2023-04-21 13:25:09 +00:00
{
2023-06-14 17:31:25 +00:00
"type" : "bundle" ,
"id" : "bundle--574e8687-8af0-40c5-b4dd-baa9950d210f" ,
"objects" : [
{
"type" : "identity" ,
"spec_version" : "2.1" ,
"id" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:58:52.000Z" ,
"modified" : "2016-06-01T06:58:52.000Z" ,
"name" : "CIRCL" ,
"identity_class" : "organization"
} ,
{
"type" : "report" ,
"spec_version" : "2.1" ,
"id" : "report--574e8687-8af0-40c5-b4dd-baa9950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:58:52.000Z" ,
"modified" : "2016-06-01T06:58:52.000Z" ,
"name" : "A Universal Windows Bootkit An analysis of the MBR bootkit referred to as \u00e2\u20ac\u0153HDRoot\u00e2\u20ac\u009d" ,
"published" : "2016-06-01T07:16:10Z" ,
"object_refs" : [
"observed-data--574e8696-dcd4-433d-b99c-0c79950d210f" ,
"url--574e8696-dcd4-433d-b99c-0c79950d210f" ,
"observed-data--574e86a6-3ecc-4004-8b70-0c7f950d210f" ,
"url--574e86a6-3ecc-4004-8b70-0c7f950d210f" ,
"x-misp-attribute--574e86bc-dad4-4f04-930f-0c77950d210f" ,
"indicator--574e872a-610c-417d-aa99-43de950d210f" ,
"indicator--574e872a-2594-4f73-b21e-4a3f950d210f" ,
"indicator--574e872a-e448-45b3-86fc-4714950d210f" ,
"indicator--574e872b-03a8-46ec-9d51-401d950d210f" ,
"indicator--574e872b-ce80-420b-9210-4cd4950d210f" ,
"indicator--574e872b-bf98-459f-b13f-48b1950d210f" ,
"indicator--574e872b-ed20-4e3f-b5b2-4471950d210f" ,
"indicator--574e872b-a3e8-4750-98ba-40fa950d210f" ,
"indicator--574e8782-508c-4f62-99e1-4377950d210f" ,
"indicator--574e8782-95dc-4fc2-b2b1-45ae950d210f" ,
"indicator--574e8782-14d0-4c28-bec6-4d08950d210f" ,
"indicator--574e8782-1278-4a87-a5c7-4d88950d210f" ,
"indicator--574e8783-16a0-4120-a1dc-4361950d210f" ,
"indicator--574e8783-efdc-43b5-a160-4b28950d210f" ,
"indicator--574e8783-dde4-4e65-9e56-426a950d210f" ,
"indicator--574e8783-f444-4e62-8d13-4d25950d210f" ,
"indicator--574e87ac-3ba0-4b91-893d-4bdb02de0b81" ,
"observed-data--574e87ac-c61c-4865-8f37-408002de0b81" ,
"url--574e87ac-c61c-4865-8f37-408002de0b81" ,
"indicator--574e881d-07c0-4197-8d83-4e35950d210f" ,
"indicator--574e881e-0e40-4d3d-80b6-4b34950d210f" ,
"indicator--574e881e-d238-42e4-baa7-4da9950d210f" ,
"indicator--574e881e-1168-4207-919d-405b950d210f" ,
"indicator--574e881f-a00c-4d63-a9f6-4116950d210f" ,
"indicator--574e881f-a23c-4400-9039-413c950d210f" ,
"indicator--574e881f-50c0-4cc4-b7c2-4c5b950d210f" ,
"indicator--574e881f-2f2c-44f9-af16-4534950d210f" ,
"indicator--574e8820-9428-491d-a58e-4782950d210f" ,
"indicator--574e8820-60b0-4003-8c7e-4476950d210f" ,
"indicator--574e8820-f5ac-47ed-8444-4534950d210f" ,
"indicator--574e8821-bfd4-40e1-9cda-4d45950d210f" ,
"indicator--574e8821-2384-4449-bd73-4af7950d210f" ,
"indicator--574e8821-3788-4fdc-98fd-4507950d210f" ,
"indicator--574e8822-b0b8-4467-8780-4b73950d210f" ,
"indicator--574e8822-55ec-4440-accc-49f6950d210f" ,
"indicator--574e8822-10c8-4e61-8c5b-401e950d210f" ,
"indicator--574e8823-764c-4d95-bd5b-4770950d210f" ,
"indicator--574e8823-8ed4-4d44-90ef-4f76950d210f" ,
"indicator--574e8823-04d8-439e-86ea-48a5950d210f" ,
"indicator--574e8824-4ae0-4487-b200-4b36950d210f" ,
"indicator--574e8824-7194-45b5-98c0-4f10950d210f" ,
"indicator--574e8824-26d8-4907-80f8-400f950d210f" ,
"indicator--574e8825-79c8-4c88-bde5-4cae950d210f" ,
"indicator--574e8825-69f4-4855-8b95-4c9e950d210f" ,
"indicator--574e8825-ed70-4609-a497-47fc950d210f" ,
"indicator--574e8826-7830-4b99-be60-4f9c950d210f" ,
"indicator--574e8826-6f6c-4298-98f7-4be3950d210f" ,
"indicator--574e8826-506c-423c-8116-4662950d210f" ,
"indicator--574e8827-ad04-4733-88b3-467e950d210f" ,
"indicator--574e8827-a6c4-4f53-9816-405c950d210f" ,
"indicator--574e8827-be80-40d4-8954-4979950d210f" ,
"indicator--574e8828-2dc0-4109-b0a7-4fd6950d210f" ,
"indicator--574e8828-dbac-4574-959a-484f950d210f" ,
"indicator--574e8828-4e24-43ee-8ee9-47ed950d210f" ,
"indicator--574e8829-b1f4-44ff-9cac-42a3950d210f" ,
"indicator--574e8829-e7e8-4a36-b3c1-4079950d210f" ,
"indicator--574e8829-3a74-44b9-bef9-486a950d210f" ,
"indicator--574e8829-33bc-4a14-bf68-4572950d210f" ,
"indicator--574e882a-82a8-41c1-9445-46fe950d210f" ,
"indicator--574e882a-7904-43ba-8171-416c950d210f" ,
"indicator--574e882a-3c1c-4da8-9b1f-4b55950d210f" ,
"indicator--574e882b-184c-49ea-86ac-4cea950d210f" ,
"indicator--574e882b-49ac-49ba-8543-45ea950d210f" ,
"indicator--574e882c-ae14-449c-8e6d-4069950d210f" ,
"indicator--574e882c-68d0-423a-a9b7-4150950d210f" ,
"indicator--574e882c-404c-42bc-b3b4-4258950d210f" ,
"indicator--574e882d-4388-4b99-bd77-4e07950d210f" ,
"indicator--574e882d-a9d8-45f4-985c-42a8950d210f" ,
"indicator--574e882e-7ef0-4495-b8bd-4b9f950d210f" ,
"indicator--574e882e-0058-4f84-bacc-47c5950d210f" ,
"indicator--574e882e-8cc4-4c80-ae29-4ec0950d210f" ,
"indicator--574e882f-1bf8-4870-95c5-43c0950d210f" ,
"indicator--574e882f-8240-4468-83b1-4364950d210f"
] ,
"labels" : [
"Threat-Report" ,
"misp:tool=\"MISP-STIX-Converter\"" ,
"type:OSINT"
] ,
"object_marking_refs" : [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--574e8696-dcd4-433d-b99c-0c79950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:54:14.000Z" ,
"modified" : "2016-06-01T06:54:14.000Z" ,
"first_observed" : "2016-06-01T06:54:14Z" ,
"last_observed" : "2016-06-01T06:54:14Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--574e8696-dcd4-433d-b99c-0c79950d210f"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--574e8696-dcd4-433d-b99c-0c79950d210f" ,
"value" : "http://williamshowalter.com/a-universal-windows-bootkit/"
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--574e86a6-3ecc-4004-8b70-0c7f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:54:30.000Z" ,
"modified" : "2016-06-01T06:54:30.000Z" ,
"first_observed" : "2016-06-01T06:54:30Z" ,
"last_observed" : "2016-06-01T06:54:30Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--574e86a6-3ecc-4004-8b70-0c7f950d210f"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--574e86a6-3ecc-4004-8b70-0c7f950d210f" ,
"value" : "https://github.com/williamshowalter/hdroot-bootkit-analysis"
} ,
{
"type" : "x-misp-attribute" ,
"spec_version" : "2.1" ,
"id" : "x-misp-attribute--574e86bc-dad4-4f04-930f-0c77950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:54:52.000Z" ,
"modified" : "2016-06-01T06:54:52.000Z" ,
"labels" : [
"misp:type=\"comment\"" ,
"misp:category=\"External analysis\""
] ,
"x_misp_category" : "External analysis" ,
"x_misp_type" : "comment" ,
"x_misp_value" : "In October, 2015 Kaspersky released an analysis of a family of malware they dubbed \u00e2\u20ac\u0153HDRoot\u00e2\u20ac\u009d on their Securelist blog. It was an installment in their ongoing series on the WINNTI group, known for targeting gaming companies in their APT campaigns. The Securelist blog was dismissive of the HDRoot bootkit and called out a number of mistakes they claimed the authors made, which brought it to be the focus of their ridicule.\r\n\r\nThe bootkit in question uses two stolen signing certificates and is capable of running without problem on any Windows system that was released in the last 16 years, from Windows 2000 to Windows 10. The one limitation is that it will only run as an MBR bootkit and will not work on systems using UEFI. It contains the ability to install any backdoor payload to be launched in the context of a system service when Windows starts up on both 32 and 64-bit systems. It also does a fairly good job of concealing the actual bootkit code, only failing to remove the backdoor after running it at boot. This likely a conscious choice made by the authors to have the backdoor responsible for removing itself, and not an oversight.\r\n\r\nHDRoot represents a serious commitment in time and effort to develop, and likely has been in use or development since at least 2006. The sample analyzed here dates to sometime in 2012 or 2013, and is the same sample Kasperky reports to have analyzed in their debut post on HDRoot. However, all evidence points to Kaspersky doing their analysis with a 2006 sample, criticizing problems in the malware that are not actually present. Additionally, they provide no hashes or other information on the actual sample they used."
