOv4miXt0tGj8+cySz4MbzuNRXV6XHzwkFrw0AlXZ0pkEhG6ZJgcRvLWA6F4vnk83deJiNMvlW7QfHH7GlWwPFTgFKsKjcnpOrUaljhALp6QmCJC3mSCSJeV8SDDWACeYMqtCh3sIj97eRJFB7PssEcT/m5/r/o7z1QfdMW9SYJbjvXb8lPZ9w7V8ptFfkqjAAqivjxxAQUZra9C9ZZ9/lxfN2zC+qV4PXvlH5+NbzGp7vPt2vVSlzegQguY20NjS7OLK6kv1bAPl7jfUIx8n2RTmqe/wYZm05HufArfB/o0RPzTSagNAgoU485QXLTLYez6bfZCT6JkxYx3va094+B7wrGj4ADMp5hM208kpUehATJfiHmv95coORsgiXSaPPYq5C8xao8KlcEE32l2fyXq2bBoYrCv/z8RArsQ6ZXDVmiiA8SSxLihRvQGZsgYGYouDF/M6iLEnz+ILPdiTv1RNYoRCuoenQTcZKVfVdKqxvX2/cN7ccvX8/LYjGByB7FWDhR4dD/fnT7ZfAEns+LUJF1R2WN1QElMFupXpc7wTd6+M1NvdhRZqpiVqy6++EN/5J3vcPrG84bGuZr+rA013mWLY2xMCEcpQjtyxk4VXPrtEG/mD691L6QT9T35gwkVyRD5Ug6cfnXkJ5f6CbcpcU22GDiGaTT6BI1Ju+v3NCJOyM2BRqBaRHvrN8nBeEEaGPJ16TvxR35T/mgbxYQ5ztERPTs9DStSCNOuSd2BlRPZIlmzlnrvEu+pl92rHYpyFt1PrGLkQb/4q33evLs32Zx1Gdrq32GdimEzS6yYwZRD2Wk2UeZ+vW2qonLMgx/i1LjqsgL8s4ZNH2hDBC5ThsEDIq6LUmM4QqtJA93PalgkPxqzaDsST/ifFii8jmrXq97hQUTfFox072AtZUEtYxcvcPPD/D4cHltCcxQV61sgHAsYYeLe5scLzDvfyyrtTLO2HybRB3zRIzXzNBINK29/a4MV2v4N9o7cbdpopaf7ivmkKsXdy+690jqfvbm+10zmv2uqooTzcvp/PvRSKpSPgnTuXdZyAfP8MkNxD5M5WKVAogbhy3KUyfQQXDTzKQXEF2UEsHCB/5TZVxBwAAbxEAAFBLAwQKAAkAAABwdXFIDPe1Fh8AAAATAAAALQAcADRjNzYxZTBiNDEwNGY2NGY2Y2UwNDVmOWYxYzQ2MjVjLmZpbGVuYW1lLnR4dFVUCQADk8LqVpPC6lZ1eAsAAQQhAAAABCEAAAB9wAOJu/6GqQVkuB/IgfLnK3Sj2HyaczvI9svBP0JZUEsHCAz3tRYfAAAAEwAAAFBLAQIeAxQACQAIAHB1cUgf+U2VcQcAAG8RAAAgABgAAAAAAAEAAACkgQAAAAA0Yzc2MWUwYjQxMDRmNjRmNmNlMDQ1ZjlmMWM0NjI1Y1VUBQADk8LqVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAHB1cUgM97UWHwAAABMAAAAtABgAAAAAAAEAAACkgdsHAAA0Yzc2MWUwYjQxMDRmNjRmNmNlMDQ1ZjlmMWM0NjI1Yy5maWxlbmFtZS50eHRVVAUAA5PC6lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAcQgAAAAA' AND file:name = 'billing_2ed35c7d.js' AND file:hashes.MD5 = '4c761e0b4104f64f6ce045f9f1c4625c' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:31Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac294-029c-45cf-bc16-4acd950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:32.000Z" ,
"modified" : "2016-03-17T14:43:32.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_2ed35c7d.js' AND file:hashes.SHA1 = '074c49198802e4e53d855fa98cab2cd62313d24e']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:32Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac295-c148-4f3d-ad50-40e5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:33.000Z" ,
"modified" : "2016-03-17T14:43:33.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_2ed35c7d.js' AND file:hashes.SHA256 = 'd3c49c72a345734c0ee2aa9ca1df121c793bdbefc0055168238436c0ff9db76d']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:33Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac296-46c8-46d8-b363-424f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:33.000Z" ,
"modified" : "2016-03-17T14:43:33.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAHF1cUg7E8JJfgcAAAMRAAAgABwAY2JjYjk2YjFjOTMyMmZhZmUwZjBmMTA4NmE4NGRiMTlVVAkAA5XC6laVwupWdXgLAAEEIQAAAAQhAAAAabiMXH3T7vZL29y/vbiW8jk8Ks/sqV7xqyuTlKMTjxukW7Od2PV7Xo+TJ+R/Qz7QMzGMjJScQD77ox0ucgKkLsGHCUxirQ7sLtBPaEH7eC31Cm8LupFruZ2Rpr3mTLga/AKs28XD23hJkfosUKCW4UHOqjliTJfCPELvQ2XwFNyupWTI6ecSeYMX5nPYSOoJbrTjWIyJjQYpJ66FaZPpIgeG4zwiiThIRIe+V+Kn7AB5pCXzWuD/DB1QyE3pLbp3OkidApw38sv+go/fLu96BvDPNrh8ztOngPumIZyxEGDvkEnoUGhmvkVIrYXxk8uGlVOStGvswJjuc5MojWPXPImikgobh1U0bbK2mw7eZ6nR+k84YdLeVntL5JzntR2L8Chm6tBKUrVF/DcAnv/OYy4st6H8emMeex4EN0GV4dDYnAng5BSlI+GPlXF4P9WvfmqGr5QCDoZi0ndh8WhmSfEMYrvuJeMbEF6+i2FyHifPlLlZScAzl9/IvNAx3ITa+TButFW5rpo0UzIQ9REilzjza5Q6K2Rvk5o3K/vs+FA+09dwFbcLmaAWA4dsIDo9T37+FxPnJIYvZX/HzLoCu2ytYJGqnk387wx4mDO89ZXWHLFTyoXevIMJDSB/aHWaL9ttyVohHLvQWIjwB254VYDE8pynWZanTLTuEbo389eGe/yHoqUNqDg2A2Djqz8z0vRre0UarijI8xo+23aIYb7qm8Lkb8UG+pXfeDnj3eUCqOWsm3bWGx7f0nHn35I5RBgsYoV7tcIh49UBfN8FqP2ARu+1KKh5R9B2IX/wmND0LVac/oHdJiA8vOR7LRR2Bh+JCr3qpOb3I5oOolJKzzctWRqFpRVtXeWWv6c67BUzGDfFcCfqsu2hgcDRJRVuw0P989zcrIQqQcn6r1KPzty9iGCsdlaUQCGZz3Rmeb/9JaWqrsHOJl7DJ15HaiUTqE4p2sWk9T6a5kmQdJtmTNk/ATiiLH5RqbsOeJXbHdNN01LTf1mG5Ak+HCTfINEvZBB0Dvrv5tTHr4bP6OBZkksBxKygWzQ+QpAm9IH0buXCcgSM6Y0BGSKHGpo0ar5s+OZtMWeVZzM3cU2oS2DwpjoL/OOJU6Jgj9VJdEiKLjLl/hS8ZrnTWR5rlib1iTDnKiGPpYdqteu/wW50HCXCFbtCTxM26rGkYzHZxksLvmr84AJRhhj2D+VT59Lz2BBUk/m/r5/udZGtoDyOOLGicOcfXqIHLtHz9hEEp5/RaR9P4ygAflFB+45H6newV7CDqnkVgvXBrUL7zaltvbG9UMVueLW2hdc2n43dUDAUYAIjN5WOMks9ZOCjvuGOrybwaQ5SzoRO/PNLkA1+IJvIPjGtqvgtD8u52YKIZdRJTofZCcqq9jvNqRT9SxGnKvqAWi7kh48nHam5eRB/9Jm0Dbs7KkdsVnMD6to8YeA3leRpZ2Fss0K2XgKrzSY47I1ACBf4aLotCEaWmdo4PPMUQrG7KAod91JcJk7uezxL+TELAcJk9fbIcfEX1u1jQjxCS714brNO2Fqc4YGpzXWibD6zavCKsKeaWnYedyCKoNocT0lhpZmaVOfTn5xyL2kN1KMOFMBjizxpVQbCdr4BdWeKbnO71XwYHAXkMQhn67pOvdK4qxfgc0Oj7W/QYU+U0s9To/ycZnYp540l5UruxmO5PVmGNHfnrq1MdeizP+o63XghTrHb7LpknkvVWwvrt1K47zw1/b+M+XvnJ9kNO6qmGAaM3uP4mLNgKYRNJoZIWwi6nDderS33JelB29yFrT6eKR+0ggJ/+kRBAE7s8Ytls+zCwYHbhWet+BUJa8vPN7inTEwuvGQo0/fyD9kyTZJzw35S3qb9a4iFshcFFnUCIHYQLCf0CZFxi7Le9gVLoqW7Q8hI9HoH04f7JmW5l0rb6dOXildZAjMi4FWvfVuOn5xzakj4C4LBodH3aZUDU72BC3hMN/Lnxj9yMDfzwpaZlYcXKltV28O8+5mAZCJjdQ7QUM5+fOvrXYnZ/JM/TAa/cg6NcChK7FjAkOdZwowBaavO6/vnBSR27EHosWmUq/6z4Tcq8sZMNTxALAIXHdjIm9Jo/fOp0eoELWKeIYBRtmfcULJjsxgfXefE6ad/zI577G9LripK2fPTRrJtwMWgJoUp7GzuGD5ADLG4ClJOa6p1CMPGMo98BgBx/MoKdSaFyNVfvNcrktNq8ho7fuufQLaGhFT43HAjC3C1xwEVi6NaXSzlfqwJ9V44taPu6cDwQkKVUWlX7qaX4JqsG8r8QguLMSbfSHLUmXkmBjmpvjAOA5v1hhSybUatN4RIFLnstLV4ewSTcuK6ysCL+wOJaxd+qdLZbX0bv7f2FP0pf4lgi9EPFn5t2pmAyQS78GG55+uVrQ0BUX+UCasQYQCzUJOOpjmJP5Y3uvaD4LKnz4Bu9u64w5eU0WA5NfYGvp431TyXSQXiyyyTaXg6SIIVdf79GZMCcY7RiJ0FAyZEMCCajlGYmiJVvaXuHsxuy+E23Bypl8/mqvmqRnCf8EPsPsC3DoV5Oiou3lBLBwg7E8JJfgcAAAMRAABQSwMECgAJAAAAcXVxSEDVbm0dAAAAEQAAAC0AHABjYmNiOTZiMWM5MzIyZmFmZTBmMGYxMDg2YTg0ZGIxOS5maWxlbmFtZS50eHRVVAkAA5XC6laVwupWdXgLAAEEIQAAAAQhAAAAeogg/jVAUMdm9P4BulpNhzn0N/MD/ZjJXpyxTo5QSwcIQNVubR0AAAARAAAAUEsBAh4DFAAJAAgAcXVxSDsTwkl+BwAAAxEAACAAGAAAAAAAAQAAAKSBAAAAAGNiY2I5NmIxYzkzMjJmYWZlMGYwZjEwODZhODRkYjE5VVQFAAOVwupWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAAcXVxSEDVbm0dAAAAEQAAAC0AGAAAAAAAAQAAAKSB6AcAAGNiY2I5NmIxYzkzMjJmYWZlMGYwZjEwODZhODRkYjE5LmZpbGVuYW1lLnR4dFVUBQADlcLqVnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAAB8CAAAAAA=' AND file:name = 'billing_04c689.js' AND file:hashes.MD5 = 'cbcb96b1c9322fafe0f0f1086a84db19' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:33Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac296-e140-4372-ae61-429e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:34.000Z" ,
"modified" : "2016-03-17T14:43:34.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_04c689.js' AND file:hashes.SHA1 = '2acfcbb0c51384f445cfedd3cbfae3579a683933']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:34Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac297-54ac-46c4-ad8c-42d5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:35.000Z" ,
"modified" : "2016-03-17T14:43:35.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_04c689.js' AND file:hashes.SHA256 = '38cd48d60526e77711d71245f8525a982803e97faf46b366a0c8e147a3d37a50']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:35Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac298-0f1c-4dc8-b1c5-4838950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:36.000Z" ,
"modified" : "2016-03-17T14:43:36.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAHJ1cUiT8Oho3gcAAIQSAAAgABwAMjdlMjNjNDk0ZjY3NTg3ODNmMzQzMTUxMTUzODNlY2VVVAkAA5jC6laYwupWdXgLAAEEIQAAAAQhAAAAmH2JDhSdcxz3nBvuA/+qgou8YREpVTsvYII0dVUOzCNRHGwerbfn4x2xZpieVWl7YJF8jHmGvkTmPeBcpTYlKMR4mqYtxSD786F3fYxOICr15a4iQ50RtvP2uXrOQSzV3so7ZZISwOvlvp7GidjteLJvk46g2d4NLFmilBhn8cwzT2PZyasnZ/qW9IutBelDWbPDcyiOnmi+vAkgw/94XSsLn3aRpeD2sbQwTRJUqFzN3raKwRiSimID/u7EL6YOAPpLuqVthVdXYdsRzchJLDmXFq56Pj1yelPCm/+Vlp3T3D7/NI9pPe/CRcySOCe8X7QwXuZLEWJGvv0XUhSZHtu75x36nZDlSdLXe/HCcEyUIyqqdI1ZLRL01Mq5Rs+/e5VDPXeIwLgTpWE1zh40WGPILy7ilVedAaYpgttOPKEh+KB6iW/01Zvn3HCHISuzXWrTPDIelpzo2oOyBKRXSDB3lhOJmNWp9/6ZuOnrt8I8H2ggmWrcDkTWBXcDnCux3H2rB74goszNQJNy6EEgdsco3YQh7Xad0lO66GkxMgsr8aBd14rP/8jlSoAQ/WwF1pDX80SB4lQSGTnPy3+5QIhkQCQfLf1uDSd336xrkh/SJOS3Lv4P6w1JR3Tns6964xgR+XOPqDjRkm8ujvZ9MI4//KlDJvsm65EcjaKf/KWQ4sKYwgjCc5jqsHbMMFCg9zlF2cwlIu2XHeqBsQuI11k/fpeJjxkm37R6aKeVRDGowA7Yv7lj87vCVxevnom1VHtIu3+kVOlCqPzG1/EsYCsFCiajLrePddQLAornkNEFiLY7ttQnLPKTcUcGQPcifKU8A9T9QArM5Yb9/D3bCZ3h8T4eRd7KRQOcryuD1JTPUzvhyXkK7Xzmx2SjPAEXA/ZWBc+53qvzIzTa0pLmfuKStR+1MHHNbevxMl5SSnQLiMjFVrjDE0zlTzdg7rrPpNd7np771jMObeTRZMJngE7j1Xc4B098JYpN1D+RLDdUPfPGwU7G5TpnVrr4oZD9kx5pqtJw2dgs73EW8Ln1ogS9zVYoUhet70+jVPDmBFgRoJE3+3Xr6wzfJCqqnMzmQoGyYnKrIwJKM4DrWc9LK38hQRD/nhQ5JNwVneW6uhJPrX5HUd4YK+tqCREALknJIBncJLFp3X4kOYfZXcbSPX8C2StvfrVFOaOC1KsQdDBg7qRbxlzW3lcxg1AUT3rAnD4QyVc9VgmtE7EupNBf3yauu2CmQWkunPA55lHrzH1EHNg+zjwAONRkfqaACirzMyLP00zKvgUqm790+zNxQtqoHcfEYHaKNuxO98Nv/hXKMedfEn4/Xp1cSsUVx/cLmREJnf014YVLPXzamFrlutc5JFg9BeEydf9gVDYugeahzjq15Tz4DVCXz4uBnHCBw0f92H41J73iSMbLBZ4TF2m2dpQso72GuxZfOUh7zy5cV0TeBmppFQDWyBBSy9dt7e7UlJmjw4KPYfwXCLWL/iiZZK2ao285vT68JA26nU9FCnBJqpNb6JIaHvJj0ks4kSr9xRlLSVQVZ36+dA1jb/xFEyvBiRdE0trOaTKyl6s6qXed8bYMPuMpHxV0rib6++9pKzeUVK/SPdj6Ih84Kk24HL/q99dHv1dlp9EQiQQ9UlSp7pqANz5ycsrRgb3AQHOWCvvWOXySsniC6G32zINQBOVLQA39QajG8hPqDa7Ci34RpzALpn2itNVACFJR48AKEGC/GWekuJ0oG3RmImXgWUd3/gH/Z7PCL3yg+WRh+kCIgWoFfnuNLm/wzqThTH7gj2SWSIOomqjYOnBCPhaw5zjoF19+jkRagtQa4B0rIuA025M+wOVRaT7ZNCkGBmMeCmOtHoz1WU064mkkoIzci8LelLQvPjNLGdrGwR+t/U5u/n1R0e8VdgyaaGZtFGFNjZcA4QITD8a61SqMk4guQsSvzXG0V0prGVTuM8D/Ttc4jtgdTY+T3mf3qcFrrIhmcSBJ861kgZkYHhGOsznyWR4wTXgXEhScZENundeuMWv/9CH8F3XbdztxUrT1rgZ1vRUMxD6EKP88cSwGYuXkc7s6es78waUK50mYWeWsz6fri3YCg+LXmXdfC4CbcueNAJ2vcGOw71y9bwsXO6pz82iW6JtT32wfwQv5iqECLgrePYFIClyzdl+lVrc81T/vu+enp5hJaaBeJd3csfGfRl1HGAl85A4fKPmgjGo7Ta8lJCXjT1/FSHWI5gFWBt7Ba9iT5G6UWYUm/TmY8ssHO27HNCTkqpFKsR7G+BaIBNdwxW+reTUPNp/Fw6En3Co6LxfmxTktZigAMon9W84ZDOZ/9O6i56ZG0PuoCzKALadDD7x5VG+AkC0W4NYuYwrpUsPavdapp6wslAvN5SVhvGq8PiGNj8TXzF8X9abPO7JAj+YmBUm3andSMnDZPYoeS2xXr6GcC/1CRAdZYQQ7wczG2T6HUtHMD7GeoYc9Y9iZf9xBKt9dwcg+e+hNEhRxBBdqcowaKkYdEcwwITD1hAqk0xfbavVAnVvA2tuJEry4serOzUymkE7kb3RBhqTxsYF2B+OthQASB5AoOafF0VeLeusewLfQfLo2KKNfOXMb08d3y1LTarMxeuivCc37nJDw1ILPanCdSI3VJNlAqGPbSJxlJG22HNqp3A4k3gEtd1FOUejiKhFEiVBLBwiT8Oho3gcAAIQSAABQSwMECgAJAAAAcnVxSDXVPH0dAAAAEQAAAC0AHAAyN2UyM2M0OTRmNjc1ODc4M2YzNDMxNTExNTM4M2VjZS5maWxlbmFtZS50eHRVVAkAA5jC6laYwupWdXgLAAEEIQAAAAQhAAAAfshcqFe5ux6ajubniWwO9f0ZskxMGDCpcnyxpjtQSwcINdU8fR0AAAARAAAAUEsBAh4DFAAJAAgAcnVxSJPw6GjeBwAAhBIAACAAGAAAAAAAAQAAAKSBAAAAADI3ZTIzYzQ5NGY2NzU4NzgzZjM0MzE1MTE1MzgzZWNlVVQFAAOYwupWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAAcnVxSDXVPH0dAAAAEQAAAC0AGAAAAAAAAQAAAKSBSAgAADI3ZTIzYzQ5NGY2NzU4NzgzZjM0MzE1MTE1MzgzZWNlLmZpbGVuYW1lLnR4dFVUBQADmMLqVnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAADcCAAAAAA=' AND file:name = 'billing_31a3af.js' AND file:hashes.MD5 = '27e23c494f6758783f34315115383ece' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:36Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac298-a4e0-4d6f-87ef-46de950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:36.000Z" ,
"modified" : "2016-03-17T14:43:36.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_31a3af.js' AND file:hashes.SHA1 = 'fa5d781cb7081431d4bb92b9b590ae5d1e3748d0']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:36Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac299-212c-4323-aa33-4241950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:37.000Z" ,
"modified" : "2016-03-17T14:43:37.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_31a3af.js' AND file:hashes.SHA256 = '7526ef2d7a7195ccb2f9b1ed9c4be69477643056679974d2f1a405920df2f830']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:37Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac29a-1fcc-423d-9e72-4a19950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:38.000Z" ,
"modified" : "2016-03-17T14:43:38.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAHN1cUhPgiKFPgcAAPsQAAAgABwAZTU4NWI3ZWQ0ODIwMWRiOTdiYjEwMmE2NmFiMjA0MDlVVAkAA5rC6laawupWdXgLAAEEIQAAAAQhAAAAmH2JDhSdcxz3nBq+JVU6AiedjYC7aTM6ckb75gd+9Gcm8h8qFfMYFDWJoARxSf+/mxxgPekuDfBWAdN7L4/o9Dcr4H2v5qjDX0DMWKZE0pueJRTxEXz0nF+69NjQzg8iXaY+/fPalW2KfLvRz6kOHISf7Qbl/d2JAjvqdAg9ebrVmib8ocP7iVUIR9qy8aQr1SjctmeYVn0qUdZxOx8vOituVQIdXEYtDdyFVseAIFgYIUJ4lv2TFDtuWFRSmq0Yvc+1QUNBr1npidlZ5tWx4w2uiMbZLuxm9fS6tw5fIKsQ1J8HFHZFjWzDUGkIQOiN+rRqE5zH18j81bAj++FIX6Z7nT/G8quzMcKAveFXG0L/Kb3kKjJ+ktu0+QgQUF/2KOxWuTnQwMdQ1odxo3ELZjz0V/Jre/Txb0Es09sg77zTSC1BVzsTgulIKsP8IfzDW//13W6u94GJ/JZgoI/aROQSmXrRSrHbPZyijVQJUUcMGlmHhQCUS2CWgKhxHpb7UV+e6AxtchSKlHTjTiuc+tnUjqNQrxTL8LzCGSFjlJV90/az/y3HW08aWKAd0J3lT4YVltkzk7HKlBwTKeBF8acPTmWkN7hfuCil2PQXxfAOHWIKLZqZTzsqv9ugktgc4kHT0dJta9TEuiOpemgyFDDpK2TJKy4+iW5E5nWS7634pY2o1b7u1LSsRP60AYodyCsUAn2phaAFgWtt6yAndLDGC8Jkes3ZGrUsDhLDLdNOlvcZ4auWdPsD5qsERJwOUPC7gxxjUOCsYAspEYvZcdw44vIHT+i4YwKNS7D4EneRzlxAJWKslf+UNL1sDePZZqpE7TvQ5HoL3fWfiOvCUy2L/6GsabHpmZ1GNm/qmFyyJO7VT+hjTit1ZK37jOFWQrg7rlD3XPWjKv4V7sT7m/Dd5iRKFWuV6yxjo8drIZvBAvFGZxb/u+vIrmXCEj/OgLRlrPQ5Z6C2f5t/iIWg1xrtSrntAbluYht8Cfb6+ecjPOId1N3EY6jxgJtig68FM2CjjsP/QrIB37LibEADAevpSsj9/S8FwphqxhYRNBUdm16kIfmHRjvk1JO7IYy7DarbA+KBBX2QH6a9HD7E/QLUHlXnkjek8Arkyd9CxNewX8ZlT2Swaibycw5ALgLe5ijOClwFRwSFslqzGBkpMIm6ko0yFQxcI+lrk99+NOfahsYdGEHu67E6ZLHI0sbjPFGGq8wDNxkJ1aMrEJNdy7VTUeedusP4tthJynUSPneW+l5KHIjKEZSKm36wVw2hSa4eUdvRFT4PIPQVKKUMivbk3Y2fUmdg7vAVXV+oxdMEZo/EYbdIGY+SVAttLxBo6zLfsg+/7fRhpm6lzo8SCd1dZmiD5JcJbGzDBWbZRO42uaEmAcgibbDIXQ0LJ2Em+63+32sVzeRbwlUIzmmz6J/nqrjkHcwIMNay+Svm03jgLyF7Z3MqbtTtpL+4lc82ZPgjxHYTDLcmLLG2Jvenqggdofr9yv5jPnxAPh4e5q/F+8WzwMnslTyTcvgmPOEO7feGESwtiN84bVEdHMMYk+zqXfhWtsEyu0SVOc5IbW0IMoHnts2ocKHsp3R3SB4PNaPujgoinJosFEjdJU0mYamUjHS8zNDTJ2NSVb9OKGs+9Q/xuqLcyD3rZ+3gu1vg2F6cjLiQFWQo77NJAjAQ/RSN5EHmMsvV42xywoapxLKT5G1iTMt2FIpFNrV1IBERhrotlNuoh6Xp9kWe2CE6B89ECNGPPJvM9jDD+yniioPYD+M8iQk/hy2darh1GNBdTMKyx3L8ckZNy3BljePMHvF8t7f8W7LOjmcuayl2UBPVZXlZo7XxKfYP+5xgeGK4sTSPoWE6gHfhsUlD6FpnilJ98Bgd00eQNXqfLW+y5KGmY9sbMKj+Y+g/DZfOB3tC/JE1xYLJHD3mQiujUJL2dmK6r5kXs1SL4mFE89AXFB9wxuBDrRUpfxSi70i+WAZdFSSpbT9ldTKU1yTZFGTV5u0+mY8b5NQ7X1UwV9fAEqGW8AcBL4eHNCvlXy2Ky1ZUDppj9rlxRh62dc24KVcKMQziJed9dS5tg7H0o/i71ghHLwMFfCgWdpof12JJDhts3TKt4ipiWKCt/fCqE0uldjAcDGdftyo2fuh+Acrb0+BhCY2vdrfnCxCmgV6j11ZG02sbe+SLMqD1q3o/yIq7Xj8y8l4Wpy7QsZ30kkh6xCN19Qb5hrhKVQCq3Ei3kNVrXd7skJe2mDooBC83eb9CLOXKUJl6CRZe6ofzQB9MIETd+WgEZftk61OoFIx4Nse4WK62o4g0IJfNr5+tJKdhpkGIDINss42pjx6TLiKxn3/oLsJgjQ09P/Gl/J88mM0CzcU95otn3nZzZWMP1DBTOXGDsji0xgCL1olCndME8x4RPqoHl1Bvp+8/cmYeNJlIQP681aLWrOiFWwnpoQDCCQLsNdxIErnHcOXSQviRUEsHCE+CIoU+BwAA+xAAAFBLAwQKAAkAAABzdXFIRHnbyB8AAAATAAAALQAcAGU1ODViN2VkNDgyMDFkYjk3YmIxMDJhNjZhYjIwNDA5LmZpbGVuYW1lLnR4dFVUCQADmsLqVprC6lZ1eAsAAQQhAAAABCEAAAB+yFyoV7m7HpqO5z4ot5uCmC0ZHPm4wxb09YYFveqWUEsHCER528gfAAAAEwAAAFBLAQIeAxQACQAIAHN1cUhPgiKFPgcAAPsQAAAgABgAAAAAAAEAAACkgQAAAABlNTg1YjdlZDQ4MjAxZGI5N2JiMTAyYTY2YWIyMDQwOVVUBQADmsLqVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAHN1cUhEedvIHwAAABMAAAAtABgAAAAAAAEAAACkgagHAABlNTg1YjdlZDQ4MjAxZGI5N2JiMTAyYTY2YWIyMDQwOS5maWxlbmFtZS50eHRVVAUAA5rC6lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAPggAAAAA' AND file:name = 'billing_53a7f4a9.js' AND file:hashes.MD5 = 'e585b7ed48201db97bb102a66ab20409' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:38Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac29a-5fe4-4e69-adf4-4287950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:38.000Z" ,
"modified" : "2016-03-17T14:43:38.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_53a7f4a9.js' AND file:hashes.SHA1 = 'ffeee81d9c75e36b4b7a3d2ee1b8462030d7dcd8']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:38Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac29b-f2ec-4b5f-9a51-4457950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:39.000Z" ,
"modified" : "2016-03-17T14:43:39.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_53a7f4a9.js' AND file:hashes.SHA256 = '53afefa1c4657a5503c6b81292f0fbad9dfe190f5c313004a351798374ed6369']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:39Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac29c-b000-420e-8968-4026950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:40.000Z" ,
"modified" : "2016-03-17T14:43:40.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAHR1cUhxa4Z+cQcAACoRAAAgABwANTE0YjQ2ODRkMjEyMmE3MDZjNDdjMGU0NmY4YzFiNjJVVAkAA5zC6lacwupWdXgLAAEEIQAAAAQhAAAAr5jobPbXU/eDEUpITan5MjFwp4Hrg6qxNdO/XUncj95Xx3f5G0D8pSyg2zZiAz8crfsgANsLgMp7TE5l7pC3y6JzIm0HkTrj2po9GOgCrW9KBoKnSlBlDI9CNWmioB5zYNBknamG9Mf5mAPg9eKI4g/FdVW+Ba7TuJIIcYNRsXGLv5Ixvs02qzMUsTZwTnG+WeRCImD6A+S3PIn6SqZeaP+ncKyehZ8g1IGZy5HPp7Q3Oz/3xOQ4+MUSUAunj69uvzyOZXFLoYCSKNanbRBEgk/I0GKRSvLbBVgvJ9nNEGL5poy4hBgE91PLQYBIsc5RwqDl1zBTcqoJ+n0l72aR0eoOiRcp5IrMWSmrHZX4j58bc6iXXySHuPY9XIuimQ9J3V9Q/rNH2p+vf62JE7aPkOGzlja/8c1icxpERs7hW6TRPm6PBC1vWP03yQSp6d8NYHfOo4kYiAnMIrpniibse2fejyIT652gBuEFSctpX1nX8OI7iaafJ3d1Nv/zgTzq6aB4aNGMwpz24kKP96J/+tB8PY8NI1vwsUVWASbK9wwjGnPrxltbpIe6BGSzIfgQT5KOi1gUEkF8QBvO0DoBQFTYWH/cZjKzl3/eNWxy6CLm417JUmLuj39MiqKm/LRoNxFrAmSm9Zi1wZV1TIX1gQb1DdEONTQ/QqmDTaFoptovPacK+WaSs/7LFNoourLAEoxRcNVXTgY6VRW+Zdi69m2f3GhwWT57w52Ve0MsCn0tRmOpWlJtNpJh71kkGccjMHS5SCP8ssm7v1x/K0bvOqxvdZvTOx8Dg/B0SLY3YykDXQazS6EIqSflnK+YeMSInD6jeQRCr82VDBe3FKLIH4EwP4YPTxqRucTFaC0N/oPeeugySzz4mc6RLZzWgMh8Htr3uGYcg+xP8/LjsHupG3dN7duDtnlWUB2mX3h+R4bCRKN4EhDZG8r1v0yoVwGtOxjs7VIi2etGsU2MeKr2Jz8RLA7ZwvKS9PcZ+IWmgV9gAB8B3h7r8fCUqTnWKe9jW1MV9+v/hknooyDGXsd11rbl4A/FXExThriPXVSnAgc9mIUQGLN47mfwSK1NPsRw+W75Vx/9orYZNPWpD3vj0qmQnBqkujh9b3LUVJa6x76yUHJIRanBPT7qjzZobZkANgyl9iwFolEJWtMSDvhTBoEP0GD4hZU7oJmDhXrwBHlECVk/mO6iA+jZUn865ksiHMiuPGcFsoWSvX9Z3UqfIL0raNA9G4HOLtOiqWMpbZcI+03HgUeosxeG5a8QXJ/wup/zciZg7z6Dan8nIRmMiJsMnq7O7lJUuWrIThrwSVwOHBR3O5ooisuKtewG0zR6fkWRQtfeTh+7LwRLXqeKiZ+Z3/kFTv/4gaMDopB/OiF/HZxMuBdHxWCiLaILSOJtFexalm9J5piSDTSL4qU9b2BzuG01NWESqpjJKQ++Xq25bw/EtepdfbkMTMiXGh8jd9gKl8MrmBktRQ1LjHsC5+rG4jwZO6AXSlBagp6PF/jKqYH0i935NhnOCD6wdLfMg2EhBbmXQu/0yj6+WoS396mI0nazOKJzLtji0ofd6ErDkCB2AsK4Y9pquyEd0Euji88UhMKTfg++eHxWJJo1uwZCiePUQlULMA6Z5sHm6IZZMzo613MpLLnB8FG3X3CW1EMce6b0ricvqgvoIaE+G9PpWHOt+PeONskTZkQUvWNrlpYhPirZROMSGDMtCiN1QiS3N9fp1Gamb494AgrtakPTPUtW0x5cDELtVTO/QcZQpB0pJy3+mExG5uDL9nNUTH7Qdxe9zvxUJq0h9b3RDJp8og5QO5/5QT9MN4k2i/W+vOZ3wGoAHdFYzC1IbeI2HWyFHRyA3hmFKFdr7fRVqdFS+55j1tRPYLyzKbHnWwpzuHLFQ3uE1BhJUUwyhv9mL5QTuBJmPuDwXEuPN+Ny0p8WaSacPz0WxE8jrTi10NfLYWd/plHVgTELNdAus+KXdND1NYQu/pRRyn7wzjPF2lqaBZPQmm50P542s3KvzjlG4UbmtGdY8yd/P6Xegz3o7Nv5xmW4E55VFsduu40Xt1g8YsnjPl4H8h8BfVb9Bg3IrBX/iw8S8kd1rAP/HP9PQWd5t1iISBd/Jyj2oNfcr3+zewS+3Oy6YmolLQvymsCJi96ckPSwkRlvaP83IX0Tzq8oVEuBWUHgWP8hT3sv9JY7dB9h0p2e3o55ykbGq/ENlnr2kA4aPXnUH/z+/X26jOUtE1eGXrlUWDNRSdaeHUx74uVQaQfM7noo1YK3INgDtuzkk1LMKxl4Wz9cO3vlKtVeUa5NGmIeh5ihR+9uooIxnP8LKAStpoFr0Cyn+wJWLnMZyfHHZCXM8jeT9BPZjOE1Ns4q55/NwTHrae+aR6l1Co0H558HTRaOITi5c5mF16SxRKm1RXu5IfXQh6txwuZuv8ydK7pAn44jC2a8MxTEw/RsoWy53OIUWy9cDRyjziNTtiKLdRplOTxVFbpTubF6Fk6u7GW/drPWBHcGzisvwUdtw3BeLm1tBHt1au3uUEsHCHFrhn5xBwAAKhEAAFBLAwQKAAkAAAB0dXFInmZ6Hx8AAAATAAAALQAcADUxNGI0Njg0ZDIxMjJhNzA2YzQ3YzBlNDZmOGMxYjYyLmZpbGVuYW1lLnR4dFVUCQADnMLqVpzC6lZ1eAsAAQQhAAAABCEAAAAAtJiqNfIkmTGKk7dsBVX2p9g7fvvG5CXYfTIGHy1+UEsHCJ5meh8fAAAAEwAAAFBLAQIeAxQACQAIAHR1cUhxa4Z+cQcAACoRAAAgABgAAAAAAAEAAACkgQAAAAA1MTRiNDY4NGQyMTIyYTcwNmM0N2MwZTQ2ZjhjMWI2MlVUBQADnMLqVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAHR1cUieZnofHwAAABMAAAAtABgAAAAAAAEAAACkgdsHAAA1MTRiNDY4NGQyMTIyYTcwNmM0N2MwZTQ2ZjhjMWI2Mi5maWxlbmFtZS50eHRVVAUAA5zC6lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAcQgAAAAA' AND file:name = 'billing_83e00c52.js' AND file:hashes.MD5 = '514b4684d2122a706c47c0e46f8c1b62' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:40Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac29d-f0d0-4ed7-aa0f-4c82950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:41.000Z" ,
"modified" : "2016-03-17T14:43:41.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_83e00c52.js' AND file:hashes.SHA1 = '8e302994e5a73ec2de6a9ea42de401853d73c000']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:41Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac29d-e0d0-49c5-a44d-452a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:41.000Z" ,
"modified" : "2016-03-17T14:43:41.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_83e00c52.js' AND file:hashes.SHA256 = '531f61b67638db502e413e75bf753574643907186a77ff8422d0cc511ea1f45b']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:41Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac29e-e5c0-4433-b226-4002950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:42.000Z" ,
"modified" : "2016-03-17T14:43:42.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAHV1cUg/xbNLTQgAAFgTAAAgABwAMTJjZjMzYWI4NDExN2NmMjM4MzA2MWY5ZmQ5ZGFkYThVVAkAA57C6laewupWdXgLAAEEIQAAAAQhAAAAr5jobPbXU/eDEUu0CJhKPg4W6LVgjrrTy3I/gHsoN35MOzrrRpLRW/fEDUK0Sx0BsYZYGyGP+kL1qkj7l7OyXWyyKGOPeHMMPfbGYIqsEwHU0PmODkZbS0hVrqdgSci+euBg3L0+TQcWM/Sv2vYQVRfoWrSWv4ZPZCpl+gvDCYqpaU4cVncF9rjvCuGspwGYWfS12WHKE+pMd+Mfgd4JLXz2gAG8wrZa6U4Udd1CS8DXbaGqP6KNLMejFdyp4MlknuDbnqpL7/C5q5TFzSiVdprytdQwTiVwap2YE5o09V205Hv0azRZ/NuULOHdv0g7pUlyr4K+1UUQU/0SleAsMiehVTH0naztW98II/27OkU80beXr05oOhpFALmuH45ToAyMLf6mqjA/ngmuC/2pSqUaR/wX3p/oDZ0FCw5eohB9vCO2qMuxHHgt/74hBqKHgvUKTq/pzaUdyxtWgWMqTRszcuVdRxFa0IEzG+X92PjuDbfxHnqE90kw3L+1e70pAg5FTowWYP1lPKvE0dmtQ2v84KddWfGkn7OeSF14RiJRxUvhrPJOjeLVIn04m1bq3or09Ti/GzEyIs7bVeMvyZpNC005OFPxaIWi2SLaSmMQYfqmLPswbcw04zK8fIFrNpseZTEsCr6vUtbB6ye2pThz5qDbc7spg0crSfzI/pThCBnKaEVGS6YVe7lMc7UUvaKOv3XaGwouf+ibXgelNdIvCYV3f/4B/AxsUrLrwZLG16ONEOVyPAi0QyvXcIs0XCiunLC8IgDzNymn+4H2i2zhCize5E13TJnyVWe8n2fElsyxysXx57OEADGWDBUTPZu+KRhGcWpkT/809SDNrOdCfzKjzcfKwZlEAfYilxBlpvb/OSXmFffUHjsqEDxBqP1pAfUDvojF3tDTBuNWAO31Ti1F413Q62IGl5yVvDizwmemxPQ+H91XfCLp/SbwigsRPZ9M11Tj3GShl+d50JruTec29AhvUaWY871kt4kCTYbstKqPM0kuyg/VYCtnVGPxs+fWI/bqE19zVLeQYf6iI1NwQcTaJB9FXgK0hl1oKdv0hClJklpR/D1jMa1be9uqAe+hN1vSNndvbtFA1h0IR9/WSe/6wtW5x0KUZgpPtOXFlgtYKgbb0klqx+EjLSxavDSQHoMwXP3IAAWjqWY8Hy6yHtPZx0/lpWBjRrs7VxYKc+Y+2A82Y3RePJ+wwMksZ6jNzZ/17UC2ELSyCTfOqLKzCYr6wmS2S62ubaPweIqnJynbuO7ZfYLQF+NGAW6QRQT5dIWe878mN7sUcNx+HTHMeJSani5AhFOEpPZOY/6KRDV3Lr/Fom/52kTpQN5LhMKhkHs5e+1/+uV2QLgW1LiOwH37OIO8I5tR8x7DDmrE9kgM2i/jY/TeB26z8PvCY2bmegj3qX0Dt9G9u0ypVgt+H9v28710nHP8GgEduKJ29sbE8xxQPtbkld2wzu3iWfd5EeL2qdMEIWLlkdQt05+vnLHuzthsxsoWH77xfFyh69lZU/01krIKuqtp+Ozx0hIwEgIERDfmZ9Vq1E36btZRm3gmpVrCd491TLERapKU/os98kuBW/+2YRPD/gcmSIaf8kI0of4zc1gE+jMtwVPs93rjJKrqhxhFP4l3sSMx6Wu9bc44FyU7GjwKq2RWmObww2cIfydXJbP346fM3OacfQNsmd89EyrTn2Js02aSNE5rTB5RN9dpvOMCAdmfgSRgzItxEQu/0kUS7gwtHQ1KLto1Izk0X1Z1NIMEO31iPcEOb8qw6Bkb5+6F0DNVxYlbbzfcuYP+7lUwzH0v7QiIP0wzTenwlRwYb3SGqaYgmZdREUbGdz+awnQThPMsFdTwdWbI1ABMRjdjYfgThJ/KvEQOV+9widOskkXzeHLp3yNQGe/2BkMc9VWALzTuE9tdbgc6LU9+wZfS/f/zy4O8pIWB9huTP+MB5tW9aidYHNMR7KSQCT6Q9M52TO6NL+Ojx3vhW9Xoe9Bx+XDv983Tggd+kVk5i2HqjPX4PRe1V0RvdkwkjajlSHL4seMog4Ccyc163zLARU8jojuO+L3/3oIonZ4bt8FlnEF2QsmTe5tTrLSt8/GTf6F8NqdfMVb0x+PNba7E6EGzOU4VZL6o5AVUaxLWnC4W2WDjKg72kFP0+GJVlxgICn4+rpDdnEJS41pazetH4c/aQhGOavKhlkWrhRy+DbCO5HxlkuA3ao2+koX+5acgJT4jopnMTPv2TbAYO3tTpEWJImuuoVwOjixhumyRmIBWr0yaMe54VJ5LujWrkjbaEVJWLYJGtLUtv2udECMvQLA7ivyzE2P/WD9EtdvVGuaFcjv3AQyErt6V+R0fu8a8zv5aKGEC685uwPiCfppUk/cguZzSUfziltPnwVtB/Sn9J7sv+oJSV2OJwlyMjf66GDutNFDc2AFQMT4IjIBn8AdrjfZmDH3sAZx8bqsDP6dPoASzipXmaDAgvIOCynGJwj4fscOEPO2EnbAcziQX5Tw8NX+TouMUZaaE+1AOqpeioTBY1/7R/RRPYuxiT2e70PmAnx8YXqn6KaUYMoUQdCvBGpNeLw8/HaJTplCF/RrZXoJ5E4Z9p6sSlzrxtBGWJKJzTMdNjFsfy+xFmJRNoOuPqmHRMZvxrzZexirJDf4vFh8UDRm4Z/p6lQPXje0EuUmn9YXlMzHN+Rws0mPSfxFEGaxJCHcBHAB4HuJInlIZSet3D+i2DJKxi4ym9iVvVJqyec0ePhNK+sthjOEiSezVNeLWXkQdG+Kxjs2vzkMreCcxUrchzM7wGKwSEkA6BLJnMx4BwOukPzq4whFtXFBLBwg/xbNLTQgAAFgTAABQSwMECgAJAAAAdXVxSCM4svofAAAAEwAAAC0AHAAxMmNmMzNhYjg0MTE3Y2YyMzgzMDYxZjlmZDlkYWRhOC5maWxlbmFtZS50eHRVVAkAA57C6laewupWdXgLAAEEIQAAAAQhAAAAALSYqjXyJJkxipKRy0fE0iZgtcN3ZwMGNNFwfGcIt1BLBwgjOLL6HwAAABMAAABQSwECHgMUAAkACAB1dXFIP8WzS00IAABYEwAAIAAYAAAAAAABAAAApIEAAAAAMTJjZjMzYWI4NDExN2NmMjM4MzA2MWY5ZmQ5ZGFkYThVVAUAA57C6lZ1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAAB1dXFIIziy+h8AAAATAAAALQAYAAAAAAABAAAApIG3CAAAMTJjZjMzYWI4NDExN2NmMjM4MzA2MWY5ZmQ5ZGFkYTguZmlsZW5hbWUudHh0VVQFAAOewupWdXgLAAEEIQAAAAQhAAAAUEsFBgAAAAACAAIA2QAAAE0JAAAAAA==' AND file:name = 'billing_764c8e3f.js' AND file:hashes.MD5 = '12cf33ab84117cf2383061f9fd9dada8' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:42Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac29f-0e14-4ccd-b6a9-41c6950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:43.000Z" ,
"modified" : "2016-03-17T14:43:43.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_764c8e3f.js' AND file:hashes.SHA1 = '427e134a881ba6c3c2dba228ae5a190570296604']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:43Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac29f-7d2c-4f1d-bfde-467a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:43.000Z" ,
"modified" : "2016-03-17T14:43:43.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_764c8e3f.js' AND file:hashes.SHA256 = '25cae9e623eb206a3ade327d437006987ae8ff2e371737fdb6c230daf2b0f8c3']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:43Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2a0-d1cc-432b-b643-4d1f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:44.000Z" ,
"modified" : "2016-03-17T14:43:44.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAHZ1cUiMS+SmGAgAAKISAAAgABwAYmQ2MDkwOTE4MjJiMzYzMjc4ZTI2ZmRjMTI5ODY3ZmZVVAkAA6DC6lagwupWdXgLAAEEIQAAAAQhAAAAmH2JDhSdcxz3nB85YocdeRdf4b2JUJnjxa50Qys2AgRWy90SKr7kl5D+HJCGUxchLXAO1R5NWcBN72QAlLQHL6Wj1qtez4DF0qnSxoz+fRccbbBocCSna4CKTJ3wAzVx+gAcj+nbZXJtpnnwIOXx4g6OyISK4H6RYsXZgXaP8R/nMcPlLJtTZE4gANbTpQDrfL9CPMzh/MuQibLkF8Psv5LU36jYVqQWvJBKmaEBjW71/t+mipSYV6VrykIzW6TMtTYHb742AyvBd2Ryfs8wpWG5n4654g7cBricWP9CqTEijay0PF2s1C8kXb0YhXZQTVIe4VJBN18/u0txvjC7IWpikK86Pc/KZ20Qf6rt10fWO5g1hBf1o/v2ZPpqmY4u0waG8qL5waAcOdAi1J3GaBTaZOF6xSRYeBf3nlSboHafni726iWbEqy4tUP3t7p/zyQ4qNn4oCUTKAIojCmjAZV+wM/IFYFxTRsEpuyrkqPMqcSCCRDMnSlcVoCKubVnEqRIjz5GCO+9cORMt2SO4FjYxuBcoVQ8pfc8rXGRVPd7Q0yEOM7o+bTG3+ecIqp5ZA6NrO9ba02ZT3SoSyABccEZMJ/A5lxOoltkTN+RaDn90yz3tssqs+ajGphVGqDCmF1p0P2a25CC1nftfTKNEonEkodA8N3UH8LLTDVBmFYRDGHl0nIqyTU+R/prG97nnBSdI5AZnJ1Jp1xB5cCNj0T/Spr9CXmYVofk9QdU/6bbYv07tOTDiJDl/zALjEhiBnt7htZaQsmETlbwWNQ2jxT6A0ylBDj2zZQfRqRihWhaq6WNyy7wNeaU16IDyCg9ivEYAonfgeN2WX4gvolF+egmP4FqGRcLTY+irrtHLI9WwEEg6TN/0Pd0pVnhX9o37mlopLw7uac0C1+3FS7rW/HMPaZNaVcWX/pN8IyKY5FiUU0g/ja2rv+TWK43oMlbNy7013/Hop2bCWJPjMohJLCsyo9/4Zrq/aukaNn2xhdy4hcjEA4F+MfRp9DOEtUxeTfS8a4+EsFXmEvyh/GTwImXh7iQHtVLRAwgpgepgMDsXQSzPHNXQW1Ylc6mTTReFFYH+35akUQzlVaEcXVEMfSUHzB1Njx9eUu86BDJ0d4LJ/0sL4WR0Om+hexT/506hW7OcCeO/X8xVWfaZAW0imFK1qRyneO+S0pofUfiEZzT53MO7jn4x9Ei4OARV01Xa3Pu6ATl9U8BRWX03eOpOpac+6CY4Q3mYUAH7sv7X9r/2VOKt/GnNWUQ2o99X6b5h+Jf2BdgZHQRUY1fkKOM0aCrGHF9S/qjYr1TwrWAq2+XqEYM/PPzELKc46hXFGMd7NG8m6wWgPn8905UJB4JD2s5bzCoOLy9kyeYVzrvlNxeSHLyR9LoS1wi9j79S7c90d9JqIQJHVIRM5TJq5c96pm4ZF0ONJTChRpRq1QvvqMq6nrlwh+ttc4ldhzPp4tUmxpveMIF9T1Tih35iYoPbe3zV8HcL6gNKF3B9tb03PV0QkqHanRiTFuaIPeA8cxVAtBQWbLZ4SdmRPRMO4b8cbHLoYzL7xY+jPJiAHrgUMdtLXz6hqX5MixW1v9dalZCJg4q4BXQQv6qxNVDxpmNwN6cbBsPaiHcFoG1OKhJUQ2R7hYJWUwLC4TC+wqRNGXXPNHBpaazhuei7hD8bZWQH8EBmJduPBs+c5tSHpf2Lhqv1SJOCyDsJpudOwlbIxEeebEZNCKJl9j4LSXqe6IDKtfWlGVJ60Q0Avt4jfVMt+BT/DYjFPKTIo1rCqumx46gE87intfZqcL1FmKf4cmTUzKg4NS6S+mJU6ZKsRAM60wxEdTkg2WxxiTmYhxXJ0rZIbRA0xvTC3XKx7/+JOk4P2pO8+qhbhJ1auJ7B4E2yDYPi4egWe8KgxSHwohSUkHEBT5+DPB8kfz7Ygv3jGnDAEb+An4OW2bW/KNqZQhQB7SoTw8pS7tijn+oQXvfk9asC5ddddsdfPHNa7tYdMGg269utorQwk9Ha9/YoD1dLgTyGMkjwwE5HhA8Cja5fMQFTUfMurk77toj2ABoPbiKZMPhlLEjUOqHOc5f+NxtfeO9f0zLNxlXn+WGvzcwaJd6JkHxHP96tqksreOswGHVTYICyMhK4M2T/C4nTfj7TZhPl6PZiGTiYyPPi12rS1jnbntH69gbIn/FhnkK1UmAX6rWw/LXOmYD1i7CWSKUgbY1H7oRLV0lk/rk2m6QKtkKzlXizcddVI3Vp5VpZr8YkphoY6L6bZHA2h6GNx3P4mvgXDgxGslczG2PsjX0nGBGzSXROwBoyQ2xhXrtHiMzVjBt1afvt0ks57n1ey2PWRqiMVi2nHNsBYz5QYtTiHUWuiqYyTvK3r20vdNatdYhaM9o80hZ3aPdNt9HgQb71lotktqO0EYi+0wEglCSs6jeUC1SZiqMSRRmjTQtJexp4WeOc2Mf1LTNDqdlVQX0CKfy1WVBcmN5VbwaOO4PGw7b7QVUTpq+FLWptPfU3ZpUPscFP9v8rP0rAZocpHU+89ApnaiOEUxLalNNzxrhy577nnFEBi0ZeoVzPT9hf2QKaXmO7ikj5vYckRTpFXKk/cwhp/EsPnHVKjGq8FTrSgasyuWKrq1iMG0OAz3jEEJ8lQDzfU0Hqg7al3YnS7/XIcP08nktpnTiW7gGLEvTuWVvkvh4ZFVAPvbFEPilGEdU8fRhqGbuhufTlE5NlkcvmzOBxmCCrQ9/7fyLAJaKfuqrcQFGDYQ4oR1QSwcIjEvkphgIAACiEgAAUEsDBAoACQAAAHZ1cUivMqGRHgAAABIAAAAtABwAYmQ2MDkwOTE4MjJiMzYzMjc4ZTI2ZmRjMTI5ODY3ZmYuZmlsZW5hbWUudHh0VVQJAAOgwupWoMLqVnV4CwABBCEAAAAEIQAAAH7IXKhXubsemo7iD+2rXXpnrfJfBsXQg9Pwi/HBg1BLBwivMqGRHgAAABIAAABQSwECHgMUAAkACAB2dXFIjEvkphgIAACiEgAAIAAYAAAAAAABAAAApIEAAAAAYmQ2MDkwOTE4MjJiMzYzMjc4ZTI2ZmRjMTI5ODY3ZmZVVAUAA6DC6lZ1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAAB2dXFIrzKhkR4AAAASAAAALQAYAAAAAAABAAAApIGCCAAAYmQ2MDkwOTE4MjJiMzYzMjc4ZTI2ZmRjMTI5ODY3ZmYuZmlsZW5hbWUudHh0VVQFAAOgwupWdXgLAAEEIQAAAAQhAAAAUEsFBgAAAAACAAIA2QAAABcJAAAAAA==' AND file:name = 'billing_5745db6.js' AND file:hashes.MD5 = 'bd609091822b363278e26fdc129867ff' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:44Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2a1-d650-44eb-b596-4a8e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:45.000Z" ,
"modified" : "2016-03-17T14:43:45.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_5745db6.js' AND file:hashes.SHA1 = '0c76cbe8b9a3d6944ace006a8033724a9cddfbae']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:45Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2a1-2258-42a0-9f37-4339950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:45.000Z" ,
"modified" : "2016-03-17T14:43:45.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_5745db6.js' AND file:hashes.SHA256 = '4750f1a883b004a783c8978182e0279df3f00ca52ac4770fef72dcf33aa52ba1']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:45Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2a2-e338-48f6-a82f-41f5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:46.000Z" ,
"modified" : "2016-03-17T14:43:46.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAHd1cUgDq05JrwcAABQSAAAgABwAZDA4ODRkYjAzM2UzMGQzZTk2YjE3OWM5ZjIxYjNmMThVVAkAA6LC6laiwupWdXgLAAEEIQAAAAQhAAAAmH2JDhSdcxz3nB6YxTVGaD9iyO9mo1in2MYYaU6B0kowLQxSolbGZPCLG8VtBf1JQGsjIhgJ+j8XZWRpfqvLNRY04g9jRt0vK0LKhEZZwjZi1FOYswVc/fz/1APxgNF57n3i3LsJNk+CwhkyLE7Y8Pt4P4VY23n0nTftOtWnuRzecDu4dcwg3RMwiRWlo5rZ1XW7rZ3qJCIBOU+qmo+FqUxtTxU9i3f8kcUBijVMXJeKqx1ja7cbeJeHUUakwUgn7tGmhEpB2ymLC6oQNhQNtii/tm1dpme3TeKNKKWFGjeNPrK6255HtC4deM+eV/Zp+2VHaHBTC63PqBGRIRaWer7s8YnGfbUiiTG2ZXfHloyCqPfVNoqovK8M2JONN59rguYjFE5fiztAE39y3rrkFLiMoBnQWu+rn1DyUYHOAVxjwa7i2C/QiyhNGM/YHYGxXYrkCnjq0v5L1rL9P8zOlHl2u5Q+Q8JoCleQid8WTPC48G0U6Zo9gtSysb/o4+MD22CpkLOE5/LqdatqN7vufH9hOjeQR4sdccHTjUiA2XRcF7n9K3JW27hBAaJ6OVZ6cTxeD47TBCTEvjukIi9mFYQAy+Gm3ToUqHGhYQgoajqzXLblMVZ2geUoU2GEYpi5qljsfDCHEj+QHtkduSECJVm+dCni5zyH392fire/qZ++ZX/hDcMB5x7Ir0Prb8hAAWM7c8L5+HFGGTslIwM6cOeOSLYDswFMhI2fjVNHQPOzVQrlbeY7ysoqDPMaJc3HW66Fd7QJvuU3dTH4yyPkZd6WY4F+NIrKhm82fhZWJurdWbyv8hftStyKHPkDGRKnpL3bf+oIpFvY7rJGbxVCY9E5oUTPoHcq7hgjn/6BGVPGHWAR2lN7UnnT6qB0l2rGvYfiEbEmmo0j1e4Ws9/3mRY6TK0CY3OFD3YYkPY8hG8p/EmWFi0xf5iHko6a9ZuuddEPbOXxWt4B16vqSXaB1ImkeU1f39Gj4l31I9vP7OBNhQUKt14RYGOTqq5Q80Ndd8E0BX9XGLnunQA7PqsjBz6kYiYMT1+hWlSPJ3fJXdeqKtnLJqSthbVYv0TL0Ht8UjAVLW0Q1OLaL2DURoTzOXgy758XKWyUeBDKfcmSfDKp+VAQquGoskiZrdGXcTngxiHcRKBdB+gN0D4vV83qJTCnrk0bj4vNXN469DErnx9Q9LNoB9wMfAsU8r6PaRz6RinEGYU4vhNtOfvyflwFEdYteBp8QDCPyQYFybOV2looVIC9vx2T080rvUW4dkSascBH/dPsfg0rqERoyXthxY1sReBqfKiqP5KulPA63wgVTU3Qg/6q6Swb2kIz2nOMOPRk1cdclG5nr84CHLrsui8GVspQI3CYgZISOMmVLh9W4Hha7enzdSr/S79nkdutOEWct7yaDTX0kAGLLA0+YvfgBsczT5AsX0DPCTCLsFLTmvXE2xhHwKsVWvtOMGVgFYOXqmscaBQgblS//Bnig7U//qlnBlj7CApPU3wekmuhu8/OK8LWg2zKcVZMKQjkwkxTsFnu/OSUttYDMi6/24llpsYgBNGLa7xhy2cC05MSsgOaFFRgIWphgacEtY5XMk1X4WqVxb6tytf3721DLEmiw304HTeVlYxMPezkTxHOHoA6uVXAJfR0hQeiEXWOmE0zyn+bVUoFb236yyWwOJ1v3U4BwVB8Mg7DZD5XGv1skW5XPcm3K+M7zELeR31ciJ98IHns9B4gu4MBFqHQ3KjNdfa30kQyubEbeGXZyXVUHfhzQi1rCiwk+uoOnkO33RCNyfzuW/hjIXabeOS/4qXSoQuyh8/+Q0Gp9uQN3qMluyjQjfCsOBP5aOJWnCwYQ5EcWsWp6yoTUL6oHkk79xK0n99qA1cVGM1AZqSlY58yG3HUUJwZnUgjWZ7S8RZ5q03BSSt0iT/5wQK6OEywmemT8GTrlSBnHal7lnBzPaAV4ejHDM6ym8kx48Hkh90VB4FfphuN7PqqrHb5J1yqp8h5KgjT5e0ByfXcqJ0zxZc0sPUV3hqH4mfGSa8fop23KnXqkJJniZGEylIAcu8Vn2SwX6KjElju/2iZqiBv7QNGgO/UTFV+Sf1UO/sI7jMJFQYS4TX4jFO0ZYOS2CADJtioppx0tmCic5L2yaax3cWR1qIDBtwxo+O2Tg2TCun/ZdVxC0q4ODwB7dU7oZt9z0Sa6D1WDzguFEIdfHisHHsPpzjP6C6a4BYBY0tQH/CxJkoITCBHVXkLZs/xwKe/j2HxkJ4JM9ySpmoqN4otLyor910rwry/z7MMoOC6qkljei9xF2DEsLwtdASLmavxg33pR5XdjZE4jAZ+IQL2aeywILfPpr/72inOOqFVq5G5cjwqBVxTHk/g2dglH18nmD7YRCfUjyw2OTWPYws4eGX1MHMFuIgk6m9TkjSA1PbACCsRJ0S0lNRa2y+A58Lirb5lhGK+LYvFGM2HIG8y2QUijUFk6nnF1chLq3KLp9WaXANxv1FIYVD3sN+i9VtEbHc0tk0RTWrCA6KzZz2DIsjsYfcaugyQcL7Mlc/+Xi29wohSCoSc7ZLA/HMsHYb7OyMZ5W3fwq/dmyp9z3UCwpzymLevAEEhPPOsgCt03nJQSwcIA6tOSa8HAAAUEgAAUEsDBAoACQAAAHd1cUjqEJpDHAAAABAAAAAtABwAZDA4ODRkYjAzM2UzMGQzZTk2YjE3OWM5ZjIxYjNmMTguZmlsZW5hbWUudHh0VVQJAAOiwupWosLqVnV4CwABBCEAAAAEIQAAAH7IXKhXubsemo7jsVW3SnBppAJRt0CIXFMts6dQSwcI6hCaQxwAAAAQAAAAUEsBAh4DFAAJAAgAd3VxSAOrTkmvBwAAFBIAACAAGAAAAAAAAQAAAKSBAAAAAGQwODg0ZGIwMzNlMzBkM2U5NmIxNzljOWYyMWIzZjE4VVQFAAOiwupWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAAd3VxSOoQmkMcAAAAEAAAAC0AGAAAAAAAAQAAAKSBGQgAAGQwODg0ZGIwMzNlMzBkM2U5NmIxNzljOWYyMWIzZjE4LmZpbGVuYW1lLnR4dFVUBQADosLqVnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAACsCAAAAAA=' AND file:name = 'billing_8971d.js' AND file:hashes.MD5 = 'd0884db033e30d3e96b179c9f21b3f18' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:46Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2a3-3cc4-40f3-bd58-46c2950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:47.000Z" ,
"modified" : "2016-03-17T14:43:47.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_8971d.js' AND file:hashes.SHA1 = '7a3199983bc86098460a134b02c7c90c974b9d94']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2a4-61d8-4299-af23-4e6d950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:48.000Z" ,
"modified" : "2016-03-17T14:43:48.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_8971d.js' AND file:hashes.SHA256 = 'ca00087654668db0a670ad2368e6ca000cbf29a65d2e93c4e22bb0f4a85ecbfc']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2a4-8698-445b-b528-4c36950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:48.000Z" ,
"modified" : "2016-03-17T14:43:48.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAHh1cUjIrULLZAcAAGsRAAAgABwAYTgyMjcwMDIyMzdkMzdmZjIwODU0ZDM2ZTM4Njg0ZTNVVAkAA6TC6lakwupWdXgLAAEEIQAAAAQhAAAAoYjkKS/MUOw04xt9b25ViiKHuHaN2Yl+/rOuU+QG8A/O7VKpnsEQA9FDj0pHFgEmZJxp7KKru84GKoX3rwMeE397QEYdcIB+P/sq+xFf/1kkqzWqOkq8Ypbn/d0QfydILP7GAjC4mULaVlUDXvxJVaEMVZ7EVj4ooliq6PgA5Xy6bdysyhbZpmjlTyJGbWJ0CcSRWu3wnYMHiLPMe4wSSRA/lEGiEmGr0CcF7Y3pfi3g6J4tjHWpZV0uOe7mYkM0Y7VAj9NOVmx2ciH+rOL7SUTxUfx1rzY4cc7luSnNaHcSpM03bAXhWORGe0SFV8Ug+hzQhM+bMwbDMQpI4y+PTH6nqDvJ8gIYEGLp64s9UVp6/lqh6z915WrKOawhCdX8CfjDE96wvHf2P77Pl1xSw2fbcXiVPcjGQTv5awVY2XPm8OaET5UCEzF2hvRL+MOJd/gswogD8k/s13WhspXZa7ADBTemcIXpz6Gq1exOoyM+sGXKyXeurlTJmK+WWwQ9LO52v0soxNnyxt9Pg9X6ot7UrJbRd2Nkjis8bKWZKo8P0vUwEYoqiSHQtk18uY9jJx/hRN6kwXh5kN4TgFInUpoSCPgJHDkJ8o0pv3TjZv0rFS5/Mhzz6TcGtqgEAAXSE7gA7k09G9/GOD9muJQw+lIqYonR0jABLCY/s1ex14rCcOW6s1c2pfYQ9523IVjt888arvY/1sOItbVQRsF8KzPmY5n+sQrQQSqSzR7N+fpOdf3KAZc1JFCrqp6DZD4Uc19F/R+F1a3y0RdrHWv8wokJdY1pSER5TMsVkqSCU4hBS/10la9+L4IpzkXnJNzI2sCQ++h6ULHufvJOrw48h079wZOKqMFhJ5JdGKNKk+oAVL7+pzcBbWb0nPEFL04PTHh759IExZKMUGmmjFfvHU2lJr83333AG+HEUN5IGn7h+MgDgxqXAnyebNjApzoAD7LlupUE9VAG6y7ecKReDR4FRg7cEzse4NHdEiB1R+0xuNRY4ixdi90dQM7V2IdxpNCelBc+q87CAY0ESiFDfLryiULO2xGz1fipmdRgcB3QMxWsc14h30RYwXD0wa7Hno/9Nq5ibTH23XOyZNI/Fy3RmR60yyCbeOV9zKeOVGvUSfNAo+/4B+XcoATtSYOoXFcLqhdrBXAOdiqYJIqO3/zMaOf6RKXE0YE4hk9ucwONa+7Kc5XTKQnmHv7blwtO5RC1nYQ4pAvip9SkkcdFCaViHl9STQv+ifDgJdmRPYbtGKi5MPhvZa7wh+P3UtLCYwn/6pRRNONsRFlxue1SPBSkzvaUBHmlKTbVx5o1ehj0z8mHYRyocHwxru7ukRxSZTE/5Up7NurfBlsQGIpNplb8kTCR2/VOio5LImouby7GmT5kp0eSVFh+YXYDyiwLGkebl1o1nKjdvDdVDkZThmeJcEN8a7Wq8IJmJI3oMVHdsMA1AQCqiiFvX/o1TsjO7KwXyB2qpQk4xTvjFZ8ojjBAQRIAkHHDxG6pGhZzB8YnVb0PGCeigOMaVeJ6hRsJuVjjSOaq9KBExbfxJhGBKeWWzTuyNBfcuj40QgFqWE1ZxYHztW5D37ou84HQwitfaFyLHeb0VcdiDbJ9tDnLMNj94g+n+WFbHFTEG0t22PjTJEri7daYSEmjwaPbQ9eTiQvs3BEZT31K8Z45wRy+hXSPlXbbqm1e46vpR1RPtqaJF18k3QVeu5cquRjMnwAnSleWE0qbTzv/3RvHLmV9pedNDuJ0K228LuAD43fKgu8p4qQJAOEywhyfMuIYP0S/kh2uC/2KjhQt+amyU3goHDRUdNG3raL70m7YX61Y13fa59PLKyfjiMP3rb1medwl1vKUZTBp3H1HjyP9tQ60Cql1f9tfapOUf2HnBgi5aJXz6hYovi2+mr1DkLm5iI97OpFjd1q0wKnWgeebVWIk3UH9J4mhF4KFCl7krOIgKUu3TuAvu3DDKl1Z3LdFAiE1NLYrjlnLIx920ClfK9SKca9l1nJDpMxBTGtkJe6pTEdUJLtclWqTOCNN+QTFXbKVRFbWZHpz+iuEBxdZH/DcgxBcK8YUg5zvJHU2HALZ3UK+7AcT3w5GE7yzaz16s+AB8+ulUJShDsbpKGo3tHeYS1mXn4cL5rBzHzT16AyIrW3/z76epeM9bt5/RlLZ6Lt3VmhcUfAdP0fVXGQ5lT7rfWmzs58KOlVEkJB2o6ovJ/jyxkfhdExYH7q1v5++p4LmAeYy8RQgArOIUV2I3kskmgFYiyYRPHjp5SB9Kswo2G4DQwMn8EeqQvkVhhyRVUFxFUP7epcgvAFLCP/zRpeP+05MxirMu1hXtmzPjQXQgiFLa7XPuh5l1GPuYVTmz9cyzAo3srKGjOVIDVgif3CQZ+hIAalJo68ciiANfmmNy7BCr8dz/L0B8pn4PF7BqRfBwaa1a59m+qRsOg/GQheMrWK3mfXsudU8a9exN8gRdxbxWiEp8jKzRLTRm4AZAOH50AvSde6pFKWf5uzWPc/Gbce9mx1QSwcIyK1Cy2QHAABrEQAAUEsDBAoACQAAAHh1cUggi9yKHgAAABIAAAAtABwAYTgyMjcwMDIyMzdkMzdmZjIwODU0ZDM2ZTM4Njg0ZTMuZmlsZW5hbWUudHh0VVQJAAOkwupWpMLqVnV4CwABBCEAAAAEIQAAAL/+r5WtLRhutLUyvV+sEsPuYj+LgrgzIHUQ7fO7iFBLBwggi9yKHgAAABIAAABQSwECHgMUAAkACAB4dXFIyK1Cy2QHAABrEQAAIAAYAAAAAAABAAAApIEAAAAAYTgyMjcwMDIyMzdkMzdmZjIwODU0ZDM2ZTM4Njg0ZTNVVAUAA6TC6lZ1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAAB4dXFIIIvcih4AAAASAAAALQAYAAAAAAABAAAApIHOBwAAYTgyMjcwMDIyMzdkMzdmZjIwODU0ZDM2ZTM4Njg0ZTMuZmlsZW5hbWUudHh0VVQFAAOkwupWdXgLAAEEIQAAAAQhAAAAUEsFBgAAAAACAAIA2QAAAGMIAAAAAA==' AND file:name = 'billing_71281c4.js' AND file:hashes.MD5 = 'a8227002237d37ff20854d36e38684e3' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2a5-5068-4743-a642-4dbd950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:49.000Z" ,
"modified" : "2016-03-17T14:43:49.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_71281c4.js' AND file:hashes.SHA1 = 'c41d7bc429fdcf64952ae7901c02f472dc7b9ea0']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:49Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2a6-99d8-4015-b2c5-4ed7950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:50.000Z" ,
"modified" : "2016-03-17T14:43:50.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_71281c4.js' AND file:hashes.SHA256 = 'abd2ecce75354954bfdbc859c571dfc04bc7fdad6a6d13306e3a08e48b55fc24']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:50Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2a6-8120-4542-804f-4d17950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:50.000Z" ,
"modified" : "2016-03-17T14:43:50.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAHl1cUjaIXIh3QcAAGUSAAAgABwAMmMxNmUxYmU0MTg2YTVkMTVhZTNkNDk1YjViZThlMjVVVAkAA6bC6lamwupWdXgLAAEEIQAAAAQhAAAAoYjkKS/MUOw04xqXy5GkKdETWxVAA7i6SduwJZ+A0gzhET9J6aaW09fLdFdpkWmi5myGGAquCGiNXzwI9E5wZystgvfasri6QH8jxn8UTLM3ygkv2os+KWQOyn++AX/b0DiOswIGwjaDbk+tss6V/cxMkrbY+zZXWhNeD+0xoUPW6TzZPePPTwIE0IM+jIJfKQbI8Uto4c5lJ87Z6aEsGAZkKtSz1+TIpzSK3LtGi1Scfe2vZovhM9NW6nNnQiaIU6yDwhFASjOfPneEITVmmqPLQpC/cazVoUHFQQHKroC5nmZq74PYAW4nzGT3d1VjGDqMx/usmTn64VGeqSOGf2kGTv4XvT7ZvEygTn1pEcnz398ts954wgA1R1b1lbod4Jo8qXiu8y29w62kKIXXN5QlDYCvXJBMDOHgusac2J84UZLCAsG7EaOmzh7/SeHRaweIJJbRi9vIBnVnhAx+K+YzSPnmw3eoTYFiH2qAUTEl5iExo5cMi5MNJgAoWQ4lWA+uMd9fD1TMkDgeQ8NJD3TWhzXKZCmmwdELvcah5JL3T+n0gsNhnCcTdsMqwijqQ/+l9gyCAidq4LvBJFocSjwKYpslcTMi4d/Mnd+oMQqsCX7yxl0n+fvSn5LdEJatxqZsyVMaikSNFsR36ssUetaP/cEFecceb0I04UOuwgR4z0pvDgGeu49AROBpn3xvEOJd8EoPKfMT4HRItVRPZl12i8Fhx1zSsxLW5OjWiycwvH0kX/VeI24a+7y/T10QkVDzfPamI4W93G9j42s1br0lRo5jYsnPUtPg8hupM1HgfpOgqVR6ufFjxV4nnoeChLkLDaL2D/CBSvPOFp5scsCXe6PfNVQ0g5F6RRJ083iXkXlhWKDLZjzY1TAUJ1v2v42uqTsMlLpL3svMn26HewcQ2g+Gb9emAOhKaiRuDxoeBZDRgk4hnkS5qev8D84t+2iMFOGFLyjTjMP/zgTygCUym2q27BIwJBaGI05KqRBfKlNbyzKmLg9jjlfGnKDX5rKsS8fM4OaYYBp6XCAhCB/h290SL0bAOe8V5tI2is1Co5R3FyQkQdzULtdgTvaw0SkvjKDTxs2or+NgT3VuguyA62Bei0N0yy4EXX7ij9T8nhemjH1dKSq9ioQfwInmDKNgDzmPv3ub29AFgp/hx7EyfKFcGW8j8IRJjzZ1q8LVHuS5bsYHlb3dM1CCpK58tsDr98UVosyPxzmRdW2/aOjI7Q8TUzCBqIrNCT1OBcZ+hleiGsMvDmOACWSPeyW+TKJ6CUMCo7j1uMKT6qtP67wm+AXLg8e3JEsVphXOkhs9hgPIurkQZM7TQcSsPvSBPZ+EKGCSgJJmoWaU+FQZlDRAeR2dS1vz+AIPtYyMWz/vvQS3v73E9hSOevjXXcNW5OxHSvJ2lfSxHlPs7GH9fg5DpvImGWQX2zDa0h3cjefrXpYwiF4YZxfoohizbOllrRpP/o2nlg+b6u3f45oOi3hcmGcu4lN2HleWT3Ru6f1wCp9kwT5qdjVB4zk2mxhC2FMwc/MjvbpK9GRjXg2Fwb5CohJs5JCAaJ7L4CIOSvIB6HbzE/GpdEAf2scLUztZF5JYRy+3VKlGnsRKxg0qHVpFPF/Rk7z6DAyMrTbzED+F14ic387IMEzCeNsG1pjLz4uETWIxCD9+G+dsmhHi4huDGY3zmWeZQS3M+3CyCk1OrPEnpVmFYAiQ9/47xtnuz4Ch7+PNdyo4Mojc+9aoQ5sd1XSMqrb38Dk8NpG3R5GgnEDGty5PzriJfsCTmlU27OHUg7VYDZT0WIYXDS3weRSrBwoHW4P7syUdDp+XYGzsQCHaQeqhEOR+WRgU67eB1dyh2G3SDITa/tmBJRbwnkY8R43XDDETz4MI0orTpIJNKyHUdtkykpz9j9CAKGonc5WBidbcs0UjHkMBHEBvqXFh7wnhnW7weBVblKjZpYPEWTIywa/xWjdlQPOglB5FzyJXzqh5JmnrLh8nKLWqJNHCqR7JFXxaghmtma4yDzKf6qjPgv+ugrBZy6VYhhMax9MeOYlgz8mBUUDwKIRs5Y1DtVRUDXSkzo0JQRKhy5WGaPxiuDqnu5j5+MtmQXrCDXCBOPRn8wPVdwRmQ28SaF4kKza0a+Ast0sY0BxWLx1nvPHZqyIhZI1wB52R21T9AuIzw0lzLo9daMibeIfGuwr00cd4nXBlT0hwOXJy8p3IoxSaz0vknKW8202ReugAU2/a3Klu8tD+sndP6A8q2KFzKAqYtwliufx6VCuNv2kP76QszKXgXj6n98QDtk/4R3zh/4fGrHpKxuP4H1+ZBYg7p1aGHHnet35OC0JbF6kpciKe9uSSCyYb7nOpwZnOYhihu5fkmmFPpnNaIHEFy+4CLIFyHu9LiTG10mfrRAWeBdxczbR3EByFZQSvPP7/jGwp5u/v5YQdohdcJkLc3HIqPAwlfGHRJ9DyCDcTx2XvMUBWo5j6+xwXUhbcQbEArtjzCEgQUvcMcj6qVuRzvz4NJ+wPytWp4jTwr6H4H7I1DN/vOFIWOyC7Bbs7m8OzYrIMXnh/C06qmkTCrwHfVsXCI5yEuBhHDVcr+AgfSsvMQz3qFmEQY3js3jVVNzdJO6C2prIscVAOijzTJhPZk0/7CA2srNOvzXMP5jPGinbYbpSXkiPCw80vJGkVUEsHCNohciHdBwAAZRIAAFBLAwQKAAkAAAB5dXFI8Dw5eh8AAAATAAAALQAcADJjMTZlMWJlNDE4NmE1ZDE1YWUzZDQ5NWI1YmU4ZTI1LmZpbGVuYW1lLnR4dFVUCQADpsLqVqbC6lZ1eAsAAQQhAAAABCEAAAC//q+VrS0YbrS1M92YsUGh9eFMyWIRo3Hn7fr8IaaJUEsHCPA8OXofAAAAEwAAAFBLAQIeAxQACQAIAHl1cUjaIXIh3QcAAGUSAAAgABgAAAAAAAEAAACkgQAAAAAyYzE2ZTFiZTQxODZhNWQxNWFlM2Q0OTViNWJlOGUyNVVUBQADpsLqVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAHl1cUjwPDl6HwAAABMAAAAtABgAAAAAAAEAAACkgUcIAAAyYzE2ZTFiZTQxODZhNWQxNWFlM2Q0OTViNWJlOGUyNS5maWxlbmFtZS50eHRVVAUAA6bC6lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAA3QgAAAAA' AND file:name = 'billing_6736343e.js' AND file:hashes.MD5 = '2c16e1be4186a5d15ae3d495b5be8e25' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:50Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2a7-6bb8-4cc1-9591-4685950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:51.000Z" ,
"modified" : "2016-03-17T14:43:51.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_6736343e.js' AND file:hashes.SHA1 = '829b37ce01de23bf24e736364977ca7bceba157b']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:51Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2a8-3d88-47ac-abb2-47c6950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:52.000Z" ,
"modified" : "2016-03-17T14:43:52.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_6736343e.js' AND file:hashes.SHA256 = '7cf1c14e28cb186ac8f87968d68c765db84b50633490cba38d4e718e6996f453']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:52Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2a8-04b8-4ebb-96ff-4156950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:52.000Z" ,
"modified" : "2016-03-17T14:43:52.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAHp1cUgUJWHv1QcAABESAAAgABwAMWI3ODkzYTAyMTU3Y2EyNDlmYWRhYTdjZjI1MzJiNjNVVAkAA6jC6laowupWdXgLAAEEIQAAAAQhAAAAmH2JDhSdcxz3nBOP440hCseh3uFTXZroN1RUpz5ZY+jd9CqLhyx8c6lR2joFwg0U17qutKm3wjZcUku47A0v78ENDtsnjgnXF2+9UIbYO9iVrz7HmnZSLtJID2QJNWNGK3Dcll3eWQkwnyHLvVQegK/Hc4TfwM/f+Pe5VleeFXYiL62+9nPmLo9M3iZuGEdgeAreSqU+WUIBoY46lj5BkftuTK6RyPFfs9ABHxpt6a/FfZJAZ5gHRLSaumZVTGeiDi1gsLmUguC7QSKd9RCFdZVEA+7EFs1vmCgyOZw7eSl9Nmy6przZFyVesegAMjykjBU4Z4j8kF/vhPR5ZHBqnjziVjBTdgS+QyCKjp3NmZPKBxdmSfzg2/r+eKdZZpip50V/wtdymYo8NpK+DmGcYwRMe2uhNAlK/eNb4OY0+7vK1Nd4Ln4NgaHJkVZN5xMhIzaCA6+sixyA3/oZgN7xkm5CaSG89BgPFIitTkBxHJf2WQROSvL9phYaa6t3Oqc0D82FaCwlwZ3ByHf23d0WRwHxEYnW45fjmJWEhxbBeZfCxZVilFDNsQBzeIO2amwSh8nZJV+pekvE2OZcL4/qfCEDW60+19r2UwMUXtqKp76kDByQYI/1a1bvmZPvsaFbElOBT8XCdvWC4UtCiXEir8UgYKc+wRHyTN1AlC9zdcu4dQqRa2vBQxOn203CJXLFJO1w0F7BlwqdbZHyL9YiAbLl8KtzFVlx+vTTLFItcfT6CfS19Oil80fAtsoW0GK0HyMsxi6edC3GaFyY1wCkV4WkTkDgmmWDGhv06d7pxosKA+DgLgbPSW/1LFv2y+Nskgnde8R7UYX7G/WQGrNhP7IY8cx8qVAP4oyN6RHmd8mArN24Vcp2vVxaWv45wmOb5GNLOP1kbYMaQebC3nStwFFCz5A7e6uh3GiWu6hylrccSqEEfECeyLLYyBqOdr1pw0U3w0dgEZ74S4UTz8kk1Y05UhqwVvRb7yOk4ycY91n4juMPpnQKiGz10klTX3FAG22hpyBE6JHywUaSE9Ti5FneGqD8L13AlyhJUoNRnynbFnV5okB1VgurOLMfnHZtK76QUuwrh4+M9v8FTsQKbbje+/6cNXOLSpp2ZDUE0fjk+59OlMqjf6gFlZM0PjnvYiZcvz1Ed1+iZ1SwYi22hg7kh9B08b0cYJz5x4wLOkTV1JV64Mt8uAmcWuxiUt6hcw0gsKtDcD8oA6AjY9+LuRN7+LMrnN5UZqS/UnPBrwYqMLmKZuriDw6TS+Ba/NjSuwAUi+dShI5hvTDsrpn+uWs7OHenM2mcc2uOnbLXho+7Bm0MBZ0kN5l6v5mbXYdVXUoh1DsCf7lmTDiU+GkRgIit4KYK4YiLvvMbgKkkbNmqUGziils0DNy6u8Ep2EXTfCFZ9uJsa2rvgTTpz933TNnB1zAeup/haX7/RYVizxiphxis2UE57ff0DK5OZBZu49s61pvOjkQQSq+eWmLU2bjBdWxYi7JculeQTVDnavJeiu9bjVQQXeF62bS3JWIxacMa4VNi1fXHuJ4H7JQ1V6zzoW6t55mPzJftCDOQA2hm7m9WHHNGKVICKTLRIXjsjo88HTi2plZDw9i6kriEJRIyEK/QSvg2EWHhUpmrOxa20X8usnyTZnGUKqcLwCe4DG/ievb+AQFh/7Gt/rdPbfMNEQ6woEn6HEhDtG3IOcd6WPwjMpdqF7T8fIKJlAqnO6eQ+sdJQEE7mLRoot7PUtFZIJ/OdivO0as+3QcVLom2UXpoFa+WtqEPEOg+7Byz5+4pnWcnqmL3jh2Nm0GmSF97zBPkIwHtZw6qB11rjzZs42RvDoIfUhYdGktAlC7CNrg1Jdst4Tt3UnUTiSgxsMTTYRchx7jwRzyxWDxAl5wnzf4eGFyIZAAbYYmYJ2Pb9cRWVwzcSFL1Qvbskby3ccunPUSYThO2PBLW18vC1TDqgxY7JnnrTxlmEXFDxLeUoeB/xVQ+CrcwDrfgvD7A9GeJITX/XEpA+uiALd6fXCvO8XWlF5BzaAVrAWRzeY6E3GEW//xFyCZHcA6MVHcQvzp2Iu/+9oWcflgT5GrA1CrZOPvW2NXYQzWbwpwPYP8eLYltkcB4Cnrfxb9taMsMA1ch7tYiDWMteCllmkukoKTl2EQQdEAanXDJzYkdk1Vv/BeKZY+dcl+UUzK6BCGfBVv+xLumrPiESXZcAVLoy6u15Yk6iRyqGZtvxpZSCKmlx+h6e/Sa1NiVJa29KRvu0D/TIQdXw80QBD94RjNH06WjPWefUR5sAfI64Q0XZQfAaSFGXQ1OzWrYdxWUwq2aqWe3CnuObuDz9x8jJYUpQQx3mCU7S1aWjFJBy1D/b7vFXKG0a6MczgaBdOwa9TfYHKbA8bXUSB+rRbOVYZc5oAI3WSiWfrfTJGAxty3aILw201j87H/uO0zimI+kIHFAA+ckjam1GajW161O6Op0P/4CHtqlQlTRs4zRGPPdmld/NMoOJPE7nSY/ChVMstDay3hKtLSFPk0qnNzbSHiTZAO983Sl1UP028TQ6jcUmFLLMNxPw/+HJI55xJwYDYc9o8qOk30js8zzM73n/sFLeU7L5a5CruStDHGD8RIrTpSaS9WpZlT3jybDAWseJnqYJBLpORnoExdPbMYPwR8olXXh/vD6vlBLBwgUJWHv1QcAABESAABQSwMECgAJAAAAenVxSCOUC/UdAAAAEQAAAC0AHAAxYjc4OTNhMDIxNTdjYTI0OWZhZGFhN2NmMjUzMmI2My5maWxlbmFtZS50eHRVVAkAA6jC6laowupWdXgLAAEEIQAAAAQhAAAAfshcqFe5ux6aju5DbTJaLSBDfwKFzlOzSC7oCetQSwcII5QL9R0AAAARAAAAUEsBAh4DFAAJAAgAenVxSBQlYe/VBwAAERIAACAAGAAAAAAAAQAAAKSBAAAAADFiNzg5M2EwMjE1N2NhMjQ5ZmFkYWE3Y2YyNTMyYjYzVVQFAAOowupWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAAenVxSCOUC/UdAAAAEQAAAC0AGAAAAAAAAQAAAKSBPwgAADFiNzg5M2EwMjE1N2NhMjQ5ZmFkYWE3Y2YyNTMyYjYzLmZpbGVuYW1lLnR4dFVUBQADqMLqVnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAADTCAAAAAA=' AND file:name = 'billing_a769be.js' AND file:hashes.MD5 = '1b7893a02157ca249fadaa7cf2532b63' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:52Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2a9-5420-4193-adf9-4a60950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:53.000Z" ,