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e872a-610c-417d-aa99-43de950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:56:42.000Z" ,
"modified" : "2016-06-01T06:56:42.000Z" ,
"description" : "dropper64.bin" ,
"pattern" : "[file:hashes.SHA1 = '4c3171b48d600e6337f1495142c43172d3b01770']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:56:42Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e872a-2594-4f73-b21e-4a3f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:56:42.000Z" ,
"modified" : "2016-06-01T06:56:42.000Z" ,
"description" : "driver32.sys.bin" ,
"pattern" : "[file:hashes.SHA1 = '7ff22bd8667ce23e7db8c759bd03c15fb7226c76']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:56:42Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e872a-e448-45b3-86fc-4714950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:56:42.000Z" ,
"modified" : "2016-06-01T06:56:42.000Z" ,
"description" : "driver64.sys.bin" ,
"pattern" : "[file:hashes.SHA1 = '268dd909933c187d2798b5815674d70b930b498e']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:56:42Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e872b-03a8-46ec-9d51-401d950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:56:43.000Z" ,
"modified" : "2016-06-01T06:56:43.000Z" ,
"description" : "pe1_decrypted.bin" ,
"pattern" : "[file:hashes.SHA1 = '24a80cd100274e2c39180741aa688a4e73282552']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:56:43Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e872b-ce80-420b-9210-4cd4950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:56:43.000Z" ,
"modified" : "2016-06-01T06:56:43.000Z" ,
"description" : "pe2_decrypted.bin" ,
"pattern" : "[file:hashes.SHA1 = '5d6c1a3c2d827c714b764b1c5a3e7370ed737986']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:56:43Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e872b-bf98-459f-b13f-48b1950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:56:43.000Z" ,
"modified" : "2016-06-01T06:56:43.000Z" ,
"description" : "rkimage_encrypted.bin" ,
"pattern" : "[file:hashes.SHA1 = 'aaf677acc05ae94f98f836fb44fd672a4b2d90db']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:56:43Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e872b-ed20-4e3f-b5b2-4471950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:56:43.000Z" ,
"modified" : "2016-06-01T06:56:43.000Z" ,
"description" : "rkimage_decrypted.bin" ,
"pattern" : "[file:hashes.SHA1 = '3c22ef94a737484e2f708393dcbabdfdb9d6cfbc']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:56:43Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e872b-a3e8-4750-98ba-40fa950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:56:43.000Z" ,
"modified" : "2016-06-01T06:56:43.000Z" ,
"description" : "C_932.NLS.bin" ,
"pattern" : "[file:hashes.SHA1 = '88912b5227145d3a715ae6eeebd5935c89955721']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:56:43Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"sha1\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8782-508c-4f62-99e1-4377950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:58:10.000Z" ,
"modified" : "2016-06-01T06:58:10.000Z" ,
"description" : "dropper64.bin" ,
"pattern" : "[file:hashes.MD5 = '2c85404fe7d1891fd41fcee4c92ad305']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:58:10Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"md5\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8782-95dc-4fc2-b2b1-45ae950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:58:10.000Z" ,
"modified" : "2016-06-01T06:58:10.000Z" ,
"description" : "driver32.sys.bin" ,
"pattern" : "[file:hashes.MD5 = '4dc2fc6ad7d9ed9fcf13d914660764cd']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:58:10Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"md5\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8782-14d0-4c28-bec6-4d08950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:58:10.000Z" ,
"modified" : "2016-06-01T06:58:10.000Z" ,
"description" : "driver64.sys.bin" ,
"pattern" : "[file:hashes.MD5 = '8062cbccb2895fb9215b3423cdefa396']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:58:10Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"md5\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8782-1278-4a87-a5c7-4d88950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:58:10.000Z" ,
"modified" : "2016-06-01T06:58:10.000Z" ,
"description" : "pe1_decrypted.bin" ,
"pattern" : "[file:hashes.MD5 = 'c7fee0e094ee43f22882fb141c089cea']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:58:10Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"md5\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8783-16a0-4120-a1dc-4361950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:58:11.000Z" ,
"modified" : "2016-06-01T06:58:11.000Z" ,
"description" : "pe2_decrypted.bin" ,
"pattern" : "[file:hashes.MD5 = 'd0cb0eb5588eb3b14c9b9a3fa7551c28']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:58:11Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"md5\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8783-efdc-43b5-a160-4b28950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:58:11.000Z" ,
"modified" : "2016-06-01T06:58:11.000Z" ,
"description" : "rkimage_encrypted.bin" ,
"pattern" : "[file:hashes.MD5 = '76e1e42988befbf13b4f934604206250']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:58:11Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"md5\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8783-dde4-4e65-9e56-426a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:58:11.000Z" ,
"modified" : "2016-06-01T06:58:11.000Z" ,
"description" : "rkimage_decrypted.bin" ,
"pattern" : "[file:hashes.MD5 = '613fd19d0abc3d018ead52afabd59fec']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:58:11Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"md5\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8783-f444-4e62-8d13-4d25950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:58:11.000Z" ,
"modified" : "2016-06-01T06:58:11.000Z" ,
"description" : "C_932.NLS.bin" ,
"pattern" : "[file:hashes.MD5 = '287fac6f4dac57253ac0061be1508f9d']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:58:11Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"md5\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e87ac-3ba0-4b91-893d-4bdb02de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:58:52.000Z" ,
"modified" : "2016-06-01T06:58:52.000Z" ,
"description" : "dropper64.bin - Xchecked via VT: 4c3171b48d600e6337f1495142c43172d3b01770" ,
"pattern" : "[file:hashes.SHA256 = 'a9a8dc4ae77b1282f0c8bdebd2643458fc1ceb3145db4e30120dd81676ff9b61']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T06:58:52Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload delivery"
}
] ,
"labels" : [
"misp:type=\"sha256\"" ,
"misp:category=\"Payload delivery\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--574e87ac-c61c-4865-8f37-408002de0b81" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T06:58:52.000Z" ,
"modified" : "2016-06-01T06:58:52.000Z" ,
"first_observed" : "2016-06-01T06:58:52Z" ,
"last_observed" : "2016-06-01T06:58:52Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--574e87ac-c61c-4865-8f37-408002de0b81"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--574e87ac-c61c-4865-8f37-408002de0b81" ,
"value" : "https://www.virustotal.com/file/a9a8dc4ae77b1282f0c8bdebd2643458fc1ceb3145db4e30120dd81676ff9b61/analysis/1461169271/"
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e881d-07c0-4197-8d83-4e35950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:45.000Z" ,
"modified" : "2016-06-01T07:00:45.000Z" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIABc4wUggXMvC9AIAAAAGAAAgABwAMTViMjQzZDJkMDY1NmNhYWIwNjE3MWQyMjc1NTU2NTZVVAkAAx2ITlcdiE5XdXgLAAEEIQAAAAQhAAAAw9xcbaE0Wc7HkOnXp/uz8xXecvBvtGdmIz95GRItW6+HGGoNYiLhH2o0/0eoV7a99TwVgWaIRglv1oQXSNM2898P0mFoO18dtxvf6mv6z46JbrkAjbZGav2bFV/t+/1Vk2k+iQX8JRTuw8K1a7sFRXGinKy66z4bkwRO4yea9DNfwns/uwnXWzFOB4Nd67mNVFfAoTrpIa+L0JwyE8pO7E+gAMUaRM83s8njw6oZ1m0P/qIwRYdOctygT5jlyZsrlZzqa3JxgMcIAP74fg7/4ArdpUuRvyMVtIzkMA8fjB+ZTGjxAWcW7wM8+zWZI+jprl/2ji9mDZG1QkmJQIQFQDwEgEHSCznKfROCaXHkLMiiqX7tLGeE0I/iv3FRcxvJxkOfVXaCSjXZSoIp8z7YXoqE8rYX032kb+wNujrA3WcrbtKa5XQnkqTidK3adLIP6DN3+5/sue/pbmpsOZR5kc2+1Ig1cryYb5c2iPkg1orl6JphuXuJp/+YYUxaJZeKcx+f4OwwbOtlExCtXl+5ZzmpGyxQsT5Z6i298sHbfeO87U5nWAXDS5RidW9Lxub/1UdRNJQ/pG22/9AmyLF9g9QShSi48F/k3X6lPf1gsXgD1HEJV72GThHVJVfDBpcB57yXi9AinqNyMrhBIm1prXARURtMtnCNUKlseim1VFs+l6qvVAeoP/8PUmCRqEPwcAB8eSwFYZgxiFXoId3p5ZQiosvx2PTZGpPiktWUv6aDxKDF0qOdHFxuVtjwyyyRZFHaQdqmlzvVe4Q2h3rbSvAddt5SYfp2rSX2VaeN/9q+kW+OY+Du+XIUHSeuDOA2N0wL3ZwthXj/nqByhaxDeVNXk9j1Qy/EpOfDddY8qO6VWJ9SR/jvzty9Z3tnmlOBZNoWo4tIfus0iVvSy9Btm8Lklx8l2ly39Aw/gJu8Ra7+J4VE1UbfvBKGnA54RAnc5YolgOeUABmsFrHpkoHkxaJN3ByqVFT7wfsZf8cgXBQCOdd4UEsHCCBcy8L0AgAAAAYAAFBLAwQKAAkAAAAXOMFIQ7Dq/ScAAAAbAAAALQAcADE1YjI0M2QyZDA2NTZjYWFiMDYxNzFkMjI3NTU1NjU2LmZpbGVuYW1lLnR4dFVUCQADHYhOVx2ITld1eAsAAQQhAAAABCEAAABhq+9lJiRdLo80ZfHW642sB7+2wqEp3ezXO/DK1OqcH1C4ADu/mB1QSwcIQ7Dq/ScAAAAbAAAAUEsBAh4DFAAJAAgAFzjBSCBcy8L0AgAAAAYAACAAGAAAAAAAAAAAAKSBAAAAADE1YjI0M2QyZDA2NTZjYWFiMDYxNzFkMjI3NTU1NjU2VVQFAAMdiE5XdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAAFzjBSEOw6v0nAAAAGwAAAC0AGAAAAAAAAQAAAKSBXgMAADE1YjI0M2QyZDA2NTZjYWFiMDYxNzFkMjI3NTU1NjU2LmZpbGVuYW1lLnR4dFVUBQADHYhOV3V4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAAD8AwAAAAA=' AND file:name = 'verifier_win7_encrypted.bin' AND file:hashes.MD5 = '15b243d2d0656caab06171d227555656' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:45Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e881e-0e40-4d3d-80b6-4b34950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:46.000Z" ,
"modified" : "2016-06-01T07:00:46.000Z" ,
"pattern" : "[file:name = 'verifier_win7_encrypted.bin' AND file:hashes.SHA1 = '441f067512cceac809eb50cb8639050d7231787c']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:46Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e881e-d238-42e4-baa7-4da9950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:46.000Z" ,
"modified" : "2016-06-01T07:00:46.000Z" ,
"pattern" : "[file:name = 'verifier_win7_encrypted.bin' AND file:hashes.SHA256 = '9e36d2f6e0a3ac8af2cfe28fc8a7310eb5ee0a5e5ba5d74e5b130220dd70bfc4']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:46Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e881e-1168-4207-919d-405b950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:46.000Z" ,
"modified" : "2016-06-01T07:00:46.000Z" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIABc4wUgDVJyU9gIAAAAGAAAgABwAN2NmOWM0MzUyNGMzODY0YzlmNzQwODljZjA4YjhiZDVVVAkAAx6ITlceiE5XdXgLAAEEIQAAAAQhAAAAw9xcbaE0Wc7HkOnXp/uBJnumEhucqtXSnFfRgK8u3COVW2Z7aP5eJo8B8HZjsfIBeJTX4rfP7Hc0SEiHb+tNvtZUYl9cx8lU8nTiWD6FOFddNvr/2ZV7AmzTwZFDZ87hf/7J7yu7YU27dJ8DGblfFdycDL74bK/OuBLjcUIMlvcoGIL3ZJv9o39nubBAWw2S6rz8sv69zxQZkYEwqK10kcHv4DTzcFLn3wW3j36nLCwffSU2y9r3hO7n1OcNPzOuM2h0OddWv0NiaaN/J3Jck4GcRIngFdZffFREAu5AsvD0kEKptQDXyfPEPy6CfRPIz/XYTc8AObq+6iLPAwUOmw8KGKGxyM343D3Sci/6FQPOTqC0FOziaobKqJ6mqNUCpe8QZoWpcLC4kI/55CKIgXWzo7UW8wC1OJidvJILuJMy7cQimf11X790RpxAXdLIaJBRzHYSVhrbY5lXgcs9Kkg00xTBHc2PFsn0S4nAlXeo4M/75PULagUME6Q+agsUX3Gyck3w1EnXJQQgU5P48OLzO4IK0jipJxAoc1e62TgK+461FhtXohaRX5asklfOI6G6P0On4OoceIHLZXgzzxB4Np0lInZrncHqeXqElwCn6dR93/2VPZ/Hup+pHi7yIRaI1uhRZpxEZhPCUJ1Di36gNDT194oVJrZ6KZ+7GxSkHvaDbFD6O8lkvXs44dn7wnBaIBOvs3q0AXuo2Rtceqzq7R2gCOsHdTdHJXH6qDNtMIL6mch1dJbyw725+R8K9ndVA1iLql/XAWYYLVsxzpm7IlaAQVLnDlZy79m5mQ8rmxQxa4mILiGCfX8+AiBXFhh+IACYKbkyQn1fTk3KhDzj/9ysV3tp53uwMZ5nHvT+yBbxxea8zTzO5e8mn6AQDc7KlyedbxrI0YKJK2fOTXlp9qJAf6HjZagVuNr8dHTjxVTmv3ey6h+8hCTiY03OBaD88jTQ/jI5qi9Wh74UUrFL1APF+MTyf1TW/dsgoPbyCaPY3J9QSwcIA1SclPYCAAAABgAAUEsDBAoACQAAABc4wUjIze5RJwAAABsAAAAtABwAN2NmOWM0MzUyNGMzODY0YzlmNzQwODljZjA4YjhiZDUuZmlsZW5hbWUudHh0VVQJAAMeiE5XHohOV3V4CwABBCEAAAAEIQAAAGGr72UmJF0ujzRl8dbrjawHv7bCoSnd7Nc78b3XWkXz9LCcjSnuYVBLBwjIze5RJwAAABsAAABQSwECHgMUAAkACAAXOMFIA1SclPYCAAAABgAAIAAYAAAAAAAAAAAApIEAAAAAN2NmOWM0MzUyNGMzODY0YzlmNzQwODljZjA4YjhiZDVVVAUAAx6ITld1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAAAXOMFIyM3uUScAAAAbAAAALQAYAAAAAAABAAAApIFgAwAAN2NmOWM0MzUyNGMzODY0YzlmNzQwODljZjA4YjhiZDUuZmlsZW5hbWUudHh0VVQFAAMeiE5XdXgLAAEEIQAAAAQhAAAAUEsFBgAAAAACAAIA2QAAAP4DAAAAAA==' AND file:name = 'verifier_win7_decrypted.bin' AND file:hashes.MD5 = '7cf9c43524c3864c9f74089cf08b8bd5' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:46Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e881f-a00c-4d63-a9f6-4116950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:47.000Z" ,
"modified" : "2016-06-01T07:00:47.000Z" ,
"pattern" : "[file:name = 'verifier_win7_decrypted.bin' AND file:hashes.SHA1 = '82a0ed1de3aac4e9aea4342719b98beb6655e087']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e881f-a23c-4400-9039-413c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:47.000Z" ,
"modified" : "2016-06-01T07:00:47.000Z" ,
"pattern" : "[file:name = 'verifier_win7_decrypted.bin' AND file:hashes.SHA256 = '590c202719f42138a13aee4588f7ec004eae56b79f5a8f6a918593e552f51aa5']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e881f-50c0-4cc4-b7c2-4c5b950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:47.000Z" ,
"modified" : "2016-06-01T07:00:47.000Z" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIABg4wUgfQLJk/AIAAAAGAAAgABwAMGQwNzZhMGJlMTk2ZDM0NDE2MjdhOThiNzNkMjFhZmFVVAkAAx+ITlcfiE5XdXgLAAEEIQAAAAQhAAAA0+pbkjbsxVwi2yGBzIBGKH2dmIBW1VCVYfUcqj4OyiXL+iII81D+49vSylzXXaStJiK30rG6msbDdwnsIUlyHPe1Ojlt4oEKmbdoUEyBiRugB0trL0c438p8JEDRXYp5grc1JaxzjhSrgVatQwWAp0BcpdgzAkzlHVZxkbfAEbvcm1XXksKZNuviYzzb9nvGg1xcRDCZOB7KOoo5Y7f+pgOTx8W41YmjnjVcVPMJ+S6NpsxpHJLqGCumf7TnXQ/TrHoRZAlRW9Rg2Xij3ZLdSO7yI1cs98dEvA7qBK3DywlnSlh9FuGR3mKryb2wBUV7dYPRVyOwoHGTFwkzDDinSvqtaEjk83mbGBspX3QbgXmGTSumYn+5SnV1BnvPluvv/ED1kGpwm3msfQUbtAyJOaJo98BfBQijeF7oWTFx/sJPTeSl1qjNa5UD0k97++/qElw4FcoIZaJLn2GIvax7iWm1apTFN0wVlwPG3mJPGk5jV+34ohzsboAIL+fgYnbV8cIUBAUre07SmbfI3xVTpp+qpjJFGTIHVSeGzUPBM6d5PCDnZerRzK//DpyyItJLR1viaBj5kVLvYhoLlr+DGKeydlHs3UUs9rm1vP8zkeY5SUU8TaLZ6gXspUAL23qUsUQFm3S5yWACYMUSJ3GGrXLVPHmQLSLoBR1Bj+o7anAoiEBlgTYyAOaRkaoiDd71VQX3fEy2Uqq/eVBBDp53biNR2KMNbEOhtu9YIKgZZswg2ByYfqLXjjcjhTtolVu+Cl8EmkAp40ergup+t9TK/ZYoKBtzPH5l1zK8zbgkWoyrDWGFT0bdbIs74+JpUVwtyR+ASxJsWx6D5FlZYBNlPBhXbhiRpQJOpdSkzuc8qfTeMMsGixpXDRGoG0voofg0oSQsT6vOq+90RUNlzU/rrrKwcFP60hvd8525bMsaDMtxgmXYKY8VR5M3Na2G7sykj2qR7NswP6jWILWUM1ykfFFxdvlDHfMrdqi8p18GyAhDpy+1BbFk4+ahkm5QSwcIH0CyZPwCAAAABgAAUEsDBAoACQAAABg4wUh5VJHnKAAAABwAAAAtABwAMGQwNzZhMGJlMTk2ZDM0NDE2MjdhOThiNzNkMjFhZmEuZmlsZW5hbWUudHh0VVQJAAMfiE5XH4hOV3V4CwABBCEAAAAEIQAAAC+T27l8ktqTCnr8hMu9tu2SGpl7J7GPOlK9WwdHr1JzmF9QiYY0ncNQSwcIeVSR5ygAAAAcAAAAUEsBAh4DFAAJAAgAGDjBSB9AsmT8AgAAAAYAACAAGAAAAAAAAAAAAKSBAAAAADBkMDc2YTBiZTE5NmQzNDQxNjI3YTk4YjczZDIxYWZhVVQFAAMfiE5XdXgLAAEEIQAAAAQhAAAAUEsBAh4DCgAJAAAAGDjBSHlUkecoAAAAHAAAAC0AGAAAAAAAAQAAAKSBZgMAADBkMDc2YTBiZTE5NmQzNDQxNjI3YTk4YjczZDIxYWZhLmZpbGVuYW1lLnR4dFVUBQADH4hOV3V4CwABBCEAAAAEIQAAAFBLBQYAAAAAAgACANkAAAAFBAAAAAA=' AND file:name = 'verifier_win10_encrypted.bin' AND file:hashes.MD5 = '0d076a0be196d3441627a98b73d21afa' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e881f-2f2c-44f9-af16-4534950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:47.000Z" ,