"modified" : "2016-03-17T14:43:53.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_a769be.js' AND file:hashes.SHA1 = '5dc0b9abe2a44b647f3493de8c4acb018082359d']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:53Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2aa-7220-46f1-99af-4444950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:54.000Z" ,
"modified" : "2016-03-17T14:43:54.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_a769be.js' AND file:hashes.SHA256 = 'b43dc041a17ca6714cc49c1731f348298fd34750774e7dab6bc5c4aa4f69b8f0']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:54Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2aa-abdc-440b-a717-472c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:54.000Z" ,
"modified" : "2016-03-17T14:43:54.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAHt1cUiC4MmwyQcAAJYSAAAgABwANDkxMzliYjRhOGRjNDU1NThmOWZlZTkwNGY4NDRjMDFVVAkAA6rC6laqwupWdXgLAAEEIQAAAAQhAAAAmH2JDhSdcxz3nBIc3NHGS4w0/zRdjfRZ8dzNwkbl1rud560F3iY20Rr1bBryjzfTlGPTotMtneZtuYXXveR2cNjodcz10RsDxN43suaygyNlyy1CReZtOMacCLplhyQOIk6YKxP63KBJ40+ikiugxIRFdWYExZZwwiOTWHANijmFq++23bqoJHQtsE8xrhoU8JxfIh9l6jNaNIfgP5EiCnN53OGzFpawOLVxZgcVKvq/hOQm3pdlEX3sn/oQZYHoDmgxBK8SYsqVsjtRYWMwGp39qUNoMqDSRmFp2N/Os+AzNfsqEV8fEzLoaSlTHX3bAWfXEeMvM8dpSLaja4gdNZ/Ps+3dR6W01qOYCfjDHpuc+ZoknSYHfi5uaKtYMLiFR+crF45qNofaB6FWCP5PwLF2sgtTIj0gXUAZTxItxQ0sxwcOGsUZk0xXS7O60dlXLdbrCEDvNFg5lnnC3cWLo0lpj5EILV/Q1r0m2p8U0u/KT6zbok4kZwd65ALuzodRyWSKj5Wo5wzr6y23j3Q+tX+jshL8/Wq/m5tapgtsSPDgFsVfjPKfifgm7n1lAEL9PLhlztvR0Waw2a856sQRyRB0MtYpmwGDghTXbqgdqn3uxgz1NjXy9DFTOe4S541vjszS/a32eeTKIz95v35P3YbjcR3nyjd65wP5hQhydOvyyN3mK+9+aSVp9n/xNqnPKUcgjWdVLGPfHSapjXhtw/LAwDJz1XOmC3jdIy93VjdOmZGELqkfT9vx4UHfSEQkTTTX5LXHzoz3lZQOaQQ6vUd3nvTxAM+jom1Hv8XXEC8liUoOTZTGR0AGy3ctoHzE98u8fADIFo+t9lX8G2NLswaWuYbzmPm7dvV6BFZWoDURopk6e5DQ/EBsMwyhES/q5V8xJA6lDItDZnUUiI8qAPkx1StwrTWALDm1nSgJeCKYCfejqS2X46i3NYUTeGLEcGqpmL/MzbsvrR4lUgxqaOmIXBmn7oyOaTa6OTQdgpWfz9YZackgiIH6by4s9pxiysgVffpQ1ny9RPf4BYtnUyneWugkwG41qriXqEfs0OewLSbotJP4uGZRbqA+OtpB9/vveAUncucYi0OChjiMgQ6hILXuds6ttfbm8GhrZrMevpsuADU+ztmZoHrSHqMAn0deNrdjHYrsjxLTAheTx7m/EX/hwMqYG/709oE4RTquJoW+4Io4WpJXmUvD1lrTqS/kUM++BGMAnyanoYRYsjlwOcGSl3rhzQzs4zNJVvGkCPjhUxFoIGCDEBJYvR/rikb76a243ls9E9wUw//wDQtbfYt7WLXOPRTaRx16VH4bNw0wnFPHalg4Po1NuQbwN74eq6fjwbbyUC+wxkgIuUrvoSFImu+uvZlDqDZwyeQNoHds1Fffoy6KI99xwd9OUeLdnQQnTf86Vsmn/0BKp5KPjmgN4RUal2dRBzg5htbK/yAT9cBf9ltjGMr5Xjku3gFu9BIGsujrlXQTexgSpbze6OEITBztffg37dqyc6r36XLQyM8UYj2dm/F20PTT5rzHCoSoM9bGobgJYt2sRAGHloxP7G3pnAQ7PJiavZeJYin3qVeYkYQk0QFFD1cGV5n94owcvgf5QYgtYwGauOuf5KmO4s0uOBc6J0gB6KrEvBmuCzRmPAVMlVJqtvm+wqziZAMbrWavQX+FTCZkFgzgIvpVfpkeh+nNPCMSjwTu+xpw/KnXMOhf2GWdxAQHVo5G552FBhMdQraC0GoOo2NcY7KpvArdYXlx9LTwefNoqYTfkSCLs8IB+ypq9rkJ8MCrZ6rRxfo7qtXs6/6IG52IMZile4bp1G33h2YcGJcAVgA6SUXuzT41I50Gvt6/SkA5U42DvucnHLZZylMTJ3ocigXPCh0UgYDCXP88rUzaZL5Zo+38r9GxIqFPljLVjcOihsrYqOzdga1mCDQ1IROGXWMM/z09WDEAMiLOSdnRAFXi/o227N5eyEGQTFxOpZB34zwAXFRf4JL9bZJu+yOCYUsoIEfskk0w7egtaT3akTjFuIPZRVWcg7hAfkd5n8K4sAHpE84yPiu/Og7SNCSKcXcqcw2RTEbKV4+B5hogO1FkkcJvpSfFkUYCkhnGMLFxMMurbZ8JVKC8B9wgjcX4ImrIfWmzmH3UWN107sCxkq/I5zSpbtwtNMgEp8lYG5d/sYv2U14jR0P+1ODqnbKhSFGaL8tk/IG9HcmNT1FP87XdajFUh0KWnwQiYZROwyQqw9Kc+6I+2+L+3gLEUFfmj63cnzLzklNZe6WAfhjua7sQkJVdFipriCO2sws19Vxc/nsEw9so9CqHqs7mL1JhbpdbzTi0YySjmyaY8xBFupHd187cDZjlAp3Ld4VpGIMAKgUyDl+G43QHoEDdKkM8y6hz/nPIvSdK9UJ6AJWdtzKLmssUuvHJX3shnCnyx0jGJ8tX8fc/7IPQsKxI5nQJoIc/jFq0wK8aPMW9I2WZZEwwQlrSFyevILXYzTKtyoRJJbiLF7TQ8wZUYBjIKuHFC4xJVPp+0YPNmFK2Oyuq6tBBfDHGhLYOS3eTwgbiwfINL4Jcfvg2gSRNzAjCvYWdZICJcpAHuBV2MdyEH2EJ3qYd/5rQGW6tiMhBZASssO0PidMou1SLK0saCwN+uRuGyiJ67ydqHFBLBwiC4MmwyQcAAJYSAABQSwMECgAJAAAAe3VxSGKTT3QeAAAAEgAAAC0AHAA0OTEzOWJiNGE4ZGM0NTU1OGY5ZmVlOTA0Zjg0NGMwMS5maWxlbmFtZS50eHRVVAkAA6rC6laqwupWdXgLAAEEIQAAAAQhAAAAfshcqFe5ux6aju9O643ShI7b5wBD5LIsr7X7a7udUEsHCGKTT3QeAAAAEgAAAFBLAQIeAxQACQAIAHt1cUiC4MmwyQcAAJYSAAAgABgAAAAAAAEAAACkgQAAAAA0OTEzOWJiNGE4ZGM0NTU1OGY5ZmVlOTA0Zjg0NGMwMVVUBQADqsLqVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAHt1cUhik090HgAAABIAAAAtABgAAAAAAAEAAACkgTMIAAA0OTEzOWJiNGE4ZGM0NTU1OGY5ZmVlOTA0Zjg0NGMwMS5maWxlbmFtZS50eHRVVAUAA6rC6lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAyAgAAAAA' AND file:name = 'billing_b0e0a5f.js' AND file:hashes.MD5 = '49139bb4a8dc45558f9fee904f844c01' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:54Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2ab-0550-4439-aab1-45ae950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:55.000Z" ,
"modified" : "2016-03-17T14:43:55.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_b0e0a5f.js' AND file:hashes.SHA1 = '85cf7c2d6a2b931ad9ab25539aa36cbbb66caad8']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:55Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2ab-689c-4b2e-b3f2-48df950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:55.000Z" ,
"modified" : "2016-03-17T14:43:55.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_b0e0a5f.js' AND file:hashes.SHA256 = 'da172f592cdef05518bbd9ded4812c987dbddc5b4dde020be15bedbe78349fcc']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:55Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2ac-4030-45e3-ab10-4231950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:56.000Z" ,
"modified" : "2016-03-17T14:43:56.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAHx1cUjPjlrKZAgAAK4TAAAgABwAZWFhYzE4N2E4YWYwMzdkOWU3OTJhNjM0MmU2MzU5MGVVVAkAA6zC6laswupWdXgLAAEEIQAAAAQhAAAAS5jnj5CuhHexrEYRlpBXFJOxfQS6kQ59a2HnsXZjML6znj3z9n3cUHcGGBd+j4i9Q+ZQ3VJ8EbljtvuG9qht9fiZljpf8qGLUUtsTneHonjWEb474xfc2hldG4GcDuCRmPXIzayJnanO/MfpYptbU5/GIaA2LRIm1CwiskXxdregavlefBxU91tAhtdl47ujs14X7qpZ9gE3lV7OuRbIq6kJ3NBtcn5k9tPU5BnBX6rPXFavN/lUY/cunDl2Fb97atcNf6t6Xa9jKIkfJ4haSWf8wUOi96+BCTsu2yW2kV2NPaVLCpO0e3XucVUNXaGY4G1MTE/BcHDfpqgbNUKMt3u3FoDAUZL1S60CcZPOcDkv5MW3c4/nC57BxV2aHzlIWKA+rhXaEq3Vrw+kMhAKsyLlNQGRk2OgdyNuZPojWI9LriR+V84qDNCxrTHVTZnml4WmpO7zqJjUF6/js2VkNxgGksGLzo3JHjmBjGFjOMIcM7ftkFgkJtmF4ZgIP87vl0V/46DZph1kCZIZ6g7G6RfpsRuWDAfRTpSzGzm65On4aKidMz4usDl7L/COobS8LBASvMYremXw24Oan3cmgDOi4nPmxK2j56u7+lkfHfrztl8F1Y+Oa5IU077B5ZrJR1PR4x4m1Ja2ZmnWLCu+S9s/yQ2zLtbHArAsqQF/DzcHcg+1k8S6AHEo5gf59zfvYbxVQ9kdN/pQpgD6ppsCUPMjeYyVAgssF+KJGPnoAANpcFXNG1X6L1FmpWtlN/2fKJebSPXA7GDBNxwWiDsJ6mC5lkiiKbt0Gp+62AZpHaYvLWPJFTqaTKgiooFw3qK9ErNZhewO9FDFzibgpkYHEkK1cLQbVG3IuAMcwstpPz3OCX4ZX3Ivhu9x/xXIgzBlvA03+pIQ4DTEV4HgeLe7JzISmi2Dz36qeEP8wGRmYvvdUVSDGOmLQbhc5wVRB6rv/ezgF5hTyzAO6UfK0l22z1IZkUjUa/jd5P86DgU54tB5rCH8HYk9r28LR7UyxY45xx2HufcpTAWqezT/iR+wvQWGwpzYOO/lQhoWOuXrPDIE9xDsEZC2MYN6iEhED21ZI/y62gNuYLOwtGGiOdRLt6N89Z8dSiykJz6kVIavbx6BraN7TobIBNjmIqxPRsFRqol1d5MrUIeTFYuqbDsU0Lg1tUB0wftJm+lU1ESlbJzDXk45cjFgjW9bFPcRBiHKRNYAYKAhz99T5mSiJ2ps+eI4mnqFHARs1XAB6Fx+IhqqgJMPGdMatOe4mDUaSBFP7h0k8TBDQphvS0eCXGTYcu4NMW9wphTThTuHMdcytc0rZ7YzTwDZrf7j/n2bUvj0X7XVDMrvOjy5Q3TSVQ73gq+aziXie21u8qoH9XtVTTOCIuMf6W6Z9LIBgKr5wYDM/DD4meO3ssgZEm4YqNAOj68LylE7mv1ssDYpXVbj4BjyDgQ8cxsg6NqRIYCAYM9+ZQM6Fi+fJ6MiJ6QXMgDWyAVTMYJZFjK09wr0WYPUHto55oQkieGuI/+xPmRhEI/8lpvgKsK3gDm/FoDBz+iuzt8hWZ/+a8H2Sc1z/07QYCd9igmJVFuQHuKik5DCNoqqe+Jxdl2y112IWdH7hxnb9Ny69Sp/T9PwSO84hDvXsBqTHCmctGqbW2SSc2QWkSKyVgDLG65Cm2Q1oOMKpjITVUoGx2uqas0LONWExZvy8+NsB46tLwqiAOkNdMdMryFFXthaBjPiWFXe9BC7QDJRS8eOCMrO/M2Ms53gsQoTw2SdNZ4W55gxT8+U6Nsp1XkM4Xzum+1i/YSmiTaEOcTsl5kPOs/P17pQDf1z08z7XDJbJz4Z6u5zZY/tYgj7fACIXw1zyZijHNO2bhLyfkoqCCV98mIrQxKfEgvfSXV/uu4+xIMLySVe7n4QkjyW3fv6oS3ShsP6H5D204aaxhXs5M2sBG17BRjj2k/IpBAFeoO8H/rk7AnWIUTGfEhK6ucJ1Fb2XuU8LPRzWsUBal5pcEiBExMTXiOMOLfFY2x20yv0mRoWMNF9btQ2cqkibBoW4v6W19kuaPMQ2jg1fIu9ynInVRUakzJqudwBIPC2YnS1wvvoLsTK7Y8iV6GdwzQc6sVfNpbI1Cl9pdUPEMNID/5HPCpLYELy/pZeOjKWO489iGKIxcuMoyyXeVpiYW2c7txWSeMqZ6gtgNXxy77h1NaVzbx06vt0vEVlQC9gxpPQfIcEpLww3B70dyk0iY8cYJ6P3pfCXYH/pIOsP+88eFIkZ1NZqJVD0RzxtUy3iOikh51NTZm3p8bspABV4ML05OQiyQbBTKAj3lpeb1vHXgfK8ZVlWq7wKlaLWb7kjxbj3DDEzKRZLuTqyaY1mSs1xljvfNjXqWI93+aiVBApoUrO9y2rP82fL/jAKMGjnmTCOHvWNu48uq21udRRs4LDOk4tIjOL0cBZIxPDMVP64LLjfOvbkvQofa/ynu33ztwd6e7Q9cVA1a0fZFhBiuvhp5y7Cm1NQtoR6twMWyNq9NRRiULA5IawBjspUftdDNesrAIU5eWzxfUPOoBigo+hGcf1zyPe1hxK9Kpx4hSLTUbbosXiF1WU0SBgZBhKKt7/IUoJFuRkaHhyWsr1fPIhyBtfB0t1qKxmu1zwKAUatpS8yIy8QnIPTYN0VN9Lu/8jF1CvqG59EyjqJi4ny3Dp0XdrAdrNzs5nMFQFZHi/zJaoWLaEQeAX4kQwnX8KfOluSU3yAogdHVPfgSMlVGtz0OhBOBfZ+jYLAYukpclwhbriq6J7QHgRcRinaZ74PyJUyGjVIcYHg0nX7r1L8/h4K8YVO0SCau/MXdvwvA5D33g/UeTP35Z+2EhdgeiqCWg8/9RBUEsHCM+OWspkCAAArhMAAFBLAwQKAAkAAAB8dXFIEvSf6h0AAAARAAAALQAcAGVhYWMxODdhOGFmMDM3ZDllNzkyYTYzNDJlNjM1OTBlLmZpbGVuYW1lLnR4dFVUCQADrMLqVqzC6lZ1eAsAAQQhAAAABCEAAABUqZMIdVj6CrH7OSKlakb4g2TgqDpzLFaxfRy8sVBLBwgS9J/qHQAAABEAAABQSwECHgMUAAkACAB8dXFIz45aymQIAACuEwAAIAAYAAAAAAABAAAApIEAAAAAZWFhYzE4N2E4YWYwMzdkOWU3OTJhNjM0MmU2MzU5MGVVVAUAA6zC6lZ1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAAB8dXFIEvSf6h0AAAARAAAALQAYAAAAAAABAAAApIHOCAAAZWFhYzE4N2E4YWYwMzdkOWU3OTJhNjM0MmU2MzU5MGUuZmlsZW5hbWUudHh0VVQFAAOswupWdXgLAAEEIQAAAAQhAAAAUEsFBgAAAAACAAIA2QAAAGIJAAAAAA==' AND file:name = 'billing_b3b79e.js' AND file:hashes.MD5 = 'eaac187a8af037d9e792a6342e63590e' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:56Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2ac-b168-4c5e-b21f-471d950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:56.000Z" ,
"modified" : "2016-03-17T14:43:56.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_b3b79e.js' AND file:hashes.SHA1 = '264cc70d445f5d3657db5a3309fb850a8691d327']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:56Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2ad-895c-4319-9f3b-429d950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:57.000Z" ,
"modified" : "2016-03-17T14:43:57.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_b3b79e.js' AND file:hashes.SHA256 = 'd314d5b902fe1e2dc46e133732e04b2d15fb5cf6f8a725ac1bd7c5264154ae3e']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:57Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2ae-a38c-492a-9745-4437950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:58.000Z" ,
"modified" : "2016-03-17T14:43:58.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAH11cUgPSGl6jAcAALoRAAAgABwAMGYyOThiMzQ0ZDU4MGYyMGExNmVlZjk3OWVmMDc4ODlVVAkAA67C6lauwupWdXgLAAEEIQAAAAQhAAAAS5jnj5CuhHexrEdPeaBFnSnXgQp45i2TtL90INiLuvMhP80q4Mmm6/oTSyaG4dM0FLsVmx503ZNXs2k2IJeWRxDmxq8Ia3t07qr1FyVTLNm7vfyQkjAXgdMo+dinbhPzZaG0KOaks6Ar5B8+xnBMn9qF9IltQwx9hpjfFrRYFArqAE+yLEHeXUPhmDJcy9YF1XGRPupOtXD5oJzdzscHCoEGh0/4ulcz7Moczs48y8oucj9KzLnoiYF6QX7Ew5SsKt/pXN5AtAGsXDbBLsdnbZDTnKscX5JQ+gJVJEvDaYPJTqTd9h/31SbadeuVA6lojryphLruNA7CHguoY9e0nh4X8UGhLl0Bcy8X9dr7L0cp4BNAs1AVX2Sard09EmAEDJn+MfPkf0TGfgSCGIgVjlOWs5mVDYQvda95dlqRJAMdiGEsV89OJ8fJuLir+QTO2q8QWPjfCfi6L1X0xBsVVU6BnOZgHRgW2y+fVbNywi0lIyoh/Mk5IhBcBBNdl3gj6sJquTTb/QRY0BPppb8fyv2wEdhQHhUvoyScxk5yCjHqNDLz1st6+Tng3SA6INC51SJbkCPlPKoiIvDmQpT1yRpCdNtncES7qdDXGdlkK/mRpendrKoZ/Ala4iOreQqyNmIZwn6TseC0Y/PL79eY6eK705+kERqaNA/hPqNBmWs15z6eCplRh1e3ghqFxnolHaq/OZXtuEUn7UwZHYyWerOqS/qWv/MC7YT4zHxki2ksMylRHqhfdY6bNe/1RRBsFJjebprFeez/tV/oL1TQ9CW66q1RA0AZUGaVLSzojRsXJE4o3dBIhUYee+up+Uo14WJXzd/pWv5o5MoJ2lVGHVRYtAJg91vlHX5vzissrEI3NUN3YkZKWt/oHsVl9zXEgyL3JKc915X6/vIG3BkkE/aWzFFJTpvRrAsWWmru/rA4v6OY705XCSTb0uigDfskUJZCX+2we/4MB4EfdjD2ijczU6rCFPqiYYJ/MCz5xAMFSU1uLWpPLuRX0gv8hxwCxF6xW0AS+agrEG5UJ0auVvtaapDlNfPSd8wsxNiCoE3Vgr4S5hCI36aK3SumrVd21QwjBXPsBZ0/ejB6F3siU+zXRgFBkqq5goRvP3N9PnARTLlvai/S2qOj3d9LmMMCaqGhbCnjHKKlB2pe/DugpM7heSbgiFaFrAGrf4+2PawQSEhhd2fJytuKJpqC4x2uyLs2Ymu6AVHPNax7PYV4ZjeFIUt3HtMV1xlfIKuzRKGlsjBl7lt+LmKVfx4XXqBqJKV+4nmI1v+xKjw4ot3gzIn82oDYLNabnpqXFOcxgCoIaO+C58cAzueT7SCj+Tuukq2EHDE+/i8YO9GIkYFbqu9k0cH5Yu3LO0irApf92AXsOzoy7QFuna/DHxsY0R4TJK+2jtgPoWCt/+vJKvMb7yuLNTV+FTqyk7gtvNeByKPpK1hZWQbb9c8SWBnCvb/6Xn/SWBfW3mxVa5DGBDWKmEkR+fmxLgQz0qLNceCQ8MDNxaizMmKI1BDeY13dvTtTLcopoOfg1z4bh8OPhRq1IE2y4Hgd5Dg0MHNyxpDVYD0PZ+4/kUGkYvZvDYNs9eYdoQNJN1ZvqQcuvEwTCajUcpWgwvG26ebJt00u4tWe0gvj6g2H8zlweIYf3AjnARTH/XFv7nzj3RALzvYrV7zCtVZT07feO8Hsymyzp7qFYfV/qd/DgJnfwMFzVknC6O8JUBkI8Nn01fp7MRpvzC7CMIPDlJbpV4nvYiVFm5XreKel0pp/sdzEa3eKDUNsKKfukVazgoheE2xfzPgorh/mCRG43Kx+vqEW5rqjPOhXLSdeUAa/CvBljfAlHeYIaaxpWovTO364RZo26kDcdmX3rt8xpdjxL1tARp8/Pz79yHYov5A1DFo7XXJvngdGdpAJF50IYStODtIyCg/xV8TGN34YMEgTixCncgKKMIVFeH5KqPLhpeNX3ximwsK/O6gZoHvXHOuaU1jFjsWsINWHhkI4uwqxO4Sv7HDTe17Pxx7VaOzYtZFYTAhzBpe4czfRULMNZGR1nNAky+kPrQy7wys4Z1WCTtlM6Gx09cTTd10hoLuUAc4c691+gmyRaqX0ffu3lJzLPf08w2if8SyLEdNnoF520UMm5uajgA9Yxyby/GVxSmMxjaFtNaFpR08aIvflgY7uB6psMpnmnaanAZ3gS7R5cYGu0B1oi78OahhOz5bcAZadaKHLX1E7ulLpoj0eEURD+V0QeQh6GEyiHGfBxtwuXPvTKwn/fwvHhjvwDu2g/65rah5yXTEPW/ys+OOt6qAqHkmqeMtU10lnHshx1ix4giKcTUblPI1AtRiZzxDjNrAMeiivQOv82czlI4vg/MFSS0znBYv/r/FaXdDI7hXPBfLkrcSAyOJxNJk8VRvoLZOBctIxAtX5xclTqs4iKU4JlXaiU1rztbYmozvXjF1bUQ8Qrwcyp2bdfFVpztRUYQj68vXdKemcOigblrrVBFIafdmwNLJGDeA4Ncq2pVRIsAbL0y51UOGg+MymiP1tiFTMXwmSHl4DCVq94bI3mD9pO6CUrB0HUEsHCA9IaXqMBwAAuhEAAFBLAwQKAAkAAAB9dXFI6JxcExwAAAAQAAAALQAcADBmMjk4YjM0NGQ1ODBmMjBhMTZlZWY5NzllZjA3ODg5LmZpbGVuYW1lLnR4dFVUCQADrsLqVq7C6lZ1eAsAAQQhAAAABCEAAABUqZMIdVj6CrH7OKq4uyw6I8TDEpz8lZyZo+FPUEsHCOicXBMcAAAAEAAAAFBLAQIeAxQACQAIAH11cUgPSGl6jAcAALoRAAAgABgAAAAAAAEAAACkgQAAAAAwZjI5OGIzNDRkNTgwZjIwYTE2ZWVmOTc5ZWYwNzg4OVVUBQADrsLqVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAH11cUjonFwTHAAAABAAAAAtABgAAAAAAAEAAACkgfYHAAAwZjI5OGIzNDRkNTgwZjIwYTE2ZWVmOTc5ZWYwNzg4OS5maWxlbmFtZS50eHRVVAUAA67C6lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAiQgAAAAA' AND file:name = 'billing_b8322.js' AND file:hashes.MD5 = '0f298b344d580f20a16eef979ef07889' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:58Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2ae-3310-4539-9b4f-4994950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:58.000Z" ,
"modified" : "2016-03-17T14:43:58.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_b8322.js' AND file:hashes.SHA1 = '606acb1cdc22895208c395334a6694eef889a5db']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:58Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2af-fe60-4b72-8d9d-415c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:59.000Z" ,
"modified" : "2016-03-17T14:43:59.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_b8322.js' AND file:hashes.SHA256 = 'aad79a4d8083ee17b4693018e660d66d9b039c9ae88ca21959bbd7cb9fdc35d5']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:59Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2af-9540-4f68-905f-402e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:43:59.000Z" ,
"modified" : "2016-03-17T14:43:59.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAIB1cUicw2jw6wcAAHwSAAAgABwAOGM0ZjEwZDQzOTE1MDk2NzhkYWM3YjMxNGRmMTE0NzlVVAkAA6/C6lavwupWdXgLAAEEIQAAAAQhAAAAQy7Bjapkfhc23PPH6CO7xX1GswJEYqID6/ZW4qWp4zFzHDlGIfpOU5rz+bjkDs/DzO/Ytme58wlOB5IvCuqyRVZ/LbVeujx/5Wc86qKe92B2C0qEeK+ESlosUCWDO9Y4rRluCZLA0ttaPDsNNn1i3uYzIH6SI1bGGgKTCffjBOXGyWInZBUDcbnpC0rxlw8SzhcSrYmg8b5ps3EXECF1sAZbCF6ZRqf/LlfCgXxXR9BHFuhv3cu9ZagiUdRoZ8T+FwAqI4/pn4rjTxTvtPSQtWxlqEJW4tsvs36gKut7xKTSyDyW6m5wCtrVYDYh9qYiGCLUsXqT0TSGmdjBR0tbYgTtWYWrQGcZAFIkaBUPMVvIH6X5o4UwPqN2V+m7UZDT/GXBkrzOuSHzUJLq3h1BA1/XCSg8GpsvRmSbofeTXtljQyInFbUmUVugFY2o/NcPJa4Tj2HMAAxiKFVJvet7haL1GrrJ0s+eTNtZ8K2R2EyoFsFokCPXaXyvyKgNOG5hR+Vmq6U8VvsURxUlf53mASWsqe1l4tZe17v4nUof3Q+nhkPZ7W2HrUazPcC0rBxmu9OLsv+qdjpZUjqkoEo7a8VjxH1HdJ/jyUzANPh8KlQULJJIHOq+SfqC/sgG8NPP6NVtHAzPJ/PdjF21SW9uFqb3nfE5uvT2DKnpHolEjLUkW7obti6Qbrhp7jigEveas0X9h5WpFGYzgqINdSB1vfsDEY61tGu3GWjPKxRdHH75nePPk9QP+nkxOCcVUwm6E4bBmtgySlbcx732vn/B2F5wIn6GfFydvuQxgenUqQpjsQL9JgFlHUk916907/wHPTHF3rtf1sofa8IeR5Qs5Xh/FHRmLGhQcGO30nVSWBHZro24tW8kUy/Id69NITENG1qe23xMmLRaM7Z9ga/HW6pyFQebRH8Sm/b19HgUFd10ZFHL55rGRKBssysu6gtsnOMx0Tx5LEgymCjaUO855wnXfTHMSCr+btqrFBAjqJjp7oNrPc797WaYxuLtnjah8TFoFDGWNn7qWE6FeAXMVjS+KuPVKwfG/0RqxQy2o3EieOTVFMRAjyUO/dcALcJstVMyEpLA02BQqlSuA/YEkSXR9EIi7atbuvK7oliAS+Ii3Hg6OCThvpryqk3HbsUsQPAVSsJlzWF7j82vUDNXPji7g4VgRNPx5uLTjywncs+q7z9B8Q9OtmzYkEgNTHNn2rV/Gf4yxnSsg1OrZHckdVBeDQprU0S1yGSG5hRk6WWouhbwbw/Rc9UAzhsv/SpiLDoQRSXbjVyTlySpbmD9syETQ89qMjIoNRNMak29PfNgrYEhDtihNY4GfznTByhFBMAnLs4ZhfRUyd0Az6jvhuT0jO3LKCHCbUQnwdbyj+32Z3CMJcmqEjF4y2EDr43pg4ZpJEpC85AaC+UA065yTSNoJWFZQyyH7Zj+EzkT5wvjaF4LHQyn+ex7m1myZ6JgcWBv0Jbf58uXuBZDh18XH7PWHK4Q//sn4COrQLIathqzw7kQwjVq7y4xY7Kaoe5/4YGLqjJT5vh2idMfuAtxGUgmIC89dcFnFSRWduW6Hke2qSHxJdNKrto3zt6KQ3QWYVGLHvLnc9aagwVQRWVb+pv+wiqxAA7KsPriD2uZEXwp16BwriuCpc+CjvUadDyx5sUGqb5xYy9AmeAkDKqdEX7M45zF5jkUz9MPTmtYzj9pkPBfpmLkSAVIzKQjf9g76Q5E0ra0cFE1oW39CeWH6a8ABEgjVPdMXfbJC2W2z70RGX8OxN/kvhDO/QS5tUdB3h6xro4QdakKywSLDQcdBl5bW3LQ96UdkGCrC2NQUQAsRloakbw0/XK9aNKdTGHLbuVRnPz4KXoHmkFmYvAVyWN2vdT8Qa9s8PR9dkts1Yv5hBJVinBLOuT+RZgGDcHKq79VUyhM3P8E5TpL0rsJoRDFtUphnmMJRkMOgwaIBLzRNSUxAkPQ8/ZliUn1SjYjw9gp1TKJpJaQ9xr1rffpe73fpCBLNvw9480QebQAu5v4BIhYEkcyFXwc5ueEcF1TixE04NzhfTI/sLLIAjEpDXcQx3qBhIe7YRtAELhCLoM4Pet+AqhsKU2QCx+CF1ifJGvFVEfQCJCd8Yi6fdxxgaXm1CYuureCSDtiyXnSY9L3uJNozv7y8wpCoeRwA/f9c5sDidpp9B63IM2JPoWd8VJpeIusoDxv8dh/q7WoIlobD4SGSmunEFrRaC64A1yF6NTaFfDhLCDqDfu5LquO1nCEbCpaMY57J3MyE50jFFB/6uRWy1q2T4zJA9gIuP5+0vXvm4Ie/jcgQRYJHj6hj08gTuc9rdJEmlbsiJ4bSPYuuX43YD4hg3890EoOYa+Mx0OJeRn1r4P2jGi1j3rWxpLkRyVd9W1ZwgqniTn5C5VPKqaEZOCPU1ZjdNGYmZGNi0f3K7u5gY0irIwikci/Q7VnNi9VUTtkIrwYR1JrzE0mlF55P0skC9DjjrQxVD3Wjp2sbNcA4n7UGyxhQQPzFbtdAQQfsO5tFFSyvY76O1kO+Q69zYmpjJTz9bK7pkkh63T6c1B4IvNsoQdm1yam+8wRqfwmgwwoWpYH1CgGJP9ti7TnnTUtdKpz17U1IvDw1AaJh1xamuYwLv1ke4zqcC0Qdry2GBN8mQmEV/VUN1JxSwGykGxUt/+7OZnSLAWvm644D9gn015TjvlQSwcInMNo8OsHAAB8EgAAUEsDBAoACQAAAIB1cUizXj+fHQAAABEAAAAtABwAOGM0ZjEwZDQzOTE1MDk2NzhkYWM3YjMxNGRmMTE0NzkuZmlsZW5hbWUudHh0VVQJAAOvwupWr8LqVnV4CwABBCEAAAAEIQAAAARTnBvNVUDtfa8T/qkg9MgHLrreW5iKOJId/80iUEsHCLNeP58dAAAAEQAAAFBLAQIeAxQACQAIAIB1cUicw2jw6wcAAHwSAAAgABgAAAAAAAEAAACkgQAAAAA4YzRmMTBkNDM5MTUwOTY3OGRhYzdiMzE0ZGYxMTQ3OVVUBQADr8LqVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAIB1cUizXj+fHQAAABEAAAAtABgAAAAAAAEAAACkgVUIAAA4YzRmMTBkNDM5MTUwOTY3OGRhYzdiMzE0ZGYxMTQ3OS5maWxlbmFtZS50eHRVVAUAA6/C6lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAA6QgAAAAA' AND file:name = 'billing_d494e2.js' AND file:hashes.MD5 = '8c4f10d4391509678dac7b314df11479' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:43:59Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b0-b874-41e2-a4f4-418c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:00.000Z" ,
"modified" : "2016-03-17T14:44:00.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_d494e2.js' AND file:hashes.SHA1 = '79a7d9dbd7f0c96eda3872d4abc5615f44846d87']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:00Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b1-7840-4548-85f6-4e87950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:01.000Z" ,
"modified" : "2016-03-17T14:44:01.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_d494e2.js' AND file:hashes.SHA256 = 'e44329a4350e0e92481fc632a4588c2f7988cecc0b9ae8d12243352363690ee3']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:01Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b1-7fe4-4e90-adf9-4403950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:01.000Z" ,
"modified" : "2016-03-17T14:44:01.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAIF1cUjUCq+MZwcAAC0RAAAgABwAZDQ0YzA1OTI1NTkzNTYzZTYwYTMyMmY4N2U2YTE0MjdVVAkAA7HC6laxwupWdXgLAAEEIQAAAAQhAAAAHA8MWDeQ7PLxIK/U0oGkplfKpgdPgbcrLmKVV+Dy7Tlk6ws5t0zg9KBdfop7jjxr5UsoEXdzFADI6hk8L+QvZrW38joJJ3ZqfmoBB8t86OfRtn+Ta72Lzkc21NLX2XwMKoN58FfEQv+OO1GfTMthRDptGqI3+p1wkCXf5gjD5E8oBJ+qKoljtwectXfFkDfpNngpMP2Tvv1j0LCHZCjyum9r9ucS3nBkCLDCut/vjM+6QOr3KMIEG5XgHEq9vudP6k3p2Mn1ouSCOYkagZvD2KihrH4N/w4q1izkX1mpAhtNiyQ4Sr4pY7Q2W6fP1yCg8l6+oSeH6euMgCz1cUjabgjEPL10qMQLbxXXp3LLkTe/tafBTkX65E3Omca56kHD0upCbr0rY51+XSNFSzGr+wA4GlmUINZvRmLqUa+v1nhGC4VO76w9TvQyqFYD2LKqBU1f1z8hsuewZC6/Cqg3QvX1BVDDUHjJ3tVIT9XX8HPxPnPma8dNnAHTPNK0YU4a26j2d0Ze+/cSMx7lMzJoQCKXokl6PsKel4SPcegyq7LlxcSiAbx7PA47k+Ho6zlP6r8RAgE938YJnw5Q8AYiYmCQpoyQqrlQDxPBuh0H0TBTTO7l4zhq3nqk+Sd+IKOKaIrRDOdXuGAuxzZeuIPTGPogmZbAjN0KoN3sWuqoXD2fo+Sp1E1ZLiCtCi5B9kXn904pgyU4eszXaQizizgU42slZFRWM8kvyedMXaRurAYJjM81K6Y0ETUVMEsBJ0SpqnEKHOi9tdtXp7f8W+rnWz8DWE/SuLi6zuyZjiL26NxMfXvwYc/+6z0Uf9ObENuQzmjoiJcdf5S/6wHUNdStHb+Jsg7hOKcIUqUsP8KL8g1I7qJIKw/OgKeMHl9hFhhSVScJ3mEt1S87JZI2W6EBdZB7acFgPRJ0m0h2xYT7h8sU7gHy2tG4IvuZqVuhPum/W/A2LBBDHKK6RGf54zb/qAljy/7YVSS02vTFa4esLV+yeJvcTbhuXEB4LvYpUdfwSbUtbheCLRXpMYAf1cuOsxPYSMSF9e/McT5vcR+9KcNe2DybA3BwBET1hfy9xPm5+pYKE8qTzm61KcMuLLroCtjefXv02CPS9dd656FkvIbYlUxVuS5rmFRIhI7FNQDca7+iX4KFAyW9LsOc8vqrF6SfDvXKUAdtQp8k45yMhOMgR7ecuJ+KhhcbVypC8D9fSoBy3CdqUfJMIfb8l6t8qSjsv+mFTKBqfF2F770EFNabR2xV1CXbUr3ODZZFbjsesv8GBwzITV4GS15lqQOwmxKN799l90joeVupzraXSFf4mqn3INP/pPUzgcizhjw9G7ZKTjO3ToFMLPf/irO2ZuPVSZUj/kMjb3PsG+i+/p7PsImaoXUZym7QUVrS4nc4U/EIJ5eXyc+tY+pi2SoUI7ScfYaIkdRqGfk2LR5ImFvxmLJ8pPiWpwR3aPpneDsp63nWj+QfdGej0kYP8zjlc4hE1hIWtFsgEKmyAnefqma4Ks9+8EbRidWhwyBYLbPsF+M3WhoUfF8zFIvS2oleUmK5xWdn26n9Ue13TnMlagnHOMAAgDJZacKNF67L06PnHITGqL8F7ZLqAQbfXvbd8YbY8Gm56FpFMJDJNFmDgyMqO4+C5I1ptEuMl80OB7UjLONN2cWowQ8LZ6xHxdC5AnskGpuX9EuFhcus3G2RerbvUrTByCSDfTzTBpIW8F3b3IdZ2GGsRU3pCjr0LZbyKWAaMxsgraBI6MNG4gelCxKDARHry1tZG2v+vsbVh9rwEgU2obXJfdv5mHQPg5Lv1+stnfQDTlxyUBcayMOj7t+leDF5IqPFrReHWj4o5PXyeA5rKqOYECR//2z5F5Kbd2SRy3pab2aLNOcg9zAoHdbVOJg42jeVL5oYa+pKKLnX66+PfkHFZB0MaluPJ2XssOMcGFLtD0Vi3qiZc2sBe+ETpb5zcIvuyBcwva0eiS4OE2zNZW1DVdax1exvjlQulX0E6cV7soW2ZpibUc7I5L9ueAh1PRmSU5y34GOjwlVDNg/kbBe6kwDm33ucBkUbTe1H8ZEZmrNZhUvndJkp+1FD0GMMcHW1C3DrxuN0mMNxnUdEtnbZMeFAhcNNpKkkqDCXOe4ZliEWtgpNzvrGjkVjHNGnSrIr+Xa9+7ueGaeHn99rNkZPv4GNLFjjcKdMqtgl9gSbIoOmqyVC6ZIAP0uN0u0hesb9srCp7JkrAHPYlpMqFfHP1iRQuzmRL7254ZrJNEjqg2ZQ6ys3lPxJEcdHmUsgJYBo1OA1f3ids3MTxN5gowJCFNMDSpu2W36qA94Hsq0ZU7M7xM22fkXiZBOmLUBp1PWfOJ4yos0W+Rou4itObG8+j9QOJOPNzR6Q0iyw0e1vejWMYzHQOlNbMX49Nd66wUcuoAU9vCVtidHA3Gi9xCl1nza6Z+actfkb95HsiOvWdN5RcJ37gkxFV1EfneSk2/tTCd3IPfSej6yWOeg1jjl0UGEciYS6KPIxTWOD14I/EL5QSwcI1AqvjGcHAAAtEQAAUEsDBAoACQAAAIF1cUh1PJFvHAAAABAAAAAtABwAZDQ0YzA1OTI1NTkzNTYzZTYwYTMyMmY4N2U2YTE0MjcuZmlsZW5hbWUudHh0VVQJAAOxwupWscLqVnV4CwABBCEAAAAEIQAAAPiv7SWrDjyg4IUTKOYySHeCahFH9C33WakxfvRQSwcIdTyRbxwAAAAQAAAAUEsBAh4DFAAJAAgAgXVxSNQKr4xnBwAALREAACAAGAAAAAAAAQAAAKSBAAAAAGQ0NGMwNTkyNTU5MzU2M2U2MGEzMjJmODdlNmExNDI3VVQFAAOxwupWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAAgXVxSHU8kW8cAAAAEAAAAC0AGAAAAAAAAQAAAKSB0QcAAGQ0NGMwNTkyNTU5MzU2M2U2MGEzMjJmODdlNmExNDI3LmZpbGVuYW1lLnR4dFVUBQADscLqVnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAABkCAAAAAA=' AND file:name = 'billing_eaef9.js' AND file:hashes.MD5 = 'd44c05925593563e60a322f87e6a1427' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:01Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b2-f520-4ed0-b00f-4383950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:02.000Z" ,
"modified" : "2016-03-17T14:44:02.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_eaef9.js' AND file:hashes.SHA1 = '248388ff365309fc40bd0c4b1dc12e8ef57cbebe']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:02Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b2-16c0-4ac4-bdd3-4ad6950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:02.000Z" ,
"modified" : "2016-03-17T14:44:02.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_eaef9.js' AND file:hashes.SHA256 = 'cdc30cfb941e21e9baa5917a27406f317c3e54dbb851e170af4aa3333149d68d']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:02Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b3-e874-4844-aa76-4ed1950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:03.000Z" ,
"modified" : "2016-03-17T14:44:03.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAIJ1cUiaU96x2AcAAEESAAAgABwAMDY1NjMxYzY2YzUzNDUwOWZiOWQ1MzhlZjQ5YzExZTNVVAkAA7PC6lazwupWdXgLAAEEIQAAAAQhAAAAlXEPX35+sgEqnobuCOJZprGi92bjXMbkDmBGU65crwcA8KHQJWZICQtMflrFT5LGHqiPbksv5LKiMhKFfH+17PjRzb8STb6wGfxoxcflxLrXflT/qD6QJq6Gz+SISqIreIZlE1OMF1AYvJyBEC/umV1JIOAcKvHlNOdRJf2XEG2L6HZekwIdkJuicQiUTeRXVVxCpaO81aEI4H2FlTb9udHrv8WiahUkF8gZJ19iuhaavZYZ0bQZ2sqAgJuadjtMJ5nE7WwhEiwigzSyu8SlA9OViFzYBELj2AsuPA++JeMUC4sVquWYZp/jLhy43a5cubtS1tkI1dMiOO+f9gAyWElOrPadYUXtV4XqfcePKG2II2blffiuZ4N/eXjMwd6JrQDqd6ZNr0U2GTuEUOwRi68R1h/ncpnG6PGI9Bh++87zFD0hbxSRNo22BcMlVLmcnGJO29qVvBJC9Smv11iiO8REjZOnDeIglpvlnpo/ExDuljmxuGNpYX+zFGoURVRmSaGxUfOyoh3R9NKuTx6VPou0NI2b+b+Os9xvKzUsJyZE4ttadgnDJJOh9adM0aHGutcCsIMY+UNsXeS1w6K5YssoDvMMGrbfBj3mI7u2LBsyiqBqD9DPyf/E6VSbQCcPWJIKbfQm4jW3IrUbQ8WUum5bDHVZ1whiGZ9RHKS7n48KuggAEPJ9VH/flO8UGuZRTK6BZn6IMndPKrHsWPbZ7PXcfEOikdDMeKYUpSzZTSjGO+n1Yg+mUUP2d09Aui9Y95AbtGU+c22Vx5KZxLssS+eZ/lY3p5MCwS6Oe4T6qZpo4UNT4NNjNtGSr/ZGJY6QO0DXmr/ZJvKvz9MfoauYYiqMSwGqXbu8QxjDo5z8yDMKodktdWqKFPvLzwyC2GvTC//HDmlPxnVRgjhaxG29nrRXMv+uWB2AOB1zlsokhosAkDPE6Od34mczzxTWWnS8ra8RlxDFjhvhl8PSYw9tZVX0m9sHwsRnrBOoRLo5VeC+grzVSJjgj3gpQX8RHBpgLn4n8oJyyuEz7QcAbz7Ss5sEOkc48KwEsKDmVw9D0lmRlvxmoTKKDEbLGnkscnZAlH5CQ7xFpWfiGF7mNit1d7w11qOf9mJK8w6tgMM/wlsPl24Fbqxsmy8NDIdX0YdgInpXNN+qV+AGufEqXXZzarI203O0UB1ekKvHgSlF7K2/sJe7WQKaqBmehxXevwFLqHThdqGUVLLIjuW3vvTlSaNQU0nIuK/orvjsrRR/wrA+6fXHNUdqrNxUdM0f264KVAfm9M+BFV4Fa42NglY6Zq1Bz0+WRyq1cOlAxSC8ZrU4fJRUs5dMBaa7csJNdJOuwz4LTDXcK40sGT1lY0aRTBjbpNnMIN44FKKggmeGtiRpLqvso8o4JNQDXSQDyWfsZzk7WSPKI57oL1GfC7zTyXXkKenJDyvPMVt/vVm7qjq//Z6JPrEBGUVwu+NY8/hMZZW8fE4qF/Lrs/okbaRWze6rEMfkkrDw9Wdye9Sj6Y5IRjcOrLwKk1DhF8k6y7/5hfEpACSXEHMrxZDFtoPuYdYYWznZxXQMxou5wX74qo2mULz7k5YxmBfMKYttDQyTAMAeVVD38ReRlnGrsgVYb2j8TFDMSJXdLf54cV5BU6bya+0vWvCSxLr3nUFbSi3EqaZbtMbXs11eT6ZD8lriZuNy52+VtN4v0h/YWx4yPLq3RFm1hKnBG860bToxZ/Q7S9NAU7X1jmoNt1uCYJhfJjV+X3q5B1nzssHmGaRrbZDf9U+UOuHidfN7uIxadM5RCB+sbjwk9QdSoEU/XtcxAiSIzMcMQUqSLjcBMcb6zh46/M7wT8GaoPXYiEhdBSU/zA3SI22xfVGYughGjz7ccNPrRwx8EYKBU5rdkxlFNSKH7+QXI5PTAFeCBzE1K6IIdyBihc+knWF85XeGWufguJCSXXUGfNE1xQWgyDfndxcf4s+CrgN+5s2Y8YVtMrtw1TS8p0oJq2fAdDfYpmJy2ANmGF1y38xWLMlTEj0lGheSns0fOxF+IzDScn/quFC3hxN6nwWmGILMDAP0Hg/eFuj/xYd4N3V7nNdhH4jMhrORBdyuDIWFsBC7yqxvA+P+NlxhCkyCIM6D7s7Iuml/1Pra85ZecxfgCOHk7vWR/prLR9KBwX08ioCjlG7aL5NFKCicCKrLNcRl79uqAGxK8xd7UX5CRsltJ3fzb4/FpuLA4G2DDC9L+n0l5cm7SMMYJV1CrnX67V0/zjWZAXAGR+CJN3e8fHXrlHHt4pBtkkjztFv83IRG0CfCqVeYyZZBvf2hKYYD3oyWvE0d7mS3/psRTCHKllblqTR6WZ+vsq6kx9xD6OQYT2fc5yfFsqilElmHQ3KekPGRVI+6CZPcubUwO3vRd85VGMT0e1Ey7uMKkWLDRjqrW+Yizc5o7DBiqTZUzCb435kWXz9ykI9ql+fafW1td1XvIkWUAQ9YCJPvuwK+/uV+ZqqAMZZXZ2cqAAHmOshU0fD8SSwjzEYCsfqDceMOYToFKZ/tykUZSpSbwIa/Rs5TkEpziX+hjoyEPXAji1jX7fC5JEqYkPh+HVOuy7hKrb30ggubhA1oCsQHGFwar64Vn1GnHq/h+f1DFSf5YHOz8Mk0KSkD3M7jt1o0DQSQbD+TyqSfmbMlOMRWNUwrxD6kLFBLBwiaU96x2AcAAEESAABQSwMECgAJAAAAgnVxSCQPaXMdAAAAEQAAAC0AHAAwNjU2MzFjNjZjNTM0NTA5ZmI5ZDUzOGVmNDljMTFlMy5maWxlbmFtZS50eHRVVAkAA7PC6lazwupWdXgLAAEEIQAAAAQhAAAAfcADibv+hqkFZEp3OU2NanmEGKajCUJZq9PNHRNQSwcIJA9pcx0AAAARAAAAUEsBAh4DFAAJAAgAgnVxSJpT3rHYBwAAQRIAACAAGAAAAAAAAQAAAKSBAAAAADA2NTYzMWM2NmM1MzQ1MDlmYjlkNTM4ZWY0OWMxMWUzVVQFAAOzwupWdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAAgnVxSCQPaXMdAAAAEQAAAC0AGAAAAAAAAQAAAKSBQggAADA2NTYzMWM2NmM1MzQ1MDlmYjlkNTM4ZWY0OWMxMWUzLmZpbGVuYW1lLnR4dFVUBQADs8LqVnV4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAADWCAAAAAA=' AND file:name = 'billing_f36bbe.js' AND file:hashes.MD5 = '065631c66c534509fb9d538ef49c11e3' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:03Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b4-f9ec-46f1-a42a-44d5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:04.000Z" ,
"modified" : "2016-03-17T14:44:04.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_f36bbe.js' AND file:hashes.SHA1 = '339718e53fd222df0b8403cb25d123f088a0f9ab']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:04Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b4-9864-4fad-9d46-4884950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:04.000Z" ,
"modified" : "2016-03-17T14:44:04.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'billing_f36bbe.js' AND file:hashes.SHA256 = '970de0d32aa3299ad9fd22e51a86e83c0ba58fdc18df6eaa9171d033aee3c1e0']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:04Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b5-0940-477c-bceb-48bc950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:05.000Z" ,
"modified" : "2016-03-17T14:44:05.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAIN1cUh9L21ZdgcAAIIRAAAgABwANTU2OTM3ODE1OGFjMjBjMjM1OGViNjk1NDIxZmQyY2ZVVAkAA7XC6la1wupWdXgLAAEEIQAAAAQhAAAAabiMXH3T7vZL2y4v+7r96vVmsFjyWzSuYYqdnxKOMIOrOSU2Q6ZZfMumFWigIUOgs2PVLJcYRb5roTwCb7Z5aYNvJF5vdS0L3NPgBjy4tqIwldL2n3a3fSvJHL8Qi9tqyxAk8mXWKdgL5lAsSoAnnlgBpb3Gc3AS6y5dHMhnU/rkgKxRZm+0WkKhbc+bJmnh8kje7PfWGmS+1RXLSz8+HAICCMMqJYFXeym3Nm0Swy9X8KnPtK6d1sABP8Fkjcar9z3G9cHgreO4rUaYpbCC7pmyTUJmOX0Arb4caxcodKWBHWvP5V8E1HaTQH50AuNVLT0h/pnpHqACoUE3aVUJDrj1INfOSMOCqGptngpHNLvtXkSjzP+QvufSDWN+LiQZw2/2YWOvCmq8NM512YpiKLydKN2weC/R7aOM2/Pfwjyil4SqQJX8CqyY3wFa6bFfF5P6j0DpR1yulyGYFG7KDqUW1SWn7t2z8OI4KwXjw7DRWqxE5R5Au5A2UG/oxq+N4MXXCvVxc+c50/tb3JoXaeGBuugpD3RMAyEBOdQ6iyoNl0/0QtRITmFKLE4ltCMR/DCK0KE03trMGd9Hms4tsLBbn07pVVPBYQXyu4PwKfTKndlVb0SPZTjg3Ecxm2cu/k11zzhXVvrv5j+1Rez/7xE2VgKxWr/AqzXZ8OfQR/mpjov8h2tXZ2akpBX2USSev6XbbhzJ3ezFYIoDZT1sZJvH5Kgjmvw2XifQ+HXkguJIFE0AjLrAd6bU+XJ8s4jo9tzt3K7amNChY7V7a7pLWYrGVLjcgWDRJDvOx5VWL31EMRuEyz6cB4RTGcKJGiFniOr8wXGaIpVfujOVK9ixoLUXxTwkM7qTBcFRfhByq6tLqIKlxS4k4BXujUeospcyTiV40/mAJBMQvgfXskWcjZ+oWTdUlIfL9Qmzh1FbaDRZsFbPnZQw7QG3WoupIdm1iaFfznIvvrsfHYMlzQTwIghfrkHLTSn+jOZhg7Ghpf1N58MzwnMc0wJoRhS8wZKlkC1bZAzi+L7Djh2lxJVX9dCTJAaYNcKKF2VlfXsu57ci8+AeCZuHVVzQFEYbmEg5vgjvvyZKknTS1SKyvmlpJaZS01u3joN0j3LWygFs/KQYdGIzvkXITJYavg5Kxiz2w13EmyVHISerW1Zzpa6Av9qKxX/Qt19cJvHypaT/4VFpx5gwNsChwzA5wFIceIprQxVCAhvYR2uTF+PLXazfgybgc97gkZaLcjnD8xKxFtUy7zWiCPW70lZAGAKq+gg/UQbhWc7zSKJROybXqHZiWbkWnppnir1StD6bGu5byKBxMairOOUTGx8b+VsVHsqYcYqX9O/r67VHZ0foHou/V3L6TIZCxtP1uHwUSU9Mw9DItDRFnx389a5oCszNxQ4AZ572O52T6hhvUFA0nEpwG9pexWnct9dbk++qD3Zzc5d0Dcij0lPxFNBJM0zErU1GKGpQJZ97Tesqw4OLrm0/9ed/xmlyKxujjURXVs87Zds2Qht8UWsLN7owNGGYQCIN3gr9GrPvl0MSHGfl+7aHn4CCYY27ckgcZCRBXc0CUG439g1w9YLTJdU2LEaYIrpoMAxjOO15S3TwiaZ0rtF7PWa2wJ0HNO3NEeQlQd8oYYIJIQqMUoEV8Sl0+dXjmX4mTwXnrusMVOWF5pX9b7R2rRQndvwOjBK1sEYb5RkhVinnnOn7URZhGxzveOKEBvxNKphtjuB+AvmC3SmDV4BaKu9Zh8yDQVIuvVU8YpQ+txN+WNINVpOPrFOdOX3WQSuK09BGKvIQXZb7Z64a8XnAAaMil1qTSpp5cwWQOinD+7PB15kbw+BF079s9XbTVqYLrC5Yup6VybTTF1pzycqqYh/kU7DdWS3X4gEEwbVBef4Zvh/GP02PmTy/pAbft+piIg7slhUOsIwoTv40SaWNkxJ14J66gQtPpFZZBeryTyefwhgX2MaxULfYjfJyEj1eU28DBu+L6iRKw9nrBwNGiysVu+Q7VCHSrhIxAvFdip2hHci4FoUOjT4M51ejhROhyLW/L7Mrlqpe0aM28vLjoOU+zUoZszsRvlRKC22uA5V6k/NcQnXYX1/5Cq5Pz34KC0uGjyOLybDK9pdLkO1ni+J2o9wGh+gZ/M4heW50SlCKhUPAsnoFTQbdRrm7SAhKpUD9G7m0JEoloKFksRSB9Y9xaQxbe9ZkZvuqwPDoe8Bj2NiPHtbmtx8YAVJcQtMZpegcEiF6ZpEujxBwtW4IVMopvaVLv/ob69MvxA69lIezQTlmROc4ZAIHtgjCAcXXAy4uqQ/J8G82quV74s/uMeNRRmFWhUd9DZMui+B2YmTTgi/C7BvZi7lHrW5l42fD9plYuGkO3DvDDgTWiJt6XH6SD928ZZmO1oDE+OqXNFdqAhbUSE5LeU+Rb2ZYAafKO3G9upl3RNnwfsB9mPAhNMIsIhsl5bKcA1mOlyRq9bGT84hos9t70gClGHA46mz8/8mzQXStuKC+7NFnsG7AeBb4+DkExA3H1ZKCy8drPnDR3I+OHWRQSwcIfS9tWXYHAACCEQAAUEsDBAoACQAAAIN1cUj07RR+HQAAABEAAAAtABwANTU2OTM3ODE1OGFjMjBjMjM1OGViNjk1NDIxZmQyY2YuZmlsZW5hbWUudHh0VVQJAAO1wupWtcLqVnV4CwABBCEAAAAEIQAAAHqIIP41QFDHZvQMvUrx0R0llEkDC+pwjNfDBmIoUEsHCPTtFH4dAAAAEQAAAFBLAQIeAxQACQAIAIN1cUh9L21ZdgcAAIIRAAAgABgAAAAAAAEAAACkgQAAAAA1NTY5Mzc4MTU4YWMyMGMyMzU4ZWI2OTU0MjFmZDJjZlVUBQADtcLqVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAIN1cUj07RR+HQAAABEAAAAtABgAAAAAAAEAAACkgeAHAAA1NTY5Mzc4MTU4YWMyMGMyMzU4ZWI2OTU0MjFmZDJjZi5maWxlbmFtZS50eHRVVAUAA7XC6lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAdAgAAAAA' AND file:name = 'details_1de720.js' AND file:hashes.MD5 = '5569378158ac20c2358eb695421fd2cf' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:05Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b6-26fc-4e41-8dc7-444c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:06.000Z" ,
"modified" : "2016-03-17T14:44:06.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'details_1de720.js' AND file:hashes.SHA1 = 'f7d2d5fa2dee663b299c3f224cc20acdcc8f5ce3']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:06Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b6-b19c-4ad1-b647-47e4950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:06.000Z" ,
"modified" : "2016-03-17T14:44:06.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'details_1de720.js' AND file:hashes.SHA256 = '4128071eb23503b6bb9faaa8dd5a2fd7724b9ce4bc9f4b36cdf40e07824aae23']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:06Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b7-a288-4668-8a74-457b950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:07.000Z" ,
"modified" : "2016-03-17T14:44:07.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAIR1cUjGe91MjgcAAI0RAAAgABwAZTViYzkyNGQzMGJhNDgyNjQyM2NjNjI4MTA2Yzc2MjhVVAkAA7fC6la3wupWdXgLAAEEIQAAAAQhAAAAlXEPX35+sgEqnoA/9zz7uVtx8hgNhMJ9dacRFEYxQyDVZl/DisS5gVh60P+02emWZVUJJHwriDu4fbTz/MprbITUGj0lyLnAbjZmyXQ3RsyPWf3YI7pVMlsCwIm8+WTG65qJkFyfKDxAj2qzhWUl7bxRMkRrSsynaQOFHgo58RFmUukLZQjOpempI+gWA7yvPtdCvehwe+RO27dMvq9uMEO0F9WJVkuIOodftj8p9+9hNyZOV8kQxjs4QJ3W8SvtbdI+PwqXMdG6rkDrVDWh0EFfzy9ZDOPRwNOagNWFpxwsbcUrY1vMU1zPgaI67wzEWpk5QAdbR4oCMaLuHyTGM3VfhysN6rkZetbVl7kLNLPe2+4KAdYTesYEOwzcM9Zc/dZJ3+oGgZMsW4y9l4hrComau73BgNGKlqtLOL3T7ZwOkWpX1tw9y3dmWiAt3gckljqrrnivk9Ln1vJAIK+h4nZrC6Iv5NYHYDaMRcIVaIsU1EAmoiWNGxA2z3fLyiiKLV4J83kWlfOu+P05lSXdrx6j78/vDB9zswN2WSod1IFAlUJawlZAKkSdOvcnGn/5f8ABddS0naUpZgXBetD0pZ7GbxcqcQslTG4MaE7wDrcLES4+85HEBEYoW3WenJiC2p5eLE0ZBjpOlAvktmE/mGyEAJFOloiQkm/wtNJbOOTtMVJbEHUCwrQmChwgICxBwuBArkjEjD/f6jo5cFFF/uC0RHEBsBybfaUpPE9tju/uEJ4cRlf4jRjXqNjadoYILJYTtE4mX9nhDyxD18c7XyvCqkrLVJIjt5EmYNaqDpBie5VW/14kM3dQXSLUUcCcEr+BgABczvdnNdpIJMu9p7UkbE482bZ8LZsstkEs1WrZfUMW904kJvqTXAmPoJWwArxEFgAKOoPA3nu0k0gTXqtrLHuon6V5gtlH/R8rZUW0YaxAMFAHK8wnkdP+XbqQYHI4E1km2aG/eGyxnKX/Ew+CES/du3C4ubAjk6FbmcNoZf1N9NYS26thdBKBAIzufjxZMYE8BenwU4YBMrsW7vLLA3rtwm0DJ/ZxtFE6hKq+th72Oand4nLiLrdzja0p9wjGx34H3ZERT0SiceQ9ybF/U/O9SkMqKez5zjKP2oC/b9c5rPAKHuF4F3Mi0AXucakf4nLHfWBcybZLcS7cPdtQjqJJA8HOcU9gJiErVqYoPAikPsXxKuC8jgphDtHGw1GXzz2CCqNvec5U9hLrezq8a1f3kwn/ArjOiA9Lg3f/1CgxSXdvlN8gpv9BOC2zej/IAdAaoEKZZl1xbslBwM5Ic76UEVHVWBAvAuu0AOZL8D4pToYLKmzJNly1rF+fFlKTYbeHcFpOVY/y9WZWa/2WwarUJWqFk2bUUD5w/e6Ajpg+i+smGI4a/eXJ94tLphLQHlWk4Z/+MJyrX3D/6K0LvKXf7xzeZke1a5Bt7hHroCPAHxqYEBn8O7hnAsjm8Lo8lIrE6BZ4nCe+eDYLFJyTqkaegLYOJra/5nboGyNrRpgKJC5aj7ssQftN7e1njTF/+K9ug03NePWWOtBH3VziXXsGgc/UPxaKLisJszhQn20YbJEs5++UnahpTiUUAZDiML81XZOcGvKI4Ak9XvYC3eqy/N9h5JUgRS7GQHv+wU89xDVhtsEnNM7K5cyfy9Z1SLsdwlR6oHJNeRA+2RBaqnhGBnFf8lhMbvtUKiIJWNFD7ssCiPaoOAckEZ75ZoR9NP8I57EvbgMupSw9HpArY2UHFTErMjlGPpZXXfO/sWEkG/oYIoSfXDhqoigyC33wr5EkPDs3GEVMYTf4k8SzBKJPy7r29MpEONaJG0Uh1yQJdEsLdQL95Ar59gJ5nQzp64ugSHWcNekUb55jHXyk/N555iWMR0uGVg3I2VuWccl5rXvpaDaYuWNvEvg4/AOuXX6j47ZEo+r00pA4b8h5EaowrqBEsAMhM9gIvU3GZbt2auPjmmWxeWRg8zEPMwt29L46zCtYAJXI4ZvTvdBHmbs34nz0pQsk7N2wM8twVx3n8aTKnbxWjTzUBoa38ndA8jG9QtchbW6jDsBnoaHu4h59MTsINdYBabJM1Z9GYCmqTYcRQB2jXczqXF0DNPi9v+LuzYfyhhhzuxyq10KdYPEBkqlfSYKvIzS95r/QzQQulWN6HHOBkMmYcP5ay1REi20VRBBZUni/yqM2msi5bboaCZr7ME0ODdDrJFufiDERwH4K7M4gIZShFMluRElAVBQSBgu0GXXTiPfbLspVKeOs/X1EpSmmZh9UxZtjkuEovK77q6JykAWzfjnvbn64K2sjr9+hO3zXYnmgMjFvKlDMdM5FSxz108DQCoV07CUzpJzH314JHu+Z6V5UN8cYQ2k4aiGcGJGRW7bCLW8RVft2U83W3Ju/evagcWfotS1rJ6I5vrpVf/fS9A70HnKBgSZbVR5jIZIuPwIQWwHjV4M4VaTa6po7G97lJsKTa17/0q2Nd+X5O6snkNPvupQZusfNBeDxwImPipXeJcnsZfmCjZNVj9qv4/Yg8TZVTGVrIyiN67X0OuQvTHW1vr2dQog8I6RnuSmSQwZQSwcIxnvdTI4HAACNEQAAUEsDBAoACQAAAIR1cUhXPAfrHQAAABEAAAAtABwAZTViYzkyNGQzMGJhNDgyNjQyM2NjNjI4MTA2Yzc2MjguZmlsZW5hbWUudHh0VVQJAAO3wupWt8LqVnV4CwABBCEAAAAEIQAAAH3AA4m7/oapBWRM/Crmb4h8yJpE5FhdL1fIwkqoUEsHCFc8B+sdAAAAEQAAAFBLAQIeAxQACQAIAIR1cUjGe91MjgcAAI0RAAAgABgAAAAAAAEAAACkgQAAAABlNWJjOTI0ZDMwYmE0ODI2NDIzY2M2MjgxMDZjNzYyOFVUBQADt8LqVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAIR1cUhXPAfrHQAAABEAAAAtABgAAAAAAAEAAACkgfgHAABlNWJjOTI0ZDMwYmE0ODI2NDIzY2M2MjgxMDZjNzYyOC5maWxlbmFtZS50eHRVVAUAA7fC6lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAjAgAAAAA' AND file:name = 'details_03bb2d.js' AND file:hashes.MD5 = 'e5bc924d30ba4826423cc628106c7628' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:07Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b7-3cc8-4a79-af65-4531950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:07.000Z" ,
"modified" : "2016-03-17T14:44:07.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'details_03bb2d.js' AND file:hashes.SHA1 = 'f237000ba2f879942308ad2bc2ea3984f8fdc713']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:07Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b8-21fc-4990-bc52-4764950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:08.000Z" ,
"modified" : "2016-03-17T14:44:08.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'details_03bb2d.js' AND file:hashes.SHA256 = 'dffed482df627d474717ed5b65a3d44446c39d93f70f1979f50e8c4315a881a4']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:08Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b8-de40-4816-9d5f-4258950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:08.000Z" ,
"modified" : "2016-03-17T14:44:08.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAIR1cUh8e2e5aAcAAC8RAAAgABwAMGY1Njk5ODQwNWY5OGZhZTk2ZTVkZGVlMWJmMTE0ZjVVVAkAA7jC6la4wupWdXgLAAEEIQAAAAQhAAAAi2utK/QcJ5vOJmEYzwz9II6G29q2OB725EAeu948tYFM1kyPBwzf5OEFnUe53Zgm91VOez+EmSD1BfY3mZua06kg9WiS0wBks2UcWTHJUfW2MWneSa+H0gySupboWtFntUC0f4TZzES227wsd8oZ7WwyhO6ry40jg9nkHaz9Oh4Bj1VNxBcAcpFZ+SjBd4oX1d7LczA0CFJosiscwRSO+ouSgKqAXzJ+1sx8o5BKN3KW2Gu9N/LKlG9qQ1PEo6ANC7i++uGVzULP9BfB6go0/TXKuFgyhSv/2BFSkyH7IqLOpzi2gd+Oba51pu1SO63CcP1eIh4ebbHu/DWuoxAELs5KgGZUXNLhW/tleJfIBlvCjL8j54+diGfi68H/+krfI/CKRCNSuO8h/f7SnGQJwBUMeFSzWxMDHjlXmyOtK0wm8dsEiVmHHulj50yD0lPeDPa5ArHlaZvzhDs5P8oNyKtwlMpihY1iyS158GQB7S09ZwNh5uVpeEHJfxY4f9ZeT0UCye1VTzO22LmzoVorkn8Q15tiMbp+1nw+9+ATrB7YtkLaWn6WcbGbRNEatNUgrOCtBdElFWuMpryZpcGo87epeVeRngwReCyluH6pl9eMd7+elP1h1MT2klg/y9dRgaMuzfNeUoQ/l8xpW7mgWJt4ldWtEhC0pVLs//wuRKbif+1OqO/1oBWeqM3GR28DdC/DoZUV/+bXPn4hP7ZyPE56fqFBjqaF3Qk0F6BfG/UI6qL+BozcpIrdHvfTVzzPFWF85g5pO/yDvpprcxvmIS3h0wmz242A3fRCeK/H2Hm2LrXUu+95/vG8wB74AnpZe3mcwiEZsXB21mfmb0fxe4AMv1fQdjH4/nfaQwnZgA0ggFPKwvnd1VnF9vKS99SRxrkzit+4XQrCV1WgdmVp8CSGOhdtoPtKUJntPlch3hG7RsFo6qSwfJgQOcFMXCiD9C8sCwHwYFDXUeFNaukofZbt8jUaG1tK5A7TPDAhv5yJqq5dMyffBadJRWCQ3heu8xdP9HSsB9J5E2PFaBFhoGO7T4cJlkrpBCEZR00e0NDHhprcC9Kp7ocXvCI5+Uk4pN83omXax1KoZt64VaPFABEP0+QE2zNYtwXcHZj5L3W+MJb2saaAwqLgYNaIr/n4jyNCY5jD8DokJXoknWZgN1N7UHyGE16XK6KbVW8jffGmIUE+qLDurtnjisb+JAEmhWMuZR2LqjnPoIKtC6kIX3rOy5bc1eDFLnDrCCJc3VL/132MdCK+RQgr1ZEFi67c/fXm4DmR56Jplea8BF/n6giX6iucXFctMbGyUYKeJ+rEyHdyhan+3Ilet88OtlMCWQjUhXe1zA1NmrbdfnsNg0g00hGJkW6KGB3SD256o5B5fR9IPuqrQXbNfpSCeSVa8cr5GwW6StYKx5yoX+hooCE/mDxlePRKGI+hcRrpnOmQDwMvXjFt5ZgMScNECdE2b9MtHcFdjSLNA9GcVvELcgmAwyNfQkEutrnCQDkOkt9NCKKkaB3k2HkkJYdAJ5nDJkHK/GnN2Vxw4Uh8jGDSjzPpDgwa3k8hzRMsQgDxiOQhwWtQeoexgI8ZnEoKzgQoDgnhyglV3jrMIZ8N5iwo4HOJhRac6XBBWRQcJZS5pl2FZ54cq+7wQaOL7riO+h+tFKZOvj1rwSrwUgknQ4gkI/6F/7ru0QS+H0yNOgK1/EsWS4z3DqXWV6NKPbYv81r0MCtOnty0NX5FdF1iNwJte1TsoClEVPxj5yNxSJk9+FB10L4Rr0kY/aImadpa21cRpPizUAN2vz4dX6/xFdq9ZXdEXHce/QkBkwK1o2ICWXnsMj2CaSEUOwEIxIMVf+vJUPqChmcQ3ioU+Vy2oXy112Ppynflf8HRkblBl5YnW4FEgC04hGYkJlTulEYLi4rs9q1PlncoHH1+jpoezYuVHY5ps01LQ6075UkXFPJv5GMIdYvN1ImWU/3yZbDaCKnnSASqGxvrnN6P1x72JvCKlp8argphS40eyRb4/xnoSqdXMObYOFlxmNmaLB7h7X3axod6feOJl2Kp1atgTmA36+Fs7gmthiV7cLMJYvh+lg1SDsdk5BGHCocgxSAJcvDdsw4pd9RNen+Rk8xblYGr+/ezCyY2ZLWz81vwPxrwYJ5YFSMKqkv/EsozLmTL2Cbd2SWKTxATvpjoSflkGZQaVsheXQU62yfoQpVMjpJ2XbvDk2R9Yhh28XA+F3CyFG0FzLKWi0Q+QjMU4U8xU+iE9Kdf21beSh1Dd2i5v2H1ifHa76RibOpJB/v5hRf4SocqCdo4aq0M3pkwACZh8Mb9pe00gVi9lZ+nyJx5prweqoIerhKlaaKMEE5a0JfIukhNSPHiytELA7wXgafyJcJ755dlMeTJAKy1DwCe9+fUrkzVCZdEBmhonD8HKGPabyiNaBqZOWx3uUGY1rsqPu296aY+ARO7OzrR8J/3mV3HfpgmH6xyV9o+YCE2uhmp4UuJbelKt+43fzd2O9+wLD5mIqRhlZFdELZ4UEsHCHx7Z7loBwAALxEAAFBLAwQKAAkAAACEdXFI0vQHaB8AAAATAAAALQAcADBmNTY5OTg0MDVmOThmYWU5NmU1ZGRlZTFiZjExNGY1LmZpbGVuYW1lLnR4dFVUCQADuMLqVrjC6lZ1eAsAAQQhAAAABCEAAACFgMYLmdG+mFfpfmEqflcOOnXFbXQU2f1BKsqqoon5UEsHCNL0B2gfAAAAEwAAAFBLAQIeAxQACQAIAIR1cUh8e2e5aAcAAC8RAAAgABgAAAAAAAEAAACkgQAAAAAwZjU2OTk4NDA1Zjk4ZmFlOTZlNWRkZWUxYmYxMTRmNVVUBQADuMLqVnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAIR1cUjS9AdoHwAAABMAAAAtABgAAAAAAAEAAACkgdIHAAAwZjU2OTk4NDA1Zjk4ZmFlOTZlNWRkZWUxYmYxMTRmNS5maWxlbmFtZS50eHRVVAUAA7jC6lZ1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAaAgAAAAA' AND file:name = 'details_6c6e3af4.js' AND file:hashes.MD5 = '0f56998405f98fae96e5ddee1bf114f5' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:08Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2b9-d520-4976-8625-4660950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:09.000Z" ,
"modified" : "2016-03-17T14:44:09.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'details_6c6e3af4.js' AND file:hashes.SHA1 = 'b974e38af190daac41efe2d66f477d528c000363']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:09Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac2ba-0dc0-40b2-b5e3-4595950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:44:10.000Z" ,
"modified" : "2016-03-17T14:44:10.000Z" ,
"description" : "unique .js file" ,
"pattern" : "[file:name = 'details_6c6e3af4.js' AND file:hashes.SHA256 = 'd2bb6869e33049d104c2d4cc4cbca7c9099d8e928aa555007fd1f4143ce2b04d']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T14:44:10Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eac362-3b08-465e-b1a9-4dca950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:46:58.000Z" ,
"modified" : "2016-03-17T14:46:58.000Z" ,
"first_observed" : "2016-03-17T14:46:58Z" ,
"last_observed" : "2016-03-17T14:46:58Z" ,
"number_observed" : 1 ,
"object_refs" : [
"file--56eac362-3b08-465e-b1a9-4dca950d210f" ,
"artifact--56eac362-3b08-465e-b1a9-4dca950d210f"
] ,
"labels" : [
"misp:type=\"attachment\"" ,
"misp:category=\"Payload delivery\""
]
} ,
{
"type" : "file" ,
"spec_version" : "2.1" ,
"id" : "file--56eac362-3b08-465e-b1a9-4dca950d210f" ,
"name" : "Archive-js.zip" ,
"content_ref" : "artifact--56eac362-3b08-465e-b1a9-4dca950d210f"
} ,
{
"type" : "artifact" ,
"spec_version" : "2.1" ,
"id" : "artifact--56eac362-3b08-465e-b1a9-4dca950d210f" ,