"modified" : "2016-06-01T07:00:47.000Z" ,
"pattern" : "[file:name = 'verifier_win10_encrypted.bin' AND file:hashes.SHA1 = '07371beb2b4634b2ea0262df30abb72b50bea8c8']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:47Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8820-9428-491d-a58e-4782950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:48.000Z" ,
"modified" : "2016-06-01T07:00:48.000Z" ,
"pattern" : "[file:name = 'verifier_win10_encrypted.bin' AND file:hashes.SHA256 = '3f2e2b0b1611360b5d96bf493bba2710b53afa71729bb4597c9628e458359901']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8820-60b0-4003-8c7e-4476950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:48.000Z" ,
"modified" : "2016-06-01T07:00:48.000Z" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIABg4wUg8SOUy/QIAAAAGAAAgABwAYmUyMTBiMTZmMWY2ZGQzMDc5NmE1OWVhY2Q2ZjZiMGJVVAkAAyCITlcgiE5XdXgLAAEEIQAAAAQhAAAAYRbgbx+dMDaNbLAvOrBt3FCXhpHHs4ilNlvFrxsbZMBWoNGF767yu2MR1NC7mL/jjAdKgJnBFWxs1exVcdFOlPbcg0jPdM+sfRPAP4BLMYA6QL6L7gidpRuFRqqvZx3VOFnaDv0aHLvFJPCTR2qk4byvL0tAcNPgev8vtTINdRsv4PaYCTBxu91NX4YOLlNe2sc2HOFURBDS4h/1g7ri6IXxr3Wy7F2qj6DUuKTQ5npytyZ3VOVaLVKmcvIyJYz9A6msYkzYVM1MEq51eSjjWSWyAlIGuZUgS3UbByG91kQwdJUMRT9eTIaIJoMgzWBJ6xPXgLyWHzTapid6+XxreaIiDbFydL8n7GEyMaZPCIkGvWUM5EAjbcmVoj7vwBeaNn1BIT8WCxgnOv7D7EhAIF5YTkZ8p2UdO6Zfiq1i569uXgEzyyfmtKpugaJ3LudPoKugMy0GpY7Rsvf6raFNfEdy7domsm9Dshe++fOJFoRF5BEf80I5qA5hmJTya0hoUo36kJ18IEQrd3znktIO3p9RrQyFO+LNSemaBS57EqRHn8bQ/m4yPmOYeJK0MPONtpCasctQYTgHwiwARPJXK895PRQr1kzTvOm4lwrYTzj8LEX/+DBPJ02JQvnJ5wJBQMYCaVV0BSdffFqLz/GO4QdNNQ3kTMTx3FwkFprN+QJXS9yJvEJJ3cjDWZVHflr2HhfK4Z+w4HDIGWojiM8c/pMFJShHLwsJ4K3cdgfHaomNe9WNe7Hr0pzv1TLa4+Fl6bpBS23xSju4CpCH9Jr4KyaBjNDSK6jpkSD2zMFDQknA8rS/jHNjuASSgKoiSLDDM94V8lxdpLlujObRF+GDzcybzVWT8ZMQQzIMKd3iBs26CIJyzTFFMGNyE6OBeLR1D0a5gReWWxLQg3dtY4Wy735l7Q8g8hBF9TZKC9avi3nrYBPyw3mGt/itAYSJ+9UOnltp48+kHGNMqvDO8OzrRF5blkmmIhZIv1Q0sme9GBJkDWHPA4iMSZmQgWBUUEsHCDxI5TL9AgAAAAYAAFBLAwQKAAkAAAAYOMFI8imVSygAAAAcAAAALQAcAGJlMjEwYjE2ZjFmNmRkMzA3OTZhNTllYWNkNmY2YjBiLmZpbGVuYW1lLnR4dFVUCQADIIhOVyCITld1eAsAAQQhAAAABCEAAACRN77bb7lGGsZdDg+H5+cCcGNEZMv8RxQX9rxH7g4ANr/4Sl0T54n4UEsHCPIplUsoAAAAHAAAAFBLAQIeAxQACQAIABg4wUg8SOUy/QIAAAAGAAAgABgAAAAAAAAAAACkgQAAAABiZTIxMGIxNmYxZjZkZDMwNzk2YTU5ZWFjZDZmNmIwYlVUBQADIIhOV3V4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAABg4wUjyKZVLKAAAABwAAAAtABgAAAAAAAEAAACkgWcDAABiZTIxMGIxNmYxZjZkZDMwNzk2YTU5ZWFjZDZmNmIwYi5maWxlbmFtZS50eHRVVAUAAyCITld1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAABgQAAAAA' AND file:name = 'verifier_win10_decrypted.bin' AND file:hashes.MD5 = 'be210b16f1f6dd30796a59eacd6f6b0b' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8820-f5ac-47ed-8444-4534950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:48.000Z" ,
"modified" : "2016-06-01T07:00:48.000Z" ,
"pattern" : "[file:name = 'verifier_win10_decrypted.bin' AND file:hashes.SHA1 = 'd6fcdb19448be5e75ee7a715f174c1325c915051']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:48Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8821-bfd4-40e1-9cda-4d45950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:49.000Z" ,
"modified" : "2016-06-01T07:00:49.000Z" ,
"pattern" : "[file:name = 'verifier_win10_decrypted.bin' AND file:hashes.SHA256 = '3215e61bf465e0d584a11ba9bb3b7046a2829f22db7216b46e217e27af11e803']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:49Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8821-2384-4449-bd73-4af7950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:49.000Z" ,
"modified" : "2016-06-01T07:00:49.000Z" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A B k 4 w U h 88 k u 1 q 2 w A A A D w A A A g A B w A N z Z l M W U 0 M j k 4 O G J l Z m J m M T N i N G Y 5 M z Q 2 M D Q y M D Y y N T B V V A k A A y G I T l c h i E 5 X d X g L A A E E I Q A A A A Q h A A A A g j a + 0 X 6 i 0 d x q I R H 2 G q o i + I e x F f 0 8 L J 1 E s y p Q f h l x C a 7 / D d 5 M C X N X Z z 4 p R H C 6 Z N F A V d 3 r 3 A s G + M f L h f r s g d T n h y N 77 D 8 G z v Q N i A D 7 I G 2 t s a O N I z k e 9 K F s x 7 h q k C L Q J g S / v Y K y v 0 L T R g d n T H e 4 G 7 i w A K j 3 K H u M r J d E o L p O p z s u 5 L g q 2 + G D B K P L 0 r 0 72 t D 4 Y w Q d C 6 F W y c D J g 7 d J q 8 W / h 852 a u A d + S x 3 z 12 u j h Q v i d + c X I Z h B X J d i 8 B k c x Q x q 8 F y e Z s j 7 F e e Y 8 u 0 S b a a i e 7 e K t k / w / l J M 7 V f w y 4 u g W c 96 Y u U T 4 C 5 J W H w g g u 7 N L u E H L u D a e d z U A f 8 n 8 H J y p k L f D h 8 T 9 m 43 s v c D q z v E 9 r 69 l s J Q W 0 i J w q 0 e u I / i M C w k r I e 18 U 6 x w v k T P M 0 A S H 5 / m z 9 X d K G 2 L s f q b Z p m q o S G P R f Q J V 9 k f a 5 o i p 6 J 4 R W C w T W K j b Z r 73 g e E x u 12 d f O o N 7 c K R p 3 M d o l X I V 6 B t I 2 M 1 s 3 m h 9 s Z J i L 60 r L x q U y I Y 6 + 2 E m s / j s Y u g m 4 g m i M M W n q D b p N 6 W v p z i T H F h Z n O V I O v a 80 J 94 i 8 e y N A J j q D J B C v W s w W z M o x c D M P e u 9 V t Z h g L / 9 k e l j p Y o H E T R N + F x n t W y L d l p I x z s b Z n P l M O V P L 7 i O j t 3 e O E 7 B a h 0 y 7 V 1 w k U U s Y F z K s q P s h e 1 d m V c Q d H b w M d Z i u g Q 9 s e E P I y B 0 z 0 A 70 E F n w S 8 p M M E 22 V x X e 4 L B 13 O c a s X t N C o x X r 22 h A R 5 i d S f W z U n E T Y M Q T J 5 H K s 0 5 / G l o w D D D / 4 q a 4 q 7 E t h Q 1 O 0 r n c N C S N Y o e u x U L s u v G E 2 M q m O r z 97 I L u 3 y v E T i 3 T V i 0 q V 5 a / K 5 E S n 9 W V X O S w c L E N c m p z i o G x n H q g 0 L P g M j E O m 5 k e m 2 t I L t M X B W K l 5 x n S Q N 2 k U q 4 D o p 5 S w 6 r n d 8 b Y j o u / 9 K a 2 p j s r n n T A N Z y c a x 7 Q t G y l A H W X + I j O 6 n a I v / N J u i B G N 6 b J h q m + T h H 1 v C X W f q V I x o J t X I / 5 e / 2 M 4 e H 13 h I g i Y e L i T 2 i h H n U + q N u j 1 G i h c O l 7 Q v + o + Q V N p O U R Y 18 u l y J i g J / a n W U C r 20 F / d X w Q X W x 9 w n O M h b Q Q U O 8 g 8 q n 0 o A 5 j l G x + e k k z m 9 q 8 X / 2 i R M n 9 P a K d E 8 g 7 M j I l v G f 8 Z 1 h 6 Y f u Z P t A w P 7 I B R Z C C 1 D J Y 1 Z m k w W x + u 4 U Z p G w E H + X n M q a L c x H T t 3 h n w l q D 6 A z d g 0 Q M W K b j I J r g v N / + 7 e Z Y s j T H J O 8 t X e A z N u m 26 n E R 7 m E / a g e n g J R n H u w Y c f y a K k s 2 / l 560 u w H t B 9 j z / h 7 w S C D Z 96 u q d 5 Y X K 6 b P 5 O M 3 c c l 4 x g 186 Z w 53 P p V 5 y k X c x 9 C g E P 7 Z 5 p M e v T G F U 7 p Y g 1 j X / X B I t C j m J O D X l Q t F t F K E / R y B e r 8 D C g f R d f g y 9 j p o o B R T 2 K V f r 2 x Y K w Q P L 9 N 3 q 67 g 5 o f F x O A k / G L A 4 K J i u B d 8 H / e O G K r S 81 G F 7 t D 4 F s x e M c u h b N V u f l I K b y 0 L K 6 c w 1 k 188 B E n h P h w 33 O a e E h + u C E t 4 P Y m 5 e V m Y E t I 60 m x O x h T u v x w g V i A z p H S c i H A f D b P 1 p I J e H A + N E 4 b 4 u r 7 b 2 Q c 0 5 c U 0 n i F F 6 m k 9 z 5 p + 8 y U j E O P F H 81 L Y U d a b 0 K t V L Q r l 8 k Y / Z a n 4 + P M f w B I 0 G S I J K z y + + 9 f E o n o g L R C a m x K i X k p 39 D Z c r a f W H r c 4 E F r 2 s A k x 6 Y 4 h p 7 A 5 y E 0 G o T + b r F m C i 3 N x p J R e S 3 e / j F C 6 q a m l Q y h 4 i T y k Z 4 t L q u 3e9 n E Z C Y L k v B I m t C N 0 F l Q P 6 P h e 8 j V p F 8 l D B / e X 9 g v c U / A m h k W 6 W x a I X A R y 7 r 3 z m Z G X e t E 2 T Y 4 S u c 3 p 1 H 4 F o H s S p w y M c t G 3 T n J 9 N X n z 6 C 1 e g t 5 I Q v 3 l J 2 V O 5 V + v V m m 740 G N n A S 77 g B f a d 5 E r L U F M M I u c c d 0 w Q Q 3 P 