"payload_bin" : " U E s D B B Q A C A A I A P x x c U g A A A A A A A A A A A A A A A A R A B A A Y m l s b G l u Z 18 w N G M 2 O D k u a n N V W A w A k 8 L q V g y u 6 l b 6 A R Q A v V h Z T + N I E H 7 m X 3 i Q V o o 1 M 0 w S Q o D J j l Y 5 H X K T g 4 Q w 82 D H d u w c d n D s X I j / v n W Z Q F Y a z d N K Q L e r q 7 u + O r u a j R 4 o g 4 E W K D + U 80 n v N v V p c J 9 f m + c X E 0 c P 8 m E i o + Y 2 w N E I 1 s i g T 3 X X O y d K c 4 I E J Q z 2 C h P m z q A 4 R d r P X X r C p L 3 u I G H x c 5e9 g t / U G i e 8 V J i N W 8 x 8 l R T m v e c j Z W h m 79 O l b T F 5 i s F u d Z 0 i c l x m f + 4 u b 1 J Z 3 j e 6 Q 1 o a S K k b p p T q h H V t 2 v x t 7 + u r w k e S U Z 8 h I f 7 c j L o D / I 4 c d 82 U 6 c 42 V 0 h C z B l 7 r z P Z 95 D m T / k r n H T p 3 B t b B / H X T J y 1 Z j v W L J t h i r U j M z h A u Z b j + w Q n k i 3 j 7 U h 2 p H y W x / R J a 0 P 2 s + d A F A R a k 7 b + 3 F 1 f m r K 7 u 8 u T x h Z / m x p Z a Y J m t 0 X e Y o w k d 3 F 0 Q K W E l N v + y u h U 3 i x 9 x Z b 21 t p K A F 31 f e Z f F w 0 k 9 f Q N f z 8 v 7 y h m X B + 4 R L K l 75 G 0 I i V u A a I Y 4 O 4 h c D q 4 E i 7 z + r 7 l n X p W c 30 R Z 4 t O x Q o T M m l x I R n M Q 61 F V j i U 8 E l b S I X f p C D V o x H p d r m x 3 g S l W V C 15 h i k m R s y b y 3 J p 1 x f w 6 / I c p b F 0 a O Q k y J t R X z h X k I 1 R o s c a C T J C c 2 O 8 n e y E 2 F l U / A r G n n u F l c K F w D 5 U q S H I j 0 D B 2 X E V v M B J V a + J I L J s d Z K 3 N j Z i t a X C 6 Y c G r G j + N s d 7 H p I 2 a 9 D X a R Q b A S W f g z I 4 S T 5 M U K 7 X k e / p 0 j 2 N F d / s 1 q K r b a g P B B L 6 A V i n M F m Y 5 c S K 87 J 7 R B d a X u R j W U g 7 Q A o g C p 7 h 72 + / h h H O t p I o j N y W 9 W u 0 K 39 l o l U H r Y m s O n i 2 P x z K M a 9 X O F u y Y i Z j d R v o k n D c A l u 4 Z u W b h 5 O A 8 C s r 6 a U a 0 4 Y o v O + i 5 W j E a W o V u 6 L l m 3 d o 3 P 8 l S X O 5 Q D m e S + k c m j M L K l 0 7 m O 5 Q K W g f X A 6 b 0 K T L H S u d w / k R j 0 U Q + y 85 o D M W A y Y U H 72 K W l 3 R 0 / q + F 3 T t h f x n h a Z y M B S U G N S u 1 N b E u 6 q 1 O S o K Q G l l + F P N q 7 U z 5 S 5 x a t S Q / I R v / 8 S i w 0 P J C n Z q a f H 3 q n r K 6 t I I i 4 D F T w j s Z z X D 1 L o r 8 R e h 1 k k / r t F H 0 7 R R 3 F o x Q k h h T V O 5 E z v W C B m b e P h X Q V 7 L B d J q r e U 8 i x H Z P H 8 Q K L h w W p T J f Q w j B G f + E m 3 S l O K v f I O P S w n S n h l J G I 7 Y T c k / 1 b w A i q 7 k d j C b / n P c X J 7 p o R n c N / n D A C q a D X y C O A C C + q t G H V I Z j X d b b v 8 H J 0 a 8 t C b 98 I 4 V V H x o z X r z p i i S S 6 V Z 6 O n U 0 T H w W I s K r s l E k p 6 X O D J n / G 1 e n V U s + 9 U C Z c A v 3 + g W L c m V K N F 3 M y Z W F T K F + X D e j P K v y G 9 Z K T j n v l 2 V 0 x c 3 r P V 52 M B f / 1 f B a q 9 u l l g g O E x f g 8 a X Y P W E V 3 V t 3 p H 5 K I L l W r G J 6 g t M 8 m o x f m e / g 6 P 8 P i x L a + t j 1 g e n X f 1 J S M W X J t t y t 57 o 1 g 6 V f d A t x g k 8 j E a l 2 S A a q F r + N n y M j z d 8 R j M a n T 5 k L J t K e U b b y G R k 8 H L K I 1 r 4 q 9 O W Y p 2 p s O E w W R A I h p V S Z 9 I o 9 j B u + G m K X d M w T G p t o + a D U m d d X X c I s H N X h w Z Q 9 K r 5 x X W + 9 O I 60 Q t b o 26 A E e s T T V m W m k s b o e n W l U 3 j 85 C b H e D 4 O W C 0 Q / O l M L x Q o S O i v a S k n g i a t 6 u 4 o t m 3 Y i k D F x d C 3 e + I u Y V H i P u X j J W 25 D b I z Z b w G H x 0 N M w m o a 9 S e C u w q d E T V U + K w m D / u Y r 6 q 9 E g g T R N 4 G h G e G k G W l C s 6 K q 5 u z I m 4 Q u 9 G 2 W m d A K 6 g u e / p Q g 4 / C 5 Y E M 4 U y t 8 U Z L w o + Z e j 1 s e N u 2 E + h J Y Y R R 4 S o L M T 3 v I N z Q D x 9 G I H q V J p / z h B N / r v j v h R J P 3 j P v B / M i Y T r 9 f M m H h j C 4 Z s I p n b Z U Q u t S n B A Y 1 n f T o A H 41 R y y V 5 w 7 W K v c p 4 Y e 0 C N l D I y Q V j W a J m d + s i 0 l J K 5 C v s E Q 45 L A / k L e 2 / k 9 p 99 O + / 0 f y u O V 1 d E q g S o f q + 1 l M A M x f y V D M R 8 U 0 D + s 4 I Q l f g S V 3 J r 7 g X V 8 V L f d K 8 R w Y F n Y 7 t r 4 A J t s P A A T a A U j J H A x / K y k c P 38 G n 7 k 2 I E q o y i d Y U 89 e z s 7 i z W E Q g Y A z A 5 q y e e 7 s 9 R U Z a U 19 w b r G I U r 3 G G k F N x 1 r y w a B y 5 E m e G n S h B O g 67 F h Z x G m C F z R 9 I k X O E 3 g m q f x T q U B m g I e o y a N 1 E r Q D P o M T i j 6 i 42 J m l P w d q Z s y C n z 3 + b m g 5 q b A 3 Z s n x A G N l b q F z A D 9 l 0 M E x o 0 h s / Z C k 0 d j S 3 O J + w E G S / 2 i j x j K 9 T m D K t w D w e S + U n U Q p S H B l a 4 k x Q D W 8 d d W E o C O O p E x 8 a Y D d R Q f 4 G b M o q q v P w + L l 9 z m 4 K / f 6 c u Z T N o B T 0 6 M Y c c d d D a 0 0 j t P 4 Q z 7 n p K i B E I D F N W z E 7 v C 8 D w Q 0 n J Q o 0 X 6 H X C S s I T B j Y C + J A r j t 3 n g l Z h Q a 7 P v s R 3 l f o r P h + e X 0 T G p x m d n 5 Q F e L s x U H j X c V S U a F i M Q U j 4 R U k r 8 R H w d q Q V e l M S d C i b o Z p 7 S 6 Z z k s 8 x A 89 T Z t 6 y a x k j v H b Z v / A O Z i v B K 5 k m P k c o P a 0 5 o O H Z z Q F U n + H I + f E P q I s v d l o p g f e + Q 53 n M k v / A u A S v P d 8 K K A W h E H s x Y v y x P E T C f z P A r P o D I T + M S F B T 0 M j W H P R H m g B u O v 1 X 1 B L B w g 7E8 J J c g c A A A M R A A B Q S w M E F A A I A A g A / H F x S A A A A A A A A A A A A A A A A B M A E A B i a W x s a W 5 n X z J l Z D M 1 Y z d k L m p z V V g M A J / C 6 l Y M r u p W + g E U A M V Y W W / i S B B + 5 l 94 R 1 r J 1 l y c I b P s a k V i j k A 4 g g m Q Z O b B N r Y x M T Y x 5 o z y 37 c u A 5 O V V r t P K 6 F 2 d 3 V 1 d 3 V 9 X 1 V 3 s z F j J c o p f y g f D D s f b X 6 p f v h i z 8 y 4 m q g l r b K B z s U E O / 3 w A 7 e M G j Z N b j 10 h x Y 2 P W 5 e h T t s J d 935 f x e E Z 0 g O k Q u i j 8 p L N h i 4 / v u o s T N e O 3 a K O m D y H a g y K 24 Y 9 V s o z x 3 k e d 2 K + i a P L R w K V N n s Z 3 P o a Q A x Q W L n / 2 e L C G C d j j w W i h y z R V I i 6 I m S r n V l A X e z u + L r O i y a C 3 t S x / 2 V J B V p w t 3 S E 5 Y s 2 A 5 G y 1 p C x 4 q 0 W i o f O N O X U w u R 9 x u k M 2 r 6 a U r / t l k z z z o O 87 S Y k t h i l I Z l x a v W Q 6 t G Z 3 t o D u O 0 o 0 + Q y E T 7 g 4 s L B e m 6 F I W 3 t C s R t e 0 t k e A 8 w x w e O M N s N N h z f 52 p E 9 k 2 k I A h S t 4 d P Q m i g P R 29 j R f o O C Y V Q H L d m u s 2 m G t J K 5 O U H 8 S E 7 w I + G Q G c 6 w v Y z Q R j 8 R Y o 1 S 1598 l 6 L h i F 9 L V + L E S Z U 2 P n D A G e W s C H e 3 h I q f n B Z e N B 7 n K N v G 4 k T 9 Z + 7 Z Q p R y c b 8 U u E g j W j p i 6 x V 5 x l x w 69 b e r / 10 i M w Z H T y W F P P f d 3 n H Y O k w o o W r e k 8 X N Y I Z d 5 J l w V R s K R V S j 970 m i k l k x S M G w o o b p C H 9 i c i m r V 9 y u G S K R x 2 K Z T L c W E c H n H O M c 5 W q 0 W z O a H o T p M u 8 X t h P Q b m 6 n q y K Y 7 f B 78 x b R J x c u L 32 L + V F U 1 g X F m 4 W a s S g Y K v g Q R c 3 V p I I o C t f D n t e V 8 l Z i G 38 w i d M P a 2 k 6 J f N i P E e 7 + V D r 9 v B A S g m F y f R y 2 C Z B n L 2 O W Y D P z 69 e S X J u 1 q l m A e y v 4 m e 61 X x d 0 S O 0 T d B q A m V J h 0 j A R F n b / 57 U r f C y c k Y T l L Y 30 G y 8 v j N Z n U s + a Y v s S I L c n M F E h 7 P v A k m Z T z x 0 i j X H o t 6 F / Z d 8 T f L 85 O F A x q z 9 f S J M 6 v l / r 7 A D 54 b Y q U w U H 2 m u W F 8 p L E B v e E x r D W g e 1 n f x X X z i d 3 D R R L e z S n / H J Y 75 u r U r Z p O c d V i r z K F L t j P 5 R M 5 Q w W U y N l M I a D T L u n X V 5 e t p L j B A W e w J b I u X B D K D A 3 l R B r S a o t h z g E X e U L X 0 J L t + 5 v 0 q x Q k / Q p s V Z C 9 i G + p g R q d y 7 x l R 4 X I 3 L X 9 G h F V p x F W O 7 E M 868 S / u a S o 6 r B 2 n m S 5 M V 5 z z M g 99 W Y u v w 5 S G i f N / x B e v B v a T / i 5 K Q 4 p m O K v 2 I / 5 K m Q Q V H M s 0 D p U m u j y l z R W F q h k s I 2 v q h N X 9 v v + f X z 5 L 19 e h Z Q L j 4 F g R + O p w 0 k o 7 w s //ywudV3mu+507in+f+jhgtabsXD6ppghGrV2faD2Z1cWJAetK8tNsktU/biYnHq1Pe3Xrj5exkNwt703VCXvOOplteIha
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eac3ba-bcd8-497b-aea0-4c0a02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:48:26.000Z" ,
"modified" : "2016-03-17T14:48:26.000Z" ,
"first_observed" : "2016-03-17T14:48:26Z" ,
"last_observed" : "2016-03-17T14:48:26Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eac3ba-bcd8-497b-aea0-4c0a02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eac3ba-bcd8-497b-aea0-4c0a02de0b81" ,
"value" : "https://www.virustotal.com/file/d2bb6869e33049d104c2d4cc4cbca7c9099d8e928aa555007fd1f4143ce2b04d/analysis/1458220875/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eac3ba-34f0-4332-b943-4bf102de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:48:26.000Z" ,
"modified" : "2016-03-17T14:48:26.000Z" ,
"first_observed" : "2016-03-17T14:48:26Z" ,
"last_observed" : "2016-03-17T14:48:26Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eac3ba-34f0-4332-b943-4bf102de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eac3ba-34f0-4332-b943-4bf102de0b81" ,
"value" : "https://www.virustotal.com/file/4128071eb23503b6bb9faaa8dd5a2fd7724b9ce4bc9f4b36cdf40e07824aae23/analysis/1458223239/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eac3bb-1c40-4a77-92a4-4fd402de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:48:27.000Z" ,
"modified" : "2016-03-17T14:48:27.000Z" ,
"first_observed" : "2016-03-17T14:48:27Z" ,
"last_observed" : "2016-03-17T14:48:27Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eac3bb-1c40-4a77-92a4-4fd402de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eac3bb-1c40-4a77-92a4-4fd402de0b81" ,
"value" : "https://www.virustotal.com/file/970de0d32aa3299ad9fd22e51a86e83c0ba58fdc18df6eaa9171d033aee3c1e0/analysis/1458225851/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eac3bb-e854-4895-ab44-4c5c02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:48:27.000Z" ,
"modified" : "2016-03-17T14:48:27.000Z" ,
"first_observed" : "2016-03-17T14:48:27Z" ,
"last_observed" : "2016-03-17T14:48:27Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eac3bb-e854-4895-ab44-4c5c02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eac3bb-e854-4895-ab44-4c5c02de0b81" ,
"value" : "https://www.virustotal.com/file/aad79a4d8083ee17b4693018e660d66d9b039c9ae88ca21959bbd7cb9fdc35d5/analysis/1458223150/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eac3bb-4b48-4f7d-8bac-4a1402de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:48:27.000Z" ,
"modified" : "2016-03-17T14:48:27.000Z" ,
"first_observed" : "2016-03-17T14:48:27Z" ,
"last_observed" : "2016-03-17T14:48:27Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eac3bb-4b48-4f7d-8bac-4a1402de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eac3bb-4b48-4f7d-8bac-4a1402de0b81" ,
"value" : "https://www.virustotal.com/file/d314d5b902fe1e2dc46e133732e04b2d15fb5cf6f8a725ac1bd7c5264154ae3e/analysis/1458219112/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eac3bc-a7ec-4fef-876f-4dbb02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:48:28.000Z" ,
"modified" : "2016-03-17T14:48:28.000Z" ,
"first_observed" : "2016-03-17T14:48:28Z" ,
"last_observed" : "2016-03-17T14:48:28Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eac3bc-a7ec-4fef-876f-4dbb02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eac3bc-a7ec-4fef-876f-4dbb02de0b81" ,
"value" : "https://www.virustotal.com/file/b43dc041a17ca6714cc49c1731f348298fd34750774e7dab6bc5c4aa4f69b8f0/analysis/1458225852/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eac3bc-f4f0-4364-b50c-410602de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:48:28.000Z" ,
"modified" : "2016-03-17T14:48:28.000Z" ,
"first_observed" : "2016-03-17T14:48:28Z" ,
"last_observed" : "2016-03-17T14:48:28Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eac3bc-f4f0-4364-b50c-410602de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eac3bc-f4f0-4364-b50c-410602de0b81" ,
"value" : "https://www.virustotal.com/file/abd2ecce75354954bfdbc859c571dfc04bc7fdad6a6d13306e3a08e48b55fc24/analysis/1458222597/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eac3bd-31cc-4257-915c-446702de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:48:29.000Z" ,
"modified" : "2016-03-17T14:48:29.000Z" ,
"first_observed" : "2016-03-17T14:48:29Z" ,
"last_observed" : "2016-03-17T14:48:29Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eac3bd-31cc-4257-915c-446702de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eac3bd-31cc-4257-915c-446702de0b81" ,
"value" : "https://www.virustotal.com/file/4750f1a883b004a783c8978182e0279df3f00ca52ac4770fef72dcf33aa52ba1/analysis/1458222882/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eac3bd-5778-4e85-acae-49dc02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:48:29.000Z" ,
"modified" : "2016-03-17T14:48:29.000Z" ,
"first_observed" : "2016-03-17T14:48:29Z" ,
"last_observed" : "2016-03-17T14:48:29Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eac3bd-5778-4e85-acae-49dc02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eac3bd-5778-4e85-acae-49dc02de0b81" ,
"value" : "https://www.virustotal.com/file/25cae9e623eb206a3ade327d437006987ae8ff2e371737fdb6c230daf2b0f8c3/analysis/1458219525/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eac3bd-f844-4519-851c-490102de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:48:29.000Z" ,
"modified" : "2016-03-17T14:48:29.000Z" ,
"first_observed" : "2016-03-17T14:48:29Z" ,
"last_observed" : "2016-03-17T14:48:29Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eac3bd-f844-4519-851c-490102de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eac3bd-f844-4519-851c-490102de0b81" ,
"value" : "https://www.virustotal.com/file/531f61b67638db502e413e75bf753574643907186a77ff8422d0cc511ea1f45b/analysis/1458220089/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eac3be-7d50-4c59-a0f0-492402de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:48:30.000Z" ,
"modified" : "2016-03-17T14:48:30.000Z" ,
"first_observed" : "2016-03-17T14:48:30Z" ,
"last_observed" : "2016-03-17T14:48:30Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eac3be-7d50-4c59-a0f0-492402de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eac3be-7d50-4c59-a0f0-492402de0b81" ,
"value" : "https://www.virustotal.com/file/53afefa1c4657a5503c6b81292f0fbad9dfe190f5c313004a351798374ed6369/analysis/1458222964/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eac3be-5674-457e-9a66-424f02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:48:30.000Z" ,
"modified" : "2016-03-17T14:48:30.000Z" ,
"first_observed" : "2016-03-17T14:48:30Z" ,
"last_observed" : "2016-03-17T14:48:30Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eac3be-5674-457e-9a66-424f02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eac3be-5674-457e-9a66-424f02de0b81" ,
"value" : "https://www.virustotal.com/file/38cd48d60526e77711d71245f8525a982803e97faf46b366a0c8e147a3d37a50/analysis/1458215292/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eac3be-75bc-4d5e-a326-4eba02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T14:48:30.000Z" ,
"modified" : "2016-03-17T14:48:30.000Z" ,
"first_observed" : "2016-03-17T14:48:30Z" ,
"last_observed" : "2016-03-17T14:48:30Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eac3be-75bc-4d5e-a326-4eba02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eac3be-75bc-4d5e-a326-4eba02de0b81" ,
"value" : "https://www.virustotal.com/file/d3c49c72a345734c0ee2aa9ca1df121c793bdbefc0055168238436c0ff9db76d/analysis/1458216455/"
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac9f2-f6c8-4ac8-a41d-47f7950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:14:58.000Z" ,
"modified" : "2016-03-17T15:14:58.000Z" ,
"description" : "Download location (via .doc)" ,
"pattern" : "[url:value = 'http://bakery.woodwardcounseling.com/michigan/map.php']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:14:58Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac9f2-8c28-47bb-8c21-4e0b950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:14:58.000Z" ,
"modified" : "2016-03-17T15:14:58.000Z" ,
"description" : "Download location (via .doc)" ,
"pattern" : "[domain-name:value = 'bakery.woodwardcounseling.com']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:14:58Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"hostname\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac9f2-7d9c-40ef-8095-47ff950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:14:58.000Z" ,
"modified" : "2016-03-17T15:14:58.000Z" ,
"description" : "Download location (via .doc)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '176.107.177.85']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:14:58Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac9f3-a41c-4e36-8f5e-4873950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:14:59.000Z" ,
"modified" : "2016-03-17T15:14:59.000Z" ,
"description" : "Download location (via .doc)" ,
"pattern" : "[url:value = 'http://groccery.woodwardcounseling.org/michigan/map.php']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:14:59Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"url\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eac9f3-4068-453c-83db-43d0950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:14:59.000Z" ,
"modified" : "2016-03-17T15:14:59.000Z" ,
"description" : "Download location (via .doc)" ,
"pattern" : "[domain-name:value = 'groccery.woodwardcounseling.org']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:14:59Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"hostname\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca0b-89a8-48c5-800c-4c43950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:23.000Z" ,
"modified" : "2016-03-17T15:15:23.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A O x 5 c U h X t T q K c S Q A A I k 4 A A A g A B w A M j Q 4 N G R j Z j A x N j J m Z D V k Z W U 5 Y T V m M j M 4 Y T R l Y z A z O D B V V A k A A w v K 6 l Y L y u p W d X g L A A E E I Q A A A A Q h A A A A 6 c 0 G f r n E d o G v n k V 4 x 5 q m E Q I s E m F 0 a Y / T F x U 0 F T a 9 x r M + L H l F h o 9 m 6 M 4 z z K C 5 Y e T N u i G J J I 5 w Y a 6 X p e y S z B M K R a u K j 9 P s J s b X 0 s s I A s 61 E f D G l J S H O f L a X 2 D S u p q K F q e t + R 1 a 1 K v 7 B s b + t G M a k M O C 2 u f q c l n e r k V k g t K 9 n I j 9 r a P k Q 67 y 1 y b t 3 M z 59 //+lsJqKZVQVFy9qWQ4VSYA92T+gSHx/PBiHe/XnFr8tkH0pTZBs5jP60DTapjSwP99JjAOmPtybXD+suy/sAwqrKDKTLL9MasZ67CHZ3laeLQiZscLxAnyPScXdX4MzmCluMMP5rAAAzT09yN/NxZUQNA7y9+r0Mv/JRFBWLl94sadukf2QdpspspRrvlZ7n8T7Mwl2IIRb7aBhTMcECwNJumbiw92H2Ndtt2ffzAmPh56PXQQ1lud+TtadBQQo8fiGyaEgVxDNPMEbAMXaCAorfOafst0I7UDKV8OPCOk6rzwy5I9wcllnmwYIFKdF+nI7Q0eXTPJonai5gY4ONTEl1dJsmfmY0uH9jfVpbg1voOkAOZXoKnzyWagOLNsu6HE+elKjHoM1wL8PcMr3FW4kXvSOr0Q8yyRkorkW8jqrRuVDPTlqs4qF9QoAenZsifwuLr0Oq0sQiz4Jzdbes8iXXaZ1anU7d37fotXiUDKMnhdLSGMTFi49eDNByOnTq9SLCCuasH6Am3IbSJ6Z/A10MNn190AFnQN27iqnv0ZsoTsUt+2ax+NASpptG/qwfuzV2icBEV8GJJbMbae/CzH6IUXKI8GG06qchQiY0/IX6CadXHCUr1wa4kYAdMZWnN9o6j8Z/cXcDWxdn+EAoKVPyIGevAnGWDdhOWluR/NszRfDIU/xTPBoctiW43O3DXX2nUR93o4wMag+C76biGM7poaI6Bc/OS51fdz6LIZpuZjOjRmSdN9Lse7K4i5M+/ZAv4tJq/8n2hCZRE4ooNFe5e02oz+sfgaaQ0qNX9MVqtgRL8+xLdiYNPF8IQILEkNKi4G/unhEkDflrSUUetlqtoSPj8ra4UfQykmdOIsgs6xRzzGbfOkVpNPnBoeiZKr9VZHInRTRmA8dB4UBIYTgeH+L+76RAWUCqibPVX4P6wEOOS51tpntpg3APKHfgK6Gsbs7SibWTKkXwCnGLDNme9xLkrN1xT/2mScP/dNxtidGPqMhu++m6pPpj7Jn6aWvCjnq8eDxtluWBHJGxRQ3QWnx7hnByqDBXJq8ovoWfKgZE41v5AdhWkQCuU6ZRY0uNPT1QwH+Ec05s1IsQpdvNjcPOBjT0yAb+tsTnFejc0PV/QRzwVPkhfn8YcX5AIGpmpK/rHsf5zR8XMtX4uvdYSjJtxhKMaDXebS5b4boNTbycRck+nZg8So3TeEltrpnDX6PRItFYLzwjI1FwVK5z3ciOC3eeNdXHZcFGPALyf7Mc2HJ2bTfDOrJ+7z5C1ZlQuGIeeN8wIhCOxV8mk+2vHa4vtCDbN4fnNaVr5Oz2ZIgwFUAmi9/L60EFoEokK5vdaqT9ykmH1CzwowMNlUzEx+g2xL1hJlEGcMjkffYC5MXxRcrpDOxhAjuzs+22ZIoyRlYd1bB3EvVD4SEDC0DrXHMsimH3lpsn3yu3Cr42ScTfUa8LCbL+W/2iMpmSCm1oPeXqBHICtMqa+mFn5upKlFshxzFDVyszJ7+B8bJS4j51BVkcmr2wcwC57tE5QfM2Tu3LdKic7Xq05j4H4FZ6BkyHS5pxHF12Mwm4aC6zppxjZx8/55pMH8/Zfo0loFGewONGuKySt/mYRyi9dLwrPlr6mvTPS2o/X11lkXe+DnrHt28f6UbIdqK4xH5s49mVliFMdY1yaIlSu/IXpusVuyEs+L3jcLBcWerw3eRhxPDJDJqhOZtNUiVgDecOhkZ/IJ4F5obrIK96+R5yxYkruEOSJGVEKpTHaCqiWYUNGr+6oSXALs/hK8+iOG6wCOMrmnUWmwBMTb/fa+kQWGxK0Pu6d9Ot/h0GExIffyJd7XiEORAv0phhJ5s89TmV2mp0IszeVV7jHLraHLUHPCgrWm8go89HP3H0h5nntIoyRopVuUKb0Mrx9dwwm3s8sjecwDnyccKwuzl1LNMTr1arYwbUT2wldsnLaaEsA6LDw4A2xTXC8u2xyAGWxOv8JoeTd+7uzjO9NuNi2Kq58/LBA+wZl1jJzwHTACg45jMp0/JT7DWdOR4kQCjyWaE5sRJXgusF9qasoexWVhlhFil+nK+Xv2BefCjh8vtpl9TMC8kpw70mTNjucpwupDkKLPy7/oq/D12GbrnZWhXWui2XElhIlXEZAJvbcKx6weNRHoQUpuf6B+YYFFoGoVjXJ6DI0xpSSDYfhhOEY44WK02unZfoOfwc+34r/iNLqPi6dFbkKNqLcPY06hvWJQxGBrXo5YQC+k9LBzrjahL/DHR82NIatZ5IcZBG5o6uzSY56dD4HuBDd5HO4PMjDg9vnQxHRGZUbA+4heAdhnXu7xGWb26yIR8ZqA9xD722cTAnBKjiB1iZyqup/7/kbizxGurAO+RcVk16vrxck1ygevOPR7S/0PjL96Mmu4ohBO6K30vX1DwZVQYTNpSR/jSc46Ud86dpbibKEGFqkKy7t0WU2toOzHrexMIXSL7At6Okun3UpEM58Wiktz5Zf7nNohThpRddpOuFNyQwbJr41SZpFFklRhdnhCcEDqB0r7ukHRJ1ctB91S+2JNKaotV8nqDs0tP9vh1axbJ3eAFa7+VYg/+POiBd2BsRewpoO0krSB9g48R/6n1cYrc5GsUpls3PAXHMPkepyl4b7hVeQ9GHdD7Jy/JioMgrR7S6xb3N6jelrwzdLZdojH32ts1Ut/Sh0du0U1KriBF8GMKi2dNOQVxUxufcQK0TxWG0B6+9mRW3gA8oRhfR3BBqjbMe6CtkQ1IM9bcvNBNbHnJlu1On3LiYH+OK6qaxCL/i4lVFyzzXFCX64FsmbbMvjz3QtDpEpyUG6ZSLL40OJ2KKCL12hzbg04/URhOSQyPLB9obbuNK7nspjYt8NTrohuLmCTtBUKDS54gSZ/TlcmcbHsdneJMast43iINaen7lONAqICfMbItQMpopKk1d3bkZxbXPQt3MksIxMztbbkQD+KJWvGJhiY8JqwPRGoYIQxTEMue9h5/5tExPYDOMjhmxj6FEjw5571dZ6xN+bXYMJZpgvZ1IPcRi0LI/ekp7qesrENbg+tio2XL+z0AbrSbfdDj/ZOc8Zktaj4Vq4elmNZOdb2Jb+8rnzzBBiML0vMq3fCRmgZQgjNFAFaIj17LC+cARkVWOP21y2JjiUBvbfvjh6wM0sC0weO1pZrcW0csbcYObygLGkqEqv7TB8lXIWLfyneLzdvoVN6x1Cu0zxJEvGnUaLpio4gr6JvTSq3PY55ZlMlCb67wpy0rkxoxzQUUZ4teI6v20ZpPLtnNwLkmNG6wPlSLUNwhR0ZwZqzePY9qF8mDVd/YfdVKnjvbu8Y6KPk3jesOPRWy1zacolalhsC7jZIQ3xmLICS/1f0n/wad14uYm1f/V3oPHuSHdPvzy8fCxvx7eWv7V8WT8cXqYp2Cg4HkovuoIPfNe8W82vp+vFZ9R5H1HOcCoMuza2LB/EnsL5xzl08UJik9XJXqHEYNf5FIrKiMK73iwEX9fOYrsuQF2gmJGp7k9D7/06lyrjvrsK23ieB9p0tHsOrK4TLdBolWaoUmGyVZpEXKCoc6Ucj1OhjKM5/ZPU5TQLfASKTmCCCRjtwRwh+UT/CV0nTVG3gvEoZd6CgqjwC+6xxVOeTaCSHCe+HZlhhtZTWle9MXuLd9XgCH0xX6bsL5ZQloAJAawrGf8N/BreL6MyNF+L2Lb7H5EmL8DTCyx3ARUuAPWAoT6lqhy2ogH
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:23Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca0b-0dc0-4e7f-b549-41bc950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:23.000Z" ,
"modified" : "2016-03-17T15:15:23.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'bestellung_013-adf2312827a2f5eb.doc' AND file:hashes.SHA1 = '875361fb375952f3928803a66b6c87ca9f80665a']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:23Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca0c-10c4-4c06-9e71-4009950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:24.000Z" ,
"modified" : "2016-03-17T15:15:24.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'bestellung_013-adf2312827a2f5eb.doc' AND file:hashes.SHA256 = '63ea608da741f812883454c8c0ee8f167ba5ee1bca829540a41d493842a22001']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:24Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca0d-1c44-43f8-84fe-453f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:25.000Z" ,
"modified" : "2016-03-17T15:15:25.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A O 15 c U j 5 A x m j d C Q A A I 0 4 A A A g A B w A M D Y 5 M G Q 4 Y z c x Y j U y Y T M 1 M W I z Y j A 1 M z Y 0 N T M 1 O T k z Y m V V V A k A A w 3 K 6 l Y N y u p W d X g L A A E E I Q A A A A Q h A A A A y 9 G 8 I K s p k L D S G P R v 84 H b n i e 4 p I V s 3 Y h A F o / N I f Z m k i P m 4 J U 47 T B j U D W P e 8 V Y 9 h r k 55 Y F x Y D a B Z g w c 2 H A M k o R c L s o 0 W 0 n B i X d R s b a + M x G J c M 76 W W J 1 v p 9 G F k 4 e T t z D n 73 s A 8 o c S o Z 2 h 6 i Q G K d u a T g 2 q + S k L z C m Q a p u f z w w o i b + e X G k C u H b G W w M l 9 D / 3 m A B T z X e j x 7 e l w e Q C q W E J S d S z A O L i 6 t / v g k d W w t Q W o 5 I / j S r 5 o g o z C z y q A T H 9 + p w M C 6 h S 6 m H P X V a e g j T v C x 7 T C + 5 d n / m h f W S K X h G C I C 4 b O 4 M M c G r 7 y O z e f D s a 74 n I R i C p M a f Y E w x v J f g v h K L 5 A D p B t X 6 P q a d a B m x 4 o D W 4 q B Z h N Y P k p l i L h Y D Q 8 s 4 / + Y F D G x G w 8 n 4 N N n + p K O a J J K p m S Y c l 3 k z x c G A v l 8 h r o 7 l V Z s j n I h A D D N S 5 Q / X O d B w O J o G k c z Y N h j M W P / j F I t L d 4 w 9 b k s g f + 2 e P 1 M P W T K + h G G F 71 Q 1 B Y D + x 2 p F 4 q d 3 t 273 y l u X F + N N 2 Q E N 2 K G z b p 7 l g 1 e O j + g n 51 / e t A G 23 M I O u V b 8 Y q l Y S z / H / y R 1 u G A L T c + S h 9 X d J k a 8 Y U e 0 r 5 i 1 o P 7 f V R j x d Z P L G 6 C j h R V O n P b u Y s q i m 2 L u c h a i B E k 10 t g 8 e X 3 E j L s P 4 K 4 t W I T v 4 O V 7 k c X h q 2 K r e M 8 c u Q M V O L B G h G C p a H F 8 f i W q c r F U 9 m E J B P J + O B a Q O B 2 e N c 3 A A U 4 Y a m H q w + X y A C e o 0 Q Q J 9 Y 5 y B L K + + L V i i c X W K X I + p o G 1 q L b E c f o Z N 0 M n b 55 X o P X V q O 1 d E Y o O n E 1 c 2 c K O x S / h F h S N 98 t 8 Y A t f A X B I x r U q A X H p t 7 C q t a W D e n + v S c 7 J y C V U j r / d F 1 M w 6 g 538 s / Y l 523 s u z P z 2 j p v / p N k V h m n N m 0 h f i O T e d A h 47 S 87 r 5 j s 5 W 8 / 1 s v s 33e9 G H B A V n q b d G G R u y e B o G o u N s Q 4 E P p R t 2 i 70 t R u G A w 7 C O / 2 R q P 3 h 0 w h Y w A R 4 W E 3 i T T 3 b Z j x S 76 H G w h 6 t 8 N + l M U 7 C Q e d 5 I 4 p v w c H w C W l d m l s f f P Q 7 G 5 P S R 8 F t w + 4 H x L n C l s D D Q 9 G 3 i S Z 2 J 5 h S T o v J o o T 9 t K m 0 J Y 6 k R q 1 + j I I O 6 x w E 0 C 2 T + X O 5 V 0 + N 2 + Z u v e E U 9 y B M v k y T E P e z J w T Q c h G f q M b I + E G / C l i a u h W A g d D 4 n K 5 c + x I s J K P r 0 p 5 S F a x 5 s H q G Q U 9 r F Q y y S t Q c Z 8 v 3 h n A E S 2 p J s a v k c E k C c e d c B 4 A z 1 r h P W F F O t f 6 m / u z A k H o d Y 0 Y I 0 c C H t 9 D H 3 p X 1 c w 9 g o O s C P E p E g S T A v 9 m / R H 5 c z F i C k k E Y f / B g D 6 Z K 13 F x o v + X / e Y 0 Z A a U V q 0 J 1 H l a R c v H 3 B j + G S A s O Y E H j / g p C + g K F t 5 c r Y v u n Y H l K r z C z Q e e 2 k X u U O I n g s J I M 36 G i O D i c Q R 6 x 64 H b z G C O 79 w B 6 i 1 + I T 5 a K s 1 h l p i T U P J q 1 U f K A R i C N r x o n x + i n h I k d P K z + E A 7 + G p h X v F 7 R A Y F W L + w s W X g w g t Z Q x r W E U L 0 V / W 1 p g K S k p m P c a k U B X W 0 6 I B T L B r G O L n / 7 y R 39 I G j M N O x F d K 0 Z o G 6 J Z F x 8 b f N Z R 2 d D G Z g i W q R 9 O I c L + H l C 4 + f n x Z H Y t E j 4 o z R u c n b c I s E L I 7 E T j 5 Q R i 1 V a r L f v z A S h A 1 F 3 Q F S 0 Q k G s E L A L r B C h V s t H w p q U 3 Y A n H z O 7 M i K D p i R Z P d G 4 w g r l R s B u K s T g r + m v 73 Q K A N F E o L u G o 6 a B v o o 9 R z J 9 a W 6 A R + + d z k b q y n H Y c z E y A J 3 F Y x b 6 d 4 O D I l g e D 0 54 S m V b P x / w n u l r N c c K V 0 A 91 N Q t p L n G E H 9 d O T F z 2 y F X Q I 1 l T i W g i M K u Z C F z 2 E l B Y q e e 1 H T n e J j N O b n L E M F B p A X v V M Z P U + 9 Z 0 P Y V 5 d 8 q 1 f a 3 r r 8 k p B 3 n x 0 C O 7 P z S A + 4 Q d 6 R s O n a 5 M p r M e q 3 K J N b S Q i N X I z D Y k j 4 l q 4 v M y X 0 Y W t z 423 o / Y Z d K x M L d 5 A h o G m w 6 V s M x Z K D D c J E s 1 L Q d / G V k 2 B P v y e L E l u B l y 9 b 2 K C S N Y H C y e G N 9 N 3 m M h v I 22 J 9 i Y / g U i A H n o N 9 w 8 b m + W p B 8 r y 2 P R J Z 6 v R D T 13 g s d 0 0 i O t v 1 a z 1 w 14 U t g C k m 2 T K I O j 9 S f q a t r K 0 2 V y 4 Y s b g Y V 1 k o x D v / R q I N g R O z S d 2 e n w e k k P s y c E o K B W / y 3 T f 0 n s n C D R P L c X X e R p O u / M H k W 4 n c 5 H r w m I o / G u Z f i l 30 F w j B w u H q H C 0 m N 9 D J X O 0 1 T Y D 1 z P B s K O 5 V x I R n S w 3 d C A w q e g Q / y g r 6 a 7 e z N 2 R W I 1 b 48 j C c g U F 8 X 4 V + 4 a 2 Y r Z 6 x G 2 U B U V U v f F j Y f J g w k 39 j G G P j F 9 t K h D v R G 4 y U r 2 P s n f r 3 V 6 U y R g v i P Y W g w s 7 I L k Y z 7 j E 996 E F O M L V R f 5 u L N 9 k R a a 2 G j a B e k e p U O + l S 52 b H T K W E T c t h X 0 / Y S 3 r p A f X B C v 2 V 6 y W G b Q 6 y J g Y 2 e i y t G Y 1 + 3 O t v r Z d a C i 2 M O S 1 u R Q w u j 0 A K F 8 + j i j w 5 x + q I + m c e X 7 d R 32 d W u T c v g / z 7 m d L H Z 79 w H t / Z j / F U V K c m r B P 1 F a 31 i d q l d k X 7 H e j B g C N N 1 G Z n L h E 2 M r t L D F N Y 9 W W B M X 9 R X L n K K R T M y Q x O C 3 M v o I v W o y c z K 0 x Q f U p f n W k Z 9 O F 44 e f U b H b C 6 + M C 6 F O s b 7 N A G 3 z 9 f s r G s P E 5 j Z / y c 73 z + u 7 m q 0 d k y L 6 X 9 P 5 x p j J Z x h o Z t 55 O B q 0 Q p q g G p c g W d G 9 U z D c h u f h Z P R v 9 C b E x 3 Y + G e f + 7 c O W Q r O X j B 0 P 9 x X J 3 a F 58 f / l M s W t X F 9 h E m m R N b j X F C Z i G L Q a e i P V i v B 1 q I B Z l Z p g q i t w Z P b t d v F v A R g f 2 x N W D b Y n a J k e b b T V 9 J M P m x C B X g l F M c E r f D m c 21 O d L i F m n X t 7 u 0 g P 8 d K 4 a t 8 j d L c m d r Q z C C K G A e 3 M p G 2 V s E t H 1 M 4 t 9 u / T e R r n W f e Y d x P 0e0 k t w 4 O l l 9 h 2 v O / 2 L D V U 9 O V p Q 5 D b t C 0 X L 9 H O 2 o B K 1 r v n m A l Q B V g R U 4091 k U V z Y d p y T d G 7 a U Q j 91 k F Q v x 7 / T 35 E o i y n B z V f e P N V a 4 F 7 h B W y R H O h r x a a O 9 i e K D e u l + P g l M k 5 X E A d u x e g s H J F N I o J Y E d W G v L 1 E H M t g q J V j A P c F z M r I J G 9 J g V Z W p Y Y E w X K / D r I X k R K m 0 0 I C V / C K G A G j / O C r y m 38 Y U W / V A 63 P + 6 r z g k X y T B J t U P m D P U T z A z / 16 e y Q i 88 / 8 R / S t 461 z B O A q v A L e C i Z L H f f H a v j X t 5 Z M w f f K S K k S X V F Y e B m e A t q s 7 Z j e 9 Z V d S p f 0 r o g Z Y M o I M + q o W F e d I X H w G i t M u b f 7 A Y 0 f z w 8 w J S h 6 W 7 f 7 v 0 Y p o E 8 J / I b O d j D + Z X i F e Q K G i 1 l v / R j 68 O R L E j a J E o N z a 3 Y a I v 7 g V x e v a y J S D 3 X d R v X A F h N 6 G V Q N F 3 c d P B N V k X O b j a 6 C B j F S 8 W R Z 53 L 1 R S N P 8 Z 1 n H E o D 0 9 r R 5 c 6 s Z D N / 9 Y N 3 o 0 c q a 45 i V E Y T a v O o P 9 o L I 7 q w 7 z m 2 N L P R 1 T k G b Q i K D S 8 M A o e J m F R W C v A f i I S e 36 B j X N R h d + t n 2 L E v A 9 y j Y D G c a S k F Z 63 g h g d Z i V 3 j a 4 O Q 216 p J R x V m z z V u P c 8 X T m y T k v O A m M 7 r y l 5 M E P + 72 z I b m 11 s u 9 h U V u O Z c t 5 l T g Y 7 T i Y G w 5 l m M 9 b A Q 3 K w T 2 W r m P j A d 0 R t t n t T R F m o 9 S z d N g t 2 s e D E T O 32E83 g w 9E7 t s d K i Y K 0 y 7 a D z K 4e4 N x J d O v W h Z k d e c t J S j U d 0 41 W E Q I v I D c 2 x v 135 Q E g J 1 v P a n B q A 2 C 3 A X z l v p G S a J v K 7 c T L K W E H Q b C 1 s + / M x A 24 I V S Y R 58 r J u V E 3 C 0 4 i l n i l o Y / 7 h J 1 Q u 6 j z Z l 2 W s Z g 2 H I 0 926 Q h Q g a P M 5 n 5 z Y w U u 8 l t G Y t l p r Y j / P 1 + T d N + + 3 g g k O m i / e f 5 D D 9 w u X v 4 Y T D j J m 5 r G n 17 T C v d H c q 7 W U r 7 N 6 K f N q u q l Y u R z N 6 j / C g b V v C Y W 2 q R n B j v D 0 68 Y f j X 3 e k o j / e a L i c 4 p F f o n C O N 5 l a 8 d h L N L t B c 28 v g o i i 4 T E S X k i y 8 U f U 7 I u C 4 U I Z h 90 Y s Q z L A a z t 7 I 5 l 1 N y x D / L t M r i 1 T Z S v V J l s t n D 9 Y U o m u E M M t S B c N Z I j / w U P X 3e8 E H 8 t L J X M E k
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:25Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca0d-5910-4bca-b0b7-4489950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:25.000Z" ,
"modified" : "2016-03-17T15:15:25.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'bestellung_020-cuajhfmy.doc' AND file:hashes.SHA1 = '69d602034569c52d31cc7301ef27681ac0c44eca']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:25Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca0e-81d4-475b-8938-4ab4950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:26.000Z" ,
"modified" : "2016-03-17T15:15:26.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'bestellung_020-cuajhfmy.doc' AND file:hashes.SHA256 = '188e5ff3ad3e4294e2ec9bb760fbf3eeb0319568d80cc2df8d369d89c6cef512']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:26Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca0f-17b4-4ec8-964d-4f92950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:27.000Z" ,
"modified" : "2016-03-17T15:15:27.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A O 55 c U j 15 w l 9 c S Q A A I o 4 A A A g A B w A Z D Y y N 2E2 Z W J l M T g w N 2 E z N j M y O W I x N W V j M j h i M j J m M D V V V A k A A w / K 6 l Y P y u p W d X g L A A E E I Q A A A A Q h A A A A y 9 G 8 I K s p k L D S G P e S c J 0 g M 81 Z 9 S y O Y K O X o t n F K q n q 5 q S Y b C H y E 7 / o W e C m c c m c w l g 2 g / D G E l b m o o t f O 8 l Z 0 K 7 N Q 0 j + m l k d R B H 5 w w 4 B x V R H H N x 4 c A B J s y n C L 2 b 4 H p d w J / I c o V h Z X a Z x s J n O N a i / p E m D O P 8 c M Q Q x z J l r c F B a P 6 R n v M p / j N X L 6 A 1 a m w f D R W F 7 J G 97 D + b 2 B Q j x H T x V 620 k Y T 7 p y A w V 1 Y p W p S q S 8 A x H V 3 m X L 0 u s 0 v x G 0 U a g / d g v 7 a C k 1 k H t w c 4 N G 2 a K U D c S K Q 59 D k x 99 r e c z c J i z W l + + I R Z 3 u 6 v m 4 R T C I 0 z W f C A b p d o L G + 35 T X R M R 2 L J 8 r t O + F m 5 T J 5 C J n A n m P m 6 N v C x U S o C o e l A 8 b N X H 1 C T u o Z L v j 6 Z 3 T J L P j a F x O C t Q 11 I G Z m h T K a Z m Z C h p x W a m H f U w L Q M p l l d 0 G + u F 1 M 24 / X O + W P u y 3 J L L N F G B s E E a G 2 N u D 7 P Y k P 4 R d f b g 1 A F B y h o Z L Z a F K I 1 c j s P T i J y n 4 H u D H o D 0 3 + q r x G t y 996 h j / w Z p z Z K e i z j / P V w L 3 o 6 g C 4 A m H N I 0 M I + 2 I F K x M N S P z E D O e l Q 652 e B g P M 2 c t Z I C H u J v F 19 I r Q z + L u Z p m L f t / e Z x w + y g 1 v T u 2 Q v + W p E o 91 + 3 V e q 7 R l 68 D b 9 G e Y g t x o i m 2 F S n I i V e H n q k u Q Y E 2 c 9 n U O e U / q 0 u K v 1 s g x z Q i 1 E V d v p b 9 C y w X G z 3 h + P T 5 T r C 0 P W X w 6 D O Q l 3 y k a c H Q s F N i s F a O J M F 3 Y T l c Z E O o R 7 z S 6 Q 8 D y Y H K f c / 7 r J K 0 C p 2 R S B P X O U w d u i r a l 0 h M N 4 m N 3 U A y 68 C K K n f J D X m a A K I + p b 3 r + s z 43 r y 3 O h 3 l 35 G 6 m 40 V n L u R i Y B P 3 O y r b f j 8 y M g M A 8 x p i L 3 a H 2 X 8 / y x 4 E c 5 g F d 62 b Q X p D p y 9 a 5 U P v P l t B 6 I t p E M r M 17 k t / y + V b m D Z Y n U T / D 8 y G Y 7 l G N 73 x U Y z U D x k 4 U t H l f / t 3 z l V a g 7 G 2 Z G i g z w Z w C T e l B P h w c C h 1 r 8 v m I P + F + i k + S Z 4 c l Z x 0 f T g F / O M + o I k B a p i U r 4 I V P t K N g P p 1 A h Z 3 F K w h E x e r y H B F P D Q K K i 87 C w v 6 v S e u v n U K 217 n j T P M N P r q 3 f k c u 2 s x W A O R A 8 T 9 L s q k 5 G 2 w f 1 I m z U q 9 O Z A n J 2 r 9785 M t g D j t 8 Z b 0 j v m a R E Z z p 8 r g j 6 i X b k S h 5 k h B 6 K C p Y T S 8 M B Y V d j 7 U e n k z H y C Q y p T 7 n M j J H P d u F + E + n L Y C 8 T M y O B j J u 3 T 6 / W s f 5 c F 414 t A 0 x x t 2 w C R 6 d K 0 85 h W G y v E V u l E 6 G w T v 1 p i v P + h d U l x B D q h u 6 Y b d 73 W 88 B K s h C 7 w c b u n + H D U H 7 v E T k z f z C l U e x A L Z y 1 Z e i O 7 m A f K F N F h H S O K 6 k O o M 9 U c w A 7 H D s K F s 8 S b a g C 4 + o E E K n q H q o Y Z i 34 q O p R A 2 N b V X X K g 7 c Y G B S R 7 r 8 V / d Q 18 O r P c j Y x e H X T X K b p 0 n 40 i h a N C l X H f N c B g Z + Z z 7355 u C W 3 P E 321 V M f L E v j B d 1 u 3 h y V n 5 d e N 2 d b q E b H 9 u E G U u / y l l K 1 Q N 0 d 2 m / Y p c B I F X r H E x 1 v r F E 6 n c e 7 g 7 / r 2 K 9 X V I d A 2 m x o j e O g H 7 V m 3 I X 2 T a n E k o 5 f W 4 B F P 1 A l v H z O M Q o o e H h 4 t i 8 Z M / r M p f 8 Y I 9 P + z / H q 8 H W B P D 1 O h f t e 1 h T G G 3 k i t f A L J L M v g t s z o x L R Y Q c R y L e y W Z 227 u F O X 4 I R 3 w g 5 T J X F X u b C 3 p Y N y 2 x G f h S f q 7 i E I N j Y k c s 9 n w w r p a + w 8 J X D M o 0 C y q g q E j z / m N z C q B H j D B e s x q e 4 Y t 2 + d 0 J 15 b P + O M O a V P 1 m 85 I k v Y 8 M 1 l X R Y y d m n M Q n I v h k s a Q X v C Z V c 6 F r G P f U P / p H g P W E 2 X n C D y g f / U D b 42 U A R l 7 A D A j q C + y A R / u 5 G e n w u S R Y E h p A Y z r Q t / Q G 26 I K G m R g o Y E Y U Z h u T n i K E T Y v S X M A Q K K B I W U I z / J t v t b q u D Q E n Y 1 u c T 8 k h u 5 L 921 x f 8 m Q H f M G g E n h 7 H Y t h E n B N t Q 4 X k 7 V l Z U W O j n O 5 t X O U p M d V H t K z K n V c W D D R w B V H 5 W H 9 X m C G L k n H q j z M 0 + c R v H D Z i Y a a Z f S e u 5 q c Z Y F v I E R / F b C 4 h X H b d p A W 3 A P x S + B / R A o X l c t m L s 67 / f D w U d B j x l 93 r l 5 m q y e B H f G s 59 g R T D E K h o 0 z y u 6 Y c J A h V c c 2 i X c O q C m T L t Q / q U 4 v t 8 Y n m H T J E D W i a 2 f 7 F U n e D m s A 3 / 4 j W v C n W T q D r K B m C f A O R D V u n Q l i s w Q S f q Z S z + l A A F V o M M E s W 8 w 8 Q D C h H A r r 93 c n Y f q x f e g 91 u N 0 k Y S u b M 3308 U j T f u R N A Y A E 9 g t c O z P Y c l y X U V k M Q e 3 c y E y 4 T d B / n i E R F X t d L K g v g 1 X p J a 7 E B E 7 n z 98 h a M A N v Q j X J T G A Z i P b B A o j 3 C m D o S 3 e d R V Y B r 4 c q 2 X K j T A v X E u T f 6 s 1 T R w k X u G i B r 1 K + V v + 1 x 2 T 2 U F d d D U u 7 j E K c J S y p P J d w 1 E V g R 0 X I Y 4 L J A P B / X x v p 0 j b 8 t 4 e x i H G j z o k L y H K T j j F L Y K u i J F t e j F K 5 P b U i z Y M g t u 5 X U D h g 3 q U L m J V y U + l M Q B t s q S X K G d I z I q 9 r + B d I 3 u V 0 G 14 w I I z p p P C 0 q e e F 813 y C 5 b z f h 0E45 W v d 6 S B s l E F S V U 97 z m O 0 m s J k z X l M x a n V 45 x X 8 F N Z A E W 8 F e J q / q D g C C s F t Z e E y E I q k I m T n Q h K M + y Z + + q Q O v R M t N X r A w p p z F G 9 T Y d O K Z P C u V J v T 5 W 4 C Y F F g K M Y L f t v t u i / + x C 1 r B G N w 0 T E d V J V s G b + w k S B a 2 k W U f K d U f K X N f d 0 7 p Z D X v h W h j + / f H A j P a h h C 0 1 x t k R X 6 o U 9 s a d F 8 z p m e d r I y I s 7 u a w g I P D k A A 8 + R x t n 8 K I / d E Q A O j K O K r m t l A Q i v O V N Z t y H f x i Q K v W P N I L I I 0 1 g Y U Y / c n 1 A j b Q l R k G r d i o U W / D n o d T A v / C V M C x M Y r E y T B 0 s W P M F D 816 q t v n B J d 2 K 9 i V L S K b C A v N R 6 b g q J N Z S / o u x M e 1 T c o g P W N i X l 4 J F V y i C a Q 78 Y D c 8 P p Q 9 A S C l K M m 0 c K + N Q + A / 5 d g 3 n X r c 5 p D x P 4 Y x f i y v 8 D b X t a H 0 V 1 e s 462 S G d x g k y u d B 85 J v 96 B U C M A H D 54 I U B Q 4 R 9 D 0 M S b / 6 l R z L 2 O Y W H + U j o n 7 s o h r 7 V 3 Q 2 A U f j x + B 3 f f z 9 X j E u A W s l C 4 H 0 Q Q e z M I R M 3 M n x w i 5 D d W e I V / N d 5 B X E W e q m C / 4 s 8 O B O h f A s j 7 P N k i A j N m H i y a n N V W 3 u G B 5 k J v p 2 a V b b B d 0 q f L H W G v m W 6 + g X g o w K X x j A e j f a l a e l A t u U q d Q m O L d d Z Q s s w y O 2 u g I 96 p q 5 m A v 6 z G p N 7 R d y 41 I D M a o i z + u / q E H l D r y P w j I J 3 N Z J q y Y I z G d M 3 h G U 8 L s R D / J b l p T n G a I 9 T v L K C v N 9 R e M l E b W w R 936 z + b X 5 s O x L m R q K M n m 71 G F s G E Q / C b O H 1 m G Z F N 0 J R r P G S n w o e 43 f 0 S / 3 N J U b x h L U R e J 8 H W I 0 y j + y j o f P F W 4 q B E m z s o o C i s v 5 v N 2 L 4 D U Q m a K A D r r q R v J Q r S n / z U a a Q b h 4 X Q K 6 O i J e m D p J Y L r K Y W d a r b Y h Y z + j 4 n E 9 m 1 / i a X 3 X K m 54 Z d m f Y U e d D 2 T a 7 p u 8E5 B 7 m i E 8 D t S 51 N 1 b a l r + E O 2 P t v n e b f a 6 F v J V G b w s 37 l v z u 1 e c F J H t 0 u O K p N a X v 43 u A U W c 8 G c J p Y u B + u 6 B D P / W k O g K N F O 1 z 3 i c H 9 X O v e l K S T q 70 Q 3 M p v a C d l k P u 2 J 6 H z Y 6 N A Y J 8 h N o l R q R X c A M / J 2 a Y Q x K v p 4 w b D 7 V L 2 R A f L B t 680 Y 5 o Y q m r l h x E W 7 T w d 2 G X c 7 w J 9 U o V R i U n e d s m E A S H 33 U X 481 R W 3 L g / j K P U v g c o p A i C 3 t m 62 q 9 U H 2 q t V O B 0 W p s b z j D v 9 f 6 q p j S h 5 u 0 A 0 p p m n W r 6 X C f J r m Q W N e s i l C h 18 g C i m Q b + z 950 g w Q K d b l F Z 1 m T j + t L N J W l U C 7 B w F x v k 9 g s u q I g a M 7 n b g J m u r f x 7 d M y u / G 4 E Z u Q h N W 4 o H T g u + E G L U e V + 4 n 8 k r I g H s X F h X p x s 57 I p I I X S w z H I 0 Y N n V S q c m x K y i M u 62 f o J n P k r w L I D v R j s Y V M a Y G E 3 m n O 8 r y s k v 6 H i 0 U h a W T 1 w p 2 b k y I 8 w 6 g 9 y E L P 6
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:27Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca0f-67fc-4f1b-a31a-4926950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:27.000Z" ,
"modified" : "2016-03-17T15:15:27.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'bestellung_0061-e3cbb84.doc' AND file:hashes.SHA1 = '0a1b363a83ae8c14c6b0d0faec93864705a02bde']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:27Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca10-c984-4c93-b93e-4090950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:28.000Z" ,
"modified" : "2016-03-17T15:15:28.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'bestellung_0061-e3cbb84.doc' AND file:hashes.SHA256 = '69f5e28ba0a62eda8e9c65a5b548fae77d15644ced41513ff3b8237cdbd88afd']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:28Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca11-0a9c-40c8-bf8b-4790950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:29.000Z" ,
"modified" : "2016-03-17T15:15:29.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A O 95 c U h M l 8 u V d y Q A A J A 4 A A A g A B w A N D l j Y W F j M m U 2 Y j g 2 M m J m Y z I 4 N 2 F k M D U w M 2 J l Z T N k N 2 R V V A k A A x H K 6 l Y R y u p W d X g L A A E E I Q A A A A Q h A A A A 2 q h 9 z A Y r r + i D + m n 6 w y z z 7 M Y w E 9 i j 1 k a I a d + F o 0 0 G w R 4 c Y f X x w 1 y Q N 4 F 8 x 7 L B Q C r Y t g r l q v K g L T l 0 I C C z L O L M Z w Z I 6 l z O A T j p P j v c r n N m b M M 3 J Y n O 7 a 0 X y m Y 3 i J G 2 k J t 5 A w s G R M h q p 2 e B g O i 5 N K x U T P O n Z f I g k Y f q u 6 c x I h N 123 I H V 8 s X Z U c 7 k V N 4 r r 90 i q 6 M + n s j r U p y O j 4 V n N O G R O F o e H N x 7 j N / e z 8 O T M g r x z w q 3 W X E X G b N 9 m e I S z R u H / 15 X r 6 B e p W E 0 s + e Z N Q d 8 e p I X S p t P j 9 / z L m c I + u y v H k M Q P x K G d Q 1 p X u I 9 f B g a V f l 9 A B f s Y P s m 0 x J g S a G 6 U 9 f s p X 3 i R m W u n Y j m s C 9 c u q g / h V j F r B D y p k q q s f B 5 W w C B T p Z o N O 6 Y p P k P W m 8 L W C a E L 2 X 8 u O 3 Y 5 l l h 5 + c c U 0 8 d l I 0 7 y F C k H 9 W / f p V m w a 1 d Z / + G l h j b 2e6 L D X 4 R m + 3 D z 8 V w 0 M V q Y I l y X o M r p x R Y w O d B E s V g B 0 Y A h y l 8 m 5 W / V r q 989 m r 3 Z d k c k z a z h A w S 6 M J G R 31 v i v i P G 7 i z K + v H G b X E Z k p m x 6 G 11 p c b j K E u b X g I 574 h a x l 8 k a 3 p 4e7 M o B z n q E x 2 X B B 5 J 5 i N j 8 O z d W 69 k x R e u R j d Z 2 x S p l t s 5 k 3 P m p y + U Y 2 p C Y u p N 20 R T s 2 F u j s B w 0 7 N L 3 x w s C C s 8 s 9 N z b p 7 D 1 G p 6 c B T N S S v F / Y 7 j Z x I + R t R I W o 3 H E z U Z K k Y Q 6 G c N D F g l n 562 m G 5 q J / x M J t R k 7 i Z z I b g + P q 3 O Y J E S a B p a G q k P r Z B c 8 h 2 M / 7 a d y t F s s y 7 O o u g S q y K k M N E w x P D 0 W H u S u r s e D 5 / o A J D Z y T C q C a N a N //rla8v5n5BiWJOwEz2S/NgIJ9iD3iVSWBbz4Lb0583BZcEmCjQRh1y39QtJkQmVnUgONc1+bmOnGy8X9R2nTqWuR3NXyJlhNJmj7QjFwDeH5KYV1F3U47cVM3S0WgzVRw77rjAz2GTBQh7JncitbGEZy1wA8IC7dXl6QHrNc2ywN61wsW/FkeASxcRfwYUNkZPWJueV5PZ5DCdWuuUSOrOuyoBeIhH9NQm9sAwA71z4wnZ5tr1cHdtBc5QdS20627+ygo5dV+LtrG2f5IFfYDFYCBRYr6l/1sut2aWs/+VLxozz3sABKd1GeJdzOSKL5O87hCvdi42zTjvLaku2/tWtQylFyR/AgNzV7NEFsXJgRXZ04aDEWJzuSen3IKwZ+abuJ62YjiPnBKB17T3R9OMulutdjdZyuympWrClw/78PAaFB9wP/4fsO4SJoT16y6TjOj1bGmBdXrJreLRbSdEYrAJxA5iwRyEywj4QMWRwVJSReSOW8RmMzZg4AQ4KzfycTqkDpGeWfvnGzxplzGbqOOofcl1JFPn8nxUeqnVcTg6/1YvYCn9ZwprtXtQKXzxpgUw7yEyNJS0HzUuF+05j2n6yiB76keZ5rTkH+9LbWhrO/0fCoEBmCneOY+rJ7dvOCrGRdT/LV+KbC8hcCQNK58+g0VTHtAekHxd1F7IEchRI0o6G5SDZ/7zhraBj8Si+v/gCdDDd5fANFRPjAh3/oqERL71MWVzflhDI0LbsAxMXwKYD7D1q+nMYUnpYZFaC4qLkb7Fdel8lFjjHEr2eP+fihcL7Snd099LsQ/sFzJv2BCwsT53x8FyBHD6x7RflJ+BGh6v1D/ppZF8d9E3/buWKTry9Xiw6NlV/l3SVU6flZFf7ireR5gUmEa26ZZl1T7gHCxFK6EmnkUuty2qo6qlu5Bi94ApGx7L2I2rSI8wQj8gBmgMObb3tsdy0xi4Ue8Et8pzCNM07VKv01wOIVs5qWV3Op2msAtTcrLPq3F4nAUZI3ZFe9Ren5rlD/psOZtiNvcAW+gwcuQBmg0TdQdRX5ae4YHHSsHkX+iclE63EpXzQaZ97hIJnhB89a6rhyGTiHqGoxs84VMDR+pRGaC1oxWUi+1rnyiqnfrsKoCHQ6GPQw938P4+crCZYXO3jTsdePBMBMc+eKCbUaIOlJ+yINhdhDF+1iZSP9VB+WgtVvNCnWR78VzIwBbJFxSnrr0xN7SJiWt/PBLL4M1s9GoVBvh/lZZ5SIZUtTQNC4fNuFImnR5jODstO0+2F7eA0XWlzXXkYJI9benrIJ7Jw+X02V+JK0tmn2sphLu01kNvm3hnPdEv4VnN+Qsf5PYI7PaUrlM+LELv3Vqi3hI+YNU2vgz5sPUF9ko6FibvxvBSeLWXDdNyywDA1D57TWmjc0Wxt1YQ2CtYruqiROlpRHiWZgzDEJzVctOQmOlliry3UeYyuT0TJ5a+RmG1zNSWee76ZOuJZ+JcyHBXN5IoyRApKAFbk4TS9SGWnK+YJ1ypwb+gZDsBK8nirxLTIEF60/dN6JLDk1Ih3j/24J+xDGK65M5bU1Go/94XWPfWTl4PSMq32caqErx1MZp9GywryXPm3zIi+iDxC3RaEWQxhkIvJKkoPVXRodW4d4XG8nzKJHmjHzt9W717edEH2277x8kZQV5UVqNiaOLJFchiIFzlqfUZu0cLPgmtEW9bevbJqzn0NnGcziKGEOZHTeOQ1lzhkVGuanhU8Vi0zd79XEoQRm7kqaqFohkKgsrRfl3D5yMwahPHjn5/PbGVvWLNcC9mOnFUCohofIyFaKyYgrCFJXx9FgpWl6hiH80XfgKWYgC5jLvrIIvst0lyxjGHpZkV9JhCYHiibyL102e85VZooixZnER1ysW/872cLy/LrdR15OFhBUsvxctpPjRdyaqANYxxPm5VeMNAir7aKmejeQk0FmZ/twwoDT7hPRsDgbSdEqQCYQXAvYxH0nyZbncEPQFA+BE53HvYWwUAfLyP1BU4PQU7mQceL7yE2hec/U8J7f0JA0RJQkLs/hruDBItOSHmdr00auyKwSmiHEV9v72+k80fsNkY6ZeGd+XFdPJXbbpcntojz0vdmzmsqaSIAxRrDue8KOyf/zKfMX+J76BDVISWmQVF1SzKF4diJQuxZsHLjCAQVViqjaSK6B7O80hdpfn++mv4NDRzwQB9PepvGcLW+0iNKcDr6QNBLLykiILV0lzbOSer+NtMDadGr0RUlvm7Vxmkn4MlG5UtOYMbUz1kRD9+jyhmTsKd77Ntk4DU3f11ZNGKd3QptZbBpg58FzgIpXQ2TickFU5byOAOmrbPRWxJjoIwYMlPKKxvMXNxUR3BAI93aj/3XrL70mxdoH91/w0BzWmVBGB+6D1SpAdiFtKBTbJCikzLEoX4m7FMdMLSOA+gn+9bpwW4IdbIWgO7ppludEZVGG9tgD/+4PGtqbYUiruk8kdwrkDRHetfgN+KwscHLLvgcA5g/zeiNW41VERqA8GL0/dw3fYi2+IhdTSFwb6MnTOVam3JizAAUv7q1pPTLSJHLBk96aPlie4/E5jtCQRtPO/XE3oNYuB+eCTZZJZtZaqEp+VFmy6LdqW/JtunKK+l+QuzMbKQtnW8z4ct8jpWDGGBz0Gs5W6zzARBz3zXBTlnm9c4J7MHgBNqHdZB+OcgitiKEnmiOqlEx5qCt4D4tJ2q33Vi4/ONnvnw+kVJ4iCvao01lxFuGosv10oo7BUPdlubdVm3f4AOtsuZ0Kpk9hwgpE5HdCQ0fcXnF59R2btCnCoaBxBr9Z3sSisUahMSYU6odjozFSP3hXSIYJ6kxOstuLeyUcg8TvKICz92FJqhWmMxsV11a6ebWGXmanTFVPWB12z6xMs06N5xQ3/vSo+njblCbcBqQCdRuxldzPFlQGmD7EBErJMpRwO3IrDlK5DxbuIiMuKGSRh9d7SOejc0Lc6U2UvSEAhD4duwyqbDj8NDRjXCUIRSBAfLsMCrbUyXBVpEOHclKbHU8cDoPBmQppwkkmhVfanYotJ5dBE9Hdsrl6uKXSQYJKcdEg2Tsvh6D7PJXBrM0x550l4U9KjJ4F+1x+PLfkp