5 + p t N + f D H T i V u 2 A 70 L K I 3 L K H e 0 5 A Z l e K m F 2 w j 61 s X a e Z 0 s b j g M L U H 2 t O / V K g X Z p 3 F x S W 8 Z X E y w b P / s Y e I K g 325 / a S R Y d T I U N 9 C A W y i v t a s v B T T x j g y F W K 9 H K J 7 h K 1 C a Y y E b O i M G 1 y K v u J + z X y 6 M e 8 I 13 f 9 m o p d q q Z V N W L V C Q 6 Y G a y A Q c D F o K W V G u D 56 p M S P p F D h I n 4 y R 67 O M S U d e o s i + f q x a G k q e w S f J t o T H p J R c X 2 y 8 L d V 1 / W b D U t 0 R 23 n F j C / Q J 5 f I T R a P R D j l M D r o Q B d M B F Q b R p u r g d Y j Y D B a r j j y w f w J O q m X + a k G U X h l w V X 5 R H K d 5 p Y c q X L / b F C T r q S G L 5 U c G g g + E d f A n Q e y h U H c A a X 8 T c H y T + Z 0 Z a t R h 1 x p S 9 C B q p T F V + 56 z Q I X v f 2 u n Q s h i v e F x z a b F k 9 a t d O F k 9 m v A n D t W 6 G Q q f 8 h a / 70 r c V R x z K / O m M c X T G T z W q Q j o u Q / 5 Y W k j o w Y X U + I J i G F R U D a s f a G E 5 n p O z j 5 p X H v i m j F d N Y 4 g U m k T E z 52 S z S r i A h i f X y a + z r n b / D i t N i f U 4 S U r Q 5 C H d 8 r F F B t m J t 5 A r 3 y 4 e C o y g s 9 G 3 S 386 I H 9 W k m v u x w u + k c C Y o s L l g o D O m I X N G 0 w E s s 46 o y e U m y 3 Q I 0 6 + A 0 G + f w T Z i J M U + d P g / 9 s k p m a Z T A Z X 9 O Z A g S o D S a 8 e x x M 0 D H r 8 g F n I O L 9 z H A q 4 f P k 3 / W t o 3 X y e v m P g V R I w 89 X 7 e S B B N p f a 7 + 4 d H T f T a Y 0 v I B + P f k 37 I s / D C N C C J n w R J 9 l 7 Q L P P u l p x 0 + t L u K g L O z s g C b L L n r d / G L g M r h s O E e 1 R v B V m 7 c g 1 m k Z V U 5 A m O f u y S 1 D t S l 9 d 1 h M 8 D 2 P Y z C f 7 r 0 j k a H g R 1 z q n / P 7 d a B Z D s 0 8 d d X f z R v L 8 Y v S b h a P z E r Z z 0 M t q o x 7 M U M k x e Y U / b N K b 5 X R N N A t W s Y k 3 f t y U k a 9 X / V u 7 z P r U H a k 4 Q s 1 w a z r h 17 z x N r L 3 W j n E J 7 Y I o J y 19 U 0 9 E a U c q F S 5 m 8 E M b g 6 t 2 y L v f Q M 1 V + 6 F L K m H L z 5 K 0 A C P c j 1 X G R 2 X u I 8 t u / k O J R a e g O / 3 i 8 W g A N / 8 R R J 4 / z t A C N d 1 f K K b y h K E 4 T / H n F / x P t 5 a g w I O m 8 R T s u n C g d D 5 d 83 b C E E t H 5 + f S 5 z I i 89 b J j k 107 c n A P / N e a 7 R h v x 1 N D e k C K S Q x x l 5e7 u M D f / 9 f K p n N j 7 q Q k / l X L 7 I U 4 R w K q n l G F h y F x t I 1 B N / + C 5 u b T f r u i T x 2 y h 9 o G 9 o 3 U y l B B l p J l 1 C e F F e 2 Z J i i 76 d B 7 d 80 L P q 7 / z g b x U H U / 1 y x 8 x h 5 C c 5 H i e e 0 G / 8 q A C D r Q V i 9 D n i 2 a f + E J P u e / l P U t e 10 o H e B W 7 K B g u w 3 / R 3 Q 99 W Z T f q b l o K 0 / 62 b 5 r 5 d j W P 6 k p i J E D M 0 I s c T W K H r N f H x o s u k 1 o D s o 76 X z T d 7 h R I / R 3 Z D 9 J W Y o Z 44 Y D H k l j w S 1 h s t b 87 M G 2 T j q 3 m N p 0 r u v I Z T 4 q A p e s N G Q 3 k d v A 2 F r i P i v e M d r + W A e O o k n t t 7 A / O C z l b c 8 p 9 J S j Y F M + P 52 k D z E t u y 7 L k l u o u I 17 c e A L D c 2 V + + L M U s Z q P 4 r z 0 S g I E n k n 7 S d / U 6 n r 5 I m D q d p U X / b X W e 5 B W K u o x K Z x 9 S 9 w E Z 2 w r N U N G g g X Y E g r Q g K S H R L p G f N 1 D S f d U d 2 j J b j Z u t m V b / g H l 4 + D 7 I 8 x F s M D m N S Z K x T f Y 4 B D 5 q C V Q 5 Y g 9 Q h Z c p 9 + W 37 D H P X L F w F 5 Y b 5 M l E a C w Y p x U K W z F Y k i W w o i M z I X V E O z a X A l J 4 r 6 e N b E J g 2 a q o 1 t 5 B n e k c h p 8 G l G M V d 1 t U H 18 g r R F c u e M 2 t Y r f m z k o 47 / j e 3 o t L g 0 s 1 w B N Z T 9 F h c 5 h L l / L J B c 2 Y 9363 h x P q m a u 4 R X i H R 12 Y 6 f a J Z w n y n p E y 8 B K + l 8 g F r q O l J c i / i B 2 i S H + 0 o G b I F P M o Z g 42 / c O x 75 x K Z G k s 9 Q 81 T t 0 J p 9 O y 0 1 G E 41 b R / b a s H Z 3 L k / D 0 Z h 7 I 0 j 9 B o L J e 1 k 6 c 50 h V Z E J f h d 0 y s 77 R b 739 e i J j u s m F T 7 S X T h U J T E 7 d t 1 E p t 3 T Y D o X 3 C K F p 5 f + p D 50 Q S 7 U Z p F J t F t T K 3 / I k D 61 U y X 2 C R 5 l T t 0 l 2 S Z C 1 J C C e o / M 8 p H n r / + x D k 0 s Y J t Z p 5 R Y 6 J r l 0 d n 4 k Z 7 y C X K L S w L b 2 g q + T E J Y q Z L p w c o C e d 43 s Y 9 + z W U 2 Y 9 Q K a B 5 j C 4 g
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:49Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8821-3788-4fdc-98fd-4507950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:49.000Z" ,
"modified" : "2016-06-01T07:00:49.000Z" ,
"pattern" : "[file:name = 'rkimage_encrypted.bin' AND file:hashes.SHA1 = 'aaf677acc05ae94f98f836fb44fd672a4b2d90db']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:49Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8822-b0b8-4467-8780-4b73950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:50.000Z" ,
"modified" : "2016-06-01T07:00:50.000Z" ,
"pattern" : "[file:name = 'rkimage_encrypted.bin' AND file:hashes.SHA256 = 'a8e1709a70094b50f8e1812d25a85227159778878980b9dc52c251a052555757']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:50Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8822-55ec-4440-accc-49f6950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:50.000Z" ,
"modified" : "2016-06-01T07:00:50.000Z" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A B k 4 w U i 6 X B J o r W w A A A D w A A A g A B w A N j E z Z m Q x O W Q w Y W J j M 2 Q w M T h l Y W Q 1 M m F m Y W J k N T l m Z W N V V A k A A y K I T l c i i E 5 X d X g L A A E E I Q A A A A Q h A A A A I t d + e j 0 3 h G D q 0 G o 5 J 2 T v 5 S j 50 j K Z 4 f + 5 F l x c f f v y + s q x j E v f 54 R k O Y R m N y a l P N 7 z q 6 I m q K l w 8 E F //ti8vPkpLbqu7pwjIh6q36imj+ixb/iWYBcncpSqClpqxpB/8z+/+T4L3V+Puu6hejabygoPH+MtYPHZW4SGSarh3n1OqIXOSRXtorciFaTBC/N85IGdbVwrZyW3Ye8uk4sIwmeykYjujcum1OJWpnqYi19zm4sNYuZIYDA94coH5oi5VETU6eodwd4DgOvTAcUjc1p6hg09TTY2uLrElZ+QE0jzJ2nekWURUgRHBi0WAnoAPg0aqFU7L9b4uJuFCLEjLGaSsT6cDXA0+mCxWAHlSrCQySnY+kO8n+GtpC7/OvNXWdRaVEIGBTzBmBF7G8PXoIMGAukfO3dTvSDYW+ZQKz5K8YSIuzpza870RL8PuKgV8sdxi/T/zDh28rN/IEsc5V8+F+Lm4Jw5kv/ty8/YAev9qswxlrxQ7KX90nvkzYVsKSElnBdbLIfkFkCHFewPtYSImkR9PEcoYb0GivZyQl1Kyl1dK2bDQJwF7xsXUFqjoz6AlE8aCcNTo96A1F5NG5HOc6yA3GflR1yKJwQq8y3dMTNzxffqb4K4ZczRjOMMKLDBKrzTByTQk4peS/fx00x9dqxlRnnfDoDa55ov4zcMHOz1x0G3ZQfk6LkMAJrjbYM64vimcuff/RaVe6E+RlhV58zfj2ETs7yxP6BkDXrl/peAoPAdleECsyyrNIpL2EkwbyC01DjAxlMgJm9Sw6sJ9UkBKazPgnvHHPvMqL+1Fq3mGPr/wTDogUj9f91URiC64sqcJDEErqhdfdEfiIU8XuxQK8lIb40y27QFKlP+mSzCIrZSkp9UEnmi91ohRotZVJ3knDh64+5zn1zpJBNCc2D2ZL/Z+GqVmwHUb+HhoPXioOhoPNVq+9wNgsmU1yfe9k0z787SaTohjQIxGZ47s0xl1GJ0M0KyDZDpyzWT4N9FlIyle9yQLvpwP5AFwpf2BtpLmObFsO+UN3MDy20+WrjDempz9JJCwKOvNPUjwwTmU2cxH5pcLTRWve1V4cA6HCVDtxi+O61EzY1ca6wYl0LKwOllI1AGa93nwZqfkg2HVhOWEOTWs3KDpEQBi1eDpp6KZVCU8t4/A/d61dkkIZP/qerCaNkGHL1515yJBcK2bAmTVaBHEF6mTxXXOtH6PkhlsxiuHzRHSeAQepyGRTn36rLkFYmMbCgoRc44lqq+yHHyS9yzf44ij+/lUpStYTNEZ8kdwsch84sxS/PJef6oQ3IVaipIsyDsfwWlxeiO6NKJ3nMhnC2ERBOwayfeV0E82VhXq4/iWjlb/DvwtimQ7i0VhCaF4IlJCBL0OI+c5fSu0db9jUmi+VEN0vFARI33xbrxU2FvfdHlvdItNOXV+vxNos8D/39cw8JbTaouLRD8NgBvJ8KGoWtUGUTdUfMAmcedjuO11IprAB/M8uDceSI19v0QDS6R1p9UQmXUJVBA7tYllGalZ0bMjcIgS5kP/7Bk2snR1GvQ0u7Nyj3WeNjiqJdnVLRcdgA7lxJQi6mAJ7bKcl4+OQdP6TFNNIDj8y2VhjjyG3qu7a7gBbt+gmrvRGiZvV2wNR9slW95dvN2Qbq9Sqbhx5PXL+fmBMJv2o130OxT1zd6BGbZDwExon6XtbSS5XYH4SiPDQl2Uq7oqJt4fapo/GB8pzXnGofe6skVP1uDavYKWuP1aauTObqj7zBYwUdpL5LVkScMUfcuEsCoWqeHAnMYOMFmPlJfpw50DSSPR1/wTPNeCBVcJ1koVHTats92mU/NhtE5JaAP0tkki7KslHxp57RPV4upjOF1jYL+rrwGQUflf0TVdQiRy4OLe1ychciHz1hqHdkmvcaRt5mw6unTwQnRu5NKc9uTwhmXBZOfe+Kb1P2hoGwztLxDgO4aMlt/FFje46NyfZIFxRoLFwuU3eIXQJS6gOzF1jLxUSFt5phFTm/BWptlK7qYot6BA6j+Og+iRdVoE/Ng3nSMaNXPtQairX4ez2e4M+Yrdj8QGjc3HshPEYaQFJBUvaXnBEGT8T01qWPvtZqEVcmQF006oCHXbKEOmLAfXMtdvKUpHb244M1CUGpQ+s6C64rV58XCkijGWgmFKMMdVhTnahJiW2uw/Ue35zAQ7AiOXSbssmC/ECkvS2aNo6brJw4Wk3VCOZHpvIZEx1WRlfhClLScxfkopAOGckoq3MDCk/HfhTn7xsI+moNEBcjPNIw0keflc9xHfZ5GSus7pqpb7rciWgPsVZ4IgCxJCRgxuYpPWq9582RurR86Ssmtn2/U/ZpbAA9mS7qQL8LbNKVmCCQp1x9rnzSsjmCkrvh91sKS+FHkTGS3oicmhMeemwiHoCeymWViChvGL0stNW+ZAYaSFOSwwS3NbHNtLs3H54FNFmgDT3M8g8q6hIv92991opvrAQIjcEZrsg2tvlgAjL2X3Bu8rdoulSLqZuFo/g2NxUuAi8rieWWeJYGihv+CcWDVNk+D3fcvgTWTw4s6Q6tc/cDDk6O07+sIKRGXfDE4bH/lIY8R/F09oCwgnr226iZzg/E/KsdolMwCEr2RtanYFbHoxcnmGyFOSzQFwggArB2bIJG5YVmRact+Sds0nWvZBB49FU6inavvHk725bVW0koLoZLuR4ca6kLa4TG41SGk1SVv7G/7E3YEhOAemjhK4Ze2m/3SUvQJDyZbmo4f0kM3xuRqm1pdN4sAeue/HNHmrnTsLtI2308rCAE4UxlYIwm58HKoREUNPZFaVwa/dmfY5mzDlSusmZD8edOyP/D9sMgbYDVxOcfWh5/lEJtVnSphP5OTetoBEy0wVxA6hjuUifJIKLMJkKBoTsLDp8NVZfXa2Srs2nWNiKEyA8Q5ARfdDHBgMkScta1wAPRcZfTwzYHMuXVX8TZhKXU4GDQX2P/vV+cwMXGh1pqD87DNOIM6T2doL1EpK3iAIiALkp5X/A3Tg9OAbKJ1/QSLXQuaUoC/nQqMx0oI9+kYIbA2JcvIqwBfZjTutRbo9PVMxPJpRY1dQjggsZ4gh1oI91NGJmcP+N4kNHRrzJX/RgPAKrmgVm0Uh7rdsTFZFwc7x3A73NMw7PaeGr74CA7q79ncpePypPSlcVhXbuzvzfTqCrhTKqT5/W2Ywz6LEsfIW1j1tZSmZvamrhI5kenlefH5Eq7Yc3LRf2gZIV0ZHJr7si3Aacw0dbs9ymS5wZ6oea5VtJ7eaZYnYn2k4zOcsnjYkfccgeyGEYmG7SB/JC8pcorE6Q9x/7vhR7xoo/lXvCHIcsvoFDC2GsMY8f/MkLcR3ZESfZzPNJrcAPLwTAlrvwyKXpoZI0F62ayVQwKk9NHgL6t/cXiBty5VonX7CsgF6Ah2piDfpHsm6VrtIGvrfW5T2ZzWSAB9YkE6j9YWtT7FbCroTZ4uISxfmlVxEPsfYEebwwIcLkQWxP+MrZvWBQ7NwUJBqtA5KDXZCZ+dhfmuk46I+LoEvGOG/YvWB9lYjdFqLt+k5HJ7l/rGFPL6Libp0oxiB/BOwC97Tg1sDrfi5NBqSXyHAKgEaMngCB2r7g4MIhDRoLMUGoMV3aYPttW80BKPImFdPPDFFDEgse+uTdGmiAhhc7gaOlYBFCq3bWaJ6EfbDRbXWicqxkShamSIaXnR2p53xZiq3mvfuLt4KJtXBDLBATFrsxw5+b6lpPaRzoYwr215YMMp+UvUr+Obhe89anH5N51RCk7y3dh2B+B5wdAEZx1ZztY6hHP0AaPWzIpiKpI2aejUPwmQ3ghxQcQrxwTUteAx0prTX3QFhjOsMq9mV8K5Ajlp53t8jL+cPfRNQk3pGY+82+StrcyamZlsUdwbR08YoH+VSFMogun8wol53d593Q
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:50Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8822-10c8-4e61-8c5b-401e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:50.000Z" ,
"modified" : "2016-06-01T07:00:50.000Z" ,
"pattern" : "[file:name = 'rkimage_decrypted.bin' AND file:hashes.SHA1 = '3c22ef94a737484e2f708393dcbabdfdb9d6cfbc']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:50Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8823-764c-4d95-bd5b-4770950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:51.000Z" ,
"modified" : "2016-06-01T07:00:51.000Z" ,
"pattern" : "[file:name = 'rkimage_decrypted.bin' AND file:hashes.SHA256 = 'd881fd3322ab1e4c83c6703c330c635d0fbb6cedc99cf6518dce865ab964fdc0']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:51Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8823-8ed4-4d44-90ef-4f76950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:51.000Z" ,
"modified" : "2016-06-01T07:00:51.000Z" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A B o 4 w U i 9 Z B u 8 V 9 s A A A A K A g A g A B w A Z D d m Y W E 5 Y j l j Y 2 I 2 M m U z O D I y M T U 3 Z D c 3 M W M w N z I 3 M G N V V A k A A y O I T l c j i E 5 X d X g L A A E E I Q A A A A Q h A A A A N c d i l J Y 6 h C D I W t o A C i J u A I W D t q J O 8 v Y D a z d p q 9 q K i 9 J 0 D E L S E 9 N g Z v 26 Y + C t H o 3 B g J 12 I E y A s D Q R t 46 q p V r r + J I 8 k O 0 I m 7 f E 5 h m b l Q S D I p D o m Z d p q v L V c h b Y p 24 j g E s w s C T L 0 g N T C w 5 X M h S K 4 k m K R 4 D t S v 1 g D U I 3 U 7 L S q X i p a b D O X q C 1 f g x c r r C o S S 94 c s t w d T 3 r T N x b K s o 2 r f C N x e 3 A G y E v G w t / Z O l A 6 + i q Y a N 7 Z S W 9 P 4 Y J J K R 7 j l s R R Z I 86 X x 5 j Z w a 74 m C K V j A v 0 P d z S D A + 4 t r V C d Q A P / T w 8 U b J d o U j c Y h H 1 f c f / 4 o u 7 / 8 u C B e o 1 S z M T 1 h L l J e U m d 2 p 5 q G K e e r s 9 m J Q k d F U A / u 8 B y 2 N v 7 q 30 v w l N 4 z 4 j I c S E D C Z C 1 H G u C 1 J 394 X 4 s 2 U p w w B h T c q 8 J H 5 L Q d T U F 30 S 7 b N v Y I d F A r K g / l U g v I F P 65 X r T U W X Y u R 3 x A 5 j 1 g y m A m B m v 5 y P 9 n I E 0 O G T O C l v R 4 x l z L K P F Y O Q e E g m V J b W Y 1 Q D S d I L j B 70 k L U 8 P Y 5 g j P S E l l A 1 w N 9 L / S J 9 u q / F / A h 83 U z Y r H 7 n b q n L 4 h r + L i T k N g m F 0 e e u X o 9 X w Y h R J V e k n 7 a M D h I n b C o 4 w G z 335 D H c k Y q Z l m z 1 x 3 b I L j X i F b 91 J P s 9 p k F U O V x / P M 15 k Y F K 9 + M d K 4 T + + 1 N N C a u r U P 8 H P 7 f w 0 r F P k i C F S E / a O P R i P g Z n V Z w O F d Y B C O 6 D M e n B H s z v f / l a M q U a P 2 i G u Z P + Q a K t 6 g m K X y Q m O I / 6 m H C C G o f l 4 a z c T X J D Y X d x i N b F h + A n + c O S I B Z h J v 6 g U M R e 7 g K q h L O J D s l q 61 X P Z q E U w 4 S 8 I 2 D F X i p F M X x N F l q 3 i h b R L h 6 w 5 M j + P 4 S G H 6 O S G 8 I f U w S h A v v D X y 8 a v d S B S T B 0 d e u m 55 N a T 2 I I X 7 N W P G 7 T W u I 9 / O X L u V z t D H K N q X f Y F 3 k K 5 / I z u s B G x u E F j t H S K M y H U A o B W J R X e 8 h S 9 S M 9 o y 60 t 3 R L r J o P 6 Z Q 79 i 3 p H h o m v N 12 d j H r M 9 k u C W 80 k L 14 K b c G H x 0 + N o D Q 2 i u E P B d O z k 2 P y x P + i 5 Q j d / + Y G U a k n f 6 V M W 7 v 2 l I c 7 L q v B 5 T W 95 + P W W e V i J e N h N d 8 E p u u O d 1 g U M 2 D 0 E G i F p 4 e o k + w 1 e a A o d o t T v d Z v z F k 8 u q 3 M x + 7 t 1 y o p m E l a Z e 69 C 9 O g E W S t x Y L a u O J 4 j u Z S z T Z V z K l R G + t z j q k p I 8 + O t S X X x s e O 9 A p r R 5 R g g I 3 K Z b H J 0 5 V j 1 x u c X a h M s 0 y I P C 0 B O c E 76 j Q K u l x g L E p f l 8 R h E T Y / 4 Z H M w e c q 0 Z F f + S C h K f a o v y V j V + D j o Y K 3 J 1 M M C 94 t L d 5 h s w v 5 z A 9 w k S p m Y x i Z 96 j d B f 17 z v m p Y M B d Q z a 6 v X k h m W 9 b r H J t 4 P 0 N z F 1 A u 7 j k K y w P N W u X B A n K c w S 92 P c 3 G / y v N 1 K 36 e e k Y t Q d m x v A 8 E S B T S d t P A D s a p a 0 O u e V a L V + B S g 7 m i 7 p J 2 p D O o v j C A F 6 b D M 2 V q 2 q 0 H q T W D A B z G R s b R u E x A 7 E j 8 n H N e c i B G S 6 w U L F e 2 + x y c r O h t a v 6 a a p u 9 b u Y 6 s i y 1 L 9 K d w o B 3 u Q L G K d s J 72 U 3 u R m h y F B 0 Q / 3 C x E u j 3 f V Y R A s M 4 h k U C 6 u 6 m 5 x p y M s h r H 50 F t j X B e T O E m 0 q T W V N 8 + a q h x o 3 p B H b N N 4 S P P L U o n s Y y U p L 2 L V Q E + u a 9 G O + m F + a G S G h u B E T v Z y / P G I t A A d Z l n t C W 5 g P N k I U c E F 2 J + t a f d u x d 79 W t U 7 O 2 i p U F u 3 z Q o 6 K V 9 h d n k w m l I k y w 2 H G d D u + B S t 6 H M / t f j u B R I o J 5 s v Z g l L P / u v Q 5 W w L T r 5 R m 5 e T r P q r M t n D I N f o S X 1 p z s + S H g K s T Y W G n Y k L R k L N t d 31 A l K L G D l p Q B j c Q l C M 4 t E 1 / e Q J M x a F w E W c M 6 E f d N 5 W o R b P 8 E B m Q F g b U r f y j M / 7 / x R M 8 N q O j F u K N d R h L H i E S x l + R E 2 J P m R S x B q M 4 X i 5 C j + T k V L t 5 N J T o T m V 56 F o 8 P n j 6 F z I x G n z 0 y u 8 d p W o P C r 8 D w q w a I A P l U y e e 2 R M A W A B Z i Q O K d B 1 h B B I x E j W 8 a / Z d i B P z h + 7 l V C b C T N r L w O l V b F F P u Q K E D r v e B P W v Q / + v s 47 m j U M t 3 G b L u + q l A C Y j E Q H J d h u 112 q i H u v D e g F t q y g Q 6 H m V 0 r C P Y n v D v y h 7 q I k 2 O L U x j Z y t G x Q U b 6 L U G 5 v L v i x q 280 V V 3 K c M + Z / t r I 4 a z G 7 W H 7 i h C 8 M v 8 U 1 p C + y t k M h J C U Q E s z 4 W Z Z Q I 4 x V j k H 1 j + M d C R Y t 2 M 3 D b A t P N q P O 7 o z 0 z 6 A V 2 / u R a y l T F L D Y F 3 i h Z J H X i K w Y M f t K L S P 9 p n a h 1 / w k B S r O R n b 7 O s 1 R I O S U C K y L Q g g C 0 S Q B Y W k Z F A r 9 G S e k x f + x m / Q 0 C T y 9 w 1 n