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:29Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca11-56ec-4629-bd44-4c61950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:29.000Z" ,
"modified" : "2016-03-17T15:15:29.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'bestellung_0117-0450cd2.doc' AND file:hashes.SHA1 = '2a27e668c9c6dd39ea79211056fa806d156747de']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:29Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca12-0e58-48b2-bc37-4bea950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:30.000Z" ,
"modified" : "2016-03-17T15:15:30.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'bestellung_0117-0450cd2.doc' AND file:hashes.SHA256 = '34f328ae6adca2c91733c0dbb922cef53199ae60901581785c194a9fc1dc718f']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:30Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca13-1e78-4210-8bc5-4958950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:31.000Z" ,
"modified" : "2016-03-17T15:15:31.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P B 5 c U g w F t m u d C Q A A I 44 A A A g A B w A M 2 Y 3 M z B j N z Y 1 M T U 0 O D E 5 M T Y z Z m I w M z d j Y T g z N D V l Y j F V V A k A A x P K 6 l Y T y u p W d X g L A A E E I Q A A A A Q h A A A A 2 q h 9 z A Y r r + i D + n Y I m l R C B 6 K L j m l i k + D e z S z U U U 2 n l + K H z l S Q + E i V o q 4 z + J D S N H c A 0 h Q u k p b y g 1 + R W 4 T r 5 I m j S 88 b G e 8 R D q X f O R 6 b / 1 + I + L V M r z f I c i 0 F h s K i 7 x F E s k y m w M V l V 0 p v T H d f o 3 F 8 z T W Z 0 L F o z E 5 i A O R B P u o 1 C j 8 c J y W J X u 9 J 3 x U i y / h D W 10 u T c l e R W f 4 x e W X S r Z Y n 9 n 7 o t Z X z M 9 x j W O 6 H h n q C Q x v v b c J d T p Z r k w T 0 J b A W Z C P q h B H J S 8 T u m o R / h e R t E j M a A F n K K G P R q / 47 z p C p V / I Z d v w x e 9 M Q c u e Z e 6 k i 9 U N k a 6 Q u n 6 n E p O n 2 H x M u Y o t h f V b 28 y j h t B M W C g 7 O i 3 R O 6 e N T w 0 Y q g c 6 t D i C P 2 p o F Z N c U 2 u C h 0 C r E R g U J 8 f L t I b 2 o J j 0 O H x M S Z g i 72 W f L c a N x 4 Z R T e 7 g b Z D m W + P t 8 F b 8 D t R 50 I 4 T n D J y Z x h V q P S v i F 1 g 1 q W W T G F i b 3 Y B W M Y D h p V Z L J x n m u w 2 Z k c M g 4 o t 1 A N a h x 0 6 C h 9 B I W O F 8 f B l k j Z Y r 1 K H A u D 1 a K 0 6 v i Z M z b a y q G j Z + X x k c X f z y M q C N 9 f d D i G C O q Q N u / 0 + 7 x V m k s R J 9 x n y k o z I X C f S S z P R 1 r Z D z f c l u b Z s i d 62 z j O B 9 l Y L / H N 4 o H U 8 g F d E f V y Y B E J l V 0 8 n k u U O F k E D z 6 A 8 h 6 h c k 91 R H F c w n p f s J 8 J M x d / F 8 p S j I a b H A a K Z 6 V B e J h y x 75 E N z + k r y o f c s i O T 3 T O 8 L K i O b v 7 H x A Z j c 5 I Z f e l i c 3 w V Z J t M p 1 / q J r D T L n P + U e Q J + L P T S L J W 4 Y C B H j 2 t P D a m B R A E N Q g d w R m 7 W O f C m + z n 82 U O z E E a + q o 1 H 4 s o A 9 V z A u P X 0 B T F D p m j T j v + q 4 j x a 6 a / G z d 8 p G n 4 C n 4 g 9 + h / f n P L s k i F x z r I L L B 9 W G 73 n B a r s k 8 o a V w p c L 0 F l M C e C f k K 91 M V F X 1 D f P s H H f 7 u b 7 L R 5 m m F B y v Q h Q C 7 x q 2 U 38 k E B g 11 r d k S f Y 3 x D w I S D k K m K l d Z K 8 s c 6912 N / u 8 R m w 5 F z 540 h L C F 3 i X z 2 p y C s L V 7 m U v v A K k 2 F c K 7 N V Q L g l u L B g r j H M 5 y d 0 l d j E B O C X S / v 7 q R q r M Z n J a U b y j 9 P 87 l l V e u 9 O A 82 f f 9 F P v 0 v x 9 d c E j 1 / X G Q R x L F R C x 2 C n G U 2 A r O i Z h h c Z F W P i t U f e 9 m F + k x p 2 R W / f X M P l 54 t X O x q o w m Q 6 a X G I B u z L I Q 9 o M g / e c e I h S L h l r j d + n C v W q H T u 4 i Q y g W M 9 B z s 9 g t i k 1 n J a l z d 0 / B V x 6 L u 4 u d G C x d Z y o G v V x P V I A s N T 2 L G i 5 x g F K e C T S i u Z i 9 Z g o f Y v 3 t B h I p V s I C t K 7 R c s 9 q D f 8 W R D U s n 4 q m a n S r d I g 8 D p h A M L Z U 0 97 u e y j J p A q 4 n 1 l 2 g I L D l 3 g 9 m b D S y k M H K 7 k J I F z e N F l 4 D j h e t N P a n 776 w f N G n y R F 5 R z T W t X P b p I R 9 X 6 k l a 0 7 T Q K 6 r q M 4 C t 6 m B a Z z N 5 F s u o z G v / 4 e n B 0 K j L / V i x o Y n i T B u d 8 m f E S s f C K z U P m D 4 p 8 o j 4 / U c T O T K 0 l J / v o R b B O O l B X h 37 s o M C K f s 1 / I x N L L c W k D L a B P Z g Y B K A O Z 7 M q 4 z H m M 3 Q o t V G d M z r a a F s f o W x R 81 D 5 C G C B W v + C a S X z D H s W 3 H g O m P G q K 9 P L + W Y W U V g r m o W 4 t I b 3 H D + 9 m p m Q 1 o i + X N d f 9 w F k S H i q P H R e B W X W z u U v b I d U T R e / 6 M M d g v g 7 D 5 G F Z h q L 1 m f 8 s y q H C s f N P 4 i e O q i f P 5 D 8 i q e M A X r H b t 3 y G 23 b H O 8 e S w j g V D q j R v h c C h G + 3 e G I 6 N b j 9 a N Z 5 U s u 4 y b H f n K h C g M + k J V c v K M 8 m A I p P Y q s 4E2 o I s p O k o y q Z j i q C x 35 D I 4 f N M d 60 X 5 Z M d h d k a T Y D N 6 y 5 W w B P u g B 5e5 J 6 W h h P Q A 3 x 3 N M g G B k U b f Z 0 s T p x M T Y V J h K 4 Q h l M Z i m F 98 H m 7 l K N U M I C z D d x y w K 5 S a a 53 A E / V d 25e5 F e I c C q Y K F W t + V 5 U + K 7 D 1 H h D 0 d 28 E T J n y h R V 1 k e J 1 M E 9 Q g W k 0 6 / W 0 B r V 24 X 7 Q j 8 C y W x P 1 e n Q 4 K 4 C q R o 3 x q Y / g W L m y g H T 3 V J U b + j 0 q 8 n P M K c p a y + / 0 B u p i s a h 9 b B c n 3 n h N 6 l H y H K C p k G 6 C F d O 1 k v w 0 Q s 1 E i j d g y W w 0 Y w a Z v W Q 0 d 6 r Z b U 1 K x x b b v P 4 c q Y E O k M a Q v 5 M / 4 j R t C N G J H d g I T 205 + z L R A z C I 7 a 0 d N 6 O 3 p y I E 7 P y 49 d / A M Y n O W a O 6 u Z h X T 3 n K S + 2 / S O + a l P e h f 0 r p K q u P T s e m C H P Z t x s H G f x R v u y e b 0 K k x r + f d u t / l z 88 o i q U Y G y z x k w 9 / o n v x X u g A 5 W 8 N 8 k W n q k t w M T n 8 Y v u Q q f a L m d R n g C s g o J 7 F U M n U q q J / v Y 3 w v r S M f / F j 7 v q X k d d U u n 3 U J M h U p 4 G l 5 h s O N e F a 5 z 153 b S w N 2 S k K e 0 U + g l 2 n E 4 n 3 u t t z s k / d h h A V 8 T E 1 N m z Q G h w b c m V f M 3 z k G r W p U 93 J / Y H m 1 o A W W w 8 m 0 y x V a Y L s 3 n C 6 F q R A B 8 A 9 p e h e 5 P N 3 A b w X E 3 / W k O Y L C 7 p g K f P K X H 4 C Y M m I F N u P v w E f v A 5 K 9 z n M F E p f a K X t D D 7 f z z / L O 1 z Y s k D 23 P N A z 4 q / I d Y N 61 u j E q J S / + X M R 1 I h t 93 m W r Q 9 K S D a Q n c + b K J l m z z e 3 n W I S f g s Y p P 6 J v b P 5355 x B A 5 d M F Z W c W + z Q A X i 33 N R V H h d v g B 8 Y 6 d s o b z 6 V B w V L B S 5 n v / k F L A F Y 6 b y z x N B f f F K g v Y I Q a b Y j w 8 q Y M p x A l O 5 y + C y S D u v 8 l w S G f L w U O m v y 8E7 J + c 1 F z u U V 5 a R r 0 n P y F W Q p n l Q Q O 85 a O l F A W / Q f + i 0 o h i F k r 8 i / a K j W F d h V b f 5 w Q X L r 4 v 7 / 97 P f P k 7 Y y 6 P D G n g + Y 73 l + D C W m T W 62 A t g y n b G P r Z V X q p 6 N w 8 / l 1 i n t 7 X F n k r c x y n M V S M I 0 I U O y K b E N l i n Y E s Q R r J J R V B 3 D 3 D R C g n p N X t K B x J 9 N P H g b F 0 a s C Z K 3 c z O 0 B m s Y y E B U R b Y P E R j b F e B V N 7 V c 0 n z A S Y w p J G M I c 4 w f B o D i 5 G z 39 L M M 0 q A H D N 491 w k j S s E q X s 5 A i C E p p H y a F E u F J f / T 7 + Z + / r Q e y O U r 55 r 1 G 4 O D 4 M l j 7 A Q V R / z K l Q M U + T O 84 Z S V J p N z 2 N w 5 y Y m 3 L 4 v 4 R C 25 j o G y / Y g 3 C w a e G D z Z p I l X k i I 70 z A d C c V R c + o c k g i W O Y 8 h d u W a S F R s K x q y s P 5 w t Y x J F k 7 e m 4 h k Y b k M u Y v R t 2 A o w U b o 8 a u / t b z v b 6 p t Z 9 V M u K n + F Q B v M 1 j S o L 9 F 7 O a W i B Y X Z i j z H s f O S p O U H O i A E c / u 6 B u c 4 n c G S 5 x k O 4 k A 5 f 2 N w m H 0 2 K d 8 W c D k Y M t q a l Y x F e D L 41 a 0 m D y L X Z L A 5 U G P g g 1 p m b p I m D 5 F E v G / K h d k o v q T A H V 3 q F / z 52 r v N S 0 D g D Q / o + / 4 s w J K Q 7 A H 5 Y 5 a 4 U K v 2 W i / X 7 W x w D k n 6 o B b k M l S X m 2 j 7 Q W Z K Q R g S D T V D I w k 5 m f F y b f w d n y 2 n Z q V j u 5 d e p G M B + c p l W W z l x o E w 9 I k j 8 a e o p 1 D O R H d c G k t h e R S 0 C 4 p t / h o Y Z k D t Y 7 c i f Z b N 7 W u 0 Y K H E k + H R s E 12 Y H p g n Z f e a T r W I 1 y E 8 o r W o 98 X t o X Q r n g F P D f I 4 r r c F e 1E2 S C 5 P / J X V 76 O o Y Q s R b g s q / h L e K B P h C M q h i q J j f K 3 I q c A R V x E e U H I 3 r K n 75 j 3 L x o i / 1 X + s m V Z J J 3 z B 7 x T w G / T h B C 3 A b b H 1 n Q q q U 2 c y R e I x R 9 P a 2 g 0 m I C L H Y 6E7 o l F W I B 42 n Q S P w g k M Y J s x b U X r r 4 v U / x R 4 u d 16 Y T 2 T T D / G m c 96 j E x v j G n B B O 6 L D n n z a R f I 7 C 0 z G l G 2 Z Z 51 / L 2 K + 7 Z s j h + u 5 p O T R 8 P b 8 m t M i 607 U d k t V 8 z z 6 Y Z H m Z 9 X g Q c o 89 j u x e y L t w C X B L o B t b P N G R 7 n S 2 g q W v P D o L m P 2 Y K G 4 Q i z 2 y h b K a 9 G B e O n b / N A j 6 L 3 j i / 9 q 1 j R 0 s r 4 j y h f u F s 44 C c y t h C l I y p i w 9 s k q b s y W I + c C a A M X P i g 6 Q 1 D F L i q I t 5 V / 0 y A S o K V / 8 R 9 j l M G w L 1 + 68 S v 9 s G T u A e X 7 p 1 l n b 0 C u P H U 5 V M 7 F J 18 E A 87 q i / 9 a d E G w r o D Q j V o h q g l h t C n 6 J + k m m s N
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:31Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca13-834c-43b1-ae71-4b87950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:31.000Z" ,
"modified" : "2016-03-17T15:15:31.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'bestellung_0194-iFqHoViMJP.doc' AND file:hashes.SHA1 = '6710d33e29273ed0cf58450d09a50008f5ec5869']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:31Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca14-5428-45de-8e32-4ac5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:32.000Z" ,
"modified" : "2016-03-17T15:15:32.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'bestellung_0194-iFqHoViMJP.doc' AND file:hashes.SHA256 = 'c063a43b6d949e19cc84ed43018c11a6e1762ad76012da54133a01ae6008a465']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:32Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca15-e998-4373-820b-4348950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:33.000Z" ,
"modified" : "2016-03-17T15:15:33.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P F 5 c U h h J l s o d C Q A A I 0 4 A A A g A B w A Z W M 3 M D Q 3 Y z F m Y j U 2 N 2 Q w O G M y M j Y 5 N m Q 5 N m I 5 N T M 2 Y m Z V V A k A A x X K 6 l Y V y u p W d X g L A A E E I Q A A A A Q h A A A A u Y d f Z 9 K 7 k t w D q 6 F S C y m D + o 6 Y 2 / 8 G L 9 v O A g P s f v q v d o 4 i f s F p 2 Q 6 B 15 H R K 0 + + d J b P S r 3 V B I Y a n d S O 3 T w 40 M n Z E 0 L 36 M I N 88 z A W B 0 84 y M Y i j I c h y 1 A M P C b J P X A D t s 6 k P T g g G r H t p 1 E x 54 Y s S 3 o 4 A b V F e f h n L + + V H W / I 7 K j f Z C d h l 73 x s P v p 8 I K 1 q G W g w L Q z 0 i B r o x J g h n l 7 Q a M y 3 b m 80 Y e E w f J r f D M L z H E 3 F R a l D s B a f G q h X L U D m 4 q l i p a K N 2 z b K f i o Z b f 7 X s d i 0 / 3 k A D s S C o v 80 i b Q A o V 3 o 1 Z 4 D h I f v E s O z r J h m C p v g J 59 x O E 5 R 3 H v X P f k t d v R C f z l + N z + D V W e B o m c R m W j o D y 2 / p w B K N + Y f r c r o X Z f U z / q a c 6 S P 0 36 F P Z E f Z 0 V B z 4 N i S c 4 b T v H P g Z 7 s b D S 2 / o S b n k G r Z 7 f y D u N Q j / q c I y i 8 + g + 50 t w f K k 31 C i Q 3 A b t W g b P w h m k N s 7 C S E a o b H p n n L W G 3 D P f S / l B X q / Y 6 M z F P J 8 D M u n M b 0 l K a A z 1 k / o Q U o Y g 5 / 28 P c x 87 l e 7 U q N D x Z o D T 4 y Z G Y 5 t 16 n 12 T 9 W G S D 3 C N 8 H 4 m / l 96 w A J J a N d s q G g e h h e F W A W a T i N o 0 w N D d h Y C U L 66 m K U a k Z 5 C m E Z c r 8 a I 4 V C I b 0 S D z p R m Y 9 s c E o 6 Q M E L 9 m 9 a q E T G e b 3 r I 3 Z b v u + q K b R y 2 K U L 8 S 1 + / G T N 5 Z a g M b w X A 5 s N E + m G g S i R n z D 0 t D T G 7 z S K c s M u R C 3 / H F 4 N y q a 4 U I 3 z p L A 4 + m H h j V 0 + R 292 x j G 38 J D W o r 22 / H r F v 1 q D x z t X T k 94 a 2 p 7 n 9 + 1 c m n J A H I v i o b b v z z Q e S c c z h 2 g p r N u h H 5 Q w d N p L k c g x J 5 Z J Y M r x K y i d L m Z 3 l p 7 Y X i p b W 755 H V y / k O x j U u j 3 J 1 K A n U h Q r E 99 U s N X x u I 3 V c 4 R Z a D l x q N r R Z g p e 59 f Q h m n k s Y N S V F 50 c F j k t j O 8 I L M 5 P Q k R g o y q 2 H r P 0 m + M r L w 5 M q 8 K Q e z 4 H v i s R v K L 7 z i 7 B J K l / x X A p i S 3 G P m o N h S q l l i 9 Z y 4 h P z 4 H Q S S p 2 K b b N 2 n A u a D I t p D U q N z g x / E y a 7 N b S p L o 9 E Z / l q 4 T M Z E / R 8 i k f v + k 9 w S U H e t d l r u i J u w Q D g p B Q R y W c E Z M S J 2 A S s t X o z U m X n A T o 53 e x o 6 y S j L u n 9 S Z C W I R Z s N x e O m + m P + I v 524 I + Y k x b i 3 l P k D s M P t 9 Y u 4 T B H O U 923 T / f + + C s S O H + k V Y r c T L e d D k O s l Z P x w I G D M P Q f E K 4 E U P O R + Y k + h 0 6 w z 6 Q n N l 0 5 Q m 9 P + + m s l A 2 T 7108 m f a 6 t s W b 2 U k e a I 8 g + G i i m A e u 8 I a F O d S 5 o y t s b n v U n r m w 5E4 Z g 3 a U S 7 j U A v s g S g 2 J T C R 0 5E1 v q a 3 q 4 L P Y 8 S y r v + C Q 3 r k L y z 18 E m 9 j C d e H X 9 G j r 7 g W b G X b f P k f 1 X O O 1 w z j 5 x 17 W G g h H 3 s q H G V g X 8 x 5 q 96 l m Q V y A X 758 w 67 e n B a 2 l T L R + P f 9 R i 2 H k K V M e 9 Y p x Y 4 y P v c H C m y / G r I q g 6 r a 77 H B L P F n Y m Q E B 6 M L 2 d B s 6 L R d F j r F r 6 F o 0 T I O t a Z z y O I D 8 D F R D 2 K h 4 I n m 8 R f U U o W 9 d + w A p e 4 h 4 q x c 2 J p x W R y w 0 Q U A 4 p d i n e 4 w k L r n A v 4 J b q D H q A m I 3 H j C p o p y w z u b Y Q 7 + U L n Y m X y u 2 p n X 5 s 4 X g x I O c V o O 4 E r D J 3 o Q r 3 n I q T J E A P 7 F A O 5 l n U x S B V n E x r U W S m M t D N C P D T R G e Z Q O y X S u U C j G A z w l o n U e S c 40 L 7 M u S P 6 t W d d R D X q z q e O C r G p P b d A 1 R 72 n u 5 N I Y U I S 1 v r y 8 K n v A S L X T 9 u Z U q A / U X 8 K 1 t z O A S w m y S q I n H A i C s D b 7 l Z + u c M 4 x C 0 e Z R K 0 96 + 7 w b 1 S j n Z / P x x y v A F m g u r w V r H b j 9 L / 1 o G / 1 m Y M 1 x 9 I t O x S p V X J X n D u d k O r 0 / 1 A P b m I c K W D A A l 9 w K s 8 s q 1 E s K w N z j B U I r 7 J u l c m k o 1 i Z K e o a s p E 7 z X K b Q q E f o 27 V z 5 T 8 G j K V 0 B P N y d u / W I 15 Y m V b u x h H s b a e 9 Y e L o F R n R a O d C r k r A d E C X e w Z V F B i 8 w P Y f d 7 Q X u s b K N I m E 9 B m R Q r X r e y 2 V h g 0 H d t G b m b O Q T 0 3 a T 12 t J 2 k M + E F V Y n v z O M M 93 y V F 5 V g e x 0 i 7 i E P T e K 6 b B m 67 r b g q J m 8 V B C x G v q F A 0 i h F N L x p 4 K q A r S 255 D H c p T E h s c C K w 5 m X 66 J e s v i x t r w E 4 g r M 8 n w k w / B i G 2 G L y 47 f a Y Q w i b Y W k b 8 + w y Z G v H w d R F / f D y / U w 45 v x k D 3 Z 6 H 7 c U / i W 2 n Z + 4 B E G a n k q d U 0 / B 6 h F b F F G 9 b G A a L s i i N w y 5 J I 0 w T n g Q + e M l b V o k x v s x M A e g g v / Y z J 722 n R x V 9 q s k G 9 + U + z o L i Y u 4 F 6 j v 2 U q Q 6 V g E x e j g j + m O X e c C d q i T e L I k T M Z T q l D A m r B U a U q P A m f 2 T N B L s o h n q k b 8 l Z 1 w B V h V C A X q p / 9 G 7 C L t T M j M s / a 9 p D F w Z P g e O e H B 8 F 8 G a C D V q l I b m U Q Y N b f 2 i p 51 L s S W s o 6 N X d K I 5 t o q 4 z d u Q S z Z P r J W S H 1 M 18 J S a s Z p v X l C N J t R x / d m G E F P s z v m 8 J 3 f 9 v 9 n 65 P 8 P 0 w o 7 i Q P 62 G l I p X o 4 k p Z b H e / D m c A x J x g W p 7 w a H g X K B 7 Q G x c F r c 93 w 5 H 5 M h i w F p Z Z 2 I e q z 15 P S c 0 A B o J d o y z k i w O W t j D e r i B l I E m E y 2 J + 6 F q G T C i K b b 9 Y R 2 d u h r Q O z Y t 9 z b B W f c c N 4 Z F Q j 9 l 9 H / H n 0 V R U 5 H J v k p w o k j r x I a Q F a n k B A 2 e P w N / T j F K + I + 126 B U S 7 p c a X J 3 q t 9 p p x b h 0 f G Q z d Y u X U q X G A 9 K H 0 o C x 337 g 7 f v u J 1 r B 60 d r G 0 d n S i Z / E W E q u R 6 U l 7 Q M 2 o V 5 F 1 n H V G T q 7 I g W s 8 t W F 4 r e z G x d Z W D a C 4 G 1 u 5 z X B 4 D u I 2 m j z t p R r I Z x G z j a e b A e d j D r h n c i q 0 p / v x R N M Q p K J h x u p 13 i z H U W k q q M n I 28 z B R z L 388 f j 4 + S 19 Q r 43 D H M v f v A / 737 A F g D S i A 7 V u I e F / a l Y d d b v P H K h 4 + h A Q d i N E s m K n P M b j o F O d F n T v 92 Y K M Q V L o a x 0 Z V U d l 8 f N E j l N y e m g b N 0 X z 92 G K M U k F q k Q 6 a 8 J 4 g z p o A y g N C H J q 7 K m d 2 O 3 X k n 0 J b N Y z g U s b Y T d x F h Y W f i I Y a O c y / u k x G x B 6 H w D c P U 3 + U r Y v n R 53 M Y y w n / B V r M C 0 3 e n m g p U S v e r e A I 9 A s e 23 A l E c I V k 5 b T S Y c A w O T A Q 1 w 2 N 9 K y v v 19 n 5 Z f w 5 V U N d 3 c 5 N C K H V v t D g r b 0 1 u x v i l H R z v w q 5 g S Z e c 5 v 3 + b + 79 p z b m / 3 h z 6 j i B n 7 j 4 R O O 38 c 9 x V U 4 f K E r C q 8 E p t e + a 3 u 0 K u A Z O i n K 8 e j T q h e Y y i g f + c t 1 K 1 a C y V / 8 i s X t h t J 90 S 5 r x A 7 L 6 r b / N 1 x B h e 0 G k w + B P x X t W i v T d e u T k X Y i W b N Z 31 K z t O r 1 Z S A u u m k / u 4 j K Y W 0 O n L P n B n 8 f q N e D v F D z B N m V m O 57 w V t a h u a d r L f n h e d f 8 M s 1 U r 3 w A M P 3 n / R p z t x Z H U I B Q L / + 69 D H q M U q S V 7 P 8 U l i l 9 C P b E 0 c q G t m T 40 T r 6 T c u 6 J f 6 w l 0 e q l z x p C G g M O n n t 6 A l T i Q 4 i s K d 9 t T + p H p V 8 t c I w N W o t z u B 0 E w K / e O 5 y t g n B O r E M s V I o T E C N D j Z C / r W W k T 8 b e A G / M P C d E s r 1 p F K n 86 B o j i I E v 9 W m / f W Z j E F B 2 h i w Y p u / E 0 g m / n c T e x F U j j 9 D G c Z B U c v E 7 W + K z z t x C S V Q U C G T O N u b T l m M Y U P w b r r U r E H j f s m E k J W 34 O n t z s / h 2 M Y / z I Y e D K l 1 V P F 866 c n Y F Q p f E l 3 S p 9 + 94 f 1 q f y X N l t U j r j q k 7 l w C I o U g e 8 d 0 R k 5 o + c v m T P s H H z Q N v Y q n R S 8 N 82 A Q u p V Q 7 T m q p G 9 l u 6 H H F Q b R w 1 M z P m a G M x 6 b K A K G 7 O 7 L 0 E U y Q j w d 5 g 8 y R 6 E d N x B I Z k N 6 S V d A P j P F k Q L a T v w 4 F R f M l f m / y J e V q g 5 d K Z 4E4 a 61 U w g m 5 F s h u C T S Y g u w R l 2 f H W b j f a y Z I q W X z n R L e 4 t m / x V u e i 0 j g m N O 23 / t 6 Q 5 O 1 M W S J + X k 4 w z d 8 M D 3 n e a Y z e t 4 n v x d 0 2 S I K 36 q K D b Z k N 7 i N B G 8 s e 7 I x I a p I g h U
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:33Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca15-afb4-4ae1-9b52-4eee950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:33.000Z" ,
"modified" : "2016-03-17T15:15:33.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'bestellung_0244-da90e2d4.doc' AND file:hashes.SHA1 = 'f0832ed80edf880eee8c99313cf39f7b1ac17530']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:33Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca16-e284-4b97-bcac-4011950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:34.000Z" ,
"modified" : "2016-03-17T15:15:34.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'bestellung_0244-da90e2d4.doc' AND file:hashes.SHA256 = '5c2387775a5b868dc9c6f8405220048b273628639f16c67218ea5d0cf06124ab']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:34Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca16-bfac-42e4-9f55-44fe950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:34.000Z" ,
"modified" : "2016-03-17T15:15:34.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P F 5 c U i G a d O 1 e C Q A A J E 4 A A A g A B w A M W E 0 N j R m N G N j Z T V k N 2 Y 5 Z D R j M m E z O D Z k Z G E 2 Y j k z M T Z V V A k A A x b K 6 l Y W y u p W d X g L A A E E I Q A A A A Q h A A A A R j 0 B R B Y p g f D 7 D I D + 8 E l D x H r o w k 8 w q 4 w 7 F i d y X K C v 0 I Y V I a U n 2 V K 5 m B Z o F Z 4 F d 0 1 h 1 B b k b 6 c Q f n b E O B Y m 6 y r Z b v Q f H K y 9 d 9 k h 2 / m J S H F 34 W U p + S a G a T L 4 c T S j I V b A E G f 7 p R 2 r W 5 q a / j K Y I s a e 6 j i x w f F f n d D l 1 O Y k g U 7 l q 8 C 4 S W 7 D 7 u d B U f a / l g d E l e O t X t 29 a Z E J C t a w f g P P v z c C S q O o 9 u G u e w W N y + W W J C g u Q U R m z G 8 U V a x x S 1 T + m 1 K h 9 Z S W K o X u N q U j m h F g q V H C f o u j M o s w U W T g H p k g U H u h t U k 0 Y k c S 4 m B y 3 L 0 s V R j 6 X 4 G W x a M g H Q 7 Z Z 1 E Z v W 3 v 90 u y 5 O m k / 5 Z l e 0 z 7 Z 9 w o 65 U Q + V m J U j G v f h g v r e U b F T s / I X O J d t N o S + 0 R Y h A 7 t M 3 X K O q 6 C r I 8 u T s 9 t b r J J 1 l J / D b O 2 H V k l D B t K M o g B e G / F 1 W o U o t W o 3 M j w c d y c b F C a n V l 80 i w h b 8 s Q u G q s e S 1 Y u D Z V V Q Q 140 r y u y T c l w Q w D g 9 M 251 W S U 0 C N 8 v O 2 k Z F u 0 c D E Z m F N c 9 m P 1 T H v E U a P 8 h b r J X m k 6 F A G Y f j J r k x Z 5 y t C p / O d P U Y 3 U n U O r Q c w t l a P 3 R U 7 K T U 0 Q B E z k g r g b 4 / v z p d + j a K U S k / a H X R / z / P 1 c h 9 I I x y s Q 2E8 b 8 c m D Q h W A v J i t N n Q 7 D h R D V E h x F Z F t 7 e Z h P b 7 h K T o O b f a 3 n 8 W 20 / V V 7 c / 7 a k s b T R Z F Y V 0 S W 6 v 6 W Q r b F x 4 J a 1 h m y I N T i f 141 a T U 7 A 610 K i 7 Z v C i X v m G d 9 s r O L P 6 x + I B 1 z Q p + o e Y l U n d z j s k q d o U Y z y p P j H l 8 D A I C o k q v 5 B i m X m t Y x o b 4 D Z c 584 x l 6 w A 4 b j w H b M V j t E C W + y G 4 y P 8 H 9 r L h a J N Y o I O h 15 G u s s 3 U s r 8 Q 89 I a 1 l b A + x e 3 F b a A e 64 N r x 0 B l r B 3 X 7 o P o 6 n A c l s 6 U 8 c d m C i F u y i W 2 y E c b 8 s z c y v q P w Q 4 a v v S / h Z O 57724 c 462 V R L L i q Q y k l j b 7 U R / 1 v g K K 6 i K A F w k a / 4 h K N H 6 F Q n g m S j 6 g w x L 5 I N J K c 8 O 9 g b 8 k x g + I 0 P g 3 F z k r 8 E J f k S f X / Q p L y 8 L N B L A m c e R 2 j g h 7 t 3 j u Y r d m a D B R i B a h n O o 8 G D s L G R 5 M w R p w j G f m Q 2E2 C j Q U 8 b P H k x M s E M d W 9 i N L P / 3 s t R Q b F f r 0 l Y S I k s H t s L R f 8 M r H 8 o C 6 F q R Z v Y 1 V r T d K 2 t D l A O U w m 2 d 2 H g s k 3 L 1 v C 7 n l Y D d V o c j E z H H n 9 b F I D 2 Y 3 y d M 1 A T 0 V G u 8 I h X M w J 3 / K U q 1 I 6 w e R B P S t Q w e T S F P W 4 y U M B 6 a 5 I Z W F Y l w 7 U g 8 H g U e J 9 J 5 f O v E d d A q Q i Q u a + q h o d T 2 m Z P Z Q q Q h S m X r X N + W 3 l 6 z M J N F h 57 j t 0 4 m w k u N I l Y p 4 i o t k s v 68 K k 7 c G Y n 1 r a Y V U k y 0 D v o z 6 j 74 x o x 6 / q j I j V i D / A 2 b + 94 B 23 j 3 G A V l C 8 u d g l E j L D 8 X X p U O l 4 A u M b 2 O e e a G O H X M m 0 y H P 8 C E L N X y 1 m L S N K w n / W K g t j 2 p K 7 n e d E x j o Y W a Z e B y 7 F e M j + y l d r Z m H 20 D 2 f H c A S H D p f k i 5 U w w q B 4 Y 71 a W F U 8 T 9 Q O A + i C X N G N L d B u 6 l P P h A e r M h 3 y I g 9 / t B l k F z 9 i G L / 2 M L 3 W C l d G S R l A h G y U 5 G g A U W D x b r 1 Q Y 15 o P W 0 d s f S u Z 1 k K 5 + 0 q y 4 H r A e H R j g b O 8 D u 6 Y r N e H M C F 9 r k i r 7 b 0 7 U F a a F l F J 5 k C E F 5 o t s Q F F l 3 Q e e p i w W e U D U r a E o w J / 64 u f 91 h n B l e w M n 3 v U X 0 l 0 f 1 u + G F 40 t F o y p C y A W T v R D Y P p 174 k f t d f M W m t + m n R D + w 8 k z m Z h C U 0 0 0 m e S k T y v C l W A N / S H b Z j T + S o R R H r d 9 N R p G 1 W G J L i Q t p r R / w Z V Y p Z s Q t h 4 q a T J 4 I M 3 h j R M H s o K G N d H g i F O 6 j A / l I 4 C l B c i T m S e w F S 4 O x M J T h e S Q u j J X v E + R F r 0 y Y 44 K E z r s m F c X W / 5 z C C f E R Q 2 g U r E p V k Q I 6 V Y 4 u 3 + H 2 I e H L e s z 4 b H C J 4 C m t + I 136 p c A a q U 4 h 54 Y D Q 5 u O x e W Y g u o m m p z i k n / 5 d 8 q r B Z A l C 7 c d 2 A i 6 M 7 E m y R r C z l s k M U w g / A H h f O 698 / Z 6 F F f z c / R T 5 b 2 w e Q n x m n 92 p w 80 J L S o I F f B 90 a G Y + f M n I 51 Q l 0 U 7 y 2 Z G z 6 Y u 7 C t E G Z B k p S w 8 y u 8 m R q 7 E I Q a 4 M V J 6 a 4 Y b W c 97 v W V 1 x N A O B a e 21 w a P h 5 D 6 D 3 M p C 8 O 0 G K s S q f i l 8 O J R + m 9 P R c A P z u o j S H I k 0 s y 9 h P I p J z i T K c R T A c f Z u y / 9 g / L L a M s p B g A v R p y l i Y O z g p t N N B Y k G S 4 i 2 Q X f 2 v h i o e C R V w c A 682 e K O J r 2 F s g U 8 S y 0 b 9 b 7 U Q k F d h K k v u O p K P I G 82 Q 4 q G q Z l L l k U D 5 i d i l 8 D a F H X 6 N D y 52 B N e a R 7 n Z / 5 p f O 2 c B u + / k 8 W j R j u s t 0 w i a o R O d Y p 5 W d 0 4 n G 7 m / E l Q A Z + 29 Q y f y 6 + F k F D 0 T 6 k z o j i N O H q j W M Z b d 1 e o 6 p 8 x g 7 T S O A y M t x 0 S L 8 F T t 1 h R 3 s r 6 h 7 r f V E h E 9 U O H g k U d d Y R q 8 Z l C v F R X A 6 e z 7 y m A i 96 K M q 2 A d 2 u z y k x r v l M t V 78 C w E p 1 h a d S Y D M N s z l Y I O J u o S X I N y d T B e D 8 K v W V Z / K r H K G A W N j P J v q I 9 a l i W t j O y 73 J n R b L i 9 + Q b C 0 8 f v / f z J + I Y 0 F U 72 y x e 6 L T C J t p M k W R 8 X Y 5 o 0 N B + m N c 6 z S / F N r p 3 j n 5 o y C / d 0 2 D A j v x S 1 B r N f I n A h t l I f 7 N V G c p Z B l 6 E O j h 2 L u K v Y g q 0 H N q 7 y Y V N 7 J J d 9 J S r I o r l J 5 X 0 4 e S e 0 O y I W a B p 384 y u v A l J X g q f R U 94 T S C P i B G S h N b M c y 1 G F n e l g Q 8 M 12 m 8 j Y l 8 B p e X j d L K h B F f 0 c 9 A o n 3 J L z w p U t 3 G 3 t m K t C c e P h 8 q S P 2 D T h Y T G s O u G Z H / X j 8 D Q v z e I k 0 u L v + R H W R N O 5 n C K W l 7 d c P G E R g f 54 G 0 S n G U G e o a T R 0 B v p q x K d z P t z a x A + W d w G w 41 G n x G v I N S P g f f F S S t Y L D 0 s A 5 U O v B w I l 25 + V l m e S K / w i S D g r g Y R 1 h a v V x a J Q 4 I W f f Y l t D 4 o g X 4 j c z H H v z f F p m 8 r c m Q 7 b 7 N T 4 a o K 8E9 R B o A c 5 Z C 4 K M R q i y Y M p 861 o 92 i l 6 I i H c U E M l h 6 g j 7 p A p v T c e A g 0 b Z O X G B O 1 d / C C l + F q a / Y b 1 m q I e D e D D U 8 t M n S o d v K O h 0 Y H q C a 6 f r L g 1 f / Y 3 J R p M 15 g P I L g h 9 K u H 2 C C Q e V T Q 5 I D r 6 g x t 5 r P z Q P w Z V 9 A x 5 o f u M k 5 A 51 E N V d k 9 P 60 k x Y 27 Q Q y N t r 5 + m j B c 421 q c w q 2 + A h x z q 31 B r V + K W U 1 F c e 8 N w + z F C g M H y R A n A Q s 7 X w G 5 r x s 4 b V e f p C I h M 7 o 5 L R d h j w e T 23 M A q o k z L 3 S j s o L z 7 f n Y l S l g N q F n X l L V 5 D 38 o d o c U N I M O n / z 4 w 8 j H D w b 2 v e M F I O C u g T O c b I J B C 82 G O n 9 L S B C S S L 2 f l P Y g j T f F d / f R 9680 R Q P E n u T j r k d 6 Y w c T f r o b J 24 y J B O r y z x I u Z 1 I A f o m s a p L 1E8 b + k o n b + d H L 182 p u s p i i c E n l 7 N C k 7 p j a c M k e K b e 6 I X 0 + X D n j u n S i o r h b N u E / s v k k O v b A S O B / i s E n L 52 o u T n D P a a F z 8 I S 5 H / N t z U k y B Y n U D v v n i + l N 9 U 1 o C k U u M T X v R D K c v z m J 9 m + a X N O H h V r 8 S o G 1 r d r X z o e V Z J b C 7 B y 0 o F C U U k + Y m h s 0 j y 5 c m u S n a c T m A X D y Y J v Q 3 K s V 4 j T M c F z a N z x B S I i L d O n p F K m s 8 o c a y l R 0 g 4 O z O k 0 j c m C k u q i j k B G J S j w W s l k h B 2 f F 8 A Z l 5 c G y B O e v Y D v 48 + S M P K Z F g C B c t P r R R 5 C a V D 7 H K 7 Q F N P d l i o y G n + W h C J F j C y x s 6 E q j b G Y k 7 d L l 7 K 7 X x 5 f l u U R 3 X L F O v E z N U 7 j K K j O / S O Q 2 n e B f W f C j f i 9 y a / B L d y M 9 A n E o d C q o O 6 w F q 7 O L a D B L p O E y t 2 e H t h S T F 8 k V G s z d + M l d g V 35 / B P I W Q 4 s p f d Y y U E z h M o 3 Y U 8 L U K W d G d 1 p M P D q 1 b + j e t f 97 U Z Q R Z 40 G i C L 4 w l A w E 6 b V 1 k K T g + o y 6 x e Y j R t N U t 2 p r a 4 L q 6 r Z 5 G z l b 6 o G m 40 M P o W i Z 4 X
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:34Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca17-e698-4672-a607-486a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:35.000Z" ,
"modified" : "2016-03-17T15:15:35.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'bestellung_00562-a1e0156.doc' AND file:hashes.SHA1 = '8238e731aa1005a1777e5f82aa680a6edf614ca9']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:35Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca18-2190-4e09-a5d9-4652950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:36.000Z" ,
"modified" : "2016-03-17T15:15:36.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'bestellung_00562-a1e0156.doc' AND file:hashes.SHA256 = 'bbdcfe20dece102c30a0f6785ed2d9a7f898428285df3086a6f69d38c267c960']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:36Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca18-cf98-4d8c-a0a9-492f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:36.000Z" ,
"modified" : "2016-03-17T15:15:36.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P J 5 c U i U Q x + N P S Q A A E U 4 A A A g A B w A Z j F j N 2 M 4 Y z M y Z j k z Y z d m Z G J j N T M 2 Z j A x N j l i M D E 2 M W V V V A k A A x j K 6 l Y Y y u p W d X g L A A E E I Q A A A A Q h A A A A m / M v W w K W + x q v f 4 J f O 25 n o 6 / 2 A B v J L 3 O N n 7 i f o v t 2 Y i f A m O r l m 6 O R A W S X F n o F a 4 r 5 W L o Y V p v i a / H I 1 A v f K I l K U A + n o D n Z j H n u q 4 N 6 r Z k v Y r 7 a q a + G s Y 9 N 96 b G d H 5 W 6 S M 2 D g k 5 l k U f c h X M z / i o V v 7 Y g p o B N m N 7 U / s 1 k i Z L G y b Z k h o 5 W J z X l T i i I p X + T + t s K z Z K u 91 C h o U J e Z q K U e P H L a t P C a b 7 L d c 0 q k d G p P x S n a E C J t z J v g N E z Q f O G I s 1 R L v x Z 5 f / b 7 g 5 T q x u D K M J 1 A W D e x X B X 0 E D U S b H l 2 f E U O p 386 m 9 F t R n f F P Q n z s l f M 4 z r 96 m W K o f b e M Q d 7 r O J I A h x F o Q l g w D u / 33 f R N t R T t P f O K y c I Q / p R 65 f b R 6 M T s 5 + d G 1 t 16 O I m N s Y L i f 9 H t X r 3 o / j I R t K A R H u 76 B l S D W 9 M u G S X 2 I 63 v M i n o e r 69 M Q z b E H K / B D R m 4 U V P u x W B U a c 2 k 6 O 0 97 n z + G K J a i D f + S S n + R K z H G 5 D A 2 p P O A Q G 3 k D v Q e l L 89 x O c a Q B u 78 u F Z Y n R 1 C 2 z e 4 b E 54 e / x k g p C / e n Y l J I X h 1 m n j 1 v m o h z S 0 s W T z U g H W k J y a J 8 B 840 f M 3 v 9 l R z S 2 o h U 9 N o S 23 n 0 E T 6 S A R I x n 3 w c t Q L C h R k / 9 K D l v u l u h M 1 o R + X z e r 4 H a R d b X u P L O R r p 6 Z P I r d 0 j h o h P s h l w g u V h d J T s S t e Y / T 1 A C U P P i S f G j G x 6 + 3 A K R S 0 N w Y T 1 Z n i e P T R A T X Q 5 s F a b Z 7 a u X 2 U h 7 Y K s q B D H T m K A T N m x W X s H h c x 6 r 9 + Z V N S p M g V p m R e 5 k C O E e e s L 6 b e F W R d C n q M L X J c y c q / v C S J r M C 9 K N R Q J w 0 s K z s O R W d P C D w o c C O v n M h 8 M a J Q 2 + T n H U r d j G u D v A 9 M 81 o d A h 3 R X e 94 q s S k 0 W B 1 V Q H r 4 B 4 z l J R U c 5 m W w d 6 V I 5 M u n b 5 l / 3 j r p T s 1 B u J 383 K 4 K 3 K t s K W M l d 7 B D 8 n T w a t i Y j 9 n Q V U q H U H H z V n D p l E c n d t m K 7 Q J 99 i + p n r i T Q Y / V q D x t B I q P D W x d J U m D 2 K 2 W o K J W v w J J k 5 f b 12 S e q n E Q I T N f Y q p q 4 r F 0 24 i Y R M 7 + W 3 u s V y f V d 7 O 2 U e e Y w 8 u p T j j + l k y M a O j F 1 K L + l u d X l q 0 L 99 r Z g N U 93 B E Z i s 2 g E G N n 1 u h V C P 0 Z j 72 B v 6 F M j 6 m S d 46 a I H Q 2 G m d i E H b v b t u l 6 X s n i Z z R Y G 9 / k 5 A Z W l P k f a n C i 78 c S I j + 24 t Z U m P l 1 q r i D H 0 0 X R A E y B 3 / p W f 8 v A b j / l B 41 f o c l u u o Z R v e q W f 1 i p z T K 4 a y 68 M N 7 b q n a o m B q F / g G f A Z o A i + v 9 / P k 0 W 6 P k N G B i h s 9 G 710 w 1 + n 2 / P N K I n U t Q H r C n a M U 1 E g m o f 5 w 9 R O Y n e 0 Q / p 8 t N f N F M G H 7 k F s 3 j K y + h j a 4 l M 8 B + 8 W 73 E B 4 r 3 w 0 0 F k r 0 k 6 J L W F n U e x W j 0 y x R y Q n n k d R w L V s l c k B V X P t 14 H l k p W g 3 b g k U H 0 Y D S 1 / d K V c n F t R L q 9 v k r j P T t S J Q K r H n s U m A t 3 f u x G 85 x V 3 Y C o Z M h c a m 1 m H c B i K x x u a z U a o o g c 8 i D f O L 6e3 f T M g h C f F i R Q k r a 71 v X t g S W K F 9 g l 0 m U 3 c e 0 V g i 5 M c u 9 u k 83 T C 3 r P G 5 W T c G 1 C e 2 + E 1 z 4784 f 1 A o X g v 7 d / T j b m e Q N n K M E / S M 7 G O e P 0 n w S 0 702 q u Z + O E X 60 V y a r R D j H z h P m L p Y V W L 3 E + C j a 1 R + q K E w J y q l j q U Z W d s a 59 j N w A t r Y M i W S m 29 A 6 m c S 9 A K X B H 8 s b u W d c h c 0 3 I 8 O p Q 981E9 u z f f U 4 z d H U p b N G Z 0 L w Z K S F K d f j I D k p M S n O v T 8 l g r D / s s C H 8 h p w R Y b I D v N m e I f u R I d U x v Z g Q U w q D L V F Y Q v a X y i L M A 7 v I 3 A 48 c L w t V P 0 6 o s w V e g q 3 k K f 7 / 1 Z n S 2 U / B g z a g I t L U s f q m 3 d o n X g Z L P s w X 7 n N + P i T C 0 6 N k a c U 6 S / s t 93 O D Y p r g / H S c i b 0 o K j J D / p y x p f n B A 4 C R 2 X O v D 1 c E q h j u 6 P A / c u 2 P H E M s U 4 E s k Q P n 2 Y / n x C L u 5 R t / 4 L R G i u V I m M X x G X X n i + 96 s g P J I E k k h F Z z j i N Q O w W s e D H z C x p y l z i I 2 c n P O x D z g v 6 i 19 F L P a 6 A L J / d o y B c V U y G I Y 5 H V 8 t v s Y u x b r s W S K m 3 S D O q D C g q I B d C q N K + 828 w z 1 G m D c W 3 z y S b O O U 5 d 17 k V l a O n v o K l w U 9 b n U B I d 8 m C k x e L Y X q 46 a n P r q 9 h V g q 1 w V H l P L h V Q I 5 X b M K o T G S k 38 c 5 F + i 8 M w j E R O v A y t O D h R U V f 3 k f u N J 6 o 9e6 g C 84 o p 6 O 1 y Y s h m E K W p i J k j H R U u a O f H Y U r q 0 L 0 f l k I P J 2 g D / J Q 7 K m E C c N E 22 L 6 j I h T 15 U I w I O k p V d K K I f k l 73 z Z q + u U U 4 h Y T s l I Q t 94 X 3 L V j K q g 4 o O A c N 8 B v a R R g h r D t Z A 7 n X c y A X 8 S d 6 R X n e M 9 u e K r O F V d 7 q U O f v A P 67 d V + z M g Y y X T 6 H w J h K n v J w h y 3 n i d 7 v 9 c U y W n g 2 + I 1 t 5 W z f S 6 X M w m W s J / k Q b k M U L I O L w F Y y / W + / 8 H N e l c l v x R N R a s M w y f Y D 75 s n 9 / G j r 1 c 0 z o 0 6 X E H q o s X h n + 0 q v + n C g i q E Q 6 v j c p 2 D 3 U B 9 S O 0 E P W 2 O w v F 3 y 3e8 W a 54 G q Y q p z m W C b N j 4 C J F p p Z / X J q Y T c a O + P A o 7 b v e G M + E I V J W 2 O f j j L i 0 g b b P 40 D g r w p C o 9 a n I c t X x j O 4 k G B F U o L e Z c Z i 2 u E z J + l y W N 67 f c 0 O I S H f V Z k H Q y E 33 C q w R K A L o O U x t t U T E U o S W q 66 O Z 4 z t V x W 8e2 y O O Q B T 7 Q / E f 59 f A 93 T z D H t p R r 0 6 s l g u S 2 L / T + k A 7 h i I M B J h h o E 1 I h x c T 0 c a m Y J k 7 G h x M H C R v a Z t j J A j h g Y o W Q 3 U 9 x a X n X + V C N I d g 6 R B v 7 r b M m N P K 58 i 47 x U T N L G W A 3 G P E o c u A J U R r F N q Y 3 M e P b P m 0 2 C z P H y G h X f o j 3 g I q D U 0 f k V R W v b K D K / I F U v Q R Z 77 a I S q L J q L r a T u t 6 n N N X Y K u Z l n M c f x p A E k O t A 3 + S S S g o e 7 w R C r v H 1 H F 7 H H 1 c O F e 8 l D T r g f s o 1 t K f D O 8 j E G + o a f 4 s a v m + P R t U V T c W l z O T w f m D 7 B U a B S H 9 K b x D u 5 E p f z o i M h L Q L r V P G 8 S f l t v n L 2 o 0 6 c X o X s 49 c f p r H A n n a 3 F u h G f / E o v c 2 n n B G r P P 85 i l M n K z l 1 c 7 Z g c o G E a h h z O v j 6 A j k / K 5 Z 7 U v X v N Z U W A O 63 X B H v / J M t Q + H g q 9 G b G l 5 f Q b 1 z A y 9 V d a j J j w t z b / W l 1 A m x m 5 Q u h I 29 L U K / o W q e C M d Z 4 M b V h Q B f S W t U A 9 i X L Z 78 S 7 k 5 s 4 f 2 j Y 9 l S K X 7 b R / 63 m x W A P E j L Q 8 J S Z y 7 z w V Y x b / c n G N 5 n 4 + C f w J A q 65 W e h q E C L n N q 5 / u 7 p j Y D z F Q T 57 p i d B w d o U n Q Q Y M M O l 7 D J q W y u L w r G F 59 p p 5 O u J p 0 d V X T n o o O Y v + t U Q d x j F 5 A K I j V e 4 b k i q o z 0 5 e n w f p Z K 5 a D m Q U J O T R G a I U U + X p Y u S t w Z 7 W e I s G C Y c K u U r e H O M S x 1 N c 8 D W 5 i I i V C z R C Z 7 I B e I W 75 f y Q S S p m s 76 c n m 0 n X j s P X H 1 g M Y N V 9 V H F D n 37 p V b k + f K P N V P + r E Q F s 4 l u w O c 5 z n k s P i w x i j v U 5 I L l 1 C h h E 7 d f D g 9 I A 9 W 5 V 57 H R n K i P 5 v r x r 5 M j r D H o k + x 8 X H n W 3 X H 4 n + E 6 L k B y t 0 m + d t / H u 8 m R T 8 x R U n g 6 f f h 7 g G + 7 v Y W F F y d K e b J g W f B e d + Q U 23 i A 25 V L 6 N Y 7 H 4 F C x p B 9 u y V J w i + B o / 2 y 5 X F O z Y D S x U Z G 8 H Q 1 L A N / e / f g H b g 6 M y 129 L e b X 0 x c c J x i / x S V l i F a Q Z 0 I m W N q l B B n u p z q A X w e 69 U X M d E G N L 4 x v V l B 5 g 6 Y R 4 P V L Q J I P L y H P Q 75 W J t O r k 22 a g R T S F w x 6 i n w C 5 l p 56 j f X z s y F p q R o f a T T U a T E V h S 4 p p Y F N s r a x M B R o F c G b M o 2 i r l s n y T G y R c 6 I p p W V 51 T X x O V h s 8 z V E B S H q 0 q H c / Q H k B + n g x 0 s v L a 9 j 8 N o Q t D j g H r p f C p v a D d o C F d 8 B m I s 7 o Q a z / J m N Z Y o R Y B 9 X F p Z b 0 n T U p e N f U M 0 Q W m f c I K L c t f v 6 s R R v i M 8 r O n C O 9 J t f 6 A z L 4
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:36Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca19-43b4-423f-b097-489e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:37.000Z" ,
"modified" : "2016-03-17T15:15:37.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-0b226a77 400653.doc' AND file:hashes.SHA1 = 'be077e40183ce685091d8cdef7297644b3c03133']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:37Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca19-45e8-4e0e-a3e9-445b950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:37.000Z" ,
"modified" : "2016-03-17T15:15:37.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-0b226a77 400653.doc' AND file:hashes.SHA256 = 'ea24f79c0b98d48d7f41c0cfabeb7572b4bf99d8e8564983b3d61860718b2178']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:37Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca1a-1ff8-4a6c-a14f-4fd7950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:38.000Z" ,
"modified" : "2016-03-17T15:15:38.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P N 5 c U i l e k O b O S Q A A E A 4 A A A g A B w A Y W Y x Y z c 3 M j E 2 M G Q y Z j V i N j g w M j Q z M D N j Z W V k N 2 J l M j h V V A k A A x r K 6 l Y a y u p W d X g L A A E E I Q A A A A Q h A A A A m / M v W w K W + x q v f 4 M X Z w 8 b j 0 O 0 z k u S P R R 8 u Q 49 / A c p 2 y U c F W C Q I I v v 3 o n j 9 r 9 s T E o s m b V F R P w p y n u u 7 S T u f m W o Q b 1 V X Q J f E 0 U c l + B J Y k D 5 q D b B 1 K u H J 61 O y X w v t e / o f k 3 w J 10 X g a L + Y Q U w / 14 B A S m g j K a c R s W M i n p I 9 H t I 2 Z R L J s 4 p h 9 g o O D S A H C 8 L Z t P 0 b q P 904 f L A T M 3 T A E A X n x u 8 F h C G w R Y n J q m Z L x e W w b v G b S I K y p z Z w 8 J 7 l 7 q y q n v 7 p 6 P n J a r l k p 7 O U R c J S 5 O S N z 8 n H b m 25 g V t j e w / i 5 M e G 2 / z p N K G 637 e F q V e m C Y t T r g U O L 9 H p j a m R 3 F x w i p M y u 0 K C Q Z a i W n K k z i 2 L X y H s D Y E V j a 6 T b 5 t z O 1 z R Y x g S p z 0 X r 3 b L V G y D M o 2 V c 0 49 P f U g k o 5 T W v c y K X 62 Y k y N 6 T M H i x 0 E z K K V 2 I J X 1 z Z + z 2 L n q t W A S a N Y v 1 K k 56 n 4 M x Q W s I x t r t 5 T m 9 V s P a e R K M I 6 q R g e j W Z D C o / B g I N x 9 Q H u Y h 0 b L E M V 1 V c S Q 3 H S C R w M d g Y 1 K S P H M f M b l K H f n I N K f Z L C m W P 9 u Y D 0 N a 5 D D u z h n m a Q F i T k V 8 c G k I B Z J h 2 p + v K o E 8 a o D 5 D 8 b F K 1 s A 9 c m o o b Z L D d p R n x u B W j C P S P W B E A x N I K M E E B 9 b Q 4 W k 7 K x T 1 q C e I C r C K 4 c p 4 q e V 1 f b d 2 V D 6 M s m j D q N L W v k v y 4 u z i G c U 8 w 29 E M l 5 N K o O r t r o 8 / u p x P J E 6 B 1 b F Z y o D H Q E N L W o a d h L c R B f b / k M E 3 X 3 M D N S S r P i B k I + o 2 P M G T k S R W W U d d L S F n L C s A n J B J 8 z U H A q o e D 2 j o y Z 9 h 5 T n F z A O j f C y o V R F 6 K 5 V q M L 9 g N a w R q 1 j F r r L l Q B i d 3 d V 3 / a E R b 885 K V M j g u F A n J 298 D Y 2 D m 0 a J v 1 N L 5 P J n Z m K / y w b y z I l 5 b D O m F s o 2 k C O q Z H n m L 5 S n 901 q O J c K q 7 G Y 3 b x A x a Z D o w s E u 6 G a o m 1 A 8 k Q G b C 6 q U b M k 4 o J c 7 F Y J n 4 q 8 I v n g C J 2 G G F D g M k e 63 M 7 z L o V K 0 n e m R y u 2 q C f 3 b 0 / p F 8 Y K m Z c e w w 5 J A E p T w H j a j 4 y R v J 8 D g Z G m U W I H I 9 G O t m N 2 L 8 B a H 0 0 B z T z i z r E R T P e i w C q m I m w J F T O s V 5 y x 7 I V Y 9 M 8955 P 8 l q E L F N M 4 O j T e j W G b y E x w M e e 8 i G S i E + e y T F 2 Z a / m + R 51 v A N / I d x 7 Z k n o f W g I y 1 f z 4 b x A x m l z C g S T 70 V F 1 F w D 8 C c s W + X S 53 h l t N 2 x r c / H v 2 O E f g 0 T g b 7 A K s r r g T x 7 E H b L t 3 Y L p k j H C a I 1 D I 72 B B D 2 j 3 V X S 6 q J W Z E f I I / C u f 3 b C a F t i c p m Z C W L + 12 H F l 2 Q U 6 w V K Z c s u z E x s p c E Z A i V r D w n 3 n M m U e L j O c U J u Y q 7 A + D 12 q V 588 + + H 6 L x X 6 D p T V h B X V m W a D 0 j l W 99 Y V s P 4 Y A I 7 d A A D B v v E r V e 32 J y t W B Q x 7 f I t l W r f o L 1 X / B B e e x e m Q r 9 i I V v 7 h A O 63 o e a r g r t U X R E f O E x l 5 s n L k G 8 U D R t r S E e i + w X y K K T C h m w H Z f F p 7 d 70 w Q 3 A t f g e l E v g 2 t 9 y 0 P q o C C + A Q k B h x T D 3 R i M 7 c I U A v v L k c g U r C v T 649 Q A o 3 W A I x l h j V Q 0 5 F e O G y J K 6 G N 4 B t I i + 6 i a l G Y l X 4 Y F X L H A J c k E P f m A t + + y y / 0 x 8 p //jYZNkSLA1ITO0bsFIkYpYiX3gG+92Hw9ECvIhnvXfJqH3mFx10bTH7+gyy/0pmALb/z6o5GGhU4/VdjoXF7jBeHauXnVBYyM7EU7GH3ykX8B2r3qBVdkvgCsqEGgk5gVFkrSOly4bS9Lr7jXkcpuy+9h9tzo78YZicSsljP5W/4qekR3VRCa8x9nkuDLz8L/fUttaG9s5x0AKe3RrFKv+CmxzVikfZa5NpIk/zmAAdrUDZ8JjWQHNswKjHxfoJuXgu7kJS5c3Cdt2jYxy3F+Py9kouKMhWl1PS+qrLjxTzWUjNc4a6/701Optkp+3aYeoms2L5jqkDGHPXak/LkUWVd2gmygWi7odUMZ5HD20oWhxk7xpL4MSDePZB83FQHlC6nUbl98mx1yJD+GAxEOOLhcUFnYXufdMj0rpeObptFE3oxBJejXpB8hsnI5zg6ZU2e3NCDaE7fVoROmRuuS4mxSm98qLb1p6Z1+9dvqiCdv50qFxpBnVf9k9SitSlbdc1fZTSA/4ZvXbygt0q1u3mTgo5LPx25XjEyJYrDdNg66Tl/Da+dHCXewuoOwjDGElhFFqQz2JXDDRsSVHnnl30Lmdh7d3F24M5hAjUBzf+Klm12EyIovnVETSyUxtEIslcjNFSZu2iwhJcVvg0Xpfwu6b31iJlbJCXQ3QyiYzzRkTSj9Gp2rx8NOeA/L9mqSZfbgiqXiBOkv01uLMQWKYwTQ5F5JhaPFNmrCC/k4n6tXMoRXjewiOhemS+x5nL8MTFdI7ZFVYlyfthb5LQa2e8KTBH/r8VAWA5+KslsdYYoHouvdXDHFsbgTlX6THYbag2/2m36xou+mELmG3728IolswnBYz4W4N0CnLZeZwK5aT/pXNFUnGJBvSniAh2MC3ijL+elQW+0MpkUvbHcvVb7/cGWhC87BfLpMKF/gi3QMI0b5tT329/zEwXPbDdF7H6Tl7DSggZC9P+VMVBqtxHclIJSaDZHW7+AjTqtUpuFMc4Hbv8Tm1hDBcdP1+TelBRfGHz2Ws4/PTY1yrsxxS5FF6b/BJQEMXWsZvN2whh8vFNZAdHuPBy/JBODZrpZlmXYXetnWabgmS/VDeyPyaEnkarcEcfliXmY3qrRmZrCYPUqqJ1VAHbCYpJ09TLkQzuFaATmLX97oRMsv3Q/SpjYqtZe/WUzi0jds/n4M9fIJX5n1mpjpWteZ+g3UgCPgEmgIYiTVHKD0oUYUb8MKcBLINVGs4gW5bLpIR1JLrKZKl/Fd9EACyFYqITCFeYNn1rzVbbXCG2RGWA73lxulP/0P15EjlsSdkYkhT6+IpLpC91kHyHccYXEjKqrXF0ofgsS0s6yEKl4/DJZecLEgZNqwJZ6ByGE+kJcyGiOc79tH227hKQjhg0mHmjLIlCkALZumKupaLrxSQuNlkxauOAbh+lJE3McL04pX6xiPeFlQOoC9IN+/QTc+Ug0IGpZ7oaGgsG+JPCbU3IuyHfJbd8APgPV2HRT3mN4vYBDGG7cLmmykTb0Zt8h6TpnYVu9OkBpO+C1oy0+4RRBLLcUSJpMZ0goxvk+ZcWKsao/NaPGKuxZgV0nceASebes/sfpDitjgcbwu2/oU9v6BohgLE0Eg9XZI7CKeW1Q8QdXqZ1qg4zW1OzhDCMxE7R6TBze+KspdR3gLjpL4Y7foa7oChEu6RNEsZUwG8XD6am3pNYHhR+LZUqrxh5MKVK0ufp7NJ6zfrWS+xpgruYL5D6KhvMpLnotx8o73tEEe66zeWZHS+vaOahScRjYE1ThTB1AzA519d+iuOwjisqsjZvaN0n2xeoBWn/oHuOZNNDNvZ1O4FcZWp5hO+sffGQiZA59KORLF06ol5w5or0CpQxai5H1AGPIeCL15WFabY9zTeRF+FcYYniGvvo4zmmpZplwpIiLTVNY7Mf5dcyTjqG9E/NP47TpIAshESeDXaxLg4XpPnfRl+AF2zzgHpSiAHvrssxT1xXJFyElLIX563GW+H3qcUayFcKAdIZ9Kxwvz1asu+npD2+v9uQuvw1ZsZOQUxxWZlNcriRWcqrokyxlQht/ha9XF1s1fQVv5g+Ttc/iVPVxBwhYcBhtgzPWiDKvBRCB658FHI8qWM3gIA9WwTOY/blyDFLy12OuVzAcbfSOCXOSVXIqSJEZBguhcdhM6Iu7RBzZfWFF2nvR0POncyVYf65G7sPoGOMTxGmiCVrvFKgCQydLaoRceqUlXwpNrhDs7Gv4Ma0S9AKmL1wY5VWEubSaID0DzVTuczMO4gJkRn6GvIw6fXIGvqn/oUripEZcqVGnICRp4dkeV3mNy4sO+5o
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:38Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca1b-1174-47a2-bee3-44fb950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:39.000Z" ,
"modified" : "2016-03-17T15:15:39.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-0be67206 37651.doc' AND file:hashes.SHA1 = '6d43e89abb8cf4d497dd49b31a78c5687dbc71c3']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:39Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca1b-72a8-44c8-a6b4-435b950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:39.000Z" ,
"modified" : "2016-03-17T15:15:39.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-0be67206 37651.doc' AND file:hashes.SHA256 = '973a20ba49f510f42e5c72602a65b8bf39b4074053247df955e4bf99def1a0d2']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:39Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca1c-ba5c-4060-b2f3-448f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:40.000Z" ,