S C G C G / B H G S E V o 0 V f A c S E w G j n f q 0 5 n I b O S A k F c S O v 169 Z x n y c K 4 R K X o F + O 9 T T L A H k T j n V A 7 / 4 m F 1 f S X E Z 70 a h H i / P P A b G s d o / n 5 r 1 b t c u x p n o V Y P B Y L 90 A r j E s S 5 A 8 f W l f U J p f 3 u A s H P q s j c C 4 G n t q a o + o e l 7 + g 2 j 6 d 2 y t T Z 6 C k s 4 G P 88 Q b d V c 9 H b u s T R x i j N C 2 y s w B W a G M y b q s 4 P i S w I s S 11 r B i q r i a W O / z 2 V 6 + f X 8 W M C T 2 z Q 7 z B q F V K O s S F s E K T u F I F T J G B L M 9 l T s V D w b U P 5 y W P A 8 p R N M d P i G a D N 4 p R U 76 t F b z a l 5 C 1 N P F 4 O x o w P 72 f H D Z 3 w X X h K 5 Q c 5 Z P O I c o f 7 J c 3 T z X V d p m n N n I 5 z q U y G A c o B N w t p 4 y Q A i T 7 y M J D m Q Q S N g 2 X d z x 2 J O / o o v l w W x d y i W 73 I D t C O r U 9 g 79 J l Z V G V v t v E R I G U T R R O u O 7 v T P d p j 1 m V 37 I U 8 z 9 c C c H J 19 B U N H 8 f f q 14 / 1 G B b A d O g P l c B Q h 3 u G + Y F P h v z i X u T 8 f f V T f d f t r v E j k M d 1 h 0 d 6 r t x Z T A 6 H 8 g g F S t r l 0 a V 0 o I 5 B k i y 24 O K L D 2 x W X P r / g D F b y 41 S z 8 N m a a o b I E F + 63 v s 2 w H B A 67 S N p M v u f T g A Z V M 3 X k 1 Q d 1e5 n N H f o U g N H h K G I F 80 x h q b O / F c V A F 0 E r V 2 j + 7 p f u l + j I T w Q o g L d O 8 + r B 5 r N f n 4 B Z G o 73 C H A y t a B h h h B J S f 6 X 7 F x z U Y m o / k R H + U t f 1 S j 8 Q e C u w C Y s b 6 P C n g X 1 G N r l k t G V I M A E K 8 d q 7 p c K 5 g O h f C i k A B c G m h 4 s f x Y u w 66 P s B V R I E A V a K d d j D 4 H 1 m x j u p o r p b H 5 j a C K P 7 N M u y J b 9 j I 1 p D Y T 5 r 3 + P 8 Z 4 T u T K U J M T i + R b q t R 6 u F Y w i / E P Z D k x G k e b y 4 Q a I 5 j 0 D E 1 x 9 a v 4 g x J x 6 k h 25 c 3 h 32 A h / C a 5 c t y W B A x Y K l V X w m d s 67 T L P k E s H I G l 8 v q t H 8 e Z e q H t A Y u P M y d e K 2 j 0 N D D V U f V I e 4 h t S v Q t R W W r Y Y 3 o P Q Q K 3 b r I m i y 6 q a T G O 5 d O P a U j g / G t o L o n x x v + D t f j D 3 t 73 s n u e S N v Z W O A 7 u t u t U b C h z i P M c g e / t s X e V P Q 7 l d 2 o 1 C h R / n j u t V H t / N B z X i D 1 w i X R i Z W f w I p f w q 21 m q g h W t z U q d K J e F 7 i L F 3 u 3 v s 8 y K Q q v e p V v 5 l R m / H z g W d z m u Q w A z j T a z g K + 0 0 y b i + 73 U j z 1 J j x f Q B I Y 4 M z v O s w R v g W R 7 r //Yde+uA/zDMDAIeVVkABmVyczDG56AYvcZNSE3LyK1942nfhxka0UrPW+vs8+ml4FPPkPhSSO8+nvDU9K3ry6EUUdMWmVwqQlJw0Edtyfz0i5O2OKN37U8S50IKv3L82HFoLRcIUhZLxC7tFHAeas8ddsyjwCx/gUg1bU5J+ZhBvBQAcJrhU5hVAasu/2KEdkvBSISv3y0MoASL+nM8nZLEYU9eoiktBDS0XzjHynYAbcI50gVRwkhwGvy2ZcWzWGZfzZB2/2HRTSCZP4bS1V81SmkrVvLGoJome5iLZdzhad81330bAxG6UKQ9QIt+GR1tmJwt39g7M2QHoy6HrRD/8iJ2i97b7gb4MAgmoPTSYc6wtAPSXcip8jrF0AYclXRgVte/6XWtq4C2enrB/C4x4yBDTQXb1E4ycU5iwyPaoorQjd7J/rRrwblB6EpkTKOrGo
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:51Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8823-04d8-439e-86ea-48a5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:51.000Z" ,
"modified" : "2016-06-01T07:00:51.000Z" ,
"pattern" : "[file:name = 'rkimage_backdoor_encrypted.bin' AND file:hashes.SHA1 = 'ec1ff6fcafcfef1e9162b7b7ff10754d64c15657']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:51Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8824-4ae0-4487-b200-4b36950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:52.000Z" ,
"modified" : "2016-06-01T07:00:52.000Z" ,
"pattern" : "[file:name = 'rkimage_backdoor_encrypted.bin' AND file:hashes.SHA256 = '324c0a9711c5a4660cea661eadcbbbd68d4338d6d7493cc205583bded3d05015']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:52Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8824-7194-45b5-98c0-4f10950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:52.000Z" ,
"modified" : "2016-06-01T07:00:52.000Z" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A B o 4 w U j + X w k x U 9 s A A A A K A g A g A B w A Y z I 5 N T A 1 M z M w M T k 5 Z D Z h O W I x Z D Q 3 O W U x N T g 2 Z j g w N m R V V A k A A y S I T l c k i E 5 X d X g L A A E E I Q A A A A Q h A A A A I t t 32 O 6 g D K w D 3 k h T z K 21 f L s c P T 4 s B M v x 2 m + r S 7 / X 9 y U E k D b 9 H 2 I M P X f 2 + 3 L S 0 + 5 / V v k n A M T q h j K + 6 o c X q Y 3 X A w h J k x + F 7 q o B T p + 6 D l V q F 9 Y / s 1 E + T e 5 e x p e E L w w F x D A 7 d n K n F + y 1 w 7 P h j U H s F t X z W 9 c D 4 f g p i H z A w 623 S m 52 c g X Q 8 v T U P c 1 E P D a S D T l Y J V + L 3 O + s R G / e D 2 + L 1 U 2 r 0 d F Y h e G x b n y g 6 Q N W K J M C W C O i C 43 d + G e u H G a 14 C K 9 F X F i r V 3 c X q k M u d e J d R S F p O k b p u i U O y t S G 2 o M G A 6 P 0 i y F Q I 5 S G 9 a J C h v G A X 6 y F 9 l P O 5 F 39 r P h Y P K R 6 W k r E Q 5 D x J m g B g l 1 G m A P w 0 8 f p z / s F 6 P w N s Q n / 8 s Q J 20 h d U Q j L g f 9 u Z b 9 C h R 6 b U X n r H x P 3 G b Q e j K B C d t 5 k N J u p Y Q L 3 I 3 K b q K f F E / b u F 3 b m 1 p 5 g A v h K 0 b j g Z I 4 w D C r w A B l h q q h 4 D A q v W 439 j X l y x I A W / 2 f / x s P I 1 r t d 40 i H c G d C e v S u + a 6 G g S Y E Q Z W W H 7 M T V u 6 K A w B I n / Y o l S I I B R q k + W w 6 N J N G V x k l f a q O Q V L z V 2 f a G G s C G i J d x S 4 w j O 24 j F Y q V d b 3 u q k j V k S + G n y R S I W j Q 61 E P z N h H u c K k Y Y 8 L C + B R R 6 V 9 o + l W w Y t z N 2 v s e 8 i z C l 1 T T o p e Y e r I s S V h W / 6 q b x a E K E 1 S c B W Q h y s l v v r / g 4 y v M h p 2 a v Q h I q B x g 1 z 3 w 1 J t B E I a f C G y f A o M 6 Y r i Z S 8 b I P C B V i h X M o R c z v 6 z g V l S h H 48 r 1 / h z A g k A d V K R 1 g E D T M 663 f X V S p A M g S l z z X C F r Z 2 L H E e 0 b R C 0 J J Z f 87 + E q G C T F k H 0 6 c t 4 P Q o L P X R + 0 Z 1 h t 3 g d 7 F m w X 6 I A F A g k 1 l e g o 93 X + I J E F D H N 2 A K h g P g A n j 7 t u C I P x D h 79 w E V z w k 8 c X A R 2 q D F s 6 D 7 q v S 6 M 0 2 q N k b 6 c R v W m A P e B 4 O O h j W S X H J f X L 0 m i B O T z + b B O l i 3 Q J O l o 4 e M N q L p E L z K B A Y 6 t g 9 j I T d B k k D 52 q H S 6 P q j u P C O l V z Z 7 h V 5 K Q R X Y T k + k L 9 G C x L m R / R 1 D J N Q k I R N K Q r O 1 T E n D K 4 e + E f + f K 7 p V s E z v k J i W Y 4 Z u C V n E M W S A h 5 y X u J G r 63 G o 6 I e N 5 L 1 a P 1 g l i V T v g l U S s d k R z l i a + M k X P x e q 3 K a K W I G m z d 3 Y / 2 p V u y y 0 w Z K i M S S s z 8 N r b H T P Z 45 Y G e K + M X u h v m i w U g n 3 s J i u B 0 f R s C k K + D b 0 i F c L i 0 U y M i V R x F p J M 7 j i 3 A p z y O D A W c y A m 4 + y B N D h v s 4 C L H L / U F H O Y 0 J o a i a I O h E 7 l W P 0 7 W s + o t a t v o 0 X K F a I H L 7 / Q j j R Z Z m 0 a J r m 8 / w P I E Q k v P i 7 I i A n R y B M 7 j t F G x 6 t c I N Z 7 D A n P W z d 0 C B M r D A 5 r M W 3 Q s D k C s Y w e f S M 3 Y z c N k 4 X o D G z O m Y p o E q w B Y o Y 1 o 9 s H Z I z Z J T e k w 4 i u 9 b S i X B i B U A d F w U 7 M F 6 k R Q / d U g d 5 U H h z e R A n h k w M 9 T A 5 q j b N 0 w 9 o z M E 3 K v 79 X V P u t K X R C 9 Q S + e L f A s Q j + F a w Z F X y G c 0 o p a K 5 Y F y S 9 l p n x H I Y M O m b q v 26 b s 62 W 9 O D W 1 i C e x 2 f d K Y E 2 i h Z e E V N K w j R p y + B h L G t U m c t w 9 f / W K 3 Q i O j w x X 0 V V t l 4E+4 u c X I D f o t l j V 0 H c 3 E + x n e h E r 4 c w Q P x q n Y P h a e M Q M 0 Z a s F J S Z 9 p o U B U q h / c r o H l W 0 L n p 97 d 1e5 g u Z / i c s h 5 K Z r l b j q N 4 Q I H S L T o 9 p d v k n d + t P K O W / H t w 8 s 1 d 1 o x M c K x q H o 5 f T w g 75 e y 3 v z f j V r P R C b s C I 2 B m Z k F B 2 I A s c d X E y O C x 9 E H H Q v / q j N T u z h