"modified" : "2016-03-17T15:15:40.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P R 5 c U j / H R Q b P C Q A A E Q 4 A A A g A B w A O T N k O T M y M T B j O T Z i Z j B k M W U z Z j R i O T c z O D g 3 Y j Y 3 N T Z V V A k A A x z K 6 l Y c y u p W d X g L A A E E I Q A A A A Q h A A A A Q F L K T P b b E a M c M R r L Y 21 N O B 7 A 0 z x b g k q 60E9 T W i g 7 J E 3 + 4 a G q P f G v 67 C T P 57 m F u 1 R r t 8 z V d g E H 61 c V 7 k Y c y 8 o o S B t Q 4 a w E 4 c W K b 2 r p U C / d q X 4 l 8 Q O K L e + I z e D / w R 7 w m 6 J 3 / 2 c Y p E K c w V y r t t p b a V u A q y Y J X v Y l r M B 9 e R y o S c o B q c i z E l a 1 Q D 1 K R u a l 8 o u d h v k e S I l s j v 4 o e + z 5 e S + x g C f o c A G v m Q k O Y P B F / P C a J V Q u x 3 u r Z C 8 c m T d G G J x F h 7 S I a F v d Z g X Z 5 I 4 M G z M o x G a J f B C S i e e y p J V 7 g B D V q i m 7 F I N X l q 3 B Q 1 c i E H y n x K 8 O l G U M u Q V S J I h I z c q S Z t y r w c 6 f v M l M F 9 N R n w r G i Q R 8 r r G U S J 9 A L b x Y w Q m z J / G R b 3 f e 7 k 9 X m V x y L 9 y F b 8 g Z l t H l s 0 C 3 S x d n 27 h O p V z 9 F H 8 q z + F y X g 8 m s b q k 41 f / A F 2 K I c x D w 5 k g 596 / C 5 d r b F 8 G P a 90 a V 8 e Z k A I 8 K a a T b I I A h X v g u I x n Y C + 7 + d H G p b Q O l Y 3 O E O 8 i K 83 r d x J e w 2 V I q A a F 7 g X A x h L b A L P H 4 R X M m x g h s l / 9 r q 6 y k O 3 X R 9 + K m w n 26 j 7 i M g 8 u W o X u L C W B S 6 r M 3 c / Q L 9 M U 530 x S 9 T 4 n W T X y u K v 5 C H z P i y B b / x W d I J E A + + t s U D 1 S K f 2 W M R 8 K P 0 Z q + O 6 m B g J V h Z E W y g Y N U A J y G Y J 6 L N 0 r E 1 i I z + 8 a 5 T l B g W L W m 5 Q U L p 4 S + + T I p p u E q L Q u s F 8 c D E c P G 0 / D Q W L b b w W z 0 C S B V u e B C J h 0 I E T X g B 1 O Y x t c l s o n D d x v k 7 I S S k F e V q N 5 P o 9 N V G + t T R g 7 B 9 D Y X e e 95 S l 1 f z u M 38 m P X s 0 E H c G d x 3 A S x I y c w + T q o 2 Z x 3 f o + b g k Y P M j u / T o H C T 89 G 0 5 o y m m x V v T m / f g f m C p m + R f v / P 5 v z p H C w S f F J u O B B 2 N X f z d P x 6 k I r X g N x W + 8 v w e q e P Z S n m M A 9 U v a h R H n x V G 4 V Y o S p f i W 0 x z v K l s i N 1 + u c x h i Y U N h n x U U 1 m r X 7 b Y d Q R Z h I + 3 + P 1 H F J P d m D h f q e o V 5 U 1 N p S G C t b h J 9 o y A p W B 9 / c o H W g B y F x x r S + 4 g V 6 h X C Q r J h z g V / 9 z p M 3 K M W m i a v j B q 6 l A W K 5 I y h L Z V o A b B m t P U i u y W M 2 L M x 1 p w Y t k 1 M J u 3 h 2 c U h P + r H E T 5 O J t T P v p y s t z 0 Z T h p E / 1 H d i M z P N Q e N l t / m p W A T Q x T 2 K P g 2 O H K X R / A l D M F Y u q d Q Z G 6 k F n R g P 8 s i + u o k E 2823 + Z P M a K t t 1 / f A z o D a Y d + U r L 6 p a 7 C p y y U Y y c B 0 b X W 8 i G g T x y d 34 i r X D T i J l O 8 l t a a S K O V 9 c w 5 v / g 15 u M x T z X P U s M I d n P P I + m q 48 D A J E 8 N g 6 / u F Y v Z o s i t 3 O E 2 U r t V p u e A j 49 h i u i 2 m Q L z c 8 e p n Z + y H Y E x h J e a V L L K L q 2 u r 4 n J M b i I 2 D N E v E J P T m o P c 4 X 4 p h K 0E8 Z 1 J M 7 X 287 x L A T g K T d E e 0 f m 6 J y Q 5 Z 5 m b g 9 c y 125 / B Y J V F V Q H O U I M / + g P o P Y s I Y j H c F P / d c h 3 w j q i o G 8 R R G N H N z Q c + n 3 b S 8 + V p l o m 0 y P P Z 6 v 3 Z H M D w r f R 5 e Q o L 1 M r l 2 N V r J 9 f Z H 702 u w N 7 K T h b U J P j Z N D J F c Q d M 8 Y d x x B O / H 977 B b P k k d j R C L r k 94 R O 34 v h 5 F j A C G w / 2 g E p N G p R o w k p e + B f / 13 L A b o A + f v m F 2 N K + + M d d F 0 5 x q 6 y 0 x v W K C b 4 n P 1 s T b 9 y Q K C Z U k A R + R 6 U S p m a j 4 w 6 r Y + Y x z N T a C c 5 u O Z q S + 2 + F Z h M m + m G V j W / L Y w M S K r o 8 Q 7 K 95 F H r D o K h + u K v p Q 3 J c 6 H L O C P U i c g o T f 7 s K m Y P p Q f W I C t g j 5 n r s 6 M N D 2 F K f 1 a y f 22 r l l x p H Y O F s b n U j L W e 8 P 8 W Q l B B l K F C e 5 z L g K l o U 2 i + z w i O i O y w p + C X f Z z Q n E b e X u m p y P H f p W N h a j P B t w J X N 9 N 7 P k H P x 7 q 1 P w I 2 S A + o i h W w r v 4 U 6 R e n 0 Z 4 / U r g l f 0 1 E e x t N c t G 5 k l m 3 X v 9 l E d T l u M h d k J 48 B 1 f R N W K + s x c 8 N k E V C s S c m Z u 9 o 45 s T A O Z y v R / 0 l C s C + U 4 c q d p 2 L c d Q a f n I Q I 1 U g 1 u S I g K L J B M b f m O N p 612 Y 5 l C w v n g G 0 k R 2 M W 9 p t t 3 C 2 g d V o 3 B 7 E Y 331 V F W t 69 Q q 1 W n K K e / a y G m v G U A M L 3 L n i U s 2 w / T F U R 2 i t i f g z / s o e k + I U g L V b H Z r s a e G L 15 S Q E k N D h X d y i B 5 / h D i l j X D 2 d Y 8 R 8 c q 0 62 u r 5 D P W Y / C d 0 t J l W 6 a N D Y a o 1 R d C E d T x T x 4 F 7 + F m J Z Z p 5 N Z k G 3 w 0 i i q H j l 7 U n h N 4E1 A j G 4 s Q z x / C f Y Q T J 9 J B 5 X r d H / a N o V F x u I c 5 q B Q f W C N F U 75 w p j i 3 B 1 u T N 2 q f 3 O P o g q 0 R A T c b g U c x q t Q G n u 7 + B l b j A n 74 M / l p F D j C o z q m i Z 2 H x / O R C 0 / x E X 8 Y p z p H + W v 7 M W a g L 0 I j K D / r j 2 K 9 b A o G 0 x s D t 1 O 27 w + q i q B L R p 8 z h 5 l D T 4 I O n J o p 3 W Z d x c s s Q E D D J X c 8 w m J a q C J 26 q f c X v J y x p a 39 t f n e + n U U k V b m z + B + b / L f e 1 o d g P h P V j x P y K G D H D 8 K N g r a n 7 Q a h L S q y y 88 a C X a C s P / p Z E z h W M m q W 8 T u 8 A j w g F Q A F k 90 y h J i F X m K M s q 8 k w n Y Q h 3 h s w P h / y 4 N A Z a p 4 E O N B b M S A A C K d R B 8 Q b A a s S V T q D w t y o h h + p z v h b c g H l I + D x A t Z K l 7 t K p R k V R 48 k 2 t 3 c U t 9 i D x y e 3 S N 6 A d O o P 1 k i z U x j z E H C K 7 l N e + c Z y 4 U O R I + t 291 j 1 Z 7 T L W I T h a T o d E J C Q W Q N 2 T Q 5 f z F K B I 1 T P N J Y H l p p q 5 Y C u B 3 V z 97 M R I n A K h L r h N W 5 f m q Y N A g i Q 1 e T e j B l E 6 J c U y e 8 K M d 9 Z 29 c c c D 3 y K / 6 q i A m x Q 1 f e v Z J j 3 R K g r O h m 6 r Z r 1 o x y q 1 c W h W 0 z E y + n C O n H j T m T v P h u w 74 o / x N t T 8 v i I 7 C + i P Z R Q + g W c i y W b + f 3 U U K Z + o 6 W z I S C 7 y r 270 G o G 7 d w 5 + v J F 18 Y a X F y J 72 M Q 4 T x 7 f L W H q N S Y / c F r c 0 W F S h z X x M C k P u 5 T E J W C n M Q g S K s x g e Z D t l R + v O E k D r H e + g k X o Z C D L 4 M 3 + d K f c k e E J l S y + m p E M z O v A r L l l s r E 2 I A e f R Q I E s Z S 0 j o 3 z E 1 N 1 L X q X e T w G T c C J O N 0 i j 4 y 3 a c K G x S Z O J b + Y W i M i f Z M t a l v 4 n 8 e P X d 8 W l 3 K g 3 V t R s q i R 5 Q 2 n x K j n / d 4 p / j A F E S a C N J b j 4 V F p w y W F M Q 3 F p 8 + h D 2 J L c h R t 1 I E O p b 6 l a h W t n S K c O y 39 d x I q b W u w M T f + n K A j q B a q F w f X t R i p E j q / x w 8 + / Y i A 1 a 7 Z / M 2 u o / u 1 O w O K + i y Q A v S M C x 5 q 21 m u t f r t Q v D v 8 R 2 m v N 6 q S l H Y l v + J E u D T P r 4 a C W B V R t f M N G s q 18 L w b 7 c D R M H 48 s a e T i H B i L G q V u D e 8 C 1 F 6 H 0 b 7 B q f 3 v n 9 B A E l 3 w E d u v I b 6 Z + 9 / h V 18 D I H 3369 V d y + e T M h U L t w o f V O 9 F p p U W D w + Q k 9 U M m n b W o d k P J 4 / e k 6 L Z s b A W 8 g / G z l z 3 n Y N Q A U S / H h o c L Y A N s c f t z c 0 I E F Z 9 U q 2 j o r d o K j i W p P 3 p 8 Q u 6 + b I B T 0 y c l K 8 + u 8 n D s 42 W M u m 8 J o e R 5 A r k A s 8 U x D G e / v O 3 j h v n w Z J X A / I E 5 y W g K y j I h 11 J h I F q j Q a f r x T W i s 1 / E A p G 7 b n A r F h P L 32 J 1 T h J U J 2 M A p g 7 j / n q A u d u w B L 0 T 0 C i n z P b g 41 V B F V V y Q Q K 4 K n p J T 7 d T R 8 l G R W 9 e b m x 8 O q h J U f 8 t G q D 2 e o h n c 3E0 I u O E 0 2 u s S V P X 85540 q e W v n 7 G c 91 E c a f F W S 5 T b a x 61 U 76 L / 3 B 1 Z G c Y b f c t U o F Q W / b B o Q 0 P p 2 r p 3 l K l 2 l F 0 c Y P V d z A O m o C 2 g W y H K C G p q R 0 j d i j 52 Y r 0 L g A + F v p C g T B 5 P 2 o p W l A n e d C N 6 z t M s f 0 d i s Y c p k W G K 8 L S 7 O 6e5 q x / A X q N C d H f N d V t q O s 2 g s h l M k 0 L B s q u o g c u 6 l D b c 68 G + W 3 h c I B S l p h R F S k h g o m z r G y m V D o N 5 x G I q / 6 a K u 4 L U f G Q n 6 r 78 b n 89 K t G i G T f U l H L G B A l A 1 P 9 M s Y B D 24 g c z u 4 r u k / L i P B w y w 2 C Y x 7
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:40Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca1d-2550-4f52-a4eb-4013950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:41.000Z" ,
"modified" : "2016-03-17T15:15:41.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-1e84aa61 469129.doc' AND file:hashes.SHA1 = '69508c5c7415c94de11397fd5127d8d9db47420f']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:41Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca1d-4798-4db2-a91c-43df950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:41.000Z" ,
"modified" : "2016-03-17T15:15:41.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-1e84aa61 469129.doc' AND file:hashes.SHA256 = 'fff6df71d5b47029a44f9af1df0f4b7d144d544dca87cb5d221b30362c43cc9f']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:41Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca1e-0274-4089-a96a-4589950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:42.000Z" ,
"modified" : "2016-03-17T15:15:42.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P V 5 c U i 8 Q f u R P S Q A A E U 4 A A A g A B w A Y T J l Z T c 1 Z D N l Y W J j M j B h M W R i Z W E x Z j U z N D J h M G F j N W N V V A k A A x 7 K 6 l Y e y u p W d X g L A A E E I Q A A A A Q h A A A A Q F L K T P b b E a M c M R u / b Z L v v h 0 T j 8 p E / M r d c w o / k o f J 1 U R 6 X g k x X n p n I X 2 e x J Q / V W m 1 v I K b S p X q w j g 72E+3 r U g u N + T n f r 7 z y X w x 0 R L F m 7 D w J J U 4 C 2 A D v j t 7 l p M a C R 4 s z B S L a g Z X 5 e Q S 3 W T T B I d b G 6 Y n 6 y L Y g P 2 E c r 6 b 9 j L 429 E E t J Z A O 5 G e 3 J 0 G H 9 d I K s b y r Q Y 9 + y V p u C O S P a D F n X k x j 1 Y m S z / j U Y Y e M j d Q d 9 y B s L O w P K Z p n e 4 r Z N Q a k 8 + k u Q D s 2 h w e b k F W K J q N O w G 5 u l j P 9 u a n + X D T Y r a p I e d r w m e a c G u M d s + E b 4 Q Z X L F o / 7 b S E S W W Q M r S N 6 f p A r w Z F R b s c d H e v A q 4 A u U m 4 g k x X H f b p q t g U O 0 k L K 4 q A z t o b E f I T j u t G Q 9 j v b b / i a 5 B L H a F C 6 c t R I 4 E V p m N B n Q 0 r x b i s k Y 2 f r g E 9 q 2 T h a o 4 G 14 j W h 22 g N a w Z D G c b V B k N O U 4 M J x T q T V 3 J d + T B O 1 Y k b 3 k 5 w S D R o f 5 x x g V F o D M 0 7 m F H 8 a V / w J 2 + G V L v q i O / S c T j M i E O 0 K O t Z X / w f e i V N A P K g Q 2 i 6 S o h 73 J k 31 d f E l M 9 j t V q e R e W M W M 8 u P 1 m R E j h v n k i T I 1 Y w y 5 U / e o 6 L u Y y 3 l H E j h d G a p L W e c Z l 4 O B V o d B 1 G f T A k j J f J Q S B z i s x 1 l I W P T K l S q A U C k E L A G Q l b / d D m T f 3 T r r N k 2 x i k P j Z u m E b E k Q A M v O x B w R M U J A p g 0 L T r 4 t 6 i I 9 x L e L x Q c F 6 l d T K 7 Y v G V y b O C e m c e I X Q K A J j F y 34 a v M z D O Q M o 4 D 0 f T P 32 + g r 77 K s W + W s U W a t x I 3 d I + e o 7 e o a o g Y z + 7 E e H G 9 I X r O K h R Y v B a N 8 S 9 A 4 T e D O E A t I b t L K W p p o v 20 y x 2 g n f r e a / Z o p k X 8 A q U 9 f f E i + V E a 5 F m J C A Q r / S n 0 N M 38 m j 2 K w 87 j K K s M h l 7 y G h L P L p U 1 b E m M t j + j h Y 3 M d Z y b o n 3 c 4 i d M B x + C I U V B t Q R E u w 4 + 28 W l + 2 o n E 7 e m M R F f + s S a I Y / d W + r E Q u U 5 W 1 T O j 8 r u 1 Y E B F 9 u k m v r C C 2 z N J O 64 b 42 F V M W V 4 l D S o M y p v h t o R E o 3 E i Q 3 s + F 948 q j g / Z j l c X U 0 Z n W O 8 A w E v F 66 E J J 6 I g 4 X 3 l f C U Y o A O 2 L U E 7 Z 0 M N X 2 V C f T G H j M d o y H u I E S F W F u 1 a g 70 G Y y y I 41 m n 2 I Q M t h R z 3 J b / A 4 T N 8 g 4 x h Q m 7 n J 0 i 6 Q l B S N u L p B Y m h 10 B N I i p 59 s v w F S f Q t w I P W n / 9 Q O G a T V / y f b u h X H L b i 5 s P v 53 u 0 p e W b 2 S h U t v + d 37 d O s b T o U L 21 p L W L L I x + j u S c z 5 g u s 1 N 9 O r y I T T V 104 g E A h f p b Q F C U b Y M h y x Q / U S B e D G b 2 e M J s 7 i l 9 g J 6 P u 1 u 8 N j B T Y E k V b O 6 / 3 A Q b s B P b O A Y f 4 Q m G t 5 w c 9 J k P F P q u G C j q 3 y d K l B G F 9 s T z n T U f 63 i T p B l t 13 A l Z N a c b V H 6 R Q A 7 L t i Y Z B Y U T h 3 r X K y E p f / E f h x L k w 4 i q h + / I H a k 4 S 9 Z R 7 X B C P I b / k c I S 1 K M 65 w z q e + k e s 4 r 9 t w O P J W 6 k + c g 3 k f f z D o w G B a c 7 M o 2 p N f j q l 8 y p L t R k A B P e B + v z 8 F J H O L C M f 9 Z p B Q J q F m m r p T 8 N Q W 5 + h s H Q 399 p v 1 Z 8 g t A f 8 j n + s P N P 1 h O R 5 B W N 3 c N M f H S U K 9 N x s Y K Z v 4 l D K Z U 4 r V 20 f e + 5 c l x 9 q Q g X / O P z C 8 H + a X P h u o o l R W h I 6 h a / E 1 g K F k w e v f 6 M t f v d b F L f J 6 c F D i d v 0 r V y j E / x k P I V V f a N 71 v 2 U k J I J h E M z a 4 B q o 72 + g p M R k / n 0 f 5 z y i 1 + T G / K l G T Z W R j a K B A y 6 b v V 8 G i G U r U R n c J Q v l + A b Z d 0 O V q U F v v G A 4 s g w q 4 H B / b i h 2 G t S g 7 u R o 6 k e K n O l n Z 6 k Q S B E 2 Z v 47 h n Q F 3 J + C 3 P C g G B Q H m H H S N t k S s 9 g H Q G E p j c w E g I T 3 W e 5 J 6 G 3 q p G O d Q K k K y N v z K C E f n r D 5 n n x a B K A 9 t x t Y k B L q Q S 6 A o B 5 j Z P 0 e G m u F / M 4 A S n o n z r d f R z 7 V h P z n T E 3 / P 4 G l Y J h k z 8 U G 0 7 L 7 E B F X m 9 o Q d j a D A V 0 C Q V a S F v z r P q q 3 P N a h X z i c O a z S t m m S 0 z 0 T z U X w c D F D 8 R / h + A v y O 4 I 4 f 5 G n u Z U B j 6 u 2 N L 1 J T U S T 30 i X f 2 / B n c P z D K t U c R j X Q b z W H H 0 U + N S y k h k / c u p o + 6 L / M U V d Y 8 Z l j 1 W n E O d E h K 9 B 5 S E 1 S / C / q G v k r s d W 3 b v Z p + D / m C b 9 n L n + i v p B 5 z g i 5 Q Q C 8 z O 51 u 57 p l G e L Y n y N r H c r c z F g 9 V c M W l p 99 B M d e x A C t M 0 a c q A L v f S w / R 3 O S t + j I f 5 m z r i 3 x s k g 6 K q s u n T I H r n E 8 F j v q I V s K U R 0 b X X p v v x s + m r S k i S s T z y l J 4 A q 0 q P K w v g 3 v D D W G u u T k W M Z n K J r O g E 8 f 480 x X A i + L f D 2 x w q G H O p R + 2 U c k F J 8 F + 1 Z 6 O B f m G 6 Z p Y O 19 m w Y E p j u E 9 E s G H 311 D 0 N W 6 B 6 S 1 A I m I U t n z r L x 3 M E V 7 D u p M U V Y 2 o n q 6 N 521 / O Y B 49 c j / t t X 1 W 4 f 2 P V p 2 B 7 e G C n 7 A Z t C J A i O M Q 6 a Q 4 S B E 4 h Q + a v u C x G i X R E G q N Z L m q l Z 9 v q K 1 O k q 5 M e d Y k b 8 M + X Y Y H E 8 / z D d N P 1 w t 1 m M 6 h B F / X X a t L q 8 O 8 A f X e V Z f B K K 9 g / e X c 4 o i p / k K l Z y s h z 3 T E o / V U l O L x j 45 + f o V G m K K 8 W 86 D H 0 R D C I 2 l D o p k j 6 g E T u r b q J a h / w T s l E 43 y C B p G X 73 t i u K f r Y f C s L F / e c L A Z + x 0 9 + X 5 f 7 v l S 0 w m H e 8 j Y g 98 O N 1 I g a / Q c 5 R O 3 B U T a F r M J m 5 d b J h C M r 4 Q 5 g b I e 2 O B h c r o d P Z C Y A w F p Y D d B k X r j Y 61 f l T 4 u B t f c 0 Z E 1 Z j X A 8 w v A d k Y v 80 N e a 54 R i n 1 B s i W R z R b J r Z d H K b F i 59E6 k 1 d N 2 P Z I 6 J r E o B B T E h H 5 I D q 6 G 8 f l U o w + t O 6 O e h Q M 0 J H j c z r K f m I r W G t X D I x 4 S g F Q j U x Y 1 g / c W S b U D 14 M F 3 e f L L l 48 k c x v R j E p u W 8 K 1 O o X / 7 J Y 1 e E K u / y V K F j B v K A Q L V V C o h R X w X j 8 Q h 2 / Y e z v P I c 6 Z L x u S x g L 33 p P B K J C O A b 2 Y f A k 1 O A 5 D M x l C h z 17 + n d c 1 g B 7 s 8 o K B o A P p R Z B C c E N a m c c J a 8 y k H d Y V F c / 6 / E 9 s Y 3 P R R 5 D n Q Q a K O C X m w L 2 f d j 8 + v H e b w k 7 v l 5 p R M K 4 R / s C + n 9 O s i n s B Y h b + U p r 3 K I S h o A Z M l E T X 4 R 8 z D C b E L 4 t T T L B 5 T Z f T I 8 / 9 o 3 B v 8 K 8 a Q p Y m f m a D Q 28 T I X i 3 //WLuLkCQF0unI2mggP1rCSM9ADuempbJiNbTnpYdb0KXBDkWHLq2kExXK/DpmXYKXeZHz4nidqiKKReUHCShQiW50fSnoWtkY5omD07aaRJv7C29ynGtk69mQDA5xvyJ0keCqfDwRNU4t6biSYH/9+wH7iFOUC1iJBpel9uNLU00TlImPo4wX926OqPVA1JK06rCvxQ5kJp+8vfNoQZSpJ6WiwlTFjnAMqncSnmGY4mn8bwRK3JNItWzsZGnPsslVMFIEI8osW/xeeFBgq442IINSDzvLt9e7n57dw43XdWx4FXuiUhaTrRSwGxaxx8YKkpIDovn3dFqpykhcufpvQtkhV67lfpZT8PU8aC/DismC/oEBAXywckwzajOZf8djoQtEHPo9K8rKXIG7pAhBb8dDAZ5G4SP/MUQTyl+S+fOvUQijzPqiMCjWA6I7mJklSbqw7IRPlGkRTXGP8FshMfrze5WqStibyZj4kNjQMsRssaRnwzy0+xy3VJsOAT9dNIfmzPGo4vQEA/LIoNvKD8P6IgmRJCA3UElHZ5TMag+n+a36zJlFnujQLWMia5TTbFfdm8QWDAH+LgfD9EKlgcFJ+UyfrmZ7jUHcjIXz4j0gs2lt6Ypm2+wkBOiQDyRuOIy9Y3z9k7v/zR8Xh22ggmS1ZvXpC7n5pBBeKwkTve3Tn4Gz8fyyduOWDD7pVfdfkTrUgvjzttz8ReU9Y5zLfUXJF/7CuR+qaJFepBXZ7DEb9/7KPF0mTIWsifn6uAAPCII1Vj4kRnOnvh+BIBuIXx7MEpEKFm2J
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:42Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca1f-1784-4b13-952d-40b8950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:43.000Z" ,
"modified" : "2016-03-17T15:15:43.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-3b5e90ab1 94643.doc' AND file:hashes.SHA1 = 'c8b2d780975de00eca7d01fa26c49797c6ab632d']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:43Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca20-c958-4301-81fd-4cc8950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:44.000Z" ,
"modified" : "2016-03-17T15:15:44.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-3b5e90ab1 94643.doc' AND file:hashes.SHA256 = 'e5adf99dbfb6ea81aebc1866e58fd137cd3eb164e9728a02a0da4c5eba63d92f']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:44Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca20-2438-4c88-9f55-416c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:44.000Z" ,
"modified" : "2016-03-17T15:15:44.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P Z 5 c U j s u d D f P y Q A A E Y 4 A A A g A B w A Y T R i N G I 1 O D M 3 M W Q 0 O T Q z Z m E 4 O D A x M D h h N j N m M D Q 5 N T R V V A k A A y D K 6 l Y g y u p W d X g L A A E E I Q A A A A Q h A A A A n 0 g / c k G A o 3 h z d s O n w 0 W S m S S L V p j f 8 D + c o j o U P L s q 2 m s 4 K i t n o N b I s j c H G c r A Q 3 t v E z p X + 4 S K C n H k e R Q r 29 q G k j j C H B E b 5 m X t Y F R F K 1 H R 6 P J N I d x q + T L Y Y c n 3 B N S 9 z + O l H I R s s w l R l x q W L s n v M + p G 6 t D m 28 + Q y Z Y O 7 L P P k I l n s t u K g b Q / C 4 S r F u + K A J 9 k u i 2 X 1 I 9 b I V 4 b 1 X 0 0 90 X l 4 t 4 D 1 X H h k U 0 N W X 3 B h w W g b y 9 T u 8 I 6 V 2 X Z 7 E k g Z N 0 m u F G c i 8 Q E H a s 1 G 18 Y r t q T p o j T 7 X C z T o M I 5 u n C / 89 S 1 R K + x I n l 0 K i M e f e P z I G d / N v T R 3 + c k F M 36 r L u b O 9 / S M T I 1 p 54 Y 4 c k U h T c 1 H K t p h W 9 g W Y Y L H V u J A 0 7 M e x 0 5 h h A 62 / 4 + t t U x + O B n + q y y u T c F m J i w D 9 D b y V S + 4 c s B i D I B L W X r P X A f T z 2 D I l M v F C R + 0 / K Z c B m V I o T x c s C 7 q f 2 i Z h 2 J O 1 U m p 4 x l P 1 E t q 9 a W Q G B o L 1 c x i / N p y Y S o p g i X k 5 s f + W G B H 7 v W x 23 B V l S e h B C w T 1 N / n M J 79 Y Z o w 8 A j + K o 74 F O U 29 H f G P j r y y g q D l d 7 H P j / b j P a 3 U G w 0 S w + m p i l v G j + 4 Z q A 3 w p S t G S f I n O s C L k t P P D Z U 9 j K e 2 S + w h 3 D H Y r m 5 M s W 8 N X Q M Y a y F 3 l + B + A C G L Q g S B t j N C d B + 4 B a y / X B w Z t G Z / n r I q Y i O g J D n O t 4 + k m V 11 C O L 9 e a E 72 R e 25 r N l e v B Y y N D H e u 9 o q V 3 M p U l y e 61 w W W + b E P 6 M Y t h b N b p Q m E 1 M L N v i 3 i z n B s 2 T Y B h A z H y Q x R P S z K V j 10 + 4 v D + A 31 D V Q 3 D Z M / B 1 g E m U 7 + h H 0 C E O 1 o T h f x Y F u C F 9 N d v J c B u M 8 J W n M y G V L O B D d H f D / I e W e 6 / Y J 6 D m w l 0 z m l i L t R s 23 U f m P D p P 83 v Y C e Q I g z z y y c n X N x K q v H V y 7 i Q 2 f Q z c g S B r U Y S G g I a 9 J S V o W B q 7 V l d X M A r n u 4 L 5393 W c o i y I Z h e i H 5 h + n a x 8 x R s l y v j 3 Q 9 W c 47 / 6 P d E x t r 8 L U 8 G R m a Z 0 s r 86 f P D h z l c F K S Y / l 1 T a 9E5 h c R g k a K t e x y U 5 A S I u G E F m o D T O O 2 O b 5 D D / r a r + r g V J j I d u p 3 u F J D a F O P D T b 27 j Q q 0 x R 1 z 5 c V l l k H W 8 T t k 5 e D R N B l d Y 2 K O X M 4 m 9 w w N 0 7 a 55 a 0 91 G S h i j 4 L r h x q L G 7 E k S s j W / l v V Z N u i s 8 X K Y J i Y c h b 60 c M v e O Z e d J P I t H I L 1 p 0 b 8 a f p x C p o n G m J L S q n m Y u l + r q c V G l F 2 r i x c f L c m u Y B 2 o V E x I 6 R B F B a l a b p l a O u 4 T c R y m U q Y + V Y 74 w 9 X X B g a m I X 7 K A U f f Q f B 9 d j e M 7 G Q o z J C H 5 M Z G O h P H g F t s 7 x r k 0 A Y A i H 4 O c 5 V f Q p V 4 T U a s p X h f l 4 N Q d V t p 0 p H R p h Z T G 74 F B f I w D 6 F j u H / u X D g K 7 y 6 S 1 w G R W d b v w A G D p e s q 2 l L 5 S O Y Q i M h i o Y C m C Z X a T U l E s H C L Z T w 9 t w 2 V n Z m s 8 X N g d L X j X m f W a 72 x n q d r H 15 H O e n p R j u 2 S b 17 B n f W Q N + A J 0 40 h C C D 0 p 0 S 4 W L F d 73 l E r 6 P O x F 3 K d d 6 i f B r 86 C V J I 5 U A h V 9 G w B i J h l M 4 s M k I I d B L z z i R b b G R s o d H N f U d / 5 x U Y S 8 I l c J H x / w Q h M 4 X N X j G S 9 z n P T l Q 9E5 J p a 427 h r z i G 6 I U H r c u C S 2 i H 3 z 8 k D E L i G M 3 h 3 e h 85 Z F e 3 p t Y M a t 3 y P J G E 67 J C F z u E u + S w x y 7 t S r H 5 y P Q 5 E L n 4 A O b U i O K T U f d a A 41 U u 5 o S w 69 M B / I 0 t D h g M g i 31 R P d A d U P g S T E N s n C I E q E c f y i o 5 A i Q G l d v U 32 B l c d u G Z 1 c o U 6 b Y v t V J X O Z 24 Z r d H W E 5 P 3 v i B b m z 2 M S s j z p q H N d k S x W w b z v 72 d b q 6 k 0 I / U h W Y l L M 5 S z z U v C Y 5 e X 0 B k D p + O K 8 s + 2 h 1 J a p P Y 2 G G t B a 1 p 4 G x C Q Q 7 + u x X w S e u b F 5 N 8 c k 3 p 5 c 4 o 6 D a g 3 u 90 z j 6 Z I p K e t n u q R / f a m o Y S r S I l T / u E A T n r R h Q m v 5 + c D / + H Z Y I A N / l F j h y I w D N Q I 3 F R c p F d o a u V l p J s K J t 67 y X X 8 f B 9 b J e B D 2 q B R b v g g z p U m / Q b z z L F x 8 e h b y m 9 D W k P a y D x 6 B + L s z x w 6 v n G W Q 3 W u w X s n i 4 i c W A Y u s L C I K W P u w p j a k f 6 q T h + P C i M B 3 g E h D R E v N j E Z g 1 t 2 g j 8 o q B g t + A K U N T d W 5 H G a a c C 2 d 30 G C O K + i 0 J g Q m q K a z 9 b M m v z l Z y A r Q t g S S l J L 6 W q v o S d M i 27 V n W d m u H u S B a Z Y Q f E A S V D c Y b m w p 1 w o 8 E x Z y j 6 R 1 g x w B w a X 967 y k 6 Z i D D V l T F d K c M 7 c B D r d t D 7 E U J G i + 1 X C D T b J o + K b T I i 0 d r R f Z 2 f J E B H g 8 f w J g u X h 8 s q y l J M U o o c o 7 G g 0 S H w K 2 B b i t h O K J N d w G l W h b a D y q K I P X P W w N E k / 1 h 3 a p R o 5 S A 94 m C M w L 2 z T 8 f R / j f 1 G 0 S 0 t / m O H i L R 9 J G 1 I Y 4 d S k z x w 4 m 85E22 u C M f R y i C i E t B m b / p a 2 / d 4 F P U 0 o r b 2 k / L V F 5 Z 6 k t E X 2 x Q 3 B B 6 L / B H 7 T N / 2 V r L J 4 P j N v i / d A l V s Q k 4 v U V o c 1 f O 7 y X p p g F z A 9 i C f Q a c m j X 7 u 8 M k L E J 2 a b B + Z n p 0 0 x 0 B U z N T K P B p m 4 O + r t 2 s + D + O U T 25 b U g D D M W M 4 y O D G E T I H 6 M c 61 Q K w g Y s 0 i w 3 W b l f g d 7 a 6 C J t c w e B b o 2 L i D B k a i s D d c g 3 I 4 J A 1 d N J r 3 f F v y R 0 1 S n N 3 a O f W a H 9 V f K e 0 B 24 j O k 1 T I + X 3 g 4 B 3 K 4 Z q C 9 P o s I u U E S y h c M N p S L X G l 0e4 / h L s / 9 n U S M 7 y H o y Z 30 d f R j y D 2 s N r J 24 a A Y 0 T e V I L V m Z l L 1 B 1 l Q a A + L o P d j I c 58 c h c R Y 0 l m U B l V 9 Y G 5 V E D 9 n //ysiezux11Q2OE+bhPe617ejzr5K/qOiPMWP31B8x96e+3Zc+JjaEf0T3nloffox8P8+laq3vlxd8TjM7hkYZzaQGbmplim7qQ9bBSRjt7uEk0RR9MVzjfpNh2BIGafvtkI3liPOEsiirQXcK5rYMnFsp8maCI0ShWzF4zZazdgoievaFw2FfDR35z9+SW5iLu16B78xxGzgfrKmga2S9n4/tegpt+cYo9haL0HwCzP3A0lwY4tmb8hK/dYSYw8X/M5fhc8jnWyqV2nVxNGlFvNHGjHCn7B35TyzfcIdKORVttSZ45vdozHvszOfjHhjfR8ZWlG9PmUXCYs4W9FL+B6kO45ZlVEeoZrJAWfIgZDq2KM9PMW8otDwK2HIJ8xrA+WODSFs4TSseDBnF6oBD2vjejDM773UdzRVMQZCiP0O+reDwH3R8EIN5V+gOYXJuQIbVbEF8283WjrDd1hYryU72txH8j2KdqExNKZKjWlz09eSJKaIoC/eV+3F/gbLgJdh8IATAtzKEJZdKsNqQ2HfckXktIkVlzkc9oEw2W562FCZtz43ZSzp4Glp1Ewo99dqd9SBUUjmtXQZkjuLfKNkG2i1es4do3GiZW20RV3Y6Pr3jTPMgoihre8807DEbhg3DBRxulvD4MdnyNksbKW6LlUbJSUKumxysWx+v//4asKlN9JLdDQPq6MD9sbFokG5qc0oJyQ+Ixg8j7JeHJ0MjyBku76D0xKMvkvrPmReMkBm0HRsPlHIZQyqpw54exNHtyIPicwQcqvBB9Yl8IqpJ2I1LgZ2kB1XJOYSN7hpOAxUltRrgPZmGki/JeWcg6sNfSYSyFKQOW1Y3hyM8GA5sglNMO8wd7Cz8NVhFOIbdtt4LndMsElYmYB+k+yhjWXhzguAXKlvSnTVXWSIk5nUPjQuIRaLSY8LK8vHCu03enQW7J02oaLQZFXA9N6OijN3DBa9bGqeBGZjuzKjSIzjFV175OBCNX3jCs3H1FDwfB0gILKz+iYZgss+yJlf5dT++md6LEFYWfyKuEV3tjHH7p5GvdEY3d8VNdpBT5U+Zxo7zt2tG0AnPUGh0/C7hANoqBc26WC+KXPLllVyR4ShwTGboG0b2yxSFuWni2wfCa7w6cL4OTLx2f2HGJmWBOpB9HEp4L
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:44Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca21-e514-43db-bbb4-49b5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:45.000Z" ,
"modified" : "2016-03-17T15:15:45.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-3f4ce6d6 2796.doc' AND file:hashes.SHA1 = '30208737d5ab28855c0ede0a5ad1ed5a5c0c7bfd']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:45Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca22-8fe8-45e6-8895-4814950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:46.000Z" ,
"modified" : "2016-03-17T15:15:46.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-3f4ce6d6 2796.doc' AND file:hashes.SHA256 = '21cd52fad698b367d68a19c019db8827e7e589aae4d1171cf1f69484c9df512a']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:46Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca22-468c-4311-b4b9-4d02950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:46.000Z" ,
"modified" : "2016-03-17T15:15:46.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P d 5 c U g 9 z K d A Q C Q A A E Y 4 A A A g A B w A Y j k 0 O W I 0 M m M 3 Z G F i N j g 4 M z U 1 M W Y z O G R l N T I 0 M j h h M D h V V A k A A y L K 6 l Y i y u p W d X g L A A E E I Q A A A A Q h A A A A n 0 g / c k G A o 3 h z d s I m 7 j Y K R j E j O T 9 h x 3 S b J c D n d A K X 7 j S U W r 8 m j w U r 9 G i A i k H K 4 o M q b b / Z P 6 F T v 7 m N d s G y x 69 n y p O 6 x 58 B t K R u S L + 3 / L l r b s + i a Q n + h U v M h e t v y u l a 7 S K j d q q C t 1 H C 2 x a r a S k N L c X H c 9E91 X j 2 i o h 79 y x n D x F P m V Y 4 J G s S t T 7 a u K s 6 y 0 84 U b d 4 N / J r h W s O 6 s 7 Z j a a k 7 U 5 y X M z T y I G A U z T a J D H / c 1 h N V D i Y m A k T U F 78 n l + 6 b 8 g + l 8 P t w c C E S f w Y c o d X h D Z o H 6144 w c j p O u Z E F n R A F m + L 7 x l s U z 9 k / D a y r E 89e8 C 0 G / C V I P m Q L 7 M Z N z e 40 w g f F g X V j f P J / y Y P d 0 X 1 S B K + X C O i + / 0 4 t M k + u x H R b r N T s A s 3 v R + t 50 K J t 1 c 0 f 0 2 S i z s 6 J 0 L m Y 2 + K V 1 s o + q 0 O 6 F F 6 F c j J B I L Y b I f a j N G S N S B H f S C p X M F x 834 z x 4 p T D b f 0 h h y R P Y T e g y u E 8 Y 8 q O K 6 W T 9 R t B 1 w J e k m X H u R V P G T l u X A V h m Y b H e 7 A f 19 b v j L 8 L p P 3 W 7 c p S 7 R B 7 z M Y E u t e L n O 3 w 8 O B C j f Q p X R l p x x i c t 8 g p 556 + + r / R J 4 r I d X k A X 7 k m i 5 / b e C w D 1 D V w + U u + 7 f 7 Z F 4 S M r 7 U w G M 0 Z v 1 X k O r A g Z L j M p / I Y t W s U / h B P j y / E 1 Q b S v Z Y R j 1 L e 3 F G v K W d B P Z d y z s n a F b a G m e l N 2 i x F I i M w L m Q F 6 U 3 f H j q D H B 1 x R H q Q i 2 r l E X l 30 + b 0 7 Z 9 h / R r 4 q 9 x 7 F t n L i 84 p 4 Y w M R U 4 q l E i i n K d T b i p t m T u H / B 8 J M J P y D b C g j X G u h A o w 2 w u 1 M A o 9 T K F U 5 Y j R 2 o d w L A D l Y 7 G h M x t 9 y z t c 45 u h 5 h r b j 79 Z X Y w T o o J w B 0 V 2 r M 9 W J Z B h Z E 9 m E O 1 n X 7 h N N v K 2 J F n A G 8 h k j b M + 9 r a X r Y n V m O y g B l Y k 8 L d d x Q 6 n C x W x 7 K F n q L X N W N m X H T G q E P P n u x 3 y d 6 p n x k H x U 2 x Y A u V s I O + j Y E P j d z X 0 D G R e K R i 2 i w t W P 2 q V U k o l L c M k g m q l 8 v U x w M P F V D Y T w X o G U k / 6 w o T Y D w z D i O r 4 G g m X c U 3 l n / N 9 k h I q y n 2 K K L B 10 O s v 3 k 9 c B j t u N G W M B f J h T y M e v k p e 3 b z P j 9 s k R J p d m L 6 l h W h N U N 7 I q t S Z q c M j Y I 7 W W d c P L K Z Q f V W G + P 6 V W 6 u 2 X j w e j t Y f l c o L z C e c P K k L c 0 u j d M f K a W I D X W c O s P p l T b f m d B D Y m l G K 4 B h Q J W y 8 w J C m F z W p s 7 x a u 335 V x K G + 0 h 0 J i Z 3 Q g U 9 F S D a b a 9 q v 42 Z A Y + q Z I a 5 d / y A 91 y 7 / b O Q I 6 L P 9 e U B F V Q e C c j 4 s L 1 H d 0 E / t q w M J p 7 g t + 7 G T l m m Z R r C 5 k f u T w f x A M w V x W 2 T v C 1 D 36 J N 958 M L L i I Y I R b 4 r 8 f D u U V i e f i n c v i u j 7 F 8 + p m p P l s D k D E Y F U L i A c s r R Y U y n k l s 2E4 M S P i N X 4 f / 7 b 3 g q X 19 + 7 N B q A O p G / M 37 g / r g X S D + J m U m g n s 0 588 c H T g O i k z F K o q 1 H t A e U / D 7 L v e H i m 5 d V q G P 5 B v L p r S S 6 i z q 7 D n 7 z X 5 z E 6 G w x n 1 B n E z / p U o I V J 0 D d F W B W E v n L D n A S S b y u P s i z L K o S F 8 f 7 O q h e N t m o r y e 7 U g W t m 0 5 X B F r 33 f s r g a 8 Q Y E g T 8 X c E x e i 6 f H X H 3 Y C Z Y N 37 w B m e 2 X T w a J 60 c K v w T f d J V / I C X z J P F D W D a r w 1 s o 6 c P Y R C R U h b Q J x a W Z 0 F l R l u n / q O n S 30 e e s 9 w f 5 E t b R z a + q o 4 h Y U l v s J c k k R j U b t q o d u 3 I R Q u S 5 H Y / S P l b b j p c p K G a p e F J h x 3 S 2 T F + J B a S k x 1 S p L X d r P x Z L o u H p C 2 z 5 j F n 2 f h U W 5 s 6 d t c a Z Q S O A q B t H E x N Z B X X Q 7 e P c a + f T m 5 b 69 w W A p l p V G c B X z d M w s 9 r V G 2 g g L O h M 6 h g c o E y f 2 S Q S A r v t O 74 O 6 b X X 0 0 w e 9 t G Y Y 16 r Z 8 i c j L Y / 3 H W v o i B q M D Z e W F Y 1 S + u K h e s r Y u U W M M Z C f 2 u k 0 h M n P S m c I x 5 T 812 X 9 l i n e u P H V s F V 6 I d + / S l B 6 t Z L z Q 15 m T / g H X X D e y 8 o L 9 U z z M N 3 r R s 0 c e A Q S U s 0 b L I m y L h N X d H r 6 p B B H 7 d 5 o m 8 O x o b R n 2 Z j s t + v t v 4 t + 284 i 6 m g e L t S 3 a 5 z e M 90 p I F 9 q N w l k y r E L q 2 H 6 b A H a U f + 9 d s m 0 u 30 Q t L I p P o 3 A s M J I H h P g z o N R k + W v i S I U A Y G N C 6 B O j o 99 f K z r P b z 1 K 8 m K W y f f P w O 76 G a K a Z 4 i W r Z I S c z 7 x E / X P J a v y G G R 8 R / r e g z v H Z O a E y I t 8 B x S P x d W g i 8 p F n X 6 F O h E i q V Q O j c y 9 U M u C X o r o 3 V 9 r 35 T 0 n 1 D O E S V 2 m C E x F s z m i c q e A x Y V a d F k m / H / 4 O W f n P 3 P + Y 1 l 25 F Z k S V t 5 e H C C Y P d Z 1 n q f V 4 K g F r q K f G n E e 0 H y u d W x D g 4 f r T f / + t p N k b R N V k K O s H y v D t r k / Y d 7 Y H c / s p l K f t t Z O I 4 r 2 B a s W x n M Z V N q t l p g z Q p T X t A Y M Z n h G E b D f r R b q I u T e Z m p K E O o Z q + 9 L i I k Z V W G u b s 9 C z p M 7 U w g x B B Y n l 9 v m I 7E6 o / 84 X p 6 k X A s X T N j v 7 x B J i y e G 7 J U w n f C Y q I w x F Z c S W h k V 3 S N D 2 c 0 B z B e w O G Q k i F q 8 K e B a C M 6 K f 2 a m C K j k W 7 u b 0 w d e H y f V g E U D J M W 2 g S 4 J 1 x y i 1 L f 4 W E S d 77861 q v F E a R F h X m d Q x j H m a G + l H U D E S c g U F e c m h K M o b E i p 7 F b n z 3 f 0 c D o H x x r p k Q L G a U L t p N m a x E Q A H + 9 z T B G z H l d 7 p q P X 7 g F G A P F 7 p J q X z Z Y 0 E k Q r b U i 3 s 5 C O 7 S K Z I n J A R x E 5 H u w 6 / I / t F f n W Z 7 C f a h w q W S l k 7E2 z L o 4 v M o V 4 I 6 g 1 p F B 6 G 9 U H U Y r O E U e C M F / K V f t y o y d z i m w 3 x d c x m t J g L W S + 3 //GoUUabgMPXfN8kd/U9E2SEwKg0iYz4g0aBevpaaozxmE4XYgxDR2w9YTt4g5cXKB/p2XyI6Cgzr/vGauNXwSFie8b4ga/9KQd9+EB1DH5+eiSIKc716515GzSUG/tftBdtNpyy04zcrG3lf3lIZmIWwQPgVDwFHTFmeYOpJ2QhdGfvM9FSyFkT2l3QqOMDJIROrNeo1xSjPZzzhkN3zLTPO6K5ZcU3zIewOvpYmiy+z+ePozyM0EMEhF7KyTQ9gfFuiAWlkmrgl4HDRuGw4+I4+bHPcIBDDThwyl9oJd7L+Yij5c070wU0tn8f2RJ3cJeted3aFlCu7TDpTH3SrZHzT0tdQjCuwhx6tY5GxRODuuAxkNpxxjWPuIW4s7Yy6Kmi+/nAVciC4YYkAQfcsxshH382/0a4T0/16ELTDQQACjoRkZV9gZ8D0NPZyLk6qp/NY0Xnw43R9Oga5F1ABaIk+2xvFBKRQnxvd1V2Vs2Lyi4ppRZoX3Z88EUSQ3UtHSFA/bWXghfMgJd5kG/jNBpo0IyfREQJe2iYa1b3G+QaMUhlb2Wheij+1qNL2vIw5oMDvQxCFzRFpvbCGFnFE5iQmN/jU91RhOJIREp0uE19IZL+f6E74MVFc1ii+LTEa+JxrfaPUUmTAWlJ+3Ke/hrbCk+TOQI6dZRH0Sw138t77wO1WjtUi4oIvWubrT1ZWlT48SykOEzj77EeXKQwrfkGR1m5+bIg3vcnSTaLQJgvMQCOvL7IpKAbht5NOg5ckTkY9s2BPc3t3LGZ0pSq1sTlIX7sQuZxM8EoI+IvM50suT6X2Sg4QieDJhRDvZxfUIP0C1EcNjCKG7GHrvYWL49/hHLTpFM6/UMo/O6DA92wHRzcU9q423ir/ihKhSnKBF56641LUNLvfwEJY2xNVbBGNV8breFBgagyY05EUSXRtq++9Z2W96zSl795gt9MFh1AEyGOYFtJ79nQVVqt73TXxANZ5HqtgS+dbvVzhFuVIeIpIKaUqxs4DyFZUi5E5WVGNMh3z/Fjp6HTfGzem4lD14SnzkKyZyJgGsxqqaaRTpHX1Qz3vwY82i9qtzd5PGFds+R7kGI1lkjNludY1rr/h4EO18Ue0jXhASblx8ghC18CMJCeBkKS
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:46Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca23-6fd8-46b6-a10b-4520950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:47.000Z" ,
"modified" : "2016-03-17T15:15:47.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-127dbca 998.doc' AND file:hashes.SHA1 = '80f8c9204949e1ff11dbad4821a6f7e400baadef']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca24-09cc-43d2-a67a-42ab950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:48.000Z" ,
"modified" : "2016-03-17T15:15:48.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-127dbca 998.doc' AND file:hashes.SHA256 = '451c28e505b2051c630914185dc6c2e0460ae30b219e02fdb6e7990935bf6981']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca25-105c-4a4e-844c-4da0950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:49.000Z" ,
"modified" : "2016-03-17T15:15:49.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P l 5 c U j 1 L D + w O C Q A A D 44 A A A g A B w A M j A 5 N j V k M T F i N m N l Z G Q 2 O T Q y N D F l Z j E 5 N G E 1 N z g 4 Z j h V V A k A A y X K 6 l Y l y u p W d X g L A A E E I Q A A A A Q h A A A A c 3 g m f p X f y / 2 J M j v Q p l T Z x H Z a Z G / v A T C k c O A n / o t N T q J o W S 2 X y 8 Y U i V j s 10 E S o e 0 o H i J Q 8 G c S G V Y M b M i 5 U A b E e B h s d r G 9 t T T 99 n D n h p l J 3 b 7 t H Z z u E b H A D J A o Z 0 D R 3 J l O o e y j A e N R U P B r V C t G t 304 M 8 Z 3 V Z f X P P N 8 n T M m 9 K F e Q Z G o I n T 2 u P 4 n w B P a V k Y 5 I F 8 N z U s L N t y E o 5 Y f U 2 s y j F X 0 T V B c i S D E K r j d R R c 8 o H G z U b H F p P R q R 9 P e U q Q 20 w H J Q I R A 74 E K W L 7 V 8 A 0 i d E 4 m V i s J Z H t l 7 J L y I W l k f 82 u L o i O 2 W y H 4 j N 6 X F a L 7 D G 6 n 6 G J C 7 i 9 e b N Z P n b N P J 37E7 J k 5 B V V 9 d V f a f I 1 R 1 K g u M x b L E t Z U d G D x i J y G F d a h 7 r C u + J I J Z r s J b e Q d A 4 b e z B u 7 V z s 0 68 D Y Y 9 Y C w 5 Q G J C l F n h 1 c D A K Y Q 4 Z i / W C 1 A S Y F P G d i q p e T f 0 A j 8 j V T + s D v b T v Q F f z h U N k 1 g X j N 0 / x P L W 40 u I C 3 E d 9 + w y K L p m z h U p M z v 1 R a S S p V 1 c S B 67 P / 7 / x w i l K I m i d V x 6 O g i a x P w c p l w F O k u O h D z i W k c r v f 1 T b u 1 M T w c U Z 8 B 75 s t x I X K Z U T g a G W j 3 r G p 7 s w q V s P m j T n I 6 D 3 b 1 N V m 0 r v C h J 3 s C G 1 U I v D A 1 t 1 q z d A P s U N Z Y m y 6 + u 1 a E x y q K V J j a l + J B o / Q F u V y 1 R 5 u i G M j r + j Y J b V o p v r / m O + q I k r P 8 q r i V U t M / l H M x R C Z 6 t c O I J n R y 7 z m D K 2 F W O s J M D j q v L Q u R l d 7 O J A F l z 2 p J 8 t Q p J x A D J R D a 2 W 2 I U T z S K M k w X T p V A F y J S Z K J j A A c J t T / v c D S k e P e g C t x Q N d V X N e l J r 0 85 d R U w F 41 j S 9 F H Y M Q x j t Q S A R Y U d y P y W F Y h I r 9 s l 0 l k z 0 r v F 9 m 9 E k T g W g L 5 z + h D a q 37 + 0 q f Y T M 8 h U G A E I / F r P o V u T g 5 h h f l L Q y u g r 3 W 9 b m w / 0 O 4 A 3 z + I x w s m i C + l u U 7 X i M i B V x o y 4 T r Z M M V c b L H F k s u n n S 9 C i P j g X 2 k A S B V u T T f J y v y S o X i H c O I B i w S + z 2 d T P G s + 43 t 2 X L K 88 e t x N 2 W z D k c T C l U Y 81 g l 1 w W 7 R U L V e B f G J T 5 s M x s 6E5 p s u y 1 f N p z U N d K q E E V v u 6 z O Q k Q e n C h u 7 Y D 3 T p a O D g m b O b l b 4 t 4 S l T 2 Z Z 0 r w Z V s 0 / M T o Q E 0 9 r 6 Z 2 P B V k b r v J W 44 d A G h 4 c K 11 Y 37 G u o d k F m R h d x 0 s 3 p 7 r e 1 o Y 4 Q O s O o l C 8 T q A u Q z 1 t m L r 7 x H 4 Y H g l W e U d h t / H + j 9 R + i i T 8 i 5 J q 2 w V U T m S A w K 3 x A k N f X g V l + E 95 n J k X D E m 4 a 5 F V 4 S P c i C K n 1 j p C V F M g 9 F + 21 V z o f d x p 3 u t L 6 z v 9 q O 8 j C C 4 c f b K q l N s m M X X L Q q d k A r S H 2 x 4 z Y 9 f G E h w X G E d + d J f y N e l R T 1 e r x F d u q g U i U V q U U R a f h k h 1 C Y 8 a 5 T v V + B v 6 J F S l C j l y s 0 r e C E V d 6 P Y U k v G U Y 1 m q g R e Q t d e B r 0 M K g 9 Y u L e + M S / u Q t n 58 U I f T / l a P a d C n r c e A + w Y w 3 t 0 p k v 7 i k U z y C i U p x P y G u j o o l d S L 0 C j t k 41 + P c u 3 L q D Q h d M r e e J P J T L u p N z O 3 A T b K 3 z K 0 + F b B v R T o Q 8 j 8 d A w z M I V D h g n e q Z v b X M D v n 1 n G T s b B P L g L S D b U T 9 q q U I 5 u + c 6 f d 7 t x l e 8 P J m 88 N 4 O x V 7 o 4 U 0 3 q X K 5 k S 8 J r P T l 8 B R u X d K g 9 f Y w o 2 o P N Y B T G R j E O v b 9 a L I J M B n E r b 6 v W g n M x o K G U P e W E h 25 q q a m 1 H y m 9 D 5 C V 0 9 V m g P 8 a 8 W + S C J + 4 A A R E l q A H i l W x d M + F n o E y R 7 H K n 7 s x r v i L 3 R h D b P c k J t 6 o p 7 S v 2 / p T x i Q t h a 3 B 9 O s 5 j y 8 q Y 0 O f U r F x r F m Q o S h F A r x K b q C i h k e o g 3 B z Q 1 z g y I v M 8 + X B j T f 2 d Q i I u L O / 1 l 0 34 u / q t e G x T 3 H Q l 1 g R r b o c D g j 2 W k C C H 3 D F q 8 C b h S M S G r r p N V O D B R 6 m S H i d / 43 k S s e n L Y Y D 85 l s 60 q / t A / T D 9 x d G r x q c B R c y U r s T p 5 U U + P h Y S o K 7 V g 7 K q D w p c 5 q c R W N 21 S 8 z p 5 d k s V f c 9 p E P Y U D T A z + t 2 Q + q W h 1 V k H B w t 3 k O 5 q z r f 3 M H X 6 q U H 3 S 6 U Y Z y v K b + l G o W 8 v 7 Z i a v y U z V t o A A X n U N V 88 a e o 3 t P v w z n e 4 / p 5 X T A i c 80 d w I k i O t R + C 8 j Z T 9 J 0 J 8 O 3 c J I K Q C 1 w n 1 v L U H Y Z l k x X H l e 9 m P I K 72 P W g Z f 5 e j S j J E G p G 27 I y V K h j m k m P B 3 G W o B 8 F t s H O u X s F J 7 a H u L 13 i C N M R Q y C a A w n N E u / U V N u V 9 g j N k f 0 D g n 76 W 7 J v G + s 0 R + o K o U h M 4 K p 3 U 8 p I j R j l L j z J I W u H 83 O y 3 o E i Y 6 t k m k H U J 4 z 25 e h n s P Q J o w Q k Z q C v R I S Q B W N i a P l Z + e D 98 j 8 d P E U t c K n l H v y s 1 C e T i w s I l A f j 2 A m S P 1 Z R t S x R f O 1 Z Q U U 2 Z V b z V O b m g + O N y h l 59 u 1 M G 7 q H T 0 x W Q m G z Q T F O 5 S F h q I / v a 3 W Z j A d V m 0 v o Z p 6 k h E 7 c o A 10 s 8 O 2 i z L 52 b R o k A H T G y x u C e G d e x I K K u c o K c X N W s 4 m 3 Q F 6 S w S c 8 V I n 4 D 718 v k N X V J V M l K 7 H c l I L x d O X W d T w W L z o R h V o O 0 x / R u S j d 0 N O u C k B t 2 M y L I H Q I k g 9 / z o x 4 G h U U t I q K V g g Q E I M P 7 / t L W A 5 d M 9 G d r C c K 9 q e C r e o E 2 + q A o J 5 A C G 5 h A Y 5 s k a 92 j Q H k o p u z l P g 3 s R u 3 q 3 G x t 0 + 41 A 76 p D h B z 3 n I S C r Q 60 S r 0 S L T V U s G 7 J J H Z f / z t + 8 k M L M B L q N + b 6 + N 8 s 8 + 3 a s M 3 h / g F / I m e / a o c u f 3 q 7 f / R T l 3 H y 4 K j f 80 u d p F X g r + C L E u l z d c U M j L 5 B h U b r m k R g 5 x c T i O p 1 J 6 F A g V 6 D j a U g J e P L v Y w m Y B C t O 1 t F / 2 y W i 3 i E B W p y l t y M a A f n b K d G Z U N l I 90 L S Z p O i a A t R 3 b X F p j 7 a R p D 4 Z o x p i N g h h 2 D s I i N N T d 47 N O 4 q 1 h v h d U k e R h U 5 L X G 4 / a S x F d n 7 g C p / T I r + M W Z r v 1 g K o S W V z U 5 a Y l u Z a 6 x c 5 V R N b m U l W H l c 9 q e 8 Q a C H S Z Z R U K g / I h n 3 l 0 R 6 R C 8 G C k P p Z x x E R N 1 v 97 L 0 w 3 m a F y 30 d 5 c O d C Z 12 J q x k l B 8 c J c 80 v 8 q N / 2 i U + e a Z Z 1 p O K V Q E w I w L H z j V + s U m v k g y y A S e M A p W / G K U 9 j N y T E N K d A x v B w k n 5 + 8 M M t T W Q 2 N v D V r f I P W I Z C 5 F M 4 n B A u b l o 5 z H J j c z H i F 7 Z p T 31 w w f Q D s g o M s c 6 d H M 31 Y H A b c k q U 0 f b F 8 n G F i g 6 z l o h f c 26 Z m q T 96 q J B M 7 k 3 S w 6 r 6 N a Y q T D 3 Y w J 7 M v Y b X X D R I t m J 3 O J L S Q 4 r / V R 6 u X j 8 E j C z Q B k t g C h K N r u U k y C 4 P p z H + L 4 A z U L u v h n Z g G Q 8 V w J 0 s O 6 U 1 m T T m g P Y J E l 5 v y T D l 6 c F 1 s l R s o 3 + N b Y U W O s 7 m C L 5 u v K q R a i W 9 v j 7 O R L I Q N N g k C x w h n q Q I p 9 i c a L y r + Q C x A f X N P v 2 u h K L G g B / G m 43 l W 7 h U 17 v A 2 s b 8 I f O a 7 T 9 o d H 3 x 6 I N c A T L 4 c O E m H 4 T Q O 2 b P I a 1 j k e P d u t y 2 / w G / P Z Y b y l t v V S E n c z 0 p J k k v u b E 0 L q T o 4 e V 5 + G O q J 6 j H i / x M + h C s t f 2 v P 8 o 27 p M f u p S A v V J N e I 1 E D L e 1 c Z j A S L 3 F 4 h x q L P D o N 1 s T W + u B / F a C / S P X V G Y i f C U m j Y h T q V B R h f 0 u / N 94 / t G v h m t U H K m s x E i G J I C i H D a Q k z T w I A w o V n 26 p U W U 0 A y r m v 8 C U y X J l h d i 1 C g v z f i n B G v c 7 x u y t 2 Q Z n o 6 i g C s 1 m 4 x 1 p u 0 B Y Q M A l G J i L d k J 1 p 0 D U W i L A F f / G O r t I 9 z K y q E / F F V l Y Q N K D d F 6 t 6 K 1 X 6 W + r G X Q t S h n T y P G D + T d z h p c Q W p O x q 1 w V S m D O + c 2 E e / 2 w a X 2 j G Z c V A j s e l J a V 6 B Q o / 3 d a Q 3 x I b D F u o c p V l Z k e u 2 V w B h e V 0 y / o j A K r P H w q W s n B F 76 j H 1 X b r r g w 2 i p q g S b r C I N q J J 5 F 9 / + j k p 3 j r d c v Q o U I h p U W / Y 0 c k D H Y d K c X U X U n j a u n g / N c R 9 D K 9 K v i q O D T n A L u / 7 A 0 r V p + d V 7 l U 7 F x G e 8 u u
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:49Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca25-efd4-4887-93c8-49d5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:49.000Z" ,
"modified" : "2016-03-17T15:15:49.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-146e28b9 738296.doc' AND file:hashes.SHA1 = '72b4e1d3e1afb920e6e2c4f6a40c20548ebe3116']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:49Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca26-3d50-48f4-a3c8-4181950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:50.000Z" ,
"modified" : "2016-03-17T15:15:50.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-146e28b9 738296.doc' AND file:hashes.SHA256 = 'e4d827da6b65136ff92e5f87dbe8489fb42202b71a2dbb5a6425293e83fa85a7']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:50Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca26-0d60-4105-96b4-4368950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:50.000Z" ,
"modified" : "2016-03-17T15:15:50.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P l 5 c U h b B u A g Q i Q A A E g 4 A A A g A B w A Y T Y 3 O T R j M z k 4 Z T U 2 N 2 U 0 O D V j Y m R k O W Z h M j U 3 N j M 5 M 2 F V V A k A A y b K 6 l Y m y u p W d X g L A A E E I Q A A A A Q h A A A A h Z B 0 1 y 12 / b T E A r u Z n F P 6 k D z t x W N k B Q r O g P o j Z 81 j Y 2 s h B L J d k e n P M z 5 H t 6 R t i i 2 m w X Y M I U 94 k g O Z c f h 4 A d p 7 A + l t Z P X 0 m G X s 5 X U u B x 3 q 4 W F 7 K D p I s H o 3 v Q 46 B 2 e T 4 c i p i w D / 4 M 3 P L K Y U A v y a J O 58 t S C J A M O M O 0 k 2 W f 4 G R u s + u D C Y R g G k 5 C P M 892 Q i X B S 223 H Y 4 L N V 6 F P 6 T W d D V y x Y E U P w i h O i U v n N c 3 h k h C P H R X R w R o D + K A W u u L g r d Q 2 / 7 t J 0 0 9 o q Y I l W w c I V j V t 6 S I D 8 v t n B g M p N x c A N n 2 d v h t i V P R R n f m g M V H y e x C h s 92 / R 0 E x 6 y Y V m 7 L 3 B d S q + d x h T f G s Y A / d Y N c w x Q M m A y g W h I o X O H b 0 1 + n x I 9 e R T Q 9 N 0 8 / X g Q p s U z I 0 C V 3 m O y 3 z d k b 1 M R a g L t 0 s G J E y q O p 7 G r c 4 / e M w O f b B I d H e + 2 r L j o y 3 O u N r 4 I e b p 672 Q f k Q C h i r w c k a N n I m e 8 g O n 57 E q J H 6 R i 1 w c H q b k E t H a b j j K R i + w I s h 1 K 4 + + k j o l B 6 u n Y b 1 E h F G O r E 945 b q n + t M t O S e z P 8 o G J H t L S S 3 c d t U x E E U 7 v L L y p X R X 31 D J P f 6 e q t D 1 V c u p 3 v y y I Q i 6 P v P X y y j Q U m 35 O o x 5 f n j t 6 N C I o S u g v / B 6 c f T q R o Q W i 3e9 F m s u S V K 5 v Q K a / T h B w / P x B D I n x 6 O r a Z y W e h 3 R a U i V h V H / B m 7 G O J A c y w d r 7 x A D O h A M A G n 0 p o U 3 X T S y h V b w f U F b f J j 1 t y 2 v c Q a K 3 i j s R u b 4 q J 1 / f L Q 7 W 11 u H O x n 7 l U K N h R H o N x U f U w P u J D w D p q P g F c F L d 5 m G g 0 p O G p 9 n s w d E 8 U I H 3 X W V J G p V h l O 8 Y I u l K T Q 6 h e F U O 8 U R c V 7 P E z 8 J x 498 K P 31 N h A L t e O w M 3 U 9 C b o M c D r H O L p z V v m 9 N q I F B t z K o B l D v 0 6 e V 2 F 66 q 3 z e p h j 8 S D C 2 c G J D 9 y x W 4 o f K / D 6 M S p 9 q F o i r C p V X e e o 6 x 28 o Q Y C W z M P 2 p 0 E + U f 6 w 9388 n l 3 a Y 9 N A d g U j Z K A Y F x J m Y J a w q w W 4 g f m 4 o k S B N q F M u 8 O z p 0 D 7 l U s D y A O 2 j T l a 7E8 N o n k J 73 l i / 5 Z z F d y L 7 s N i L k 4 W M + L T g m L Y P a v W s h w X V n w H A S O D K c t r Q k c 83 z f g G m 1 I n Q t m 1 e t Y L z 0 R h x 84 Q Q 2 F V t t 2 m k m f Z t N u 0 + Q r 7 P P J U 8 J C o C 6 H e t y s P F O M u N y N a O J Z 9 H / u O p G z e A S r x A J Z Z 2 + 7 V + 4 K p Q U z k e R J S N 53 g M S 8 / P y + E K 9 N T c m 1 c g e g F C d U o X Y T P m a l V F x 1 U H 1 v q a g z P M A D r 56 Q 5 X K w u x h Z r J 4 G 9 t 4 + 1 z c 2 u 6 F 0 S G A q a L I V X y 3 c 6 S i Y T I o Q + L O D w 1 n 9 L 960 R / Y W W t C K X 19 p N k t O 4 c j M j m 8 c f S 3 l P i V J d n y b h m t c k y 4 q A 7 a J c 0 x M Y J r 4 U w Q 5 k d p b D U N m G u N b I J h 9 i H u 0 b h U N O / 1 D F D d X k e m y G y M d 6 R j u C I + 15 G O 7 q o h P q J c j F L a N S V 6 t Z + n 6 + Z a z l g W y / 5 l u I H 85 V / Z P l 0 O m P L o / g 1 l g I o K J k 9 h G X X Y z m U d a 1 o q o k P X T S W E T m p M 0 I R V E G Y z g j p e 0 x h E 6 J 1 l I s O S U d Q z H B d t X s k G Q r 7 O Y l g e 2 R h j G D 2 q m r e I V L 5 u + y 6 m D 0 1 c m e F 9 w f c g Z H b t 5 O P x m U 7 a D g T s n c F 4 V B V 7 o e t 8 P 5 o E G O V G o I c / F / R I y 6 W 3 X X a l f 8 O M Z N B j X o u v j Y G r c e T L i o d 5 J 860 s s U d W S c k o y c 0 0 L h w J u 2 v p R k J N 5 J V g C S 53 D K B E D u X / 72 V 3 d w N 9 B j E a U g s 3 G T 180 i / z o L w 5 q p M 25 k d Z B k e T N / y 9 l N A U D O D X 9 r / A J E 7 A V F k F 1 O m 8 F G O H v y z L E h T u d 4 X I b C 9 m Z i x U 5 S K 4 T c L F M r y F R 2 t 8 b t 8 i 1 u f Z A n r 98 + y a v O c 3 z s Y M e c U E l C 27 j D G B g 26 M a k 5 T h d 7E7 s t v J z m e t J y b g D 32 v + k 2 Q A D v J 1 E X p 7 K E N a Q U e V m z A k P i R 1 J X 1 u e E / E K U M S D w o f H Q q R / A s I x i I c 8 k y u P T P 4 U l V + m + d s J c M h m y d M C N c w g G 6 h e D a l h v 3 k W a W R S / e m M c M e d 7 P u w s P k o U d k o f N R F p k U i L L p I r F k 2 i l / 80 N X x S d T Q j e + 9 + S c Y X S o v 5 n 24 c j 95 k d m p L N q a h e i V a k v Q v b u a Q T X 1 M J x t R 9 o R i K z J s R e G y i e 3 E a Q o N k x e n e P f U k U I g M V M e I i Y p 3 e Y D Z 2 d 7 a j 7 v 0 2 z S X X k W q k 2 Y A V A v w i J E B 6 P Z X y i p e m T Q P S g Q t T h T K Z T J 8 j h r O O M I Q N j R v x b o M r B Z h z k b D 412 G Y S 55 G k 4 O d t X V 49 Z 5 h B K L j z k 1 G 32 U i / w d y u 4 r + Z X U T 26 d n 5 t 6 n P S 0 w q p 9 d 9 b I X k d a A b / R k R V z 8 T d o 2 j n w s i n 6 / d t U i X A z 4 l 4 q e U C U 1 A E G / a g / z Q U + a S S d B E Q 3 O 1 Y h H L K P 0 a C H T O J s s 4 N g S 8 T L Y Y L Q 8 s l M Y j 0 O Y 2 h v R O J 6 V Z F 7 l t M v 9 B l w 4 J T 0 P S r Y c Z 8 v e + 6 f K Q Y C m M v t 3 f + D P c O A q E H n X J p i Y I F h V H t O g i D C 7 t t X z 3 H j A V + X x 8 u 4 X J Q W x T 3 l N 5 z O 47 J S H Z R X / E T 6e95 K h q 2 F P c b e s O Y Y Y N J 1 w P p A q Q x H k R L Q b L O l z g M O R 4 o Q o z Z z y E q R 5 V f w p x t a W J w T 9 d r b b 1 U 81 C 9 D X 8 P I f w b W T Z d 3 J 4 X o u q x K N I U Z 7 a I E x M d / 30 / Z n g 1 v L m Y l y l i X h p N Q S h U v i S m + c E M U g K t V e B F p S c 7 V 3 h L s C Y e p a y L + n a Q F d H Z D 0 V C K L z p 3 V g H r r 2 i t s i g O M y 7 m Z a f S y M W z U l L b h 1 h L C M Q P r d 2 r f i X O s K 7 x 5 F l 5 M 7 F 0 0 x 0 0 r I 1 Q Q q + W B 8 U e H F T y n M 1 u H D u 0 v V X m l D p z 8 Z T k H H m z X Y H S H I 4 J A X Z r 6 Q I q h F B d M 8 n I r N E H S J C w b E u n f 9 r F 0 B I B s 1 N Q 90 J 0 f 8 p 2 x n C E C o 0 Y / H d g o + u k 1 P x V I S L + Z Z L J 2 N G k b 7 O r 1 T N E v r 3 X V 5 X u 5 C w T W f n h / q / 3 H H L e I S H d t d u u 9 U j I K S D k Q N p 50 d W F u L 9 E E 4 W s l x h K 2 h c U K a R V 0 Z j T W q 0E1 v s J Y 4 X V y 8 V / g q 3 p 9 j s 3 Y Y c J c H n R b s r T n + 9 K a D J P h E R H 8 p w d 4 l J 2 O K Z L 1 Z + k i q v w p P K 8 n 3 j 8 w 9 Z y l f 9 L 7 O R Q 7 F B X V 484 z k + A a G p 43 a + q 8 X z 6 I M A g 3 Q U h 1 D w C 6 + Q S z P E w H i t t 7 m 1 b R T m 6 k C l + K h Z Q T U x 8 v p B 9E6 E z N M d o E A e I x F S n E 0 i z F q j x Y R G g w o E o p V 2 Y s t r 1 w X U 187 o 2 C G i O y 21 l j Q 5 I i Y w R E D l x j 6 D 9 + C I O U / B W E w r O 9 S v 56 W k u 7 D u C w 51 G 1 i f + A 4 u r e L w Z s c m w I 0 E A s 7 Z q x j F q Y U a X v U D 8 s c q w 2 a M j l G + 3 A + q a 9 / P n v 9 I l g c d 8 J C S i y H 6 s F d B A 0 w R / V V o U 6 f B I K L u m B 2 s U w J b E L p 5 o 55 R R V 4 l 5 x D W N a U v 3 z r r D L q P K U 7 v u Q S v 1 n J a b W U r T i s o q b 96 G a x P y g 8 S t H R J T D k U l M y g f h O 96 S J V l C x J 6 f 7 H t 2 l V a m w 3 + f O Q 2 C K Y e A k e E Z b 9 e Z X Y j 14 I o d K s Y O 6 t h U a J Z S q v q l n e E g G E T d k 9 x 6 L x 929 D a c X n 9 P p E V H r S e 9 x E 1 x d 7 H j M t Z o 1 F 5 g t E R J 5 / y I 9 E Z 7 E y c n w p A 9 Q X L p z s G s N G V y q e D G k m 2 G o A 9 j W t Z g y s x 2 + O i V 5 M 1 D / n U E 7 + 6 u M 0 F B P f x u I 1 i j S p a 45 J m 65 I 5 g z g K X 6 V x v B j g o + k 1 B k y J x k S 6 Q d v y U G a V w d F X S S X Q 8 k M P A d x u R 1 m Q w B M p u m s M t 3 q n i N K c 1 Y b s B q L I I q 2 D Q T 2 V V / G 8 g Y j y + g X t O P 5 j S u y R l o I x 6 m / c 1 q D z 14 f j U 0 X i i b 9 c p A l M W t I c y Y 1 k / 7 F 5 u e X / C + M q M 32 t S L E B E 9 h 9 k F G t 4 m t S / n o R 3 l / C f p A r 6 L b + J j c u C a Z c 9 A C O k K l e U y / p 7 f x N L u j X S N S Y v B 5 + L A o K d u d B J S x q A O B 8 b f I y j H Y U t c b J Y k d g G b d O 9 A B h l y B O F d 0 T 7 v B D 0 x z V U T r S X + 4 K 0 k y 8 v B e y v W B 4 x S F p + f R I 49 f + v c i t F 9 w A k m F Z X c Z 0 0 H z h h W L q e F p M Z 2 T w I h b P 7 o 9 P Q t B m I H 50 w 1 z X g D l 6 o 5 X I O 3 + G 9 t
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:50Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca27-1a14-4e5b-8ce8-4fb7950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:51.000Z" ,
"modified" : "2016-03-17T15:15:51.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-0450cd2 322.doc' AND file:hashes.SHA1 = 'ba7effc5a30b5ebfa702b0e9a6277d2ec7987251']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:51Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca28-0588-447f-baf8-4ca1950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:52.000Z" ,
"modified" : "2016-03-17T15:15:52.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-0450cd2 322.doc' AND file:hashes.SHA256 = '98cfd4e050f4791d2762fd7387737489ea3f2a23cbbff00cd51b572ea6ee70cf']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:52Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca29-6008-4dde-93d6-4aff950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:53.000Z" ,
"modified" : "2016-03-17T15:15:53.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P t 5 c U h a U N M r P y Q A A E Y 4 A A A g A B w A Z D U 1 Y z Z h Z j A x M T E x O W E w M z g w O T g 3 M W E 2 Y z l l M W V j N z N V V A k A A y n K 6 l Y p y u p W d X g L A A E E I Q A A A A Q h A A A A l E M m j H l L z c e M o 43 i x N J f B 4 T g n Y J E u P q Z y G I 4 v A 34 U y q x u 96 O 3 c e E N N 2 y e Y N p p P J h b 6 G A q w H Q s 5 q 1 v E 3 l n d 9 T 89 p k c U b A b E d v W M i Z g F i 6 H g g d t G G T / k r 28 R E X v F t C C w p V W G b W I c F H s 6 M E R + Z M 7 x f 0 c A T L k E / u C 2 I j P t Y c Q k Z b 3 v A J 4 / f t i / U Z a o x D L 8 u j M i A s E J X b z c v J J a l 1 i p g 6 b c Y E a q h 5 a t Q 6 l o R 7 u m 4 W 56 T j Q D c 4 H M g Z L Y N q x Y r c P 3 p x W t 0 X z c I / n + w H w Q s b V a R l m O D i f I 49 //aeioEtjzbp5btLOrLtBjDGq5yTXTlyGXo/ipKG97yqC0EvE+F8Fj97/XGBZYHtLSPoygGXvWc2f4vv03gH90uj/Pi9/cWLZaG1f9+ofi7vOVfzw/0ouXm3ib5Zn6bLCYWSiQ4SdHmWwh4Ie8tOgeuXa/aEVE1Ma0dGZFJRlqdhesdScV8bOyBQdllN2X44x5+TwTl5EFt7GIdZfV+NpkdQu9fESeTnoTWNm5ity56OS22zOcAzIqfIRyY8/UXwVHC6fZ5do7vI/G6KaFfbIcd1GQMV4+caPaVq7er2+TuFUaPoO+5T7Rua/MnDYIfH94hiWRxle8N3oBDHcmFZezsLUi01ADZYPTzAW/jhs3bA11oTnMTh9827kdSpBQd3rLoQXklc7zPsIsF7DNsiSopyevNI/Nx90Npm+tMT3ohpLcIBHn83wt2VrKtz3795x98B6hEKujWrV8i3emsqpD/ZhT3+ebuJB6BZ/t6ahHuj3vHrSLrs0KaGOqI7ko0xy+K6SMwa1zxRmlSCZkvtq761JDEqsy5FgtWxwslFMp7yGBAzAhrdA4nG6IdET8e0ro84YeWhZKXJM2s3QlADxWhA5iaBVVO5HbUyS7lpGL3fiM/y3YghipRFJ5iKRmlEAGWvXMV8VLW8UD+H6aB9IKdvz54Cl82RhpQGDD4yl/raUDJ/xK05iQp7SxhnH6qdFVH1OnXO3ccfdPY9X/Ixvu5Bl5jDLoTpwkekfez8oWggUPKfhoCIF0vuGT95S6Nge8keHL9AsaOZRTKrrSBXEzhALxqIzlXAINifpkjziBW+mE3aHySuvp/s9KIPEua0R1Y/zxOsQ/qkzH0JxmjYCRzTcxVZ/+JOs2Mq+xv0O+4jIBOVEiYhZSbyClbhuzbx2rm1JMUchB7k/zcsTTGxvVIKFMTmEYDEmV8sNqiCR3KqR2M8eCo8XKrRRLPVoBdPfJYFSfpG2Lg+1U804Kzo7oJIObYgrSdt/8hlLdsE+wKJmffnKGjAA2Xf0OKZB9tZTN+elMt4o4bF8tTwdz1Zme8L5Mux0UQJoWP7K4GR7+fIf6yXPPl+X7n5DxwGUM+Uw/+v9gFeLEk3FXkXi8xF3SfGSoCQs+5UXBJYR5b1t7jKg2O4WCrt3p/3DzA20I//jmU9UTOfkwd3EJd3C3IkQQIHOiD5BoYHruAvSRvOpoJDBGXLAIaDYW9JsfoaWz+YqM2U9m5lbqWaJYpdZGsmOsZNE0DIObrvCpI2809V3AwPAumfqpf0Mhm2ditV1z9IT5/JlIloZgWqmwy+3ZeKn6q54puCFWR79sNWhjv5VwDbN0LZ0nNd0JuCJ+AbhQLRik3Wx6B1MuCc+E2iH2F9mVf2S6VJYb37V4Z316EPjBIjAPFcYIhnRB5n+qA7m043eH2XbuzMaMa/F6b/koKG84tgR45WYBjEfzFwSCEmbx03K8zxx1U0o52y49y/EgOlv5uURg1p9oz8hNiSnusDys2Oldzna2M6GEhD1q5aASPlhpLKqVVgNi3FDTHuYFz6dcxZngFmczT2du5biLwM4ZfqS1yRb8tjs0ZlYjKWa9zusaWjINtvmJR8QAqHmkAg+Ij/vXXrHzLPFgM4j1AzOm/uWqHy6p9Y9/MdLVjl9IjmrBl4ahjMAiuPSltvkzp8oEUsQ1ypDrCzFfpXs9g7O2ADIRJyDWk+dlOaDQpDN9PubhzGYG/uD1jRqIF6lljvc9saqZtjjhF0CXPJ1zN6sDgpsbNPU8N2uPnDtNAb/MIvi9ZNahvB9tHee4iJVGErpGBLUp8zZ16iaX6vT82EbuzU2l5el950sXRsENA2BSHTpGNBXNMWvLHGSyMwNZYt1maMtoOxGiguMhs7kZBTQV8rn3YGZDypMiXtfTCPku6gfvcwB/YZ94PdWrJCd5filBVNzlOQvuyeXerxHtjQa+c4FnT7ci2JbnH5Dabhtu43Wq1V3U3NlbDwpCoAgXP0BBTjyVqv1VleWmLVuwDx7v9kg20GlXm7jJx+zrqzwunSdlLZX0N9A3l8P2lM/6G6qhaVt+V62Nvks+5lKnTxaXqaIyZFOvym/SL+T5hOJyaiTO79W5wZwUHc23HD4ThBMIF3sKjAf+reJ/sHDaWiWMFtSWbHqhSpj9VQSgwD8pAEYTTxh8xw2CYNgcFNHPInv/CJwyR3gFd2ywig9GenYNhx+skwcF0dNSn5ylf3bfE5BeNF6rfQR9iJTaXg05zez0KArpNEzhKzHnUCSMVEICln+uXXYsy53S46Jp7qnxQGyN0AVvgL8dWf/fulyRvEgPCAGfK7SK2+NepDyNwtr+U5qHEqyAc6ziXT2+h4dk8d+slgQ1UfcjY7673soFbBSjsoZyvV0v4DxBaHTNtyznFgRbR3tyxEMnGTB6tnAf98tmao95qzd2BUBMXQPO63A74MmkD2CHBjVUIBAulprwsTohHS2iizlb+5AJTbELnVmVK8jXljPfCu+pCvura/TMLKoObEpqphglPmLf7Uzgx7TB9ceNkJLmsXLY8X2L+5tbknJVq+XZdrtcp+MpAmLfAghIE19oU/nTtef0xVDZxmibFGQUnitYZbO/r2UAv/avKmGDM4B79og9AlDpA4SFiKI/qLxvhEYWVf92teywmFEbUMFgbmvvNGqQRiz0iOyb3PBuKG5AqjOZKzxkNeIvyaW75PjGnVIJA5d4UlXYZMzaG2tJuvZKzn8ZdoFUVNf76O+F2LOabyWU6LkKgnH8w9SUiQvikRQi7P/bBMukZF817NcYvy0NsFpF0JL7mLi862cf+MDYzCJHBMmvxdO0RqiL6mx8p8vCLTp6L556mGGjHLG2ffO5LPWki9UcCco276CpvhcHM5Itl395Xcz0cJ6IyWlF+1AkolO4lppQxqNsVVyb4hLdXT70EvzwVuHYTNZ2+tLRl5koFnN8rH/KpVWD1OuJ3V+rezpUFlA//fZYukRSKHL5bYQhQW0W84k1FfXC9YvKKgjj9ueIArj7a2oeMCnOnqzw/NyTNzlNb9EecKn9KCCavfJhc2zM6plOu1lRhU04uQx4CCEhOrdKKEmLb/Akgk6hdDNDLgl7q9kkzhZGECybUaEcV0Ic35CfOLkNOR8J7+unMPXDsaU9s/LF2zx68wRPOVbyht3wtllQ//Bnnh3sgone4UZnjcoIDJfxmp+VhD0j+jFi6bGClJ/Equ9Qd6eZlnVWmIEhHjhrHKTQrOYzIDghyYjO+taPEqehWeOa3+vf1VXpedtEeG8nOe+aldub4V1tHUCujBEXEbhVxvhegg2ovdcTxqOKpxdk83r3sKqrJ4AG3HTDSg731uPn/Zt8PjH3wgy1TF9W05pCk6DetsFCA0cGudwSC7oNgmRfDVeKZQP1FT3t+7MVCcT6I7Q6+Ih5EAim6nvOVvEaR6F1lp1/bjigbVYWGTLBRYHpqGeCZu8HDXgWBgvYHMEf1UPsWvl11Z14o60kvsi+WbOHM35bx0nfKXxwrj5qicRudisdvJ5AnlxDS+dOJ/ioKtJ6f/VOTCji6dqu//n/MAKfKzbE/dIeU2P/5qHOwCF0UHqOctKYurwYSsE+r/clIJKMprQHimzBZXzt4iRxqFgu5RTI0iFucY+8YBrKCquB
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:53Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca29-07cc-4848-a68b-4c65950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:53.000Z" ,
"modified" : "2016-03-17T15:15:53.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-09686a0 4578.doc' AND file:hashes.SHA1 = '8f0d6cf23618d30186842ab6447ca4fb056c8d45']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:53Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca2a-7644-4ab8-8097-4022950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:54.000Z" ,
"modified" : "2016-03-17T15:15:54.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-09686a0 4578.doc' AND file:hashes.SHA256 = '7c50aa4a0175516ca9e9dced0f6a41919e3bb58cfd63decd35afc0246c6f4fb1']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:54Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca2b-7b10-40f7-a0b1-4ce2950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:55.000Z" ,
"modified" : "2016-03-17T15:15:55.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P x 5 c U g 5 e K s A P S Q A A E I 4 A A A g A B w A O D g 4 Z D k w Z j Y 5 Z G Q 4 Z D k 5 M z c x O T J i N 2 Q 1 Y z R m Z D A x Y W N V V A k A A y v K 6 l Y r y u p W d X g L A A E E I Q A A A A Q h A A A A l E M m j H l L z c e M o 4 o p T w N T t w W B G 17 f j h H A Y G / Y T f s 6 P j b 1 j n 73 l j q p u 1 l Q 3 / 9 f c 9 O G 9 / c 8 m U B M o p c 462 m y 52 l y z A v K s l G n p u b j 6 j J V x s n 9 k N H I w z k 2 v F y p U x 70 + Z I z 1 b N y 4 x 1 Y p I T C D H l K D l D 0 5 y L U I V s 3 z 8 //6FJOiuHaIy1GyGPuphP4iHE1V4N1zorA8oXfrid6nh8cBmQ0BdqcdUHCMYi1h2yDfgbEFIpgWeG2QcI0znpZdHtsSW+Z7XPbxPTSbEVNDLSK0Zcin4SlyhFTynMGpn78UviBpi52Q9U5MuqiCgEqlLopR9S1S0Mvy91fqjgY76OypdjWRi1F7+DwHZ0FlhPqoBh5LStRaRIYWc4DBvz3yC9CkYtMywljDPAA0w9fr3Zx28xhfSI5ga7g87sz/pUuv/WGMAfxWOk1MdO4Vr2IOhEvAh2jMoMr4uk3WgzJKtFxy7tC4O6wo4lY5jwF3orlu9XlKHCi1h5/n2rs5cYXVidzy/fWNqEXiuCEHI3AepBUes8S3QXOv9m9UDT55bAi8d5AeMUYMRW2Z7V1/Kq6hVHFCd1Tn7y1aUleTt5m9k30qVWAcLIscVc9CZ/8WD1uz2Yd9TBVVP4w74h9JatC4uOmmWbQOwh+ywJYiKtawVPGzHjrurKONqC8ZETsRMY330B+HUicdLL5LxQ5c2VwOB7INdg9C2XVlGqY7ukFHpoT+S6ydUuYcz77B5p8ra0IKBBdPEj8xX/9GkGEeW9ElcxPA/30GZqfZpIqgLxiCfmarAD+si+PnqSY9qjGU6FSknY1t+bC+h0BeEK0Hc/RFsrFYywke8DXlc9VpzNVLJyv0/p9DRBnmMi8+AnevTakYPBZe7Mi5pbEydmEI0+trjQP1d3ldMgHM1vZVPdC8g/3415/rDJKr/wy+6Yx2PqjqHHSWTC2HDt357pn3e2XfFPiXOHWpQHRTkpblcHHz/wQyjOk07IErTkcoVVtJfydS5nstagqvYtiywuvIj/yTvvLO3FPhjk3/F/tfkfbcpG4vXLX73Hjdnk/LtW0dip9URa/Qxoa3JzPk1ZyVMWrhcTdCsXbPHuSJpfdbwOvFHqVorfcGq/6c2s6sto6AFu1wWSEEZo+TjSw7wZBlMYZIjXn/G1VR7yG2UTH35CeTopqDHW/6rsq74fTGvpLpGpIa1quOflw1hFW5P5QKX+ZO6dR2vaehQmYZn/xlr/1Q1CO+BtJWFhCitD5ZBHcijIj/ZxZm0D59lpz75WftYT0AWiMiAy3Me4IABpA6GHJkJnrLjo8ZjG+L0a6n+1WzVQ76Mz0ayDluj62shBSFwmtqLG+MocZqEOBuM/qNApw83KzOAtkljBXSqsvFq0sH4ct5pYx+WhxZuZ+7Jj//GWjOctEw1GsvJkHP9GceN1Gg8rrkymLHdKmdpse/wdh7S2ZdP65egnD5WIadSLk5kM16/3hom9UrOvdipXQFsPaLK5kMkIs0pIPKlDCxcWsb7fr4G+j1/bChrDyvvB7yKJQbGd2yGwKJ7ul3Md7qD6g4VQRsX4WAxwOhvn+W+YD5MzEVsCkYkoLD2OvFZ5g9z0akQu837NUPFM9uOl34MQupndTau1r65RsKXKs254rMsMoZbTzUsBr8mHF044+BzpcuMgejVNHImmHdjCJ4UEGgYk/l+5bMQL3opla796sfXI90yhw1QqHJgssxtr0eBAe8JDfSH+CtZXs0KK16HSMnY9L8mlG8pTF/9Z8Nlm9AE3pFZ8ASbIa/mk6OFbJtG/s6ZXvpbaR+dSs+FrE1B9//JWUn2zchp+F0eQegGo6lSaxxF9NOYRzzgWO32Gr87ux5jhV2a+kJn/YFZ5ElcwbpwMJBKJLkpglsYPIuBbFGXecoiYRkezqIyz2u0gJf9HDXqTc2QV/CrI20Oa47FqvavC26jRo4VrkQ2PB55frC/+EtrBcJ53JYH/jvdYRvPk4LzofMAy19rei/2z98WDkGXtrbzICc/aqkj0kxT2Faz0huLzLJ1sUqn2wpbcor9cYTw1UCZjcQNn+bKmu//zLh3yFly1+NAAgcfQ4Kcnfld4ivs3/5paJHZkVMTAZ14ad+1bqlp75OBzQrdJOXzPeoXWics944z0EOOTYArj5a2k9DXK4AJgKZ7EKBED+I7D1HPyr0//OeSmACLiRQ2/24iTdzvzEhzqzR+H/Uxhu53yMktkSMXxjd5gMHN4Io5GyFF/E12QylElRBEI0M93gkc/8Qp9GZGJfeUGF7H+SqTtAZ/tU6yLEilM7nin3167nGQE/otci/6as+Pe2ADWkXLuxROSxMzQunk+Rw3ZNUUBJTK3AObKfB+tyGoXalxUiETSxkcuxt0UhWuCvfgXJuUlEO2LI5drwfp16AdRzr/Lu/OP5fhDUNcfWR2FVC8COIupXPcvpGlqXwEvs2ZTdVjiLERvY7cq23pYomHaDLhhrEfzvjD0X/qU182f5mwveEiVOWKK64VYNB9yhs9Kocf3IJ43Q22giNt5BDsd2ul4AKajPdioOgMhM8zHcVrGiONezwOVvFYjW0VCCQRGGu5M/iZpw47+6uDsJGPHf+uAqixS5zVrpz2GHmh8QbOnQGVoeDNEay9TGko0eAkZTvZBPrktbxaY8N1+1D0mvuvakLQlNqakP0pH/mPYx+ZakS8YWXXPGV3XPBVsjLlAcC/YalL1ACd0M4Q9+oZc8EjPluewRSLNiTpDznJnUr773P4/yS5iez7CdJ9DhE+0eC7RTGm9CFskdeZLiyq91lX0QpaFRsrq6RcuAFTwYJznJUHE8VOQ9GI/pklID9MQ97W67AW6fw646wrgZbxbHslmftpHTFkAhB8WyO9HGM5D69Vg/vqSIBnGXTd0MrhId+WJsejJHSgAvGW+LA5fIo7H+06FYGpu2RjBynaWhomsdz9xdKh5b9a3Q6WwP/EDWP01uIGuUXsyQWCeMqNB/cphEvuLx23/XPG/ytHY2wzP+d9Kz+avaeGJnyJULLylYXCqlYPUUcgILb0Ss2Q++VzEtin1F5OjnR9BEC4LzBDwZtPaugfXSL3pdknvjmzmqSmcmDz/ICx+ht3xPuZru6YYgJv0g2brrUwiOCW1BRsudATAneTbBRr/8oMRJZOKbeLvOMrVJKQ2fWjYWx2Lmhwpz9sNBf/W6cPaeWP/bVsHJ5uv7IPf7HvblQHpwSKRx9KqW5XvL2qxMjZJttXJOJmTPAkplTR9D+RW1UiJhJExavqvupyYKz7gQm6m77jWy/9iGabDMeFdO793enBGw2HtIsfsoUESUOWEdLzkruvRNzJcIAdFg1JwMt+gsl2tGQH0YLaMPlcVCRqzDCzzJgH4DiDjJZwT/bgJoIBtdU8wDYTe1SnoWjR/4t62vJx1K2n+xjZheJeuQm/blbGTxJTGAc7CrW+yij2i3gsmVYbtuIxqzaH7Xo8/3WYzUhjkEBeqE/H/ReQ3MYfJ1TVIFQY++CjL8bCZ+Hg2bQaHQDnGUiU/jDHIs1BSekdj2ZEzsFuHDhf4r5qYE/hsdg7TWt+9giiU6c1ZYfM/ZSFv4XR5Ntf0wDXGV9EgqzYzX0pXEOLTAbWjyuKJp9FbnelbqizeWQBgLa/+udTW9irBVIie8/9RrfSnihAuGwso/6x2TJej1krymV5qI3PZFHvI+J3iZsauqLqx2dndb6elcAiKAGaaCaVAPDA+V1WdyKvSq6JAghH++abZzyNf+0d9wUfARqU3w38F7bpjcQdK5ZfmMscW2wiaPbxvuhJ3xe42F5oE6JVZLKZMalLtYeUPv2dwbHnnfpwe70UntnmWtVYra8JAk5F86T55wRR9+THJiM1IcYGm2R6lesmOrUQmhIQH2/CvTF5/JHlgcO162KsTSc7DkkWB6M+TD2sStJAlM4++Gw3Szfi
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:55Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca2c-1c48-4194-8f3d-4c59950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:56.000Z" ,
"modified" : "2016-03-17T15:15:56.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-aRzvFnheW 960.doc' AND file:hashes.SHA1 = '0149c0a11bd250249d21ee59159c3eb62a056276']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:56Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca2c-4bec-4afa-904d-4df7950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:56.000Z" ,
"modified" : "2016-03-17T15:15:56.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-aRzvFnheW 960.doc' AND file:hashes.SHA256 = 'cf55d3d1ec63543d01e7846b31642545a4b6441503353b4a2f0bf9fdc0118ebd']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:56Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca2d-cff4-4840-a3df-478c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:57.000Z" ,
"modified" : "2016-03-17T15:15:57.000Z" ,
"description" : "unique .doc file" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A P 15 c U g x 9 Z z A P C Q A A E M 4 A A A g A B w A M T A 1 M T Q 1 N j A w M D h j M 2 I 4 Y j I 1 M T Q z N G U y M m Y z Z G F l N z V V V A k A A y 3 K 6 l Y t y u p W d X g L A A E E I Q A A A A Q h A A A A y 9 G 8 I K s p k L D S G O Q 2 V 6 / W n f U X R T H A s Z s g i E d O B t s e m 2 H Z 4 W 4 R n 2 + f H r 3 c t I 3 h 27 d b f 64 f v 2 K j 2 e / P t M k X 2 e C v K X 0 682 T s w r Z z E a T C e P s K 3 k U Z O z C h x / m e D C b 0 y 6 S B L v X 7 C I O I 1E7 t H S H J w r M + w t e W 6 f j 7 w a J l 3 Z T A z P Q I e l K G B A l b J + m i b z + S l B X 6 v B r o 1 X m 3 W l D q M i E 6e8 y p H k B T z z E U n b 0 e a O t C r t Y T p U 9 w R R E N r l g Q j / r H Y k d + S D 26 d n P e X 6 p A U q w q V z X I u N g d e I z H p A o T B L J 0 P B c h / a O D + g E Q v g P v 3 e I m z t H E c P 0 0 A f V W K V 3 d + 9 K 3 T n 3 z a 5 U a U i k p Z K j u E D I I j l A R l S 4 Z X / W g d T g d E K y 9 M z D U o 3 C Q g m 6 p c y R d g I 1 e b 3 q + W N n 8 p f 0 3 s E K S v X l Y g 6 P p u F 2 a 3 M Z S K 5 v A s G d 7 d a a U N t J R K G d 2 d R p c / g l p G / Z a i O 1 X 1 g U t E y I 4 Q C m A n o m b k 6 X x + 1 e W T c J J n a r 4 i j / 8 x Z j T x e B K m V N + K s Q S S v f v z i H O y C z S J z R n / c W F k z v r K b C L z 0 0 u R V o E 75 E + s I H N 0 Z 1 X T Y S 8 I j U U q / R P E z 7 w W h P Z / l 6 M b I N b a m z y e k V r i P n j t V G m x w L R 4 z s G C s 7 d 6 K d N n y 9 X y i P H p C 70 k B F N c w q q 92 C E E L i 4 x z A P K a o G l c C C C Z 4 G y u + d R e H 8 T T Q h P g s 6 s B H 7 B l N T o M w s X j c Y n A d u z k A R f 2 F l 8 i r 6 m G S i W 5 O M d V o j 5 G l t 0 v 4 V + B q J p J l a T B B + H i a i 82 P P l i U t h H o 9 Y R V v 7 + Y Y G p / a x 8 e A Z b g q Z B F w k 5 y j E F f w i f l U f V N E N a 3 r i X H n B 5 i x p c x x V M e n 3 f N 8 Z 7 W 2 B g Z p Y O 4 g M l i Y a 2 t 3 I O W N z r F + q E p 9 L f O 0 O W 0 e Z j 3 K z y h 7 t r A v k L u g O m M r i k d 8 Y c g L w O v 3 o Q Y 1 g V m Q 0 q r Z Y 72 x Z E L g + m n 12 + 7 N C f 80 w f F O H q f E d D z h M 8 X 3 E d m D 3 S p V g C R 0 S Z X T Z U x o / t n l x G 9 B 1 O y J U K k b 61 h 757 a b q E c n B 5 a X c d z R I J 0 H t Q T a Y 5 G o n 5 M D + U K + 3 W O K v H Z d A + 4 w w j P p c A J s O R f Z 6 Z w v t l j h 9 H H t D K R Y N S e O N s i T U y s U J T j t h C B 3 o i Y x a D y V d B x O 19 g c b Q L + K i J R 9 b M R u B / r T h + e 18 b U D a N E F T Z q g P p 7 F 9 X w M o t O 7 N 6 L V Z F S B 2 T D o w m h Y x 6 k X W m A N 71 m x 44 P X X Y a j 5 y s f i G I A S 5 F W T K t l 4 O B 4 D k i b 6 z K S K g 8 j v e N b 2 e + G b Z / t r a z 63 J V H U b C 9 h M Z q 6 t i 5 P f w U 3 P s w b B t I m k z H n 57 x E E M B w n B N R u N q T K 2 K 67 o G X z i j j r Z 1 b 5 U m c x 6 j 9 E w h g m q w r t u R t H 9 a e C w 71 T S o K 1 s + K Q o N 9 d D p 9 Z y U R B V s I T G x 7 u X l J f I y L r 85 t G z H G s h n h q 9 L 9 q e H z n u z z G k U x A E 1 b M T 0 z G E j y H o y P g Y A Q A V 1 U 4 c u 5 w V K V l Q U M K B y 5 P c W y z h z x H N I 0 N r 3 o R r 2 G 5 E q n F f B U C f Z E M A b J U L 5 S T V k P J U d X r G o G J 4e4 M q X h 0 T 6 l o a Y q k p k e v i l p C m A I E j Q x + b J X X G o Z M Q 5 U d T I L P z G t R T m T W L g N G 3 x a P 2 f a 2 y q i h t e 813 U b 6 W Y y c 4 w U E / 3 A 2 V n N W 0 B 1 a x S F w W 9 F T U G M H w I y l t j T / Y o 7 b b K X m j R F z d K i f M L E H 5 S D v H y D 7 f j F h m c H l 0 b r V 5 b I y x Q / U 4 r 9 S Z c K f p E L N 3 D 0 36 G Y f 472 o I M P G 9 C Z A b D q O v 8 w K Z 80 + U C E c K O Q V G 587 a 9 M 6 j 7 S K U 982 c s X k k 10 r b 1 S i / B y q Q x b 3 L 3 S 3 G a u K h 4 T e d v w U G K P l w y v g 38 i F O L u 6 t w + T v N g o p L j 55 V S b 2 R m R f X x 6 p k H m i j Y W + s x T k b 3 S y O p g j 4 t 5 R 4 I t x 2 N y i k P f 1 y 0 s f g j n E G 0 Q I 2 B p 3 c x H 9 J 4 J 3 K R 4 p j O r 4 x Y k 6 W J X D E T T H o A 76 U z u g l l E 4 j M e P W C s Q 5 f 3 n j A E B K r h n w U 645 A h M n 4 A m 38 G k o 5 R + 2 N P g 51 j B K y I e 7 g i i x I Y a z 7 X v i S I I R p / y J y C i o i Y P I O 5 x e 4 c Z V b p e 5 A r + / b B C f I h / j 2 o a 1 X z Y R C K O 3 W O 54 y W f u w 9 C d M 4 G d t 9 N N J 7 q u G g G G 6 e e 3 Q q O a z z b j 9 Z j n 8 l G s O m b D x 1 v / K M m k f T E 9 G i H g H C D D L m c w x n / p z C e q 93 D x I 24 L q 2 Q f P V m p B G e f J r K k Q U 9 N S C Q 7 A k c F j i 5 c O 0 B C E M m F O X i T n 1 G o L Q O L s P C K N E v 6 t y c x A F 3 a H 8 T j h 9 h d 8 s 2 j R L B s J O f P c B L K D p 2 + H y d l v s F 1 a T V V H V e O b X H 5 B l q N Z a k r L c T B R 6 z J 80 W Y G Z z E x J J 3 O i l S d D K k N k k J y x Y k h X i V D l B M a D T X 7 I i J M A w D p H y C v 27 M M p w + V v f k l X I 4 h J O n D E L A / Z 8 k H 5 e r X u e w k k z / 6 a u E g 7555 H W Z + T f + D d p 2 S e c I F S J i f q l 64 m C d s 7 a D O 55 r n y P L P T b v / t m k d Y J L 1 h H b l w b B x 6 u c Y q Z G r v F I P Y S m w j Q f v d M E t 3 l + I A n a W G L r y r 4 K 3 z m C R U X N u W R g w t i g e 1 M 9 u V t 6 G + K n d k x k x z C 5 Q J E L X H p i F z / O N t x g 9 Y 5 C t B Z Y H 0 / V H G 1 x / 6 E J z t y H t Q u G j X + n O t f 4 J k 5 N 75 d x h 5 h t X F e 7011 Q q r z K g 7230 n 87 v C D C 0 d I 1 p O 7 M r x d / q 7 V 8 n d N f O K G m g u i D v d V e t P A o T N g 9 f q r e f g k t H H 3 a k W k N J K e v f e q 7 m G y 16 O b O 3 g 0 6 T B h b M o 6 w R l E Y n F d U X F G 0 N r P E e T / T p y d L 5 m B E R 8 U W w W E Q X c b f 8 W q F O F G v V + o X k Z 5 A X m c x j 0 3 O u e a / + P g N 3 + j D g d 7 / Q R y g g + J l U k O 81 T 6 E i A a T 28 N l A Z x l W L c C p h H p U g K u q E x i I Y R V t 4 y + v t N O Z n o B U w i t q v m X + P B S U 4 o r z E 8 a F Q 1 w / G 2 b h R H 1 C f v 5 I v s F 99 x A K z F 3 f a B s R G O h V y 720 c 7 D t W m n v L 6 X Z 2 x 3 J d D r 4 Q 4 d z 4 r a E i F w J C x g n k B k 4 h h c 1 D 1 v Z O G Q r 9 / q 7 / j 54 S i w Y / l F B e / h v x w x 80 X 0 O 0 W C P U A s c u G h Y b h e I z k I R g A l m k d y g 8 l B R g S n J l / B S l E v w Q t C v g 1 r + g N G h v 2 A 22 c n 8 c C b 5 N U Q + t Y K W 0 J d Q 7 Q v M s j n m a W p c T j i 2 P u 7 b m N h c Q i H 8 + Q t 7 k 7 F F S 8 f n u M i 4 s r a 85 i 5 K F H f p 2 / t M O 577 Z a 3 X 0 V c O 9 P 6 c Q v h I X y N A 6 g Z I P p L 5 F b X l h 7 X A u U C v 9 w / v I + m V x a d 0 b L 2 m C M y I 4 P v F f n t p K u g / x 520 g V x V g L C M 27 P p u M I f 6 O g C 1 K E 6 c v g 8 + Q i k q f z p 7 o O 5 P N u l T C a Q J 7 o t 3 I d d O g b 3 e K T c x D + X U a Z l M g V N h n F h m u Q j q N / 3 p v r 2 k h 0 7 w n Q Z + G e E Y U C 2 C K h H 5 k Y F Z v Y 5 O z X D p S q W O 5 D u V P Y F 8 S S t q M D O 28 T d g O C 1 A j 6 h 1 p K Q T U n S 2 h C u + 3 B a 0 i K p K X 9 V G 2 b 2 D d S 696 X n 26 W n i b p N G g b I Q 5 Z C G Q t M a 91 l q Z j g P J s o k R q Q 0 A U B q + U p t 8 W Q w d Q s p P 1 T W n t O 2 w P 9 V T 9 t O t B x m Z r T q D J R M h B K 9 a a K 0 T w 18 e I 6 d 6 r w K e P S T J S c W M i t 84 r P 6 G r f P R x M C O t t g Y q i f b / h g H p M 4 + j r / V U w G L D a w c I + U J V u j / u V D T Y h s s + N V 4 K M p D g w n G a X Y q d t 7 D 6 F j g + E u c A 5 j k t k H 3 F k o Z q B s S V B Z P Z 11 D c s j Q H M V c C Z b f A V j T S J y H 1 J 0 k W 8 T K m E p v N v 4 K 1 q Q v Q T a r H f p F h B W 3 v D u h 7 / v z R F i + 30 b h W y k W 31 z 74 I 1 Y P 1 p u X 8 y 2 N Y P M i s 7 u c F u M b y Q 85 N I 20 f 2 R 91 B E P 69 w g E B m R L f J 9 N o d Y h k h D s g m L n N P D r H b O K m 2 Y A R U w 6 B X v m u H A c q W L Q e V Z u 2 f t S g r 5 m c H s T W X E p U y 71 K g H 0 W W T L v N R h a M c N o s J P q u K I K 9 N q A j K O C v F r e O q Q q n 8 B G m f n u 0 44 S k j n s h m h X m + n u i L w p y G B Z K 12 + T S E q P w 1 K 5 Z G P f + W p n N w s R / E C y t D 6 V t q i U q S S a D X F J v k 3 q x 4 r h o G P D c j 5 l g A D 8 y H 0 T K r a 6 W X d N / J 9 u m T P c q L C B 9 L f D 0 7 t t j T G B J J u l g 2 j Q o b 2 S + x 8 N / 8
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:57Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca2e-2dbc-4698-89fa-47b1950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:58.000Z" ,
"modified" : "2016-03-17T15:15:58.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-d9 648160.doc' AND file:hashes.SHA1 = 'c0fec20fa0a9af0d6b7d8d03ad6eb02c5a2c83ea']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:58Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eaca2e-7b08-4ac8-965c-427a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:15:58.000Z" ,
"modified" : "2016-03-17T15:15:58.000Z" ,
"description" : "unique .doc file" ,
"pattern" : "[file:name = 'rechnung_-d9 648160.doc' AND file:hashes.SHA256 = '02c690d59f7430740e5cfee1d41e9f9e8b34fe4bed3143123117498b45744c8f']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:15:58Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacae6-cb28-44ab-931b-4723950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:19:02.000Z" ,
"modified" : "2016-03-17T15:19:02.000Z" ,
"description" : "Dridex" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A G F 6 c U g j 8 T v J W V Q C A A B g A w A g A B w A O D Z j N m I y O G J l N 2 I 5 N z N h N j l k Z D A 0 O W V j M D I 4 M 2 U 5 M z V V V A k A A + b K 6 l b m y u p W d X g L A A E E I Q A A A A Q h A A A A z 4 X V 5 X w L P t d y W n K e N 32 Q Z E 9 R K + I 1 f s O O i Z f 5 L v j z U K E + w O f K d M 1 q x D g T Z y F 2 c j K w r 18 Q i 6 w 7 O e d a u A S 2 h O O g q I J V A i 9 l N o D L s O E g V B 2 a U l L A V v I p 5 F T F 4 e B j V o W w U 5 S a x o A / u 3 o 9 U D H R L 6 K r 0 H y v 3 P N k q y m l i c 9 y l t 9 + P f S B L j + + y G 4 P M U F R 4 / u 5 Z G 3 K L j S O Q v e v s 3 e L + g T d i y W G z + X 5 O P E O 56 B i M s N w B X k G L p 6 h 2 W T p 7 c y 9 A i u W y K c j X Y L k I Z q B c + h / V Q a 3 U Q 0 M t F f x C C I 1 O 1 J m j m 4 + G d f n h g Y v i 0 M C V d y u s T Q q F 5 v w P c f l 0 3 c N R 0 q U j T T Q F X y M C t h r s x G e M + T e z E 9 P g y 1 p r / Q / K 2 f 8 a V v I 4 I y l Z W 1 + g q I g 6 m i x 20 H X k A k 7 d R Y W 0 O r m g U d W 5 d 2 p V n D 4 H U f V G c V Y Y n B W w 0 P 0 b E m J M X B b Q f A B y M A y R j v p C i y B O M I R 8 i w Y K q 1 H 0 / m w V d 3 l z 1 A c G T J s r n H C h Y u W L H B z d G 4 P V 9 + d z 0 d y A 4 H W R H l i B A V 1 o C 9 M N s w o p b l k i I / 1 L u e T / 29 q N O i c Q U y i 0 W J c P o F Z 3 X x U x t k C d 6 R i U i I h z 8 m D c W 6 g 47 d Y N C R e F z q g J I g L 74 A w 238 u R 6 V W O T A N D s H 9 R Q 6 F M w Z + w 9 g + t o B V 8 W A s F R G w R i A C 0 1 C 1 m T T p M g K Z + 52 s a y R S 5 G Y T 0 O f o s 6 A E K f A E g e C I a I z j t 1 + 9 Y O D D Y K + W / m / O q o F m i A k W / t 11 + a 1 d B 2 p z Q / W y G z o p F K 4 / F p / J e Z 0 c g 1 L R t L D p o 0 m E 4 F V h M R 9 s r P V Z D t g n 5 H M / H k Z k m T B Y G B k s 5 s K d h 3 r L C 0 + J 9 A / 85 N A t r 4 r R y H c v 5 w y y m h Y l D j g R 8 S V f Q E u V + I q o X h 40 N u + 8 e S 8 Y J Y h e f D j 85 p l G X g 6 l w y f 1 F k Z 67 r B / l s u S l X j x s q S R W 6 b U Q s 7 h Z + / m R A 65 x V a i m N J V E 0 W c f P m 0 l l d 67 r g h S 2 C D i q N 0 4 Z Q J p Y k C c 0 a f M g s k 0 1 B m 53 E E i + 8 w E l 9 w Z X r l G C L N G N Y b b a m o y 9 m g z / Z h 2 j n j P Y 7 M 7 i o o c j r V G 1 k T c z Q F 3 H o o g x 7 v X A R d P K p Z z / 5 A b s p S Z B U 5 t m X W z V g 0 D C u d B w t D Q I o f P / q P B x 2 t Q 43 l u s + d w 0 b A 23 n V p e E K D 7 q W M V P U + a t 26 C h t I R 2 z 5 H d + A V 54 a D t D J k 0 s l z T E 7 O m 4 l 0 36 E e q A j F R / s a P N Z A F r 9 c i q R S E n i r p v p L Q L L L j M U E 5 k W 7 p x l J O T i S O T C 7 P 2 m h K 7 x 7 W 2 z 6 h W p l z x O m y 1 m M a K g e L 1 N t V 0 W h e e I O p 9 P y 4 K + c x T + I V / I W U e b 0 s q 4 I d Y k v 5 i D 0 A e K 1 w / m t 2 F n L P 3 D j i W c n k A Z 7 c T o h g T R d H e D c 7 e Y y 32 c x t 9 D + P c m w 31 U i G / w K Y d h 62 H g 2 N F S y s E u 3 P F M K H t V W 5 h X e W n t o Q O O q u 0 z n Q H D 9 L Y S O S + F 5 + L Z X s c b c 5 t P 9 S A x I t H I 9 G M u m K k Y W 1 H u r K C I j n m X 8 J r h V Q O P h q l x s x d J a w r J + 6 W c L k / c Q U J T v A 64 J i z 8 T B e l A W c 8 P D u 7 J R 2 L g 5 v z E s C l c e W X E z V N R Y A C g e V 6 M j T V L 4 w 4 W Y q 8 b D 1 N g 0 o t W H A Y G g z 5 R S D c / 29 M 5 A v d V D c C x 9 w B i O P s Y o O 71 l W M 4 V M P z j K X E D e b T 0 + 3 P E 1 i T + W q 45 + D t y J C 1 c r 7 C y Z g V B x 2 O z s Q v X P z 8 P 5 I A f A n s c r Y P w p B S f 9 P s b 1 p l H M Y w d z y y G H M I A K P d X p i l m y z U C 3 z u E O 7 a l E C + b U Z 6 n h h p 3 b b u e S O V 6 N x g e 4 J G o i G F 0 R m H k 0 + N e O R z P J N H E k B x D N z y H c a L b B g n B 7 a f w l J F 5 h E k S X n W j D 7 + t y q 94 e s S d j N Z 3 p F A F S E y Y / k 8 R l 5 s i G l U Y X V Y Q + 4 W m x Y n H b Q K v M H P l x H e y / 9 d F D 4 H L W Y j B R 0 p O J V 6 i M P d v v P b d v v f 91 / k s p u q m + C D + X p l G R o M Q 3 P Y G 60 U 2 r y 3 A z z h D r r A t s 46 S H P V w / N c 0 + m Z v b K H 0 L s V h H c C A C j k k a M Z r a Y b y b s q + e L Q p G j o e o / C e h d B g X k M c X Y L J 4 d D q p m 8 y l a W V n F r C N w B e G i f h M + v M P G j y K K H w B 6 v e P Q + F J N P q a z n P c L F y 1 T c r 3 D 77 z 2 y i v v 4 j U K D q 3 n 4 M K a 0 M t V U q 1 J 3 O 3 X a b 3 E s m W V 8 A o q n M 9 g e R 6 t Y a C t C E V A T l F / S O t y y M r + g E + r c u c p + M Y c A Z 1 r o x r t C + p 1 A I j s / E n y W C r Q h h U k U X j h U 0 n y Z h m M h 634 Z K Q I F j w O y A 222 R j d 4 o j 2 h c D u H H X o 2 + v 104 x R O O k 4 K X m x O 8 v x L E H R H 4 u E z M K A 5 C a t 3 a 0 m 5 n a 2 h O 25 q v e q w E 6 a e j X v i n q + J a M f a x C H k S O T X j B h G 2 S Y k j j M d p K f L 3 Y R F M 6 P P / 39 f J P P a W E l P L d E 5 D P C a f K e g H 3 g 6 j c 6 a b 3 e c G e q o Y I Y r G N J F 6 s Y g 8 n Z v q T A C a t o k e C J M p B X J T O C g a c Y X O j y D + Z H R F S 9 q p 8 U b j P K v j E T e 6 I 3 C v m X n f o + / Z 9 b f V + E c s 9 N e 8 R 4 I F f 0 p z O s N X q p W L x U h + O e A / J x i h U R K O L 4 s o q 6 U + 6 i A M y K b p p g 2 C / w D f f l o S 5 r r p j a k Y S 5 m e c Z u G B X 5 C t 2 X Q B 8 L i A C E 3 O / 9 q / I T R T K y M O W I B 3 W Y 0 F 8 x 88 r c 8 k 99 i F Z b w D j N s t L v P k R H y h q o J 0 1 S z s v H x d t I Q W k E o P 4 C B 1 M a c t n D A 7 W H 63 l 8 H w G E W Y 5 L K v X E R j n e n / P k x a C r C E 3 L 3 j e Q m y Z X + 2 J + b w L b / 8 e q d t a M Q t B e i Q C 7 c Z P R x W 4 p m 0 D q s x B Y Q 5 I 2 c 3 e g n b F p 9 V m o h c y 7 u V s X q k 9 i P j l H x e 7 h + o K + q M 1 W f z z e l i w B L 7 Z k a d Y K Y h X i M 8 m 8 M b v + 8 C O n w + + 7 e D Q e L F Z i 3 b n S 4 C e A a j l l x h u T Y t v 0 e Y U K N C D R x R 2 g x J f 9 P m p b P + + Y X J C b o l R D / U N z R w f K K m t F X e m d w p v 3 o h o A 81 z j J H F 2 V 0 T 0 N Y p H Q T f 0 0 c m N v J 1 c X C U r U y i Q h 3 v 6 l U h W j i m R 38 M y M Y u 0 / y 6 c s s V a M 4 P X U o x z U s 1 s e y C z A U D V N n + o E w G E w Q 23 j h g x X k 0 Z 477 Y X k h B n e 2 H s P 5 C N 7 S l Y o 9 g C S I + P U W I C I Y x f v J 4 i L N B 28 A 87 j u h 9 j 4 N B 35 i O T Z 7 w V 1 G Z B o C h F v 2 r 7 y n 2 c I E T / 3 b G C E E g n w u I 4 r b 0 z R 2 w U L j t d x h x H P W S N 4 T X e E f w / a 7 o u n 2 f L l + k y N e C s + 3 S w f 2 / R x 8 z 1 s D T t / o m I L B 8 Y 2 m c K x u O m s J u P l c I + G s 9 Q k D T k c D y B s V J 4 x r T W 4 P C N X J J V 9 t B I s x B k j A m u 7 K w e Y S n T + 7 L 9 v n S U G D o d B k j g 8 V N g C U I d K / s h T L Z / j K m j J M J p x Y Y a 4 Y S D i Q N h O z 12 N Y / P X 4 z P G 3 B + 86 R Z e M e J W 3 j o z L B 6 G A q M F b D T y e b q Z J + i a M I 8 r 2 p F z M T V J H 5 d / n H h N J V e U A c 9 X O 3 w 3 S 0 5 i a h c f R b t t C L 4 E w U D M 46 u Q 1 o p 3 Q q 59 v G l N Z q O a G K n 6 m F B t J L K L L O 3 M s g 8 K l B O p G R u t K u M 0 I s / 2 V v w 2 n L A / + S s W e r X C M 6 O n q c s H z Z 3 + 7 g L c 2 d B Q M f g T H 72 d t T / 10 B c k D P B 6 n l J I 7 g B N H / Z T 5 A k I M w y y i j 6 N 3e6 M k J v 61 U T C l R N H 1 g u 6 e x C V W Q a 4 Q n 18 m V b E w d F E r y e p 5 D r j O r 1 W I b E F K C L A W f V K F 1 R Y 494 a N E I k Z T k M Z 78 K d Q b F k e G w g h v D e z L h O d t C Z V / W U H 10 O y G a a N + P U l B d g g m F F 3 j 1 q o O A d n X G K O d r 2 u 6 d / 2 S 66 w d D M C 7 Q J f 0 E H k g M y y b D H 6 T h E c L B N + + 5 K P v Y c W 85 I 9 s 40 h s T P m h y T E 4 f j 5 E H z H x 0 w C j P g A M N Q f 8 H + 68 L s 0 O U x 36 Z r C 15 R + V Q f O f v 3 W S I y r E B E 4 y S 2 l m L H y a P x 2 H X G O + K j M + R B V O y T n 75 s R g 5 s + o u J 7 A D v t F I M T U 3 i //muNiKdOqPu2GnoiJMVdTZvJPWLH1eZDbCh2oOdV/tE/+QKQkTdXfeNJTh1qYvvIZuiQ6G9RvF1KCQ4mqhE03gp3m7e34eydUfFcDLJlOY6l++zNjNovwAEyq4KfcS0riDzqlXHVEGCXLUMnVKWY7bui2ODn68WB1taCsO+7Tkj
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:19:02Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacae6-5444-420e-bc08-43d5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:19:02.000Z" ,
"modified" : "2016-03-17T15:19:02.000Z" ,
"description" : "Dridex" ,
"pattern" : "[file:name = 'holy.exe' AND file:hashes.SHA1 = 'c075fe462b1254d74798337b71ef1b82a81c4bef']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:19:02Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacae7-ada0-4266-b01e-44b0950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:19:03.000Z" ,
"modified" : "2016-03-17T15:19:03.000Z" ,
"description" : "Dridex" ,
"pattern" : "[file:name = 'holy.exe' AND file:hashes.SHA256 = 'a9dd22723f0ad6316c2c87727f5b01319cf703d03799efad44f9d8930c4ce5eb']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:19:03Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacb16-5800-4c75-8da3-4a7a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:19:50.000Z" ,
"modified" : "2016-03-17T15:19:50.000Z" ,
"description" : "On port 4843 (Dridex 2nd stage)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '38.64.199.33']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:19:50Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacb16-b578-4e27-9e7a-4a3f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:19:50.000Z" ,
"modified" : "2016-03-17T15:19:50.000Z" ,
"description" : "On port 4843 (Dridex 2nd stage)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '188.93.239.28']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:19:50Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacb16-457c-4333-86cf-48ad950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:19:50.000Z" ,
"modified" : "2016-03-17T15:19:50.000Z" ,
"description" : "On port 1234 (Dridex 2nd stage)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '85.17.155.148']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:19:50Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf1-5038-4c64-8b52-45d4950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:29.000Z" ,
"modified" : "2016-03-17T15:23:29.000Z" ,
"description" : "On port 443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '89.16.145.17']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:29Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf1-f69c-4b5f-9733-4398950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:29.000Z" ,
"modified" : "2016-03-17T15:23:29.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '67.86.188.102']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:29Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf1-af44-4b79-83c4-4cdc950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:29.000Z" ,
"modified" : "2016-03-17T15:23:29.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '75.177.102.18']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:29Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf2-5564-4bc6-80be-41a7950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:30.000Z" ,
"modified" : "2016-03-17T15:23:30.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '71.9.39.34']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:30Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf2-02b4-42d4-b5e0-4e95950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:30.000Z" ,
"modified" : "2016-03-17T15:23:30.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '89.152.248.34']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:30Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf2-e230-40b3-a942-4eaa950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:30.000Z" ,
"modified" : "2016-03-17T15:23:30.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '97.86.83.142']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:30Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf3-0e2c-46d5-b7c3-411a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:31.000Z" ,
"modified" : "2016-03-17T15:23:31.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '5.2.245.43']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:31Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf3-8378-45a3-81a0-4971950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:31.000Z" ,
"modified" : "2016-03-17T15:23:31.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '99.248.17.200']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:31Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf3-54cc-46d6-bed0-4b55950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:31.000Z" ,
"modified" : "2016-03-17T15:23:31.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '83.172.215.87']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:31Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf4-b95c-4cbe-bf8f-4c36950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:32.000Z" ,
"modified" : "2016-03-17T15:23:32.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '109.190.2.168']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:32Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf4-45bc-446a-b25f-48fe950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:32.000Z" ,
"modified" : "2016-03-17T15:23:32.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '5.2.164.38']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:32Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf4-0278-4f1b-9c03-4b66950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:32.000Z" ,
"modified" : "2016-03-17T15:23:32.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '24.204.49.244']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:32Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf5-06ac-4f04-ad0c-4651950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:33.000Z" ,
"modified" : "2016-03-17T15:23:33.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '190.99.140.20']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:33Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf5-048c-4ef7-ab55-40d9950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:33.000Z" ,
"modified" : "2016-03-17T15:23:33.000Z" ,
"description" : "On port 443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '5.61.129.235']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:33Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf5-8b94-4108-b026-4ada950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:33.000Z" ,
"modified" : "2016-03-17T15:23:33.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '66.131.80.70']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:33Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf6-1334-47d1-a6cd-4bf4950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:34.000Z" ,
"modified" : "2016-03-17T15:23:34.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '80.0.175.169']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:34Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf6-cec8-4a87-9e40-4144950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:34.000Z" ,
"modified" : "2016-03-17T15:23:34.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '176.35.198.188']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:34Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf6-0bc0-46ff-ba56-4626950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:34.000Z" ,
"modified" : "2016-03-17T15:23:34.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '93.82.193.162']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:34Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf7-22b8-479d-8187-41f8950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:35.000Z" ,
"modified" : "2016-03-17T15:23:35.000Z" ,
"description" : "On port 443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '47.88.191.14']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:35Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf7-7a7c-4b29-87bf-448c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:35.000Z" ,
"modified" : "2016-03-17T15:23:35.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '86.141.111.166']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:35Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf7-ff24-4944-bff9-4925950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:35.000Z" ,
"modified" : "2016-03-17T15:23:35.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '86.134.190.171']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:35Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf7-8850-446d-a496-4145950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:35.000Z" ,
"modified" : "2016-03-17T15:23:35.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '80.11.41.70']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:35Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf8-d8e4-43d8-a92c-43a9950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:36.000Z" ,
"modified" : "2016-03-17T15:23:36.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '149.172.43.69']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:36Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf8-6d48-4568-a565-49d8950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:36.000Z" ,
"modified" : "2016-03-17T15:23:36.000Z" ,
"description" : "On port 443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '197.96.139.253']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:36Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf8-c164-4f4a-9d9b-4468950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:36.000Z" ,
"modified" : "2016-03-17T15:23:36.000Z" ,
"description" : "On port 443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '79.124.67.226']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:36Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf9-352c-44a8-b8af-4ef0950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:37.000Z" ,
"modified" : "2016-03-17T15:23:37.000Z" ,
"description" : "On port 443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '222.255.121.202']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:37Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbf9-7070-4b9c-b80d-4226950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:37.000Z" ,
"modified" : "2016-03-17T15:23:37.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '174.76.17.151']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:37Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbfa-e8c0-4f55-bdce-48fb950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:38.000Z" ,
"modified" : "2016-03-17T15:23:38.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '90.192.130.30']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:38Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbfa-461c-4334-bd48-45b5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:38.000Z" ,
"modified" : "2016-03-17T15:23:38.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '142.166.241.182']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:38Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbfa-8ef8-4f2c-b096-4bda950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:38.000Z" ,
"modified" : "2016-03-17T15:23:38.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '86.20.173.243']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:38Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbfb-b644-4b58-9fcc-4a16950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:39.000Z" ,