b 6 m 4 E s B I Q 6 O 3 F + A u t r D L H 2 J X u h L H j n 98 n F 5 u s X C 4 i 1 t X J O N t b x w I z B 1 x / p l Z U P H p U h 4 p B y 0 + B r y T L 7 l p g y E i l u W t h h c o Q N G o C / c 5 y Y P q 6 g / P 94 k 2 e a u 1 p 4 + u g + 0 d F 6 R y 7 G 4 V i K 9 W t E 69 x V e Z U R D W e u + 8 / X V t F T + 8 X w G x K H 7 x 9 F Q T 4 L w l a L Y G N F E e D 8 c h q Q v F V l S m f Y 4 y i j 3 x s e W 0 l M b U 7 g O O 6 D y h Q B m d 6 y + J d R A C r C 7 u L 6 n q k 24 o H + y / n c c 3 h 2 p S / J 2 Y g M 0 F a d c 0 D j f w m F L y i c m 9 R A s y 7 T b d 8 h N J M O f O E w Z 2 R z d s v + b p 3 + J t D 0 z l F D L c z x + 5 K k + u A S 9 Z k u 8 o 30 x x p F 5 D w U A f x p 1 h T r K Y Z V O U V 1 / 3 w Z Q N j O 5 x m O 9 a g B M P 0 I H x c E h 4 T c + Q T K B q 9 a y m N c M f L P 0 Z Q 3 N I j s V g r 7 x y T M 0 w M z w Q P M M s C l 94 m S 5 H r / n S h Z s + 6 F i h U B J X 8 O w 2 B C m W J A 6 X z J / c p 7 p 1 T T / W o o M P N l I I t M F r m 390 + x 2 w D k W M u E u + D E K L e Y b L i X / g N f z e V E A K X I J M R m 7 v 97 U G 3 G p O 1 E O F 9 f c n 7399 e J 9 O 2 t T 9 H N w R o 0 M I 5 x U E 7 g D 4 W b L k 3 R T M 8 y V 8 u / c R J X s q X g 5 F D p B 7 M 4 x U e 0 20 m 2 O n o p 5 q Q n B K 39 g f q W q j a 9 g a T y 6 P J u 5 B U l 31 f L J d a 4 Z S W t n W S A j B 1 C 6 A z S 5 j W y T L P n o c R N y P W J W K 7 Z N x I S f 8 + i 6 + P P N a r N m Z r G 6 W X U w C f X Z K U 4 k v 3 Q G s U L f u r y / O e f s s y u t p h f F P N q a U X 4 d 0 u m k A G q k z g j U G q H S f L T R T w i C 9 W K u a U 4 e w E u + / Z 0 a 6 E O t G X l E F T X + j I i A R e J t 8 r v 8 t B c Q 2 e E G + u M 87 Y U t o g Z n 5 L 3 v h W X W F g y 2 B W 4 a w c X P g b m 0 M 9 Z H A A m b c P r o f p K w w w Y 7 j k x H A V m I D C q m h 96 J v p f t n m S h 36 L a h O Z 12 C d q x V W + 3 r J S K A z f M Y f + S y c G h S M R Z M 0 c u l y V s B l 3 D i F 4 s j S A 3 H U P C 8 k 1 t I E o I H S B + z j 7 R E f 7 s G Y h d V A + b c n h i J w U l Z G X 1 i 7 w l L H b y g u Z j f c z u A B h N v 3 i C G d a E X K z E w k b P U s e 0 x F p m F t 66 c q 0 r w S 9 r Z + D i C N z r F / H p y b v f A L e C e F 18 P A N a D X d A v 0 c t N 0 m d Q 8 v y E Q 2 h u Q 4 z E / v v t S B b A d 2 x C w a m / + T o t c x / i q V 8 / M 4 p T Y o 4 H 3 P q O C K b y f l Q Q T L y B Z q J C q / K V e Y o S + j 7 r d h a q b O N G Z Y w W O v j j Q 3 t + f y K I r L i G 4 L F l w 2 k k N N 9 u p u j e q x S Y k 5 l L x 4 O z C j U Z o p b e / i x s C r V M B i V V n f 4 R n D 0 h S Y Y 9 Y F M K B y C z Z M o B x W 14 x E v 2 + 13 o Q h W W S q W v + H m i H b A 7 e a / k N B / Y b + M 0 U v W h m 2 A N 3 c K V 0 o b j p q v 2 T G j y D v 8 N W X b z T + 8 E W f 3 i A k o s K 0 5 I O h Y m 4 b w m m 60 k M D W l 4 I 8 G v y / r s A e p X c L D a q D r c K s x w p j R g a 1 v b d p d h x E 0 V 6 A r H t U H H s 0 F c r G F b J s p 9 i u 1 d / r k x / d R a h q e O P T N V K S o m T g 2 C 0 a 5 p S D X x w w 1 U u F 2 U y l G x k 6 R u O l a m k 4 M 8 c F j A r P x T X B u G / k I v G p 4 M p E m P B m a j y o U G / u D 7 / g i e a D d c x W o C A Y X S c 55 N s 0 S 5 c 9 Q 67 V I C F c k b 2 H M W W x V U G A S h C a + s x / Y H J L f k 9 A I a S n l 8 i D a C + p q F e g e 6 V / n H y 0 i K h X d J Z Q 9 O Q Z s U H F N Z S N I M Z 9 H v z H z F E X n H 4 R 7 A F e k M O f D d r 16 g 0 f q 7 h H n 3 y m l h f M d S G t 0 4 X g P L W K h P 601 W 6 J F O z e + G Y a 8 z v u a y o l 8 d B 3 F 2 W J 2 p / v F y 5 v G 7 R 1 Y l l c j G v H j c p c S 1 j z n d m q 9 o 51 Q 6 E Q K / s W V d 7 Y e P E g G Q T T C C P 2 O x E N K L 5 V 3 L A u j c H L W I h v l l 6 o g F 9 i Y j j e p h 4 i Z N A s d z k f 1 a I 6 Z X N 9 P z 8 D 70 f A 8263 A p h H w F M b A H S D K P a 1 I k W k 5 i V a G 4 o n O s V V k W V N m W p O S K i 86 S A A 8 h r e j s L x B a Z p h e C T 2 p d J + S F 7 r T C t E I E v 3 S a t i F v V 4 D m 68 d q u j + D + n j Q + P //wMLlFmlw+4zX4jOKJOk7ZsRcPqYlZ2echNOdwwVQwRK1HW8V2r73t0WgjS1QM6OfQR/MSEi/L6vpDsvwp8GSd6YXMNJaNyMDDF4ODfpxSpZqQeTz9n0osUZKvEvx7bBJBDQMz/X+UIzANX/QAoZuaCeOen9DzVELMAynCE1sa3dhQI3dHRe1aLYB
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:52Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8824-26d8-4907-80f8-400f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:52.000Z" ,
"modified" : "2016-06-01T07:00:52.000Z" ,
"pattern" : "[file:name = 'rkimage_backdoor_decrypted.bin' AND file:hashes.SHA1 = 'a5fb93890a903721529cf5200237dc0200b81b6d']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:52Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8825-79c8-4c88-bde5-4cae950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:53.000Z" ,
"modified" : "2016-06-01T07:00:53.000Z" ,
"pattern" : "[file:name = 'rkimage_backdoor_decrypted.bin' AND file:hashes.SHA256 = 'e067656af9cbdb9607a5375d4e003765de54ac43243eedca6123282e654f77f6']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:53Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8825-69f4-4855-8b95-4c9e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:53.000Z" ,
"modified" : "2016-06-01T07:00:53.000Z" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A B s 4 w U j k f r i 8 N R 4 A A A A 2 A A A g A B w A M T M 3 M G U w M j l l N m Q y M G J h Z D N l N D l k O T V j N 2 Q 5 M z U x M T J V V A k A A y W I T l c l i E 5 X d X g L A A E E I Q A A A A Q h A A A A o I n B B r 6 j V g u Q C + V f U g J V U S 8 y Y Q L n U X p n 4 x O I E b / F R D 0 y J V U x A w s 5 D 5 Q v u W Y 7 A z G x M e e T S 1 y V n 9 U 7 A L D y f J v n m 5 / 6 Z C b 8 r P c X F z S P R T L D 2 Q 590 w k b d T K 99 + l z v f M x j Y U Y p m E Y t U O 9 d r W W U j c c K J + c 1 a x C 8 J T b H C j c U 0 Z e D a r Q q W 60 Y R 2 i K n / o C X v s y L G D g Z u Z G K h m s l a C G r y i P A b n 5 e a 0 5 z g S Q z J E 5 y T T O v g B x Y 8 v c U r 2 C B k h J c t f v k l m f D q C u l z I I f 9 r Z d c u Z z 7 Y x 8 A y F q / y u G Q l R o D q a 6 m 9 o G b Y a 0 t C P e d i 4 O g H m P k w o r / c W J 89 W F i + O r Q L w d D t n R r s f y t b 3 O W y S z y e q P o 9 v 68 D F / G U E f l 8 O O f q J m E d 7 v D l q b Q e E 7 G u Q f O c L j W e g K g H P Y p q s s N 1 + C p z 774 a j H 39 / i D M P / 3 f f v i s T f G r k D 7 V j 8 j t p 0 U b C Q 5 E s r / 2 I b h 6 S X j / j B 1 D 4 k d Z H 6 T A 0 4 s l w l A f 4 F o h a w T M T N Z G K j y T U W v X h a d F q m w K H V C E / g K e 6 b P E e H P 3 R A h 1 C Y B y 2 + u I T 5 + T B d 3 a T b J t D q c s g M r 3 L 69 D f Y t j E K t M P p l D x P L G N H 0 O V O p r G s R Q l v e W / B z T O 518 v A n x B e Q j S o / Q j r K E C p l v Q K d U b M I 43 c + Q V 27 n V q N U Q 0 g e F 5 h O K e W c v 4 F x G 5 / o r e R 9 C u y G e s C 94 s A c s G 4 j t Y l j L U 5 c F h 8 x 0 V g 0 p x 0 z b 9 q P z o x u 8 S I I E e X W e i q k n + z z c R u G A N Q L b D / A o v t R w C Y l U 0 G z h P X f J Z I z 3 k U L 6 Z c G A Z H o u y 5 X Y D I A 3 n G J S Y N g 0 Z O 2 O S z i I e 7 O Z y L F G l Z 6 h R o x j S C r k f E t Q K 9 t p P C o y y k y O a q a x r g g o p L V M k v l e F v L s Z x 5 P y f j 7 F o p v z L i z Z I R m t G L g k W b l H w i O O j //1cxYroP+tb8tYlWCvsPiqKxQRv+1gW5eVctsxyNm8asQchFrmz6btE8ZbIjrEFlNl5e/w2fH1dPXqUIDYfWEBrbTmIMWTSpixymuGamJCbtmD9dv8XoD2kfoBBkK/OrCqhwokmg5jGkON6XlE0H0Yt5aI6VmW9KCrl7ZLqMRHH+20WT/0ce5yvghf7moxt6Jg1kzraF6pCAYAxyYzaxU1aIP67uOcErjr3L1+bee0yKuLPzYyfAv5PtZ0DcLUjwdFX9y08xpDybONgWcHFa+koBgqnQl/agWqX3goHmfl8by9Rc2X3fVb3QHZ5z6ZG0NJTguHDKFcjJrD757kVvgX7sGvWZqykgvNmSXX9YgfDg3j0wPdi/ushZerSCZx6NmyRhh1FRaEMbpernoB6MZJukT//A1flhYFozC/c0PR7buu3YNsSEJfznVnV2KsypDlJA