"modified" : "2016-03-17T15:23:39.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '86.166.17.53']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:39Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbfb-d958-4ab6-98c3-4121950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:39.000Z" ,
"modified" : "2016-03-17T15:23:39.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '81.136.168.68']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:39Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbfb-1a38-4f40-8663-454d950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:39.000Z" ,
"modified" : "2016-03-17T15:23:39.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '62.31.178.111']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:39Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbfc-b850-462f-9f45-4e74950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:40.000Z" ,
"modified" : "2016-03-17T15:23:40.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '74.84.92.98']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:40Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbfc-3f1c-4f7b-b440-43e5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:40.000Z" ,
"modified" : "2016-03-17T15:23:40.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '46.65.40.244']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:40Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbfc-9ca4-4acf-9049-44ee950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:40.000Z" ,
"modified" : "2016-03-17T15:23:40.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '109.157.176.96']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:40Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbfd-0e3c-4d94-9198-4a02950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:41.000Z" ,
"modified" : "2016-03-17T15:23:41.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '176.67.37.135']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:41Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbfd-3788-438b-83b1-4078950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:41.000Z" ,
"modified" : "2016-03-17T15:23:41.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '82.17.205.232']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:41Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbfd-171c-4a08-9bb8-4bdc950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:41.000Z" ,
"modified" : "2016-03-17T15:23:41.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '2.27.242.20']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:41Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbfe-9e04-4ad2-b51f-4540950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:42.000Z" ,
"modified" : "2016-03-17T15:23:42.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '85.124.2.130']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:42Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbfe-457c-4d76-8fd1-43c5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:42.000Z" ,
"modified" : "2016-03-17T15:23:42.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '136.243.139.147']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:42Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbff-3594-4fb3-9f99-4d97950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:43.000Z" ,
"modified" : "2016-03-17T15:23:43.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '178.188.14.86']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:43Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbff-f278-495d-a353-4bd8950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:43.000Z" ,
"modified" : "2016-03-17T15:23:43.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '64.206.113.9']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:43Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacbff-2ea8-41c5-9a3c-4a35950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:43.000Z" ,
"modified" : "2016-03-17T15:23:43.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '92.234.200.250']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:43Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacc00-a528-4c51-a370-470b950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:44.000Z" ,
"modified" : "2016-03-17T15:23:44.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '81.133.155.65']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:44Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacc00-29f8-497c-b84d-4bb7950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:44.000Z" ,
"modified" : "2016-03-17T15:23:44.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '208.126.217.92']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:44Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacc00-d89c-41dd-8716-4651950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:44.000Z" ,
"modified" : "2016-03-17T15:23:44.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '69.157.17.124']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:44Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56eacc01-cb4c-489c-b715-4f99950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:23:45.000Z" ,
"modified" : "2016-03-17T15:23:45.000Z" ,
"description" : "On port 8443 (Dridex C&C)" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '217.7.194.96']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:23:45Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacc9e-211c-4173-ac60-4cff02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:22.000Z" ,
"modified" : "2016-03-17T15:26:22.000Z" ,
"first_observed" : "2016-03-17T15:26:22Z" ,
"last_observed" : "2016-03-17T15:26:22Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacc9e-211c-4173-ac60-4cff02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacc9e-211c-4173-ac60-4cff02de0b81" ,
"value" : "https://www.virustotal.com/file/cf55d3d1ec63543d01e7846b31642545a4b6441503353b4a2f0bf9fdc0118ebd/analysis/1458212045/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacc9f-44cc-48b6-a055-43ba02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:23.000Z" ,
"modified" : "2016-03-17T15:26:23.000Z" ,
"first_observed" : "2016-03-17T15:26:23Z" ,
"last_observed" : "2016-03-17T15:26:23Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacc9f-44cc-48b6-a055-43ba02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacc9f-44cc-48b6-a055-43ba02de0b81" ,
"value" : "https://www.virustotal.com/file/7c50aa4a0175516ca9e9dced0f6a41919e3bb58cfd63decd35afc0246c6f4fb1/analysis/1458221221/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacc9f-3328-41a1-835c-41ba02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:23.000Z" ,
"modified" : "2016-03-17T15:26:23.000Z" ,
"first_observed" : "2016-03-17T15:26:23Z" ,
"last_observed" : "2016-03-17T15:26:23Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacc9f-3328-41a1-835c-41ba02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacc9f-3328-41a1-835c-41ba02de0b81" ,
"value" : "https://www.virustotal.com/file/98cfd4e050f4791d2762fd7387737489ea3f2a23cbbff00cd51b572ea6ee70cf/analysis/1458225858/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacc9f-f430-4697-a779-40b002de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:23.000Z" ,
"modified" : "2016-03-17T15:26:23.000Z" ,
"first_observed" : "2016-03-17T15:26:23Z" ,
"last_observed" : "2016-03-17T15:26:23Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacc9f-f430-4697-a779-40b002de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacc9f-f430-4697-a779-40b002de0b81" ,
"value" : "https://www.virustotal.com/file/e4d827da6b65136ff92e5f87dbe8489fb42202b71a2dbb5a6425293e83fa85a7/analysis/1458225854/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca0-a27c-4958-9f41-4e4702de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:24.000Z" ,
"modified" : "2016-03-17T15:26:24.000Z" ,
"first_observed" : "2016-03-17T15:26:24Z" ,
"last_observed" : "2016-03-17T15:26:24Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca0-a27c-4958-9f41-4e4702de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca0-a27c-4958-9f41-4e4702de0b81" ,
"value" : "https://www.virustotal.com/file/451c28e505b2051c630914185dc6c2e0460ae30b219e02fdb6e7990935bf6981/analysis/1458227342/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca0-3f44-415c-ad20-460402de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:24.000Z" ,
"modified" : "2016-03-17T15:26:24.000Z" ,
"first_observed" : "2016-03-17T15:26:24Z" ,
"last_observed" : "2016-03-17T15:26:24Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca0-3f44-415c-ad20-460402de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca0-3f44-415c-ad20-460402de0b81" ,
"value" : "https://www.virustotal.com/file/21cd52fad698b367d68a19c019db8827e7e589aae4d1171cf1f69484c9df512a/analysis/1458225907/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca0-e128-4dde-a09c-4d6102de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:24.000Z" ,
"modified" : "2016-03-17T15:26:24.000Z" ,
"first_observed" : "2016-03-17T15:26:24Z" ,
"last_observed" : "2016-03-17T15:26:24Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca0-e128-4dde-a09c-4d6102de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca0-e128-4dde-a09c-4d6102de0b81" ,
"value" : "https://www.virustotal.com/file/e5adf99dbfb6ea81aebc1866e58fd137cd3eb164e9728a02a0da4c5eba63d92f/analysis/1458213863/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca1-6f44-4dde-b2e8-4e5b02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:25.000Z" ,
"modified" : "2016-03-17T15:26:25.000Z" ,
"first_observed" : "2016-03-17T15:26:25Z" ,
"last_observed" : "2016-03-17T15:26:25Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca1-6f44-4dde-b2e8-4e5b02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca1-6f44-4dde-b2e8-4e5b02de0b81" ,
"value" : "https://www.virustotal.com/file/fff6df71d5b47029a44f9af1df0f4b7d144d544dca87cb5d221b30362c43cc9f/analysis/1458224507/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca1-b4a8-4cee-a226-494d02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:25.000Z" ,
"modified" : "2016-03-17T15:26:25.000Z" ,
"first_observed" : "2016-03-17T15:26:25Z" ,
"last_observed" : "2016-03-17T15:26:25Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca1-b4a8-4cee-a226-494d02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca1-b4a8-4cee-a226-494d02de0b81" ,
"value" : "https://www.virustotal.com/file/973a20ba49f510f42e5c72602a65b8bf39b4074053247df955e4bf99def1a0d2/analysis/1458225853/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca1-e5c4-4f49-a818-433202de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:25.000Z" ,
"modified" : "2016-03-17T15:26:25.000Z" ,
"first_observed" : "2016-03-17T15:26:25Z" ,
"last_observed" : "2016-03-17T15:26:25Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca1-e5c4-4f49-a818-433202de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca1-e5c4-4f49-a818-433202de0b81" ,
"value" : "https://www.virustotal.com/file/ea24f79c0b98d48d7f41c0cfabeb7572b4bf99d8e8564983b3d61860718b2178/analysis/1458226188/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca2-b798-434c-ad87-4f1d02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:26.000Z" ,
"modified" : "2016-03-17T15:26:26.000Z" ,
"first_observed" : "2016-03-17T15:26:26Z" ,
"last_observed" : "2016-03-17T15:26:26Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca2-b798-434c-ad87-4f1d02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca2-b798-434c-ad87-4f1d02de0b81" ,
"value" : "https://www.virustotal.com/file/bbdcfe20dece102c30a0f6785ed2d9a7f898428285df3086a6f69d38c267c960/analysis/1458226167/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca2-671c-4ece-87bb-414b02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:26.000Z" ,
"modified" : "2016-03-17T15:26:26.000Z" ,
"first_observed" : "2016-03-17T15:26:26Z" ,
"last_observed" : "2016-03-17T15:26:26Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca2-671c-4ece-87bb-414b02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca2-671c-4ece-87bb-414b02de0b81" ,
"value" : "https://www.virustotal.com/file/5c2387775a5b868dc9c6f8405220048b273628639f16c67218ea5d0cf06124ab/analysis/1458227041/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca2-6138-4661-a545-429f02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:26.000Z" ,
"modified" : "2016-03-17T15:26:26.000Z" ,
"first_observed" : "2016-03-17T15:26:26Z" ,
"last_observed" : "2016-03-17T15:26:26Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca2-6138-4661-a545-429f02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca2-6138-4661-a545-429f02de0b81" ,
"value" : "https://www.virustotal.com/file/c063a43b6d949e19cc84ed43018c11a6e1762ad76012da54133a01ae6008a465/analysis/1458227692/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca3-a7c8-4de4-93f2-461c02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:27.000Z" ,
"modified" : "2016-03-17T15:26:27.000Z" ,
"first_observed" : "2016-03-17T15:26:27Z" ,
"last_observed" : "2016-03-17T15:26:27Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca3-a7c8-4de4-93f2-461c02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca3-a7c8-4de4-93f2-461c02de0b81" ,
"value" : "https://www.virustotal.com/file/34f328ae6adca2c91733c0dbb922cef53199ae60901581785c194a9fc1dc718f/analysis/1458227799/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca3-2104-42a0-8075-4c9102de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:27.000Z" ,
"modified" : "2016-03-17T15:26:27.000Z" ,
"first_observed" : "2016-03-17T15:26:27Z" ,
"last_observed" : "2016-03-17T15:26:27Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca3-2104-42a0-8075-4c9102de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca3-2104-42a0-8075-4c9102de0b81" ,
"value" : "https://www.virustotal.com/file/69f5e28ba0a62eda8e9c65a5b548fae77d15644ced41513ff3b8237cdbd88afd/analysis/1458226513/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca3-2120-449d-a48e-46b102de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:27.000Z" ,
"modified" : "2016-03-17T15:26:27.000Z" ,
"first_observed" : "2016-03-17T15:26:27Z" ,
"last_observed" : "2016-03-17T15:26:27Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca3-2120-449d-a48e-46b102de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca3-2120-449d-a48e-46b102de0b81" ,
"value" : "https://www.virustotal.com/file/188e5ff3ad3e4294e2ec9bb760fbf3eeb0319568d80cc2df8d369d89c6cef512/analysis/1458227414/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca4-7624-4223-a99d-47f802de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:28.000Z" ,
"modified" : "2016-03-17T15:26:28.000Z" ,
"first_observed" : "2016-03-17T15:26:28Z" ,
"last_observed" : "2016-03-17T15:26:28Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca4-7624-4223-a99d-47f802de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca4-7624-4223-a99d-47f802de0b81" ,
"value" : "https://www.virustotal.com/file/63ea608da741f812883454c8c0ee8f167ba5ee1bca829540a41d493842a22001/analysis/1458227666/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca4-69a4-43c3-9974-4f4002de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:28.000Z" ,
"modified" : "2016-03-17T15:26:28.000Z" ,
"first_observed" : "2016-03-17T15:26:28Z" ,
"last_observed" : "2016-03-17T15:26:28Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca4-69a4-43c3-9974-4f4002de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca4-69a4-43c3-9974-4f4002de0b81" ,
"value" : "https://www.virustotal.com/file/cdc30cfb941e21e9baa5917a27406f317c3e54dbb851e170af4aa3333149d68d/analysis/1458226623/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacca4-2c64-4571-b1bf-404d02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:26:28.000Z" ,
"modified" : "2016-03-17T15:26:28.000Z" ,
"first_observed" : "2016-03-17T15:26:28Z" ,
"last_observed" : "2016-03-17T15:26:28Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacca4-2c64-4571-b1bf-404d02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacca4-2c64-4571-b1bf-404d02de0b81" ,
"value" : "https://www.virustotal.com/file/da172f592cdef05518bbd9ded4812c987dbddc5b4dde020be15bedbe78349fcc/analysis/1458227630/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56eacd5d-ba48-4ecc-be53-489b02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:29:33.000Z" ,
"modified" : "2016-03-17T15:29:33.000Z" ,
"first_observed" : "2016-03-17T15:29:33Z" ,
"last_observed" : "2016-03-17T15:29:33Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56eacd5d-ba48-4ecc-be53-489b02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56eacd5d-ba48-4ecc-be53-489b02de0b81" ,
"value" : "https://www.virustotal.com/file/5c2387775a5b868dc9c6f8405220048b273628639f16c67218ea5d0cf06124ab/analysis/1458227954/"
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a0-2f84-4b87-9215-4295950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:28.000Z" ,
"modified" : "2016-03-17T15:43:28.000Z" ,
"description" : "Locky" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A G 59 c U h s L d K 6 N g k C A A B C B A A g A B w A N 2 Q z N D J m Z W U 1 Y z Y 3 M D Y z M 2 F j Z W Q z Z j Y 0 O W R h N z I 0 O W V V V A k A A 6 D Q 6 l a g 0 O p W d X g L A A E E I Q A A A A Q h A A A A + 4 N 6 M P h h H D Y A I w R N O q D X t d 42 V M K U 6 i R m 7 Y k d V h Y x + 8 l s M 4 u Z Y S 0 u 5 w s z m H Y D f s Z p 7 / S 5 q K U j F j E d 0 / p B 2 a q F g 18 o 7 z H I / B / l 6 I 1 x O + v B b r Q H S 6 l l s 0 m w G u 0 Y V 1 / M a E e Z i 4 N l P u y A e n k a L 8 H 3 M J i G q 0 H / U 9 w N e 3 k 6 r M d 2 i s Q 2 T o G 5 V I v + M 8 a R a z w Q 1 g s A D h Z 605 c e K + g t Y u x A Z A v 4 D 5 s T p k I W z T p i a S N h s B n 2 M Z w b m Q l F / i T v J 9 Q V D g 8 L R 3 f 4 H d q L 58 r C o T Q t l d w r H 5 g q 9 Z + S X t f e m 7 M r z S u U e P 0 B N L d j 3 y J m R 4 c C w c 13 X P k 0 H a M O E Z h P n Q O A u A X 9 a X n r C a x N I e T e o P D k j X W S k 3 / o / y j U 2 r R w P e K I 8 J S a S 1 d G v i v n E j n + G f W K l X j C h l t v i o 2 z P H C X B c Z w G m c K y l V B u / U F 5 E u r O 9 p W l E c 7e8 N t e e D v 1 m c F n l j H f 8 C Z z j 2 H 7 S s l 4 D v 5 u b 9 a / + X P 0 p S x A 5 + A W L k N O U c p Y s R u 53 U 5 k t + 0 J 58 + J z J C 481 Q 5 I x i 55 J t P Z n l y w d e P Z p 6 u c I 1 k C U G d 2 g K U N 29 v S i T l p K G J q H 9 q 2 M / K / 3 q g b R u m q 9 c 5 + d C O k 0 M c e D v N 7 k m C Y n y U M 8 e M h J o 2 r Y P 6 R b w v n W V S r U e x s L 4 T u + A U n O P D a t w + m Y Z C 2 K Y U W U x E o Q P Q q 8 C d F Y t / p C N O k E Z X e V 4 W E C 3 + G I B y Z f 2 D 8 y w d f I J a t H k s u 5 P I n Q P g Q d j y o 3 r 26 s J w j 8 R n o q S n z X F B M p O p 4 R f 6 + v F h c q q 0 Q d 5 i E 5 P n k g p 3 + 6 F b 4 c Z z + O 3 r e p u W N Z t m f X z g V I 9 z l C n i f D I j s K f G e l C / s o s w / + N z E N t n P H P G Y 4 V I 141 P / 1 t N j D K p L M x S 7 I Z F t Q F i p q D W c j s F m U c i Z U / F M x Y f y t 1 U H 340 t T K W P 3 f Q G 4 r c p z 1 c H A w w t B 7 j 9 a O F X T p w 9 A e t D N P + n 8 K o M q U K u k i Y 8 e l 28 d W k O W q y U 4 T I K a K T b G M h h S l x w k o L w 5 b x 8 f m z Z X c m C v / c w g U i V c H / y D + F + K 154 L U / p r a d R j A w 0 + l + P 3 Z s p P m 3 R h o 85 h S P 2 r E L X 3 O K 9 W J U g 3 P m d d x 3 T S R G / U / A o f B h O 8 G s u 2 f C d X O F t j t K 9 R M L p m + / u O j Y d o Y l 2 Y h 0 b Y j P A Z e O q i C E Z o n 4 y 29 p e V O N s P p I U Y 8 b O Y 1 C Z B j B p W H v 6 q 9 r G I 8 i S 8 i w 9 r S j S g O c M x v a h g J 0 U c d i 3 o E B O 2 S U a 0 r m t + r u u 0 W v u w h / j E 2 O D M a I U a S f S F n j I 3 s e V t w f r f a P c 3 S U l b b X f 9 X m y t Z U h o b n v s 7 Q s + w i J T K i 0 / V U T J V o x g j w Q D 4 h a L H 0 73 t k y t W D q p C X 9 g V n 7 y I b y 9 z 2 / h 53 x K 8 i I P o a m G k q l O w O x Z o m e w Y p w X o B L C z r R X 1 m m h a o B s / P D d s y i V F l e x x Z k a k k z v H + r a a E 2 T n F 2 A m l g M 7 f h h 9 i u U / q d f l Z S T t h z z a U d y m S O u N N V P Z r E v i / i h 3 b L T W f o o n M O C O q 1 c F s 4 V 46 s u F H w x / K V C v J q d n n 3 i 0 S X K i U j J V X X V P w z B b F m i b n 0 K k O u j U v h D J J g H j D 7 j c H E d F F g L O y a e h l W 9 i q f w P 4 g v k i r Q I F O X 8 G c C 0 W V Z I / 0 a i 4 E i N 8 n l v m a j Q r I y t z P N u l p I 9 v 0 n Q N y z 4 Z D 0 N Z w r S B q b N d R I 9E5 q F I v v Y R m 7 d L k t a 2 i 5 n m a j E 0 t C Y q Z b z N y Z 0 7 R 3 R x N D s r 0 3 m E 3 / + 9 Y h 158 B 2 / T P m T l e T b X a g 2 J F e z u i V e S + / 0 e q k W R O d 8 j 53 U D m D J R m A X S d 3 S u K T S z s 320 / b p H J l g x C l d p O + Q Z E 7 O 5 / J x v T q F i K F i A / 3 i 8 V f V 3 u R x R a t / 6 v 8 w r b C u l 2 t s c A L K 2 u h E s h A G l / C w H i Y 92 x F S S t o J s N p f v k W o h Z g B S q 62 y H l 9 F O e A O p z / v 5 d c C r Y m h g 0 b Y z 3 T z Q o u v 83 U Y 3 R C u E j j 6 s l r r N x 0 w 7 + o g p 6 D p M s F s h G Q K y 7 U b i I B B K 6 B R X Y J C h Q W K C O e 99 F / g j y Q 4 S 3 N e w 9 H K L W y r r q Q M N 4 g u A D 0 i s h C g F 1 r d p 4 l u W a b 9 B n A L 0 B V R X o l / h g i z k U Q C K g v r o M Q R B Z S x t O s v X k w N c R y 8 H / L a V y c m 58 T r G 7 p m S z 8 p I u u W u h l v t a q A k t v D c Z X 82 b i 2 O u K t S I Z h + x C Z b E i M O A Z O T O e b i s Q w 8 O D h / b I Y B b r y d T b Y 8 p p p t E H p 2 k 5 N k M s z v S g E w X X b X y b i r 3 Q S t U r y J A Z c k I d 4 Q C f 9 A R 7 u M b 3 Q J 2 n 4 H y I C G 6 m i F q F Q 6 c c h D M l b f g M D Q O 8 Q v P s P 5 N O n w X x M E L E Y B W j w N 8 C Q j b 2 v e V g 0 P v 9 + W e 5 p o N H k 0 c J t T H f q F 3 V v o Z q x R f k G u r v 1 b V o r l G J H c r 7 Y O W s + E u i X k r 7 q l P D 0 8 l I m p 4 T Y 6 / j Y A T e w k D b k U a R e A r 8 s w m x J J f U H 1 O 6 x Q 5 e I 7 D D y F 7 / 68 J d o Z T u c / z N F Q n 2 j n A l V W G 0 U H H z l N V 2 a B n + E k x F O k V t P k A 8 P Z 1 H t u U 0 x u O E N S O 8 f w H L V b t l 3 D O c s L t g 0 M 7 g y 1 H u Y Y 0 L R C H T v k v x r E c + a Q p B A R n g Q 9 G Q i 62 u v b 7 / 7 a S m D 8 b Q w s A o 3 F h b n R l S R A C F t d R u 7 G L q y d h Q o 9 K s 79 J 6 g 1 R x Z N S 8 D D 6E6 l E 7 U O S + J 2 P E A X v + + O 28 Z 4 E p l c h 3 X 9 o s 2 z C T k 21 W F 7 G H 15 v 57 d E y G W N H 0 B 84 f L M F F t X q I E u R S r Y O Y Z 7 + s P k Y a b 7 O m T 1 d M G o j d 5 S L h L a r x 6 G 84 p p 7 g 1 f E P J L M T I 4 G h k R 63 v 1 N z Q J G R e 9 o v m 4 D l g 7 w d 0 A m I a k x o i X + T O w Q e r j k E Z Y 8 q d F m 29 s j G 2 M o 6 F L 7 A s T U 7 R J R r Z n E h 31 a t h 5 S S j H / Q s Q I b T N a p M E d 6 I 8 v X O r i g C t J U O R Y k 1 P 6E2 T z f e a T z J u / Y i D Z O s k w e 0 73 u U U G l n l e s K a k 9 D 8 I C j k T L 6 j n f m q Y M Z i g b p w l f i c x Z w K k j E h g y c T E e O I m V v d 78 m L J E 3 / Y j 7 e A V Z Y J e N g N W f y g e p b p z v z j G p 3 e n I Q i 8 X V L Z i 1 M W i 6 b X J 5 D K z Q 3 z b 8 j O 4 G H k d S N H + m g J X y I E b Z d h q 3 R L 5 T Q k 0 m 3 z O / J X 9 L N Z T a F k 6 d / j A i z f Q 3 o O 7 B e Y u B n r 3 c 56 N n G Q H y b c Z Y D a 6 y h U C J 7 / 5 g w z a Q s C 8 K a 0 H T K z w o 0 b S L x a x 0 v a F o q 6 i K d 3 L E E f r C V 0 T Y v n B X F 5 n o U J k J z T v q 191 + Y h E 1 N 1 v 8 E c G p q B c i / g P r 9 O U / o c J P I 2 W s d 4 b Y j w 9 w R + 4 Y I + q b Z N X / W u c m w p N D V J G Y Q p f Z 460 R Z 7 Q 6 m E S Z e I E p o W h O / p 9 d K O I u n 0 g U Y d 3 G m h a 5 d r P x V U c 7 / I 9 / m D f p B i f Q F S n K C x P 4 i B U E l 8 s B d p 6 n 1 K N S n F V r 2 h e x C P A c h + I Q A H Q u 5 M v l 2 F R e 9 J u d D / T 7 q c O e B U I U E x Y d 9 J 6 l 4 a t S C z A o o D g z B 0 s u T Y B B d r R E s x P 6 M d m E L q e s 4 U 9 r q L 0 K Y h 4 T L z x J O f a o l J 4 t 7 K O M k Y h 3 h n t D t k E O p W s f / p r J z p f d A Q Q t J K i E T 8 A N d c I u y K d O H J 5 g H R V f b x q q c 8 d D h h C k c F T 8 A O z e r s 8 G 2 r H E o R W j D q m V E N w z C S d K p p C r f / C D f Z N O i J P 81 w V M Q h d X L T S 0 N S A + f x 6 y S Q I m q 2 o 2 a / 1 S L T d u 7 J P 1 R d y u z p w p + 1 t 7 R t o i L 6 O F A a r t S 6 C e z g p b d o M f a U X k k 7 e z 6 F 6 u K G p c L r W U d A P 0 Z X K A C K J 6 o V h m N U 7 u 3 B S f O i B U 5 B l 8 v g D W N t J G 2 t y W a E l O o 2 h x a Q Q + M u C R L J l H L 1 O B E S S w d Y P u c A H A J 0 o u A 28 j u 8 L c a Y S K U M h V 8 B S 5 p I L t J m 6 r 7 e j k y K 1 u I s z G D R r N 0 F V b 5 q z v E L 0 h O N h t F R 5 M P X M x L n A t T 424 b s Z Z C 2 e O p 7 M g 2 I v H w W 3 L x D A g v h 57 G i r g 5 L b x q a f P k y N Q s a s r q o h H q N U + o u X 7 / O a O y 30 T N Q p 4 C M U 2 f q U 87 U E j L r J G H 3 H U k 5 z 8 v m j M Z H W Q z c R M T A o k j s q G w i o 8 K 5 c I 2 L y b F C j j Q v 2 s c h R D 7 k V B 0 w W e C x B 1 L e 7 o R x C k R e 1 X 10 m f W t Y W N o A p I P O Z M T Q L 13 R y n 9 b 2 / + h j C j m A 9 u 2 V e P 8 f C M H I u + K m k k f f w m y + 3 m Z E p k S k 7 A p T z G l B o Y
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:28Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a0-e120-40cf-b3ce-4971950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:28.000Z" ,
"modified" : "2016-03-17T15:43:28.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = '5ud9sk' AND file:hashes.SHA1 = '1d5a3a7af300a3ceb50462d33977e70b8765fd21']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:28Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a1-e968-47ea-8d0c-4995950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:29.000Z" ,
"modified" : "2016-03-17T15:43:29.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = '5ud9sk' AND file:hashes.SHA256 = '1f13e821d162f26ccff865e12045dc34b0d6a3f11425ae76e9797d4d7d939a56']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:29Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a2-23e0-4e9e-8f19-4b45950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:30.000Z" ,
"modified" : "2016-03-17T15:43:30.000Z" ,
"description" : "Locky" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A G 99 c U h J J G q e s t s B A A D w A g A g A B w A Z D k 3 Z j V h N z V k M D k 4 M D d i O W V j Z T k z Y m E 4 M 2 Q 2 O T h l N T N V V A k A A 6 L Q 6 l a i 0 O p W d X g L A A E E I Q A A A A Q h A A A A R K g 7 R 9 L y x 1 w S W 6 L g U R a N q P n 3 v U i A m y g r L w P 8 s e h i V m p f 5 n 0 I n F 9 K f E b e r r K y J u D e T b 2 / c E I r X W / p E S U 0 A m Y Q c + S T H m U u L T K J p j i X V k r P e m o V G E x t N x u k T T Z f I 4 S i W 5 l N y D 6 j q j q j f P z 4 R j Q u x Y Y 5 R 5 F z i f C H w u l 8 V V F 0 Q u x x H b c b 2 g e C 1 e d g 8 d L 6 I a r 1 n l 3 M O f 2 Q j 3 Y E A 33 g p C C w v k X d d y a 9 N L T O Q p 5 j P 8 T T B I B Z C 75 k r B f Y I K k 3 s k W Q 2 z j O V l v r s D k y P d Q f l R 5 X 7 Z T A V h 9 T a 8 s k C e X 9 w + T F N A a n v B 0 Q o M N j m 3 K I W O K M G j a o 5 j S l o l i s 1 B T V P e p w 2 F E u Y L x 0 L u X 3 U d w C w X j n F x + y e d t U X X d O 1 g 5 c N 1 Z V 1 h l x T t o W b I N M C h e r G g w j t 9 w q y 1 A 7 f 9 b H Q V m t o v E C n V m O / 0 538 p U 9 z Q i w 34 y n //VCzUGZaeunKzR3A9mE3agrpe3X5sLRhQ/uOVgAXlpgqNP2NY7Dj6NHdEw2wCKlgCD+7hM+B9bsSZi+19HLeQucMw5T6c/rGiLIhTiECk4+LA3kN+zCC9lS4zuNKSWDC7sNW6MblgUaOD6C/38opG6/I8r9MP0qHqGSv+w3RMZPkZ5gMbXYNZ7tCh7vyvrskja10VANe5q4Ln4IlcEa3POD8X209bTRuZIvyZpLYglLDqOKC44tSQ4Va2jni0LYCKx456/ydNtPzPgpL/Iohcmc8W47Kwl1KpcPbUVWPYkorTeDiXX0auf7ZNCiTVoD0KnZ51s63+qsDlLiJj5ok9h0tBSP9ayyD4tDrCTHRz6p7pEUZ/V0ssxOthC4orvwKVQiB5AbPfk4SH0/DtAFo8OUy2R+A30h46ytrmqNleCIrKtnb8ga3A07+37AScVjnfhbRUaO96XjQvta+JSdGAH3e/g7nneG0Owv8J7mUeYZildcvUQSBqnhUstdYvIRq9JuON4nuBYTdkEzwooqKyu48df7wFg63QpE00NZveKgApbD15s0LVf1vxQ2HnygT/hDi954u/tXeC94AZpb+1kfSGkeK3yyVWzK7wk+UOeCAmGEc2qJy2iMtK4r8oc5z7hfJZx0jD+TPqi6KS8KvYL1t5ZsdJRmDbPCOZ1YWMYS+7ak22hQKmo8DlFVKLh/Zsp49G9RF42ZKjlRDABZbRYh0OF9JKzf/Z3yE087xHnEFM6ZgW7k+3FXPfG3at9RnJ7cs4b0v7wA3AZIOEJT/UEH3ZssDi1lf5KsZDx4vxPEkarDTQCuOn47vBVg7na8LH50Oks5DwUM2iO2J5Rqnb3OPr73nty4VMKxBIII4BfIv03b6g7S2gMTHVzmU7439Ia7pmBYJwSqPwpdlAXGQ55aO4LRQkQU0L8IPjjo7PyC6getcEOYpjuTFVNEUgqJldi6Fkv7DYQRKgf2LohZLtFPRQoynQUy2V90olabl/ZNsLnSsmMsb6ojVZsySDwhd10bMZD7Ffi7c3od5J+QnwWBzRHfFbkKymbGfUY3du133MZ+geJg/TuVc3ZXnpkVsN06Qpk+ia3tz21WYi3cu/QBV4C1hZlKcPU6gCcwf5DzHIMQwu+vK4R196J4YcLbFOQKKlS7oexDqj7Ra25gO4RySMmREDfcqsCdBjQ4Yg6wN+pDU0Axe0iu+MI4JxJ4IdV3+q4oMWPbNHky4KLctQ4RdnR6Q0eq25wvpchUmVGOnJc1stVFp6U4ckJip8I1LhZC1yWcPbwlSlrXlZUuSSUxYO6cSSv4XbUrYbU0IWyOWVgd3fsfqwu0cujK+f5NvCoINDK3Jji6EPFfm7QCP7D2SeeYoF9meULt1GdX3AlRVxnF4vRwHzS6abmFEAM3P21wDEgmeZ53K98cipnViYaCpgS5r/hgMgSdY+4Ca9SCkvWk+a9isgA8V9N3NAnPWhniX4urSkB+oxw0u4wCvJf8iQC0E9u3Iq4EwxTg7aRP6FZJuTZ6cr4QDk5e4GkQmWOVqnXrkvJnYVufAA8SU0fWQz9rAcjEkp8qolwXBUqJwnwwJJHjqQwRwl6vieAZq8LOIMYS9O4iKdZ/61IG0uoTiOvgZWEl0O/OPwk4CKffVuKiSC29np2NhCufifgidMapQ2svKMDXB87jjnFfv+ioXVTgc8AX6Lc/fqMSyTcKDXxVvLMX6EBA3xxp0jvrnP0W6twhYwzbSvct4VSw+d+LkfbXQxCCW44YwuEj8sXoipo3a6dl/ek8rWa16fu9GsfJiho9V27Br+fWfunM0SY95/1XOpsLpg2ehAofd9rGQ3WxYk/fhczl9QXTo6a/kNDj2Ksi79RY6Y9nqEWGSnRTohWGFwehWlPFBvmjJe0yaZTSD76oqZ5SHrc+CyF9wOSrTJMENRbxytU1Mov0X+n21ST87aIwc9sgNVhCpd/cwpEnODgsQKpti30bzk0wXfCr7Y+PWz2wQ4d24Ykx66xLPrb/ICTmWKy4T2M2kKZuGmLEYfkE4qBo1vINshPLI2/PZ0u/5eIHPO9izp+qHcfKEYm/TslRfFHscWckVhUjcSfr/dmtq9TGNsvBqAKbYqsbzEQNCiTaYqZgoEp4dTyoi3VrAyhmK1QKOSGixjOadVa4rF/p+GHyeXX72crhTMeXeNR/CciDb4c961AEM7OunRqOHrOyEF63H6vroMczEzL/fSnryf3HfaAPqrKg/DK0WD7fKLYaYcY4Eiib+tNCEAeBplBOV/SaOpvDzuWxdZKjDJjbRRZnYbqjqosDd9mU+3kvBIf4fO5VclpQWUxPOUsbJf5jOc9a1mpd2gg6+KPFTPtuHEewvE6uwtUaE0JySu9mlYeeXQ3z4Tlb0WpmYvO8D4zt9cC/+zrRUPmlZn6c2c+tagzrfSf107NMR/vj/voIs78C5hv5Bu1KV4oVZGMmaFfdoVVDBFM/vRJucwhb9hcUClq44ixowqFA/d5BUcEWPxfJZoYKTCyfJaCGtAQw60Fwd3cZIg19HLFNCUuHygSm3jsjK/ls4XCdFnuLclMXXnhmYHbDBdZj9xJC2vk6hh1M8SIdMG66RtUL5B73NxR2ghDfSOWWA+69Zca9m/71GLfsXxCzxIaT29PuL+uedesjxc0mBnMFU4CaLeDI30DNCwz1sdgIdP1WIxGi8Yf+WRLX6rz9MaIegHxfwLBKX6thA4alUVgsRCHc8OyXn/gnf13qv29rGRGvAw/DZaPu1niccBVAmvKskpfvn1FcnoeQyGrxTZh+n7KZTrxahdKfqCQxEvWNIiVIOgr1zYnAZtqCYErY43ajYx8YTbvSyWxV9+jdmEEtpcCLRJhy1D+QxzbiIZRPfK/ktqpONgtF1nizP8oBgAlZrPRFqRcWcxe1MAnhBLDhC7zeAF5Vg4rcBGbVS7zDrPz98Nn+06sDh6t8sa5+qaOIJShZ6a3334R55DPPLW161tWIzPUY95LdJmfIQsPesp6J7DCRH8dJUWGszts2ghjOjv6528XdbQuFXxqBqMcg/6Cq3apy9GA8dl57tuw4xqceHbhRsGc3nGtL05LZYaszlppZNKticPiHKQ0hALBIBF4ZIF7X67lyyIVeRY7gFmhFC5c2F0e87bl9XipFnvu7ICJrNDbHkTfmVy9CdbUqqwI6jgBIaUauUHMYK89Paif5WpYZtEEr+y4xVDRgklbyiqgP16ZGjDw6lePaW8bqtsmjqvI1u8CI9ASwNIoaB19EdYIwryuBavrbetl0sCgnx5QShw5nzGoSLvMqT6VCTtiuKFLixVEBhr7hGt3i+bE3neGF4Wqq3//D9gn+vdxcEEkasa9At2o0L7eCQXLH8Zidca3q6eI1pf+o2ATgKvzwWlE+BGHaDzPL+wUOlu48xSJ5lX5R4/EnGvRnpuCuRUoUo6j9J9KapS1qlfhJkwexKvEPGyR7t1AixPN7jEcKuVEjWg65euwqYm
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:30Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a2-b034-45e5-8dd8-4358950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:30.000Z" ,
"modified" : "2016-03-17T15:43:30.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = '89h8btyfde445.exe' AND file:hashes.SHA1 = '9d97eaee7c5fdce152501a58b470d62074ce0d59']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:30Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a3-8b74-4610-a21a-40b8950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:31.000Z" ,
"modified" : "2016-03-17T15:43:31.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = '89h8btyfde445.exe' AND file:hashes.SHA256 = '3aec6c929f98ba3108804868e13db541fd10a4ac821d24dc8f9216ec533023ec']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:31Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a4-cbe0-45af-a755-4183950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:32.000Z" ,
"modified" : "2016-03-17T15:43:32.000Z" ,
"description" : "Locky" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A H B 9 c U g f U T s x Y A g C A A B A B A A g A B w A Z T g w N j E 4 Y z U w M j k z Z G M 0 N m E 2 M 2 Q 3 Y z M 1 Z T h k N D l h N G J V V A k A A 6 T Q 6 l a k 0 O p W d X g L A A E E I Q A A A A Q h A A A A 7 + 65 u j r O r v c w V V r X t / G G 64 h T c V G t R H M / w P P W e F w 25 H L g f 65 Z G g j 6 + l 4 b 51 c P a R d i b F a h x c 2 x l 1 M l Y 5 i 7013 h F c O Z B T g u X D p c 0 f l A W j E G y B H y E 79 T u W O N N O R E o K 3 L 7 / W q Z M A u c C 7 r R 3 k j M C F y F + 0 u j h / m Y M E w w D E X U m w V g V d j 6 i v 0 Z V w X B Q h V 8 n K L U M m u m A F 61 i H 8 H G h J 0 Y J c + / M U S x C A H j g e 8 l d h Y t b 96 n 5 m 5 I L z 6 N 0 U L Q b x o R E l V o x X 4 E f f L 9 N i j i P Y C n 7 X T 3 m W H v C w N P B H g k E M a 7 v S F p y z r H j d v 1 Z C g Z p e i Q M h + I O Q A L x H V b L Y j M V g A Y m C 9 Y C v e m V u j u o W T 1 M s Q I F Q k y b a m z h d L O o 2 q 5 Q W m g I e p y J F z f v Z I x N B 9 e G d 0 I s Y 8 / D m r V S i N 1 M 8 Q Q C s G T s G z + C L w k l m Y K 5 q I 0 z x V J Z D J f e w 84 L R i m s 6 O B m T v 2 b 3 + j T R s 41 q k J O y h Z V 5 H 6 / x o M B y H 8 o S 4 c 4 z 8 M k W w 9 / o F k n 5 o q U k r O 6 F 5 W g i u o W 822 U V N w 1 w e I 2 / t w n 86 a h b 8 N r K t f u X d R y 7 g Z 60 Y A 2 h C 6 L b W 9 D d S I h R k l n M H c H h e Q N / R r 2 o z H 17 B u V R L d d O C W 53 w J 270 b f 9 X B x r u 3 s M V o g 0 + r r 1 c d e c U l 5 q I t a N D R Q c E 0 M W a I i z f o x 2 h 8 c H K V L m 2 p x V b u / c U 8 L + 4 / T A i L 5 I 8 w A x w I o Q k d 8 b X V m m j a f k m 1 h u u G b u f u 2 M D p n o G / k u x Q + g 62 D 8 V T 6 O S T L B T A o N Z b S n M C 0 U O n 8 c 6 x 951 Z S S H 3 c r Z d R v o S y d S n 1 A t G O 9 Q O 10 U 95 o E f u t D r T G e H p p n U 4 h S s R n t + r b E 1 r 4 m L z 5 Y O q s W S P / j s j k C b F F Q h 9 w d + C k S k W c k + m N a k K I q / B X T X s t 8 N W y N r 2 p W X W j k j S a h 5 E K M c v z B H + y f 8 x 2 M b f p f N m l u i L I x c L 7 i q j 449 z r X c q L S V 3 z 6 J P F g A 2 q F w P g Y 3 d X B 8 a x O x K b Y S L h 6 P Q 0 D / J a G 2 q U + 1 V s 9 a d r n e g t Y C X H 2 b g k a G N N A N a m l m p H 8 Z + R m G M G p L 1 u R l r s 0 n Z T c W f / H H s Q / R i B T j 7 d A s S k k n 3 R D U d d 3 Q H i y e X u J F L 6 t N w M P K g R 0 a N j s x 176 i v + c k v + k T n 6 J 3 j U R 4275 s 6 n S I t d e r G h S g c A j G q e r M f p n a a H Z E y m h g 7 a 3 / W n t I U L B 3 g K 4 Y 3 C a a h M 6 x H 1 C z 0 W d o V R 1 p 4 s 2 U W g / f I o x t p v Z x Y N 6 Y n K S 8 X D 4 V i i 45 P N s Y x O J x 9 F 5 V M M M z f B u 297 b X j n t 5 d 6 j 6 h K s R U 5 d W 7 I 7 m s O u 95 b g F / x A i E d F I f x B c o o 1 T E + B 7 q h m X O H 1 n P 5 t Y 5 x k H P p p N C x q w K u 9 x s N 1 N s o 0 i r g 9 U a k Y k R 6 a 7 Q 6 V 4 h 0 P S b x s s h 5 W 0 j Z w l i Q M g 80 S t t Z i w h 8 n G j Q j h m g 2 B F e U W o x L t 81 z V E P q q x + s i h I H E i S u z v e K / 5 k p b b 3 z O j R + D 72 D S e F h 9 Q 1 f B V W D 20 A 75 O 7 u Y j g e T u y B a T g l 3 X d S M X t 9 h r m J R I 7 X T u 200 J 7 f q 7 o 5 M r M N 5 + h 6 V D U B z L D Q 1 M J p O 5 D a d 8 X D t C d 4 g C U d b q n N X e d 4 R 1 u y 4 c 3 A W J D V K y Q o Z 6 j w M E j x i 8 g + F M / F a m J 6 H O m z s Z V G W 4 G K U + S h n s u P L X h A 2 I P s f k h i E C + r 7 P Q 5 m b + F Q g t J 5 u + x N W j O E 4 d u p S N M S 8 N d I 341 Z A O P V Y p 8 F Q l v Z l 0 n C l Y 6 u W 5 / c M R W v 2 P v o s f Z l M C D n S c f m j S J T d D E H F 9 G F B K 8 u j n i l H U m 8 V j I i 5 W v q d H Q W 4 q R X V I G 7 g O Z C k + n n X l U c 925 y U u u F 0 P e 2 m h U p U s t G V v n g v E I q u P u 8 f M l 3 I C 0 F B n M 0 o x 0 e s p o z b 8 P / + J Y a 6 j + C G I t + s D U r j + v V S v 3 s k M a 7 V l V p 5 U 511 C 0 v 25 T 0 y S / g 2 t y J R 8 R F S b D 3 d Z I L N v H e Z y Z L D D 3 / h b J q z C G d o 2 N S s R Q J 395 Z O O w K B V q J f e 2 L + L 296 p 6 f r 1 Z P S m p A 5 p g l s 1 Z Q y b F o v C e B k d e J I S 8 i z P j 4 O s L f q b J P k Y L d z 6 c p d u T K E N J o i R G H N y J e n r / 2 x F i c e K p T h k l p b N + k W S t E J M r b Q q 6 i f R A c f 7 D B l f r V N 7 j l W V l 3 x I b x E 9 u y c b 90 B p H Z 3 H r s D y 0 z o A u L X i X J U U 3 h E H S / o a u W E x k B t b e r O 2 Q A i L J c n N M 7 B y 166 P u N X K S Y B k M 0 l E / a L L v U l f u R Q A O K S C 2 y z Z P j u u 3 j e A P N 6 t r T A G k G B 2 A h F + O N N z z R q w N L / X c J a W S e E 73 w 6 P I u h L O h U w K y C g n s 2 T p z t w P 7 K q L F 8 j I i N k y V T s r 8 b e d 2 m W d D C V 2 W v m 3 X T b O H 2 i + a l G I l s w T X X t D w n 2 + o O A u w Q h 58 y L P c E U G O R 0 H 7 X E k G x s V M v u 3 a C R b C A K + O k H S A M r f 9 E d G r I R F p n V h N / A A 4 + F 8 O T j o d Z X V 1 p F T i Z o v T y 8 a 8 E T 68 p D p P w r o T G S q / n y f Q 1 R Z + m a j z 82 v J r j Z F 62 q 6 a z 78 j i i F g U 1 Z u q z 1 + H 0 z Z v 67 H / Z T I Y c c Q 0 y i N / E 0 b a y p X b f n D E u h K i A m S H l w J j P 63 y 3 P x N y j o m C M N p 6 z U Z i 7 l C b q d m 7 q D j Y s Q E S A y m I t r h 87 P 4 D R 4 y p m q A K f u Q k I 7 S 8 s F s t 3 P m f 8 J 1 U 0 w o o t z x 6 N c O X r H 4 T X R u l H I A 9 M + w H C A g r Q V q h A c 0 i B 1 N x J 2 I Y b S f X g d 0 i u 0 G S B D 3 X d 2 O / G J c z o r V b l d 4 e e b k g g X 5 e E Q D a Z Q O 2 K a v B M w f s B + Q W x 2 a a H z g W P q W X R F E Q P 2 O S N C G 8 M F a 3 B + R h Q m v o U 4 u L u 4 M 5 r W l n y d Y x q V S g 7 H G l S m 8 f Z 8 a R R a c J 5 H S C f 8 w d i d n A D I S 7 C F 3 + j t k p Z + P F w d r B z Y E j g + o 3 y e K I Y i i V x 4 j L J 1 s D S b a 1 f 8 O k s B 2 M N t l + 8 f f G 1 C K s Q v I z U q w D l O E m g q K 7 b t 4 j z X B f Y k 4 z M k k 1 f q w j N o s p 7 G S b f W e a j n n 693 E a 3 m w 3 m W 5 n F H L j 8 q l H I v 7 L W 4 U d M o N K g 1 K 8 f y Y b V l i k E L 2 Z v A f i i 2 s 3 Y X / G f y O O C G Z i m w / i L 1 r a + + D S B s U 2 B e L f Z R U V i o Q e j o v c h k I k 4 E l d / Q r M M Y P M n J e u f 0 E Q R 3 d s f D U d K I o C j 3 h G M 1 o s s s y A N L 0 N 3 F u 9 V C w M a g e P Z q 8 A 4 B e s 4 r p z 70 j f m d 5 N Y Z u D 3 G e z J 2 t X / Y 4 l 84 H G i i k m Y v V W z 9 O D x 2 u W f P p o A g Z A b M d F t h w h I j e f I J d f i 5 u n 8 c y s q w + H p + y I 0 g E e q C Z 1 U w R R P y A g w w 39 R K 0 a N Q f i + i m J o 3 J 9 M E 2 M O U X M p v b B C a b i z H n O 173 H P h o a W I F 8 a + 4 D U w t d F y Z v q a I u d I a x O f Y 86 W I f z O k m Q 3 B n B j a z l p Y 4 R a V D J c + l k 2 q Q 2 C g F C d v w V C 4 W R j l T k S F M m m T d R M A G k F a E 93 B O 0 w / R a z 94 S V i o U c V U a V 0 v v E D R g Q Y f + a n X B j S s o a C f / Z U E 2 w P b d m B V 5 w 8 x S z G X O h f c Y w o U x b G N j F Y M 1 y I C Z c 4 G l e t 7 q h A w N y I + Q j 66 U z x j I p u 2 H C V u l 4 o 7 m I C 8 z H X j q 4 h T D o d N 6 d z b g E h c o n D A 30 R t P q 7 h U D 17 Y b 3 d 0 b p A 0 U g 6 P x s N x E g 6 k p y q e 1 F n L e Q q E 6 e / T L 5 J f N e d 9 h T M V J o u p 0 v A j q / 6 v 77 r y a f A i T 5 A u N w a E i h s h O H g o f N S 7 Q F X u N w i K k H s B h 8 o 4 r w Z q j n a 7 c f N o v k E P L I k L t n s 6 m t C y M V d A r C m c Y H y c 36 y A t m b R 5 G V E y M H 4 J p d 5 R K h R 5 I E 0 w s C W a M n C R c x t z E f j B e + C h E U S C h R m V y S 64 p y Y 5 k L 9 r 9 s 9 + C w T i n M 0 j f i t k Z I Q S C O X 5 T 9 P 3 e J v m o L d P z + r o M P Q o p 875 v W c a x Q G / F k G a P K V d i h e x X t n x I z w X W q O R 7 h 4 Q r W I a 6 y S 9 F Y v 1 g w r E Y 1 J x G R D x f Q M C r X w f L v 8 m l Z t g 534 C U w N g Y 9 K a 34 p S f j 6 W K 3 a Q h w H t j z k g k o y 9 z K N Y w g b W a 5 h R M D G 47 M C c B 7 r 8 r T Q S A K / O M o w f g r 8 L 2 a O z u z T x K w m M d 0 u Z 8 p N B B Z G 7 a 3 C K Y 185 N 44 z F / H K h s V O 7 i 4 o j j H S k L k E c e d H N v M F A e T K x u f A C U y M r / X G w 1 D 7 A S L f N N U o A i N k 8 a T O 9 t J w 4 x T L S b h V i t v X Z p g
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:32Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a4-6868-4a21-8b76-4e6a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:32.000Z" ,
"modified" : "2016-03-17T15:43:32.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = 'd4fj2sd' AND file:hashes.SHA1 = '4d00ff6d9c1e3c56aecf08b41f67d2ec03a0cf30']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:32Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a5-5468-48cd-8c83-47ca950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:33.000Z" ,
"modified" : "2016-03-17T15:43:33.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = 'd4fj2sd' AND file:hashes.SHA256 = 'b892a28d847a0d8d814e3447335a303d8474f17da9137c902983b518e2df0fd8']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:33Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a6-63b4-4e00-a61e-4849950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:34.000Z" ,
"modified" : "2016-03-17T15:43:34.000Z" ,
"description" : "Locky" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A H F 9 c U h T 7 M 2 g K A g C A A A + B A A g A B w A Z j A 0 M m I z Y T J h M G Y z M G M z Z D F m Z m U 4 N z M 4 Z D Y y Z D F l N j B V V A k A A 6 b Q 6 l a m 0 O p W d X g L A A E E I Q A A A A Q h A A A A q q I 6 p s T u k q M T v J B v M B p C B P y h P / B K + d 0 q I O G o V b 53 Q v X w x c B P 0 S g D O C 8 z P h 1 T 7 H 8 T S k k i N C p e T P C U 34 g h f G G t N r D s z p h Q k o w i a z Y S a q T S T 0 j G 0 E z 1 c 2 S W A / h R J C t e C W K i 51 n X B 36 z + q g 2 o O d 8 j v v 2 D P Y F 3 b j i K J E T 13 T k t W 40 U W 1 l j 9 n k F m b Z z q d 2 s 5 h C k c e C j v Q I / E d 8 I 46 B 9 b M z V O 7 u c O g 60 I A e l 1 s 0 83 b + p w j b r x S 4 j h H a F B + N f R P d m k v A K 9 E v 6 E y M R q C v i E m I n r o w 0 B i 717 B P Y v d T g j m e / L p d o 3 X J g u k d G y 4 I W V B R K Y f u 0 C A Y i l a O c U w F Y 7 J v l n W n p b 4 t n L H S f F I F c q 7 A r h z N X S A H N k w E z 3 C V f h 5 x O n W O 8 G q N x Z S / A o C a P M C M W g B E w H f P u p l u E X 8 z Y 2 B W e l o n p A 3 S x C 1 y 63 Y 5 v W j x x r j o 95 w b d Q w Z j s E o L R 46 + a 7 X d u C l P Z R G c M X B G z z p J q 8 S i F 9 R Z 3 q i p V / H t a d J P + g J 48 I g E s L o Z y h p a d 4 w S f G k s f U l 2 r E T L w 1 L g 3 / U T K M C y o D g V F X 8 u U h e 5 P T N y D L n S 8 A S c v 1 T D + 0 M l X O l J c j f F U B l J A a e d P V 1 v e z j G x q a n u U j T N k 4 E P y w c D l t g L T y j M t I D t 1 T m f j G 7 T y x p r Q Y s r 9 S l w 1 X i z F 7 t w i f k i K 9 c 4 u Y D 2 N P 8 a y 8 r K H 8 k 0 N Y E V j R R S 98 U 95 d b a w i 3 A k 8 q T n h w k u q S 4 Q R m Z t H l m S 8 v 7 s C x t J B O T D j / h r y p / n k L j H m 7 x 1 x 8 r n G W N z 6 n / g W / d d y t P B B 2 i W x F z w 3 / 5 L q h c K W Q i R + 6 c Y C i O 4 V k X 1 Z T P F c p r s b s i Z s z / S r V + D u U j U T k N R f 0 6 y X F K 8 A 5 x k Y n O B r k O s g 18 P 6 f 0 g I 4 i x L M J d Z U 6 u q J r K y m q W 3 X P O W V N e H q T M l J 5 Q 2 G e D v e o S 22 K N M x 1 b 901 X t 8 / D A 55 L K u H 3 d U 5 U C r / 7 n 5 s t i T 0 + g K C Z 9 n W K W d n P 3 E H r N y + 13 e J N s b F V U e y N 2 / j l 56 R N g 3 U a + 3 x b V S i L 8 T I n S q c D l j T s N R g y a 9 p H v q b 6 R / o R i o Q G 64 L w G Q h b 0 i j M Z 3 k 0 o j 2 m r B 4 X p o a 26 L i 9 N P f Q v C / t V L / b s 75 N R G H W Q + w S V W u S w G v s K O x I L C Y U 4 x M + J 9 Q z I I 7 A 4 o O W U H p n R v n e y 5 N / 6 F Y R 349 k a f A X n w O / Q h S F Z v W 3 n 8 x k T 5 m G W z m c V E h N 7 F q H m f W b a E u I w 12 F U B M X k Z e D Q 4 t N U Q N E j U u J 1 m 89 z z a v H Q r + m 5 w R x I e a r H K f E k M U l M 7 q B d v u J H E + J 6 o K X V S B y K C p J 0 R 0 u V l w n Y Q a B 11 / z U v u g g b g z D z n 6 n 3 H V + i E f H S H G f T P r B G T N 4 g E Y U m f A u o 6 B z T W D 8 n E d k D z v p 3 y 9 C / c J H u p y O 6 K h T q F u / 5 l P B 0 n 8 J F F m M J s u v i j a e f q N V p o P A N B y n h W t 1 V O z X a 7 O u p m t v a M K 46 x i S F 8 G C Z A O b 0 R n Z a t H K + X d r 8 R m a Q c s F h 9 K b U 3 j x X c X y o k M u 2 s J a O / n 16 t C s s 4338 W A o V v T D H Q q C f M x M F O 1 H 4 j f M X + C T M p u A H X C R g Y X x i D X S V x H x u f Y + P r p w v 3 D K M + 6 e V A a 0 j w i a K Q i 9 + X Z 22 t r u n e + F 11 w g l l o W 0 z D y q I l E r e j p f 2 O p L k J Y i t Z 34 D I h 8 W 0 28 J z 998 V 8 m U n 4 e t m o i G T v z W r t 5 C P v n w 4 W L z B J I v A 1 K 1 o f w 9 O y D 0 D q D 0 X O Z r t C e 0 / r c i G / s y i t k 1 N m 8 t e Z q g y J G s R z M a d / Z X 8 a t 6 N m o B z a p H j p D X o M r S t B U X a i 13 a x x 8 P w O 5 / v Q K S B i W 8 + w S A b o j k F C A i B y 8 I S + P + + 4 T S C k O S A + i H B 0 C V e / R w T 1 s W L b l W G S x j U / o r 0 C Y s 5 J / F v 0 7 / a 9 F x L L o r S q k O 0 y c c d l 2 c L p X W f V l Q J N c h 7 j N r b S 1 r h C b p m H D K 745 R D 3 L I n u + O w b 7 G k Y u + G Z z J p w t c T J J F Y M d e 8 O 0 N 9 l n f U D l 0 8 W p H 9 h B v x + j i B 9 E R v A c X 3 Q 419 I W R M K d Q m r w B P u Q n / i V M I 4 M o d y z 34 V J B b 82 G t r V z i C e 0 o r y E S v b m j 9 i f s E S J q k r j H b Z C h b + n C t l 0 y R 73 K / B h 6 I y m 1 / 1 r g F Q S X s O a 3 d O b a P P U A u n 4 A 2 E i 0e2 f B X Q t N 0 t I e U T 1 U g j q 2 v F 4 C B c W H + x 8 C A C b O 4 h h Y b W K H 3 V I I x e d s b A J d + e D 5 J 8 g Y A F E v W B J B t 10 C P b Z Q R d 3 m o 11 t 11 S z 5 g z S o a 1 k l E i y J p 63 r m 3 U O I k Q F j Q D R u p q R F n 5 T y a g D m g W o h S u N b O j g k / z E u 9 F G v j 7 P 8 d o W T k u 8 R D C t A j 9 l q b I f z h D 1 E S t N C r y S s d g N d z n x h j d K 7 F A a m d + 8 k 51 / b H J j N b M 5 I c w 8 d C V a 85 Y + 3 P Z V 5 //c7wCf20WsiSOZE6A9mAEEgzhXFTH1g2LH8zINfDvq6cpLovfEDasYymbPwr7jNFUqRafUPVCqss8UTb8zRC1tZ8Y7TMa5IR1Uh7Nc2W2IGbfrOZiK8W4LCs0iLA9GvI1NvoSB+pH3oDFDXoOVgDFpLESqnVZt83A/To5DkqnNYTgc5Au3ZWkrQwirywFCAX+r+vq4UAcPw/hWRv+3fzJ4dUV4GdLkfcAnMuN/iaqX+dSDub/kXrz7uV0UsLnaslI4NAJFtrL5OgePieH5BVCLRVGkhrzNZ6/An/V1lpHk/D/DcATM0MuA6oT06w0FxO05mpMeB63vxnfH5UK9+M45Kjmz4FVAjCclBiLZRZJC6LKBjJsdBhadoVyhwIeVuWbMNSC0CXuuMEPHauQ1+g/W28n+Bvq1oopIwjUp3wWjXQJTi6d3Z/goYFEBwI4O0Ag8CirQc/tpQ5/vAFjHwnrfwVpslkXIn/6awymAbPF0SWrfWOvxLXpZlNMokqs4xWSpMWdCrsrcjeoqhaoTtIl7Kk3/bK6qf5xb/9qRIIriZJCGev+VeSoP5kj1O23Evoa79/vsdbuqYOzB823ZATTL4gjVrXFv/6BAEyuEdsMnd+diYzseDJK96OgM4EU+TfgcVlGgHS8T5IwZI2OjGkSKTgjdS2Z+76DF/UCyY0eE0obaAf5HvTg99vuSbaXcoSqRTD5hnRdg2QWraDDI8Gl+Dk+/noLyn571apn8V1qkcSwTcOL1z4ODJSR6UImbwRZkqS0nbnCqtGuiinop1+V8GuoI5HiuLGlC7MhvYgsoTcfQ2KsqtEGuXmlcbX+17VPrZ6YUPRHYIAJEfC/K4xJi/FAIvosnzWdNx3VVQw7afCyUjzmHrmsgOGXL+9YyoU860w3H54KMKYffmX+o0R9PDF7NtD9NWHlcZ152MYs1TEVuPl0eQOWoqm50oRnGR4XJj/UTHhNeJ2v4fZETgjjE6ZVbq8kGE8+iejlfroRB9ubiP5tFUxdrEx2WLISTCtQcUAHe/qMoodvpnqclyv4CT0v0RcosP0vSReO18i9gYHVPsAsZia6kTx6YukxHpMRcoC+rMEuvNayEr9e7vQ89rrtQVi0C4xMHeZmYZDXIGlWmuA0Cr0sS1by0zA3mq4XYkmjPDp3dICcOjxVQ499jvHaYlJ3baj88H2Km0F7uaEFKNHTOKuNTFpEWtHXSQMpg7L9GJt/FYM41LTiYMwoOSmxnqL6G7EBvQNfNTP9eiFgszRjUFSP0C2LQA+hwM68kqdzU3n3tfLNqhKwhWUVWrAG6QJgauY/i77kjeQRH2+1RDiWr6TUcImtEi+4v/6SDu7KQMse1Hn0G5VjlWBxOllxVmPENhEzPqTV4NB/MQqeTKCSqi7hpSRcXFg63CQoofELLZhnJMT0RY+YB+ZNOCom7DYhW0/+2i3b9AB1PIhRHD/2mxzB5EKhAT51NeWJ7IKGVg6bExdyMObtvJxv56tE5yEO9JDUlvorY1fmHgCkrn9pZo7ehUBl/aHi5b0+Iq5VyFaNIzBFgK6XTvO4+K42Skw3Boza+DbW4MU4dPK2fb6GGBPL/KZbwB9S1H72J34IUqAWH3kg87ppFowwmHNlkFGwwVb3Ti67sXqBXYgiU29sSs26k
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:34Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a7-e6b0-4969-ac04-4c4c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:35.000Z" ,
"modified" : "2016-03-17T15:43:35.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = 'fik3n5as' AND file:hashes.SHA1 = 'bc0d00eebf2477f79d1f66dc064c09c0bb7ccd57']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:35Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a7-3c74-40a3-8210-4cc4950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:35.000Z" ,
"modified" : "2016-03-17T15:43:35.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = 'fik3n5as' AND file:hashes.SHA256 = '432e7c42ad13c9993ebd4f2ac8fc124fa792426f48cfb5c21f640bccfa03d543']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:35Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a8-a450-4141-b8bb-40bb950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:36.000Z" ,
"modified" : "2016-03-17T15:43:36.000Z" ,
"description" : "Locky" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A H J 9 c U i 7 V C 6 x p g g C A A B A B A A g A B w A Z D d m Y j Q y M G F i M G E 2 M W Q 4 Y j U 4 Y j h j M D Y 0 O T A 4 N T U 2 N z F V V A k A A 6 j Q 6 l a o 0 O p W d X g L A A E E I Q A A A A Q h A A A A 7 + 65 u j r O r v c w V V g r r s W E 7 x G W 1 W B l 8 c a r 8 J p P 1 T G e Q r z c p R T F p X v 7 K h H t H d O I G V 0 c 9 h a Q G t 1 r 0 X T f m J n B 3 z 60 k f s / 7 m o W 6 I T y v 2 j I J 9 o u n L 1 M M 3 R p n e e l D 15 j q I D M k m W c q u x z x z k u / H b 8 V + 8 x q 48 i u H N O D x f 4 r F D b x L D 0 r U 3 a I s s J j n h b O 9 d P V C c V 415 / g G p N e 3 L Q P R N S N H o X a N B 23 s 8 O g 0 k T V t i Z B G B A H x v A T g u A w N + S n 2 a f u H J K R q b Q n 74 k w K N A X x 8 c K P E L I i q l A b G o D O h o o s a R / o z u Z G 1 M U 3 g b 0 J H D S / Q I F X H z U v w N i 1 W r v S e y N X w I X W 66 s 5 N f x W 1 w y V g Q e g b w O D Y H + F 15 w f m 2 d R O k 8 A q B a j T y V V B u A 2 i C w c I J Y Q v o p r 89 R k G O N 7 r I g w M 0 N w H I 7 x F k g w e i c A b Y + j 5 K 2 K B O H d x I m u W / r 3 R S A r R E 9 R v Y h z r l Z G G g J O p G j + J B O r 8 C L 0 N m j Q 3 o d A L E 9 x o / w c n g r / 7 v 0 I n 7 C o N I U Z Q G P 22 b / q E L 8 y I u T M F s W y A B K I p W E 6 L M P K Y y H 7 Q w m S 3 R T B 3 u d S 6 p o z w k B J x 7 G T a U Q t S x y 8 A 6 F u J W z D O X H c t N d V 3 x a N J D F q 0 v w 5 K I k Y j u d G v K 9 b v + S R P x 5 W 6 / l t 1 j n B Z c J 1 I x N e B n F 6 J z Z q q I 19 k K j 26 X x d R P a p / 5 I a N i 7 d j / y p e M j U r A i g L u a Q u A v 3 B P a v 0 M m F M + S m 9 S f Y d F X N j x P K X g v N R v O c R j W 21 t T e m H 5 y R S B v a N I g E I l / R m h f H h Z Z z c b g V 6 q m 4 J Z 9 b R n R C 0 z g m Q 2 T b f 1 t Z 1 t v B J h Y 6 o U U Z n m S s 56 T b g k F R t i Q S b L b V j Z b J Y 1 G Y O M W P Y G l g o H i J 5 H s b E i y B G Z h M O / X C t q E K 2 g E 0 E M G 4 I E r S w y s h r S E 79 X h d z X W v 2 Y 4 K y + R a S z 2 O E V x p L m k A J 97 W d C Q Q i J 9 i A v a Q 2 n c C Y C V + 5 e L E J z u V E b 0 Q E i r t c D n h q i e U 3 c 0 s b A c 4 V 0 U p K t 1e2 q U v t / 5 X 4 z 5 R e r 2 g Q 7 Q q s N s l y 9 D v 59 a q 2 X E w N q 663 o z J 0 R / s s 6 I R f g I U s W 8 v 5E9 I 1 i i u S / y 4 S G f + 1 I x L / r E C f f / 8 E H b K b D A u U b 73 r z f v L V d d D y t J C V s o E L Y / P 3 j U M 2 O F / J + 7 p J t u z / e 6 k Y l x P I S 9 L S A t R t n K Y p r + P Z + e 5 y t 1 Z f Z p M m e A 78 e w J B 1 O 1 u Z z G P 592 n V 0 B i X E F K I 8 T x J A e 6 U w d p c 2 v o o e F a 7 j r L 71 a J M B 0 98 w Z O 52 E Z / M c z d 9 G 7 k q W K h 4 r 3 d 2 r W q 0 S g P a i P F 3 x 8 B y / Z h C H f Z d S d L J V Y E j t B x 1 V r S A 4 p 1 o 4 h E z T s Q t + l v G 1 M s i R M O G l D y 3 n R r Z U L w V + k k a I b o G F C + k 1 f i w 4 m m e X R + H n i a k t d b p K a U w 2e1 l R N a 80 f 2 X 9 T J 7 Z G 0 X B o 8 b U 8 j i o 2 b i P T R Y e / f i 9 j E k N 9 f 9 z E c o s U 2 c K r E b V z o a R n 8 N s F b F c x r e v I b c N l B 4 j Q X V o 0 58 R a E Y y l 7 k + k J Q p r 4 h M u K x / j C E 6 D N L q w P u W 5 t M N V S 40 t j L 4 M Y C 4 L W K m 8 / L e + D m I i f d x K L g 5 W l Y o T n i 4 + n F F s 2 C W f E i 8 R M h t 8 A F 0 n L g u Z l t T B 9 t Z t R 745 h T H A l r a 7 o 6 z A 7 D c z H y q j 2 q P q W M q 0 L r l Z Y v Z V x K 48 R M Y Q 4 L 72 d F J h j I 1 V a H + r M m O E K 1 s B O u a 0 0 2 / F K z J d D P w L b m / d I 97 J D 5 p g 2 D M S d 5 b n I b d d z a d r r L A U 5 D d y K y p Y o q V t L d r p Z m 7 J w Y m N F u m b z O R 5 Q z 6 D 8 y m M b U H D d b T M W D F L W X Z 2 S D C F K N t e 3 l l P K s r l + h g R B y 3 x 9 M y M L M 5 H d W 91 q E C g 4 i T r e v o B n w q R p u O L Q D m c z c 7 j E F m p D 0 f r + b Z r 0 / p i a l O Y 1 p j g f H r K 6 g A C P n o 8 Z g k q 0 299 c k 9 p p o t r V E 4 E U v M k G P X 3 J E p f j m 2 h 9 w r j j p N D z e 49 M e G p e P I b f N q 3 k e l K s E T U v l E O 8 J 9 u y z C i / K w F D N / C g l 3 c 6 Q b 9 + S q M n r 9 z N z y J O B Y 81 D + Q w y Z K a E o j + G 4 G + G 86 r Z c J V M I l q c 7 c i X D o 4 m m S 8 s l P h a J v 7 B + 7 I 4 F 2 i s e W v O j W M h E Q l Q g H z s y J u q + e 94 h T 0 d k w 3 v 18 m I i U C 3 C S 5 M i v U u v 7 Z D g u + a p b q 6 T O J 6 T o g z M 7 T G / L N w t 6 X o k z p 95 z X v S D h A v S w G B 4 r r u Y S w N 0 75 t 5 V J 1 m D G Z 8 k G A L 8 b 4 d 5 W V p d g n U 5 i M m B d d B p U r C g J v 7 J l l 517 / F 6 G z N c c / e s J i t + v 8 c 2 n 25 j e 6 + w J b k 10 a w o I 7 z g q 705 A b + / t 3 V 2 p 0 z q k e g Q f F j 1 U t 6 g u x m C R N a 4 M f T W O L I U 2 P 38 a 0 o n h + T 2 l I q H 1 O Q d + 19 q / t f 380 O A U A E L i 8 I v 4 i 9 p n b u h i e w A r I l d C l T s a b q h z 96 k q n / D J C b E 112 C L / 3 n J 7 b D N H k 49 m y S / 9 B T i m J C i z P x R z 6 I a / C q W x e I J k f 2 B h k t 0 2 F a + P r 4 S i 9 V U u k X g I V o g o j w f g w H / J J c l L 3 + z O K t 3 d P R H V 78 Z A q 0 L x M 1 I 9 M m q 5 d 0 v l S r A 7 + q y Z 8 A P O o p z x Q 8 O S x L Y r D Q l 8 I z y x T 4 a k 8 C n u P 2 o h v G m E Y N o 2 s t 1 d B h e n B A w f 4 q 3 Q 7 q + l P T 40 h 0 Q D j N 1 B M 9 B Y 9 W e X s Q t k G X b S o p a F R J b x N v 5 t a k z K m / p n F x 2 j F T l d P H q x f L E J 3 j f N H M h c / N Y h P a h a V 5 F L K R 8 v E T E f 8 Z f 1 i c N F u M n h e Z w c i d x D l v d a N R h Z m N m 9 E P y S e n 2 c 9 G 3 e M q Q P G U w t N g U m C J X 0 c b S t l b 3 H w m t g 8 o a 0 l T h e G s W p 3 o V v h m Q D p D C u 6 w T G d R / 1 l 6 O m H d 4 Y a N W u 3 R b R 7 c K r 3 I N H z R t s m h 8 r q U 998 C o I E q c a h 3 J R 8 U P i B + Z o r d 7 z 1 k s d 5 D K 3 W o q h d y h e g K w C + q N 3 w 166 / h k p q 5 D T S 1 q y H H y / n n t N + V b k y j 1 a y N 2 t 3 P u Z b 9 Q 607 / Z x h G x 0 d + m t x t 14 S g i u s 8 C r e G 1 B 4 f 3 W W E Q n 225 Y 1 f m t + H 4 h M l Y B 6 Y t o G V L h n J d z U D + 3 y q 3 p x 0 P L D F M c 662 x z 4 + r M 0 d Z h b Z O U G 1 s y 6 F 3 u Z 5 n h 9 l Y P I M q k n r 9 W j Y m I i W 475 O 4 U I J 1 k A K o F H 2 H / G y Z R 5 Y Y r B u 6 n 70 z + / o q m e N J M t W 78 t l L V z F t 4 B g H K b y R J 7 C p f v O + Z E A 31 N D Y f 3 M 47 C 0 A 4 D 5401 g W p Q e x n H S C l J 7 Y a s Z d 2 A x x 0 C u + P T K r n 3 n e w b Q a H P g 9 d G 9 D f a 7 d O p 8 B n w a X p T i 7 a I n Z x k Y E W Z Z H 3 I V Y A U o 6 a b B f d / A e i x U e V F S K 5 y n 8 k 82 d b Y B U i w J 4 l K O A l O 5 P i G h Q d b y c M 4 L e D k k 6e6 V A p U 1 Q I W + y l C V o D W e W c i D J i f 20 E W n R E 2 r h E b Z x r l s E L E 7 X D O w F 7 r s F e 7 E s S Z U 0 l r 28 u / v Z 1 c D G X 9 e V 7 p m 66 x n O s b m D v Q W G d U 4 j M u + q V F W W S K 3 b o r y 2 U v E 8 n y / 2 r B X 5 h e W C T c I n 2 P + n v u u 6 I K i U 7 j V 7 s v o 5 m O F 4 M F X k 2 L G i / Q f 8 U q 64 d N F + 0 p E 5 v N d 8 b W B S v F f u C I V 36 r E 2 / K K s m j L 4 D u P F x k P o y 8 S T L / P O o y 8 O 7 d e 0 Y k S g z L / T Q x y J k m T K T N c E q l T l d s 7 k r z C O O L z c R 39 D B d n 0 p z u l c m l K t Y d 0 l 923 U C i a 50 d w k 8 M V z 6 l 1 t k n A t Q z M i Y 7 T 20 b V a b X S I X q j I d 5E1 i e Z Z O E D m Q d K 0 d Z 5 U Z 9 z S Z U j h u / 1 J / r O Y / G g k i v i z z O 3 n C k j r S T W J Z d R E 77 q a F g M n D z n 3 t d e B X R Y i k d T J L V I S I Z 4 h X z B w f m F v 2 T 7 Q k h v V x n + 9 V q q J 9 O j K w K j v W Z w k I G s + K 2 A d C k 1 N l 4 M / I B n K Z 2 l O d y M A Y 4 D r B H 9 U j D + 2 r c W N k + T 4 U h D g b f z x b H I X j H D K W u G U I g T k a 7 l 0 j J D Y 0 v A S M k H y y B a g / G L i l O o o K N W B X C 7 n G A F F i 62 K B a U 3 q h x + w n 60 b y 6 t G q o + J O y r W d P T v s M m b B r L n 9 U 5 / V U 8 t H 0 u P z g n m M n 0 62 w S l j V F D 66 h u 7 m 6 k 1 W h e K w 0 K 289 c 7 b w 0 2 o X R G 7 R h A X h j h j c d z d Q u e 1 / t G T 4 n 8 l m U K 9 B 8 b k g J L x Q A w l Y i j l 30e3 x / R w 0 u A r 3 G Q C 7 P x c 5 H A R g 81 B S x E A / + j g C
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:36Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a9-e568-4064-92dd-47af950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:37.000Z" ,
"modified" : "2016-03-17T15:43:37.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = 'hd6as' AND file:hashes.SHA1 = '29a429ca06c7ac4e0df4432af6d57ddb7d5c8373']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:37Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0a9-23fc-43c8-985e-4b9f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:37.000Z" ,
"modified" : "2016-03-17T15:43:37.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = 'hd6as' AND file:hashes.SHA256 = '561bbaeec4345c50699dbdd373757b039a7cf4e03c54d3765ece6f5d274c0612']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:37Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0aa-4ea8-4931-bc7e-4de3950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:38.000Z" ,
"modified" : "2016-03-17T15:43:38.000Z" ,
"description" : "Locky" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A H N 9 c U i n k W M 4 g g g C A A B C B A A g A B w A Z T N h O G M 0 M T c y M D A 5 O G Z k M z M 4 Z G R h Y T h j O G M 4 N j h j N T V V V A k A A 6 r Q 6 l a q 0 O p W d X g L A A E E I Q A A A A Q h A A A A O X b d J 30 a K / 6 O S s K p l Z 6 h 9 b v E O v J F 2 K U C H A q N + N O J U F s u s a d Y T d Z I / O a s c z F M L P 33 y X D g I B V L b I S G i Z Z x 8 + f l T t d L t d i d 20 g f l 3 + h W R K j H I G x 9 a 9 j L W S n M s C 8 s 1 y 0 M q 19 n 6 a R 2 i 0 l D B G 9 C W 7 U 27 h X s p q a N V v O j d 301 g C I b h r P a w f z e g K 3 i / g b G v I G o G i F k F U a k i f x J 5 e g v Q W 5 v 9 w M f x F U 2004 S 4 R 3 O c + 0 B w O s 9 l 7 g X n L 3 N o Q n b 9 s N K C r k C Y A G 3 N 7 a 6 b F b A K P V M B M g 8 C F W h m f B Z c e L x q D s q P n m K V e k Q H y k / S u g n / 4 y t o Y V m 2 V j 6 p I E H o X 7 s / 5 m Y w + l q 8 R w b i y K S K P D w V c h p c t E 3 F s e 5 A X y K Y l u D F p j K 9 h p v N P E A Y m N 15 D R C F o h e l p h + D q k a Z V 2 l A A v L 1 h E k J F Z M p u Y n 9 q Z 0 u H 6 Z L g A + H 55 O C K h Z u S n 73 O 1 p k 5 X n o L J 0 G K U b 7 Q l v S Y T W t Y Q u c H k z Q A / e H K X g K g M S g v R 7 P p 0 X A j 2 / a w 4 t v 0 H r 1 Y Z e Q C 5 M 2 Y m 5 o 7 F R l f A / 8 j e u 66 B M P W B K L X U 9 N u y Q p D Y 4 Q E j 69 B k 0 B o I T H k 2 a 7 r Q Q B 0 p n C a b y P F A 9 j d k G M o 2 c x v / z w X k / F 9 / F P y 8 J a u d z 9 E g i R + b J l o r + 8 + f 5 + P F M j p m c b P z I v s m f s o e V Y j e g R s A P W l 5 + g S c E e z g x K I q S D Z X A y Q I M w c J b y o D I N T 1 g 6 c 98 Y f e 3 e z C n 7 i 3 J 1 D b S v J D 25 A l Q I M x G l C v K z V E 9 i 9436 B w x Z K A A 1 E m R N u z e P A B 16 t R l i 0 0 0 o W 42 r h z u A c U W V u s N q N y j s 8 i / J l f Y Q E T O L N L D s r l b l + 8 Y r h w P N P 9 n J k h d O r j q C R g 2 G P 5 / H 0 Q D T A j m U W x T k z H K K G w j S 8 m 1 Z O h W i w c u W o t N d s I E U u 0 8 e A Q y H w k o I A i O q e 2 G C 0 S d W 6 C c T n V E 2 H D / A Y n 9 g H I b 3 b r n y p 5 r s X Y A H 0 A W l r N b B B c 8 T I c y a / W d p U p 0 D x 4 Q G Q D L s X n q D S 6 u R L I u 9 i l y b u u R 0 K C L 5 q 3 z j H Q 7 m S H F G 3 w 0 t v S W H H b S u j N q 8 f i O y d I M G + 70 c B B d G w 5 D U E a O x p 1 / u h 1 Z F l f n M 3 z 4 / r o n L i R 1 g b r K v K 5 M b B 1 Q 2 x k T K p k p O R H C Y 7 m / W M n c p T 6 o P E K 5 f G o A y Y X d 3 d Q H y h o Y D g G V x W o 7 S T g V j k R 7 r J t p A 0 X y 8 y u h / o j + j c M 9 D W b f W a b o I Y w m Q 3 X L I O g K F M a T a 4 R O Z K L 1 D n a p f Z X + m v Y V B d z H I V 90 Y 7 / Z 7 Q C s b e z 8 D t C w e 7 t 2 i M U T l M k 3 h T c k W j G 5 b B H t D D Y q L 5 z O R 4 S L w v F a 6 + 0 D e 6 y 3 J j j i q E O 3 e L U H e R x 91 C R b f 0 L H h 24 O 73 U L r l q Z z + 6 S W s 0 L S 7 J m 5 N 76 S 0 i k N 5 Z l Y + w e g O M X 9 v 1 a r P p L l w P + m k 12 C q B a B M W s S 9 p q Z 8 v C n y 0 G M b q j t g i s k l Y A x 93 J X Y A 9 a A o k V 7 u 0 K X O M 6 z Q 9 N u + 9 D L P H y a 1 U 2 h U v X Q + E Z w H m g o j n T + n L M r S + 5 G B S 4 w 4 K T z M W j e + V 4 x k b + 3 q J j u m k i j E a v 36 / y I 3 N d g / d M v s s q J J u n u c G z L T v 6 y 838 i K 51 u g + o q 3 D k R k 0 g 5 e l j Z 3 r z W B O O j S h 4 A I B Y C Y u D 3 H 3 R u 7 t K x 48 d B g N k t W + d H D W R E O r l y b v + R g U e N G L b J L 6 A / V P B d O 1 l A s A R R w Z P r Z P w E 1 Q R Z g P X i K 0 B + y Z I I x W L t M X A b K s u W z R O W h v g F G o O X 27 Z 7 C R W m T f u o 8 U P p L k d f 9 W 1 d E I c Z X y S / c a s h 1 C t 9 x 5 k J 7 O B c o 3E0 U u M x 3 m b C I I X 9 q 4 K t O m v 4 J C 1 L i i i r G Y 7 + t S H n A l c u Z y B R n K 6 b N n 9 n 7 o k f / 5 r M Z k S 8 d K u v D 8 M F g 4 v e 6 Q 46 o w E G f v z M p m U a m 9 i h h 7 L i 5 Q E / U o n B y K l n k u o 9 J b o G z U M E 6 p I b f C u 6 E y d 3 Y 9 w g B + L j 55 a L 86 a r 1 X m a f i E B A q Y x n T 3 d Y Z 4 l J v 8 i Q e G u 6 t T j k P M D g F T 8 y Q 5 c 9 Y t / l i 2 d F d V b v a n v a l c x U 80 o + z y y z w b k t X 7 x C F v S t P j h X f 9 G K 6 G d x 0 R 6 P 52 D z 3118 V 7 n l q Z / + 80 N M r L M 4 P s Y L D T k W Y 9 T V 26 k T w j z z C t F 4 V R D U + n e S 1 D R D v m T n C Y G x v X s m g q y R U i j g b g Z R 86 u H H e 9 H Y V I Z s n R l 9 M c G g U / T A U j e 4 i G b S X n J h C r L 4 Q 3 x z 9 D m 5 h G W G O E I r w Q d 4 Z P O s V 9 n k k c O d j f V g a t S I D e w F L I i s Q z M 1 Y p t X k n o K d h W j R x q t z O p Y v Q e Z w R C U F 0 0 P t C Y c c 81 / k j + P U E x 2 h G Z N A t k Z T U 143 b H F t B a 4 s h 9 m e u 70 x W P q L 0 p s P E W 9 F K Z N B 4 W / p n 5 C K a n J p I Q a Z d n u Q V i S c P 1 w h L R X e 1 O x s 5 E s 1 R d m t s q x z k F a H 0 2 c W 7 F x f + 9 + y Z L W Y z 5 q C y N A H q 9 N u K d Z 2 K l o / g L R + E L T u 75 s + 3 C x I L 7 y x i c h w K F a a N / j C 8 a G G N l C U 8 j w / a 8 A E F r k L S t D T 24 S f y b c W b 8 f r 5 X 4 B u t 0 b X X N e w S Y h v d N E v w v P y N m a M k S G x n m W a T o f 4 w 6 R m i m T l r D p i 2 I I b 2 + r L 3 n 2 s B 8 w i W a h 6 u g 5 l J e Z W D j u b V H 4 U O s H Z O t b 6 o 443 L t m C 73 g 2 L z 10 n V p U L + I z 9 c 8 e N y W b p R E P W S b E p X e w D q m / l L i I K b u f X 4 J u E K J 0 P L d L B Y l k j 9 z c r 4 E w S 73 t u K g V b O B X F g P D 47 K N w s x m Y L v u 7 X w u r u c 3 b + p n j a 8 m E 3 e R I w / Q A q s P X o J K 9 H B Q M n Q W Z w d J Z d Q 6 Q X r J 4 n 2 M / G j 7 A r z k W m G l Q Z e 0 K I 8 M g L / W B L P 0 C y 0 L R 0 1 A + z Y c M h L Q g B Y a 96 N M B V u 6 n t w r O l Z 3 J K O 6 W s c X 0 1 D L M i z v 2 Q 95 W R 2 d g a H P C M P k w 0 f H S r u D r G I a C k r r G x a L 6 J g I y w 1 H m 9 F T g L P w j s M 8 V + J v B //Eg5kArEILCyTsRWTO3399B/pikAOB9Wnbyb/O5MMIOFiwhREpP5u3AV4/rH4Oxj9DQKpOTB2bdR5wQ9UeSeO2JFNMkg/qra2X0kcSygoUqE6NxFPl/BmK/dh1/SsrKMV/BESffxrx9l1iJUfYIHF4D7g8ghHU1oEUIkO9MwBeHT5BaX1lET8YWKjbEBUCJGs0YfyU5NfzY9kFKpEf1YaYHoIJmlLwMgjbUkSSRpY0I8ekr9K5JwuhxiVWNa6/raOp0S0XmaR72h7QCbs/0+KbuTFk2M6yWLIuNfHAMd04Pp6GYmU16p1vNIddpoWyby7UZCNTfU7AMa0XsmTiHqcMsXMfuV/CHEd8Adm03IUX5bl5kE4S+ieTScffJQ+FmVZ18j62mAg2rFAWNd1LUTHiKIXyG9p2T3inZojk/FrDhEmBzBMUmj+g1RHh0hXvi/2ory/l4g7uGd7GuEU3cZ8nWUmcHxvf0xVhaImqgtvxRW/OR2xJsHI/LKLim5ZFim4lZOIyQPtzELMk2jIKsXE30bp9636usUUwHc3QWw5FyDbW3uVDR/dxTpx4KLWoXqxXxwIvCP/fMNc0vFqD1kDtCaw87P58jW76x+TvNeqS0z6KSdclhEEcBdDL60YkuY9scldCOEKlqtuVKMAnR+j7mt9kj+srJ0BhznHzyGZiooe+EMyk9VZUuUGA8b2e9RsMXuNOY89Q/nbCFAOzamBm+zuhr1N6zPFrgdCcVjCMdznUkKEwCIz6/r0MkoxI5kliWFivlzTSyoH0Sqo6X1r4tgHKM9PWYM1PHgG6KHZmjVmik/+YM4jhv3M7/U3btWf9e6Ulx2GkOq+L72gHZWrlw4Dvr93gAaMykyy5Y1qDjnjJnL5SiId4wm2+kvWGLu9Xf07WVoBHVto1PTODwuEYDng0WT7pSCwpBZePpbjRiJqNLWNI27glUQVRaCPge6AaApJyT5/tVwa5UDcFTDykPmUN1PNMJk6rBC0OgjvGnEqcriN6ZDAHCoUbmYkTysvolZgC8zhQ7xuMdbO0R9xn+lKwoKar4T7hAgxqdJwLpfjGP3JThnWVBps35Ml6FhP8D0qIiGg6+vFOYYvQGdKovsylO6Dw+uAaQ5ZATM6uqf4a7wl
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:38Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0ab-a334-486e-b6f4-47eb950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:39.000Z" ,
"modified" : "2016-03-17T15:43:39.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = 'ne7ue8k' AND file:hashes.SHA1 = '2f5220f482b05ab85f7a0dd4c44ead2c277bc7d3']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:39Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0ac-e5a8-41b9-823f-4c1f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:40.000Z" ,
"modified" : "2016-03-17T15:43:40.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = 'ne7ue8k' AND file:hashes.SHA256 = 'f219c3f921ebbb953c262dc28188135b7c7ae5a6e53bcd9f817629829e87f099']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:40Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0ac-f0bc-4f41-9b92-40ac950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:40.000Z" ,
"modified" : "2016-03-17T15:43:40.000Z" ,
"description" : "Locky" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A H R 9 c U g F B 5 B Q N A g C A A B A B A A g A B w A M z R i Y T Z k M T F h Z T k w O W N m N 2 M z Z m E 1 N T Q x M T g 5 O D J j Z D l V V A k A A 6 z Q 6 l a s 0 O p W d X g L A A E E I Q A A A A Q h A A A A 7 + 65 u j r O r v c w V V 7 K l U S u w C o s / 9 K R t I x S 90 q 3 + X w d K D 4 W p s 0 9 z r U C 7 x / 8 v / y B m E n q R Q 7 G 3 t 4 H 9 P M M F 3 G n v N S i x n E h I v h t Q y b L t J q P j d b j + V U A E i n v n 8 Y Q R A L n / 3 L R N M + R w I L I Y 82 z 6 f 1 e L p P b o P 4 u A M Y n X k o l l N B 77 J E i g E R V i 61 X G a R D g A P E F + a K q Z G / k 1 W n N c j A Y Y J I t 9 V M n + l Q 6 / m a T K c N t X H a B v x x o / a r d F s N K D t / f B V y 6 + Q L i v h z 1 s K Z h 9 l J 3 P R d b 5 z 1 q h d v U Q m o O 0 7 j 90 j E P B 0 p V A S U W O / + f a F p s x I 7 N U y B t z c + z H W Q u E Q G H J s K k 0 7 L 0 q c 9 B Y l M n p X S X + W F T W h P 3 E i P x N / 3 f S C I 3 o o E B m w Q c z n 4 H O t a t L 92 q 9 w b O y P D g o t T R k j 8 J M y e O / a L q J o x 6 H N p + H D C H h K j f I 0 81 z s N n r 1 O R 6 U r p C o m y j N M d q 3 A x Q v l E q N a c c g v o h V c r U D u y t q o A f z P T T V l q Y 8 H p G B L K N 6 Q D Q I 3 Z b 5 L 4 H t F J 81 O 0 7 q K K j u i 6 l B v h o 6 W z r 5 C 8 R K N h D X l r a D O O o 2 Z 5 g Z R / 2 M d 705 P E O M N o I g l v z W F g V V z J U P e L a / G c q 1 B Y y 2 P N P e Y 73 p F b v l W + 83 a 9 N D 5 h n E I 3 P h 3 p Y Z 2 B 4 L R n 3 V N c c 9 L 0 K Q D / 3 u j V G 7 e q + T j W r h Z v W t d V r I X d 5 y 2 e b I M h w k C Y 9 b K 7 O 167 E U Z B k A w G x h B 6 w r i z v I R k c M O T n a D c F v 8 v l 8 M v W N i 1 a n 3 J c M S m / S X 1 Y 3 E s H D g c a d I Z t T X l M 2 i G 5 o t 5 + E u s P Y S 5 C 8 c 9 I v 8 X r 7 l f C s i X + Q c T q V W J J t l 9 x 6 M N q F m f q d E 0 4 k t d / s z X R W f 5 X d / 8 S f u d X H 2 L x Y q 67 B O f E N 9 i M K b + p 8 s l 5 f O w / 6 b A J x p t A P F C 71 j h N M p 0 V X A I y V + t 28 r P d 8 l k 4 S p Q I H z u 9 T R e b r c / a 3 U i r Q H 4 m i 0 n V P V K d k p J D 86 G I U D 0 M y o L a k X n T K f q l i i Q I i r + V M y r J x h 6 C a w d O v k W 45 n a 3 V / l T 5 C f m + m z H V D h + V d v a 3 z F l G S r 56 M 1 P z / i x U 1 Y 40 / a / 2 K O b c 6 c 2 B b W f a O h O L l 7 O J 1 C m v 13 C A S Y x p A K N T R m f s l e z n k k x 44 u x t n h Y t n q 7 / c E F T m h n 9 q G i d y J j I p u 6 O d U g C f Y c k R x g 3 x H v / m i t V 8 U e D R j w H H P k Q C C A w h + S A s E 5 Q 1 p + S K x s / Q 3 D p 5 N M L g G 48 i z 0 y 9 u I K b j P K u p Z 7 u n 4 K Y m X 8 a f v j E y a I F T b 7 G 4 C / T Z h 6 s q S H V 3 o x h e a F z D 6 V q M f k O o n m T W O 8 C 1 X z t 9 R h w V v L Z 5 d p X E f e I k N x 5 J F f N a 2 r o L p H G 78 o 7 h m L H e m B g E M u E 8 i J + 0 V N m B R / 2 R 1 K g C u 6 F q M a 0 X F 0 A 42 m 9 k 8 I Z L O e W 9 G x P C E N Y H R C M N o v q l w J D u H a G V i 7 i n N D Q q q v M J u / Q N X j z + P C C H K 4 m 3 j 2 Z E 71 N R X 6 v J Y M x t W P u 2 F L C R u w T P w F m R T 3 i I d n N 3 C S h 9 S b 9 N E J x g Y D s S g / 2 w p D q G G S O j c c U F P J f W b q q Y 95 U b C O I R 4 Z s p g I d 34 q b 6 P I 6 + y V J w L S 7 d I 8 K t Q m Q V f 3 O i F c E F i e k R R 482 T u L i n / V s N Z G X z z P H H z I w 90 z 3 C G L 8 P d L n P v q r K x c n 9 m z L R D T u O B m f c J X + D 5 P h X H o A Z n p t b h 97 D l m I M s M O y s A B t q h Q N n 5 / K d R U B 3 Y O 5e6 G 2 g O E 2 o 9 v D X S L a H l E / 5 g j Q E m h G y 2E9 C i t b B k E L d m 6 s 9 U H A I / x 0 9 s 76 d n N k f i X k d 7 Q W f v f I J h R P V 3 s u J 2 Q 2 C T y R 8 P 3 x S T 4 y S O i 69 X u o Y 8 j v Q q u 1 n I c F a B X 859 N F u M T q 0 0 Y E w I O z o + 0 v n C w B X k o e S O Q A U X 7 W Q 6 s z A U k b Y U J g D g r m 2 c d F 5 K 3656 j G f 7 K c j K 4 A e g c a d u x 2 b l 0 C l Q n o u y 4 P X c N + O V / T 34 I O q W L H 8 v H 55 a T b T u b 3 L m Q T P m m g T r E 4 O c t l i a k 1 M n 6 R l U Q n d V p h w d V p 4 i X 12 Y x j P p a T 6 Z t e 5 B X 5 d K J y s 5 m l W R 1 t d E S f 6 P A c n V t T b 8 P f o f J 4 R 6 C v 5 / x o K y + 54 n 2 t D c o b 88 t M s e A Q E i z 8 W 1 e w F / o n i 3 R A N U V + 4 Y i H a m h F e Y L K B l K O Y Q z 0 7 A w y d 0 f o 1 N e r 4 k h 2 f u 15 d 2 s D M O Z m n G L Y 5 S w E o Y / 8 g H P M s e w s h k P E a s 6 U Z B m h K u f Q D h T Y p O d O T I l d b L B r P B J y r 7 k c m h n K K O w n Q E v J E 5 C C I 5 a i H h o E M X z K D L m W c g 7 u S v D F n M M z u g 6 f D 7 p u a i 0 d s m 3 H Q q q 6 L 6 e Y 0 Q U c a D 3 l A q B z i x A j 380 Z P E V z 7 u c O F y L Q 2 K x c E l i c D j 7 d / r / 8 F t G m V p E l 4 M B 1 R R Y U u g y 1 L 8 T R Z U m i g Y X Z Y v s j S b 8 R c u r A c V K Q k w S + z R v 143 / g 7 a 6 k 0 A c 2 B S X f S Y 6 o k 5 q n s c r w 4 k 8 n D W Q U f Q t 5 m o c l o m 2 k I k U J q 9 M x d e i H 9 w Q W l 2 X M w j m W 5 l 7 F k 9 D I B P F / Y / e q E K T F D w N s F s 1 Q b q J q 9 J h X P R P Z i j t r F v Z 3 h u U v G 8 y a k D + e O z k V T 2 r b x r 8 g v U J w d y f h V K m 73 B o e 78 e / F t L 4 W Y 1 W z W P q 0 Y t D c J A Q l 1 E c / G Z q 6e3 x 0 3 Z m N S v T 7 S 7 O n W F r 58 i D P i O s d P L t w F o a q C e A 7 v d j A G 0 f g H Q z M f M S + 8 k 3 w y c O A w V n m o + a G 0 E q O 0 b b G Y 2 Z 5 E h R m l + f U k R f M h b 3 T Z 8 c 0 0 i r I J Y N w 4 b U / x h h I i a p k Y X p P r r a E Y D j g x c T Q R Q + W 8 d W p X c N H K f g C 7 J P 14 B b A E W v Z 8 H E V J M N B / K J j t L A S E H S f n 1 d f T W F 2 v a E G + C Y I c q 9 x k O p c X B I / U V I R / S / H K F 51 p d s q B F D S I 2 y S 73 j Z O T G 4 P 2 D a 1 I e U 0 K y w Y w F g T m j + m e O v X K n m x O J m 0 d 550 a k j g m n H U f t b f G U W y B 8 U v v Q S I p B b S 3 V c V S y I m Q H 1 i N R E 5 o N S 4 d G q i 1 Y Z j V i a W + 4 n S R d 5 K H g 9 m 0 B U G T c p L O i B P U I 0 e L v S l W S K 4 Y Z A l A 1 F A c w H f q 3 a n U o M 2 E t P T w W z Q 0 L l 5 a U j T h l o Q 1 V 0 0 D Y g y y L G 8 Q 7 R 0 K P P D s u n 5 N R / c Y h z 4 e + I R 4 b I A V K E D Y d v 9 d G + T 93 M H T y 5 D / s i 60 j C c x i h 19 q K y / e V M p 95 i p E 2 x 9 o w q c R f 8 m P B d e q g j + k h M V 5 c N 5 l D t e V W C L V L 46841 V e w 81 l m Y 7 j / 4 A k W + t x L g N W 8 s 0 t H A k O 0 7 q h S + k j h z 2 Q E H u J q D R f 0 F V l 9 Z v q 222 b D u p D P y e w i y v k R s f 7 J d c j w W x n A v v / 9 e A e V R y C U d U F l x e 6 S 1 r O B K z 0 p d N P r p Z G o g o 8 Q Q N u R D b / b x 85 C o b V X e K 9 K S O k 4 I V c v T 3 B Q 71 u c A w W N + C p Z s p R U L K d p F f A Q G y v w q I M G / l q x 350 n w U F m H 9 p 3 r a Q O Q 1 W X 86 c T + + a X V s e 8 W + w n e D M k K M M 4 t C A X 5 z g i O L o v P 5 o W 2 n 7 c v h k N 1 x J i n i E S 9 K H U T D T A i 7 B O 3 h A a Y i 8 S J o U y w + b c k r 1 C S m j i 7 W r + c 4 j 7 a E m c T k h J j U A j F x f X 2 C E d Z D A o X K l M J G K 8 Y O h e n v + N + R 5 Z L 0 V z A 1 B 6 c A p w y H Q c a 5 j y M i 9 x R U U 1 o 2 S W L y u Q F N p F y 7 h Q p u Q Z C J y 4 t 1 C 0 Z / X K F 1 n 6 l q 24 S P i c M 0 b X B F / s q H B / O x O 6 i r X 4 d O i S 1 n d k G F 7 s q n o 4 P B t c g + W D y N e Q / o q x c 7 f d v G R a j 0 F I V l O D K 2 W B r Y t N P I 2 f V 430 P Z V e I U q V Z 4 n j 2 V n H B 0 B H / g c w T j q I 0 P 4 t I Y h d a C j E A z D 0 y o + + W l 2 I h B q m G a 9 f M w T u s A U A g R E k e p n 8 C + R J H o 7 + t l g b c g H N c u S 1 e k R k f q b 8 d S 2 P b l s n a p U B C z k m r R y y c M z U U f v k + w 5 e V X G L 0 L p K / n F x n g I g S b W 88 y I g m Q U 90 y 0 c 7 U V V M J E 5 n l 2 G t q u j 59 R y a q / G o l T a L c L 5 / 6 G c M d u l G 9 b I I / b Q P 3 w / Q f / W L p L F 4 R g 2 e V Q l H X y p I B + d h F B k Z P l a + u q e g J / c S y t 6 m h s y a 1 G Q x M 78 d I W 1 d c X v B m V S D f 22 D P y g 7 I h k B 5 U 7 O X u 2 G l C 6 f 7 f w O J C e V h 9 g O w h O i / D K 0 f 3 i G b u p t J T Y a K n Y a f t L + T 3 / 3 E f 5 q f x V E E I g b d z s W E F z j U L P b D q s K / k R t W N
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:40Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0ad-3160-498f-aa22-4650950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:41.000Z" ,
"modified" : "2016-03-17T15:43:41.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = 'old5gs' AND file:hashes.SHA1 = '0bac34e79a07ec68476ed762ebcb093fc034e249']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:41Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0ae-dd64-4773-86ce-4a7a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:42.000Z" ,
"modified" : "2016-03-17T15:43:42.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = 'old5gs' AND file:hashes.SHA256 = '716d39d4b03cb8d73b94a1ff98d29cbf56b1e76b1df4f439b1385b684fddaace']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:42Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0ae-8ce0-4943-ac04-4b07950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:42.000Z" ,
"modified" : "2016-03-17T15:43:42.000Z" ,
"description" : "Locky" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A H V 9 c U g Z C D 72 z w g C A A B A B A A g A B w A Z D U 3 M D V l Y W Y 5 Z T Q 2 N W J j N T N l O T Q 4 Z T Z h N z E y M G R k N W N V V A k A A 67 Q 6 l a u 0 O p W d X g L A A E E I Q A A A A Q h A A A A 9 v o b e u x V H T o R b 2 L h u o R 5 r / z 1 f 2 g L f c L X 6 V C G B D 8 T B R H o X v m T z x / l K N S l d B 42 U T d X 5 Q 0 7 W 94 i v 7 i l 5 W + V v U A D P 246 n q i l i F 2 + D N X 0 l D 1 f L V h 0 X j j V h 1 a p z f b R r Q p z k Q S p 3 G s M 3 J 0 y z G d s a a 9 e n W D G n d 1 Y n Y D 4 t I W f 6 B l 5 B i X y k E Z s L c 7 a U y 1 F y h o m 6 R b X 5 L 1 E V F + 2 t s E f H + F v B h m m w Y a a m Y D q k q 956 n a b b 9 c w j a F E 82 B s L 242 o R d r H b b g w J B L 2 t z y f 5 R q y N K Y h d 4 s / 43 B 0 y 159 D W 7 C e G w u z A g B 8 z B r + F W q i j 0 a i J Q b o N g G X 1 x L 598 //3ums2mIBEbcUpn/VXkZvnNFi10lWh80QuHqy11mk5ujVtLzt7xWXLpm/kml7VVQGIB+IhCjbTE7//mW8vDsMGJ3SV2hWQXv9JhxrwEc93SafQQWgHryOj48VNcD0AxZDMEmbC/J5xX2XmCwa9MahWUCBsl1/zT25uiZaFrjjbIofaP0JmEMhqjalt++VC2he/6Tzw/Hv+mouWTpbuSJMT3U6JVG7BScICVaJwn50lgcQsFFprZfCFhfQpXEG300xaE9H4gIDZQooxE7nY2tTH7youvr6ishh71AFZy6SxXPGLFC+GL3h6oW39hhJXSmis3cukmfFThNrds3U5kleYeRw48aZj2Z5edWp7JWRe3y+edaGcEgs+Y4O77ElNxy90AYuCsqveRbGAz8VF3EIzkTNPHXcMmH8d2KYzinlMq/iY2U0xnYbVwgaAWD9LrjQDlIsd6kJsXHC1RBbzRXgPNNMHK8az1mgRvIDCtu27Efq22LAHizLLhB7c4YZp/LYZJkZqY6LNFRI7423Q7/OdzqXk7jMZOhIhAOOhvwLe9/hlzRXNwqlI6suBFTKQDIAmgwjV0g8VZ0Q01qpE7fFgBk2AuOo8GwzV6BLIBZeDSiwarEDxK0h1Igj5OfaJIdZvZVm7a34H3rTsZwUJR2cFHB/BhSsu+NaBbFQJ7vPGDgAfYFZFEtOv+qJhs3Jpx3+fhajd3mqeUxQkz7B9ad6P6TgV2VEIDsjUho0leA53aULIB+brKrV2fw7UUNiQMokhpBJru/HWE3qdiMaOwtbIrDdx8bEQNliYwOODnidqvKUyDEv3XxF6mtwrVoTRGY1JWQuB7FMiscf8DTupaR0pfCd4tFeTYDEmUTSyML0LJ/lETQOTxkqyxVoB/eOuNvwXtnRySA5matoflPzzO23KdD8eFa4K953MGSTQfTJWKkgxSopWzSFokOddX568IRlGDkjWoHMU8zERnH+cUitsaKprBnaZuBvylXrzGLJ/PxC+temV3YRt51QcoMSoUp4MGGYfSTnSU2pr2DF6eVURjh02L2tgrZkLSoZn0JGjJ9Q+SZey8n2ypkanApj02KmmpRD4NEJAV9jrwJBDe8ojf3TivY0xG4nfSYglsNy0shGy7fzPOEHR8Pbuk+QxXTShKl9Yh9mLYH73bM4sN7xw7z9EsZVOutgk2xClzWzQwLHqKmwNAIT6tVi3782QdiPOMSaa3Xw4TX9+82C0hS0qcDuTzTiW0iTkwKZraw7ZWTTUseurzmpSbEwjIi9rZwZcrqf1Rq5eTuKBCOuUXeT69/Lwx2/M6tAW9+9YKDXaXsWPnfzYylHAqovZAHIse9t1h/eZ6D6D18gcLKNr367HtDdLoyuLnj8qpKvgmukVu0cDmf1GT4uLkoFUbrFK8/bP9KtFHC1uOz3qp2QLvzXPsXnMZkLwxs2J+1vfD42SOYtnaFvVI13J7SXpQ3lj9thdA/bat3JXkgfcN2bi//R+uLTZ00m/7kzmhnEkT2AL+bccm83m0iD8x4vPQZmcG3gCYArMNibaGcnWX1LsZojv7BmhnZjLsLDdO6gnYNtGnbcHfWlZVEJjPMe9lofxwL5KX/8FWwZPw9svnRixsR7P2Sz44nyVC0adlT2EnvsQVd8sdJrtATkjQt+CPLcgeFf0QwaIxRMdCWimJmESf4IINw+lhcJZwj/nTNGVOi4Kuuyu9rYX0XT85b8VIzBBoUjZDxtJhyisr9k93EyL18m+MEtxP9LlXkE47RPhZ63Zq5hRugfbQ9qiFcggnxF0sdWs547xD6SjMaMlJkMU4zqg+eCChvgYs8ojWLROL19/yVfthN25qv2JJ4I4Kc9lkcuLGMjY4p1HnU4XgJnC4Fs2cAIqRdd/yllvUdO4YJYzrjd+qBjCI+WpmBDdn3yGJHAlH6nep+2QjVC8WhNBNYmvwALETKhrtTOOwxN8sBkir92Yr6ojBznGOH/4sXHehjUrNLKFNebHme0YXztLvrfHY+gI8Dd3q/ah8pfAROKIP0KRE8Q7wNeritu4FrmQeB+ksLlMpxSo3UqIszKKw3EmKXJ+h0AB5WOvTqMUDRtj6lK0BeZS0uLByz5cmO9d3/aQVBet+NlkjvQqvxdynAMPfxSkoppKdcwWkuRFwTqpgfD/mGoYENB9JYEuw89b7yHXD+pniUq0P4TkXs+ws6VanlMoAMkWjCCnLBwHwKhDtsNv0R5928qaNnVWniCRm0HsSKbNGq2HOjvh+xDj3m5cQwsVX3Qadep+btlIWZorTX2MnvJ8BFRLGPcrH0/C/GS05YhzFuQ/yN7WGQavchU+rYs4dUoPo49G2qDKndFyNKehPAxEyhJV8+L1908wyJXX07/AsmYiJhwepQmzkxSLcw+ASin/F+us5ZK5xFNrPsPxM0AFRpCrOw4acH/B0/oihS+vqwr0nkYlDNsSATrFsnwggwEIAFDVeiVEjqLklIcwDIu7QMROxgtFd0aZiW5lG4Q7d0HTCEOQRuujSkPna41fYgn1Nxo7GLLpuMJELRfXF5H8XTLLAb3EPtWoniQA4hkSQzvg3woVzWOwSb43hGqGVhDJcoHuhMLO+j08NhZfdReGxh8xqIew8PM6zn5d4hRPF9nZ3ybBWmAImG8PTIyy2K0qiNytoeU24H2m6Oog957j7Fu4P2f9f8/j9hX/GWnGKIEZ+zJfwxodvD++Px0jDMYb9+s2ull4ow+m+DI3xWmNI+8HmisHdRzRic34hjZ4Bg6QKwwdj5AZxt4MrVn0wSvkglCsoooRhhvd6BJLLm14ZS634I6lCmoYWVH6bdhi0QToVfBF3Z9UG5M0NQSa616K1EIe9eYos2SW5+Zww52oCrd+mYZgblmQD3csfqCPxxAc96X4OCzpn5io38pUWk91fMK5DbcMw944V/Pynz0tboOW0BaKrHUp/gWIv+OQmij4RhW91WhD7nZaF6pnoqg3XVsKhv7B4L33F0VVmiOqezKRsgBWIEDJzQ8bQM03mXPN7vQHVriMMriWAZuke552voNKjGCXGOxVc6kcL5lgJ9hJBODc/+PfSXFnmEDBgHgLrwIdbtdRNGj3uvs6KF4pvDfNois0EoRBHiT+eSWVdV+DXW6VCc2j8CNwG3C3qKTGe29yPVWDAJ4crMzONo1iklyRU1xQfn2bOA2wZ0mvIrubZr8MlDOVULKiS0fOmfIHxJH8/R+R0lNZkE/wIVVhsYa16g7xhls6ZsPyx6CtDVafbbwRmvAYcfNLAFCYHwN1TfH1H0qMKdYZimFlXx+/+yQpopAEaflrNhd/0aP8MtoNfYTpH3kad0dYwC0JCJrinzeWsOQVQqQ1Hh1ciGC+KPzthmDeKM3V/rxAfGwZ0MCq5BiewlQ6OLltisuD/QuSn/O+SdJlsmNu4od7pRXl8AfZdHm//QMJ2EiYMaq62PdJRQQDewAGHguxSbyx1yuW+9ZDzz6Av8EiGNvG2/J50pKtqd6hXio+JNqQdWuWvGpwsfdwrUiZg+TaaE68Sh6yoYv8FZOlVzz02BCYFsmq8/r+gmwZ8NGaMlxiK+a9wIX9tIzYa9OUHYEtCwKaJ4N2G5hU+YE
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:42Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0af-7554-44eb-9e27-4d18950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:43.000Z" ,
"modified" : "2016-03-17T15:43:43.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = 'x5ief' AND file:hashes.SHA1 = '49d388714535f719567ec6ba524d6d2ee768e56a']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:43Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead0b0-3a24-4c2d-b865-4391950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:43:44.000Z" ,
"modified" : "2016-03-17T15:43:44.000Z" ,
"description" : "Locky" ,
"pattern" : "[file:name = 'x5ief' AND file:hashes.SHA256 = '0ff66b496e463f31309b477eacefd5bdf52579f14d4b138d825341e9167e177f']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:43:44Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead11b-2b20-4b0e-a60f-45ab950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:45:31.000Z" ,
"modified" : "2016-03-17T15:45:31.000Z" ,
"description" : "Locky C&C" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '78.40.108.39']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:45:31Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead11c-b0ec-46e3-a6f7-44c5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:45:32.000Z" ,
"modified" : "2016-03-17T15:45:32.000Z" ,
"description" : "Locky C&C" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '195.64.154.114']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:45:32Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead11c-8058-4c0c-b2de-4c83950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:45:32.000Z" ,
"modified" : "2016-03-17T15:45:32.000Z" ,
"description" : "Locky C&C" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '46.148.20.46']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:45:32Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--56ead11c-9f9c-4e80-b5f9-4f85950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:45:32.000Z" ,
"modified" : "2016-03-17T15:45:32.000Z" ,
"description" : "Locky C&C" ,
"pattern" : "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '188.127.231.116']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-03-17T15:45:32Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-dst\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56ead189-705c-45b0-882b-470f02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:21.000Z" ,
"modified" : "2016-03-17T15:47:21.000Z" ,
"first_observed" : "2016-03-17T15:47:21Z" ,
"last_observed" : "2016-03-17T15:47:21Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56ead189-705c-45b0-882b-470f02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56ead189-705c-45b0-882b-470f02de0b81" ,
"value" : "https://www.virustotal.com/file/0ff66b496e463f31309b477eacefd5bdf52579f14d4b138d825341e9167e177f/analysis/1458228414/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56ead189-a5c4-4cf1-8f73-4c9702de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:21.000Z" ,
"modified" : "2016-03-17T15:47:21.000Z" ,
"first_observed" : "2016-03-17T15:47:21Z" ,
"last_observed" : "2016-03-17T15:47:21Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56ead189-a5c4-4cf1-8f73-4c9702de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56ead189-a5c4-4cf1-8f73-4c9702de0b81" ,
"value" : "https://www.virustotal.com/file/716d39d4b03cb8d73b94a1ff98d29cbf56b1e76b1df4f439b1385b684fddaace/analysis/1458225729/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56ead189-8ddc-4de0-afea-4f6c02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:21.000Z" ,
"modified" : "2016-03-17T15:47:21.000Z" ,
"first_observed" : "2016-03-17T15:47:21Z" ,
"last_observed" : "2016-03-17T15:47:21Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56ead189-8ddc-4de0-afea-4f6c02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56ead189-8ddc-4de0-afea-4f6c02de0b81" ,
"value" : "https://www.virustotal.com/file/f219c3f921ebbb953c262dc28188135b7c7ae5a6e53bcd9f817629829e87f099/analysis/1458226707/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56ead18a-c850-49d4-aef8-439e02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:22.000Z" ,
"modified" : "2016-03-17T15:47:22.000Z" ,
"first_observed" : "2016-03-17T15:47:22Z" ,
"last_observed" : "2016-03-17T15:47:22Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56ead18a-c850-49d4-aef8-439e02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56ead18a-c850-49d4-aef8-439e02de0b81" ,
"value" : "https://www.virustotal.com/file/561bbaeec4345c50699dbdd373757b039a7cf4e03c54d3765ece6f5d274c0612/analysis/1458223567/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56ead18a-354c-4fbd-b912-4c1a02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:22.000Z" ,
"modified" : "2016-03-17T15:47:22.000Z" ,
"first_observed" : "2016-03-17T15:47:22Z" ,
"last_observed" : "2016-03-17T15:47:22Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56ead18a-354c-4fbd-b912-4c1a02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56ead18a-354c-4fbd-b912-4c1a02de0b81" ,
"value" : "https://www.virustotal.com/file/432e7c42ad13c9993ebd4f2ac8fc124fa792426f48cfb5c21f640bccfa03d543/analysis/1458229367/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56ead18b-62e4-4a0d-8e2e-465002de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:23.000Z" ,
"modified" : "2016-03-17T15:47:23.000Z" ,
"first_observed" : "2016-03-17T15:47:23Z" ,
"last_observed" : "2016-03-17T15:47:23Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56ead18b-62e4-4a0d-8e2e-465002de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56ead18b-62e4-4a0d-8e2e-465002de0b81" ,
"value" : "https://www.virustotal.com/file/b892a28d847a0d8d814e3447335a303d8474f17da9137c902983b518e2df0fd8/analysis/1458225852/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56ead18b-853c-495f-9780-4f3902de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:23.000Z" ,
"modified" : "2016-03-17T15:47:23.000Z" ,
"first_observed" : "2016-03-17T15:47:23Z" ,
"last_observed" : "2016-03-17T15:47:23Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56ead18b-853c-495f-9780-4f3902de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56ead18b-853c-495f-9780-4f3902de0b81" ,
"value" : "https://www.virustotal.com/file/1f13e821d162f26ccff865e12045dc34b0d6a3f11425ae76e9797d4d7d939a56/analysis/1458225850/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56ead18b-40f0-4969-9c51-4e4402de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:23.000Z" ,
"modified" : "2016-03-17T15:47:23.000Z" ,
"first_observed" : "2016-03-17T15:47:23Z" ,
"last_observed" : "2016-03-17T15:47:23Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56ead18b-40f0-4969-9c51-4e4402de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56ead18b-40f0-4969-9c51-4e4402de0b81" ,
"value" : "https://www.virustotal.com/file/a9dd22723f0ad6316c2c87727f5b01319cf703d03799efad44f9d8930c4ce5eb/analysis/1458228581/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56ead18c-ba10-4d24-bdf3-4a1b02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:24.000Z" ,
"modified" : "2016-03-17T15:47:24.000Z" ,
"first_observed" : "2016-03-17T15:47:24Z" ,
"last_observed" : "2016-03-17T15:47:24Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56ead18c-ba10-4d24-bdf3-4a1b02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56ead18c-ba10-4d24-bdf3-4a1b02de0b81" ,
"value" : "https://www.virustotal.com/file/98cfd4e050f4791d2762fd7387737489ea3f2a23cbbff00cd51b572ea6ee70cf/analysis/1458228818/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56ead18c-b6f0-4d96-804a-421b02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:24.000Z" ,
"modified" : "2016-03-17T15:47:24.000Z" ,
"first_observed" : "2016-03-17T15:47:24Z" ,
"last_observed" : "2016-03-17T15:47:24Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56ead18c-b6f0-4d96-804a-421b02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56ead18c-b6f0-4d96-804a-421b02de0b81" ,
"value" : "https://www.virustotal.com/file/451c28e505b2051c630914185dc6c2e0460ae30b219e02fdb6e7990935bf6981/analysis/1458229032/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56ead18c-0f5c-4205-9e46-4b6902de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:24.000Z" ,
"modified" : "2016-03-17T15:47:24.000Z" ,
"first_observed" : "2016-03-17T15:47:24Z" ,
"last_observed" : "2016-03-17T15:47:24Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56ead18c-0f5c-4205-9e46-4b6902de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56ead18c-0f5c-4205-9e46-4b6902de0b81" ,
"value" : "https://www.virustotal.com/file/bbdcfe20dece102c30a0f6785ed2d9a7f898428285df3086a6f69d38c267c960/analysis/1458228346/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56ead18d-2520-4f06-a728-4bdd02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:25.000Z" ,
"modified" : "2016-03-17T15:47:25.000Z" ,
"first_observed" : "2016-03-17T15:47:25Z" ,
"last_observed" : "2016-03-17T15:47:25Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56ead18d-2520-4f06-a728-4bdd02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56ead18d-2520-4f06-a728-4bdd02de0b81" ,
"value" : "https://www.virustotal.com/file/c063a43b6d949e19cc84ed43018c11a6e1762ad76012da54133a01ae6008a465/analysis/1458228412/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56ead18d-6c48-443f-8f8f-4d5402de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:25.000Z" ,
"modified" : "2016-03-17T15:47:25.000Z" ,
"first_observed" : "2016-03-17T15:47:25Z" ,
"last_observed" : "2016-03-17T15:47:25Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56ead18d-6c48-443f-8f8f-4d5402de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56ead18d-6c48-443f-8f8f-4d5402de0b81" ,
"value" : "https://www.virustotal.com/file/34f328ae6adca2c91733c0dbb922cef53199ae60901581785c194a9fc1dc718f/analysis/1458228789/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--56ead18d-9ae8-41d7-b6d0-43bf02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-03-17T15:47:25.000Z" ,
"modified" : "2016-03-17T15:47:25.000Z" ,
"first_observed" : "2016-03-17T15:47:25Z" ,
"last_observed" : "2016-03-17T15:47:25Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--56ead18d-9ae8-41d7-b6d0-43bf02de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--56ead18d-9ae8-41d7-b6d0-43bf02de0b81" ,
"value" : "https://www.virustotal.com/file/188e5ff3ad3e4294e2ec9bb760fbf3eeb0319568d80cc2df8d369d89c6cef512/analysis/1458229127/"
} ,
{
"type" : "marking-definition" ,
"spec_version" : "2.1" ,
"id" : "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ,
"created" : "2017-01-20T00:00:00.000Z" ,
"definition_type" : "tlp" ,
"name" : "TLP:WHITE" ,
"definition" : {
"tlp" : "white"
}
}
2023-04-21 13:25:09 +00:00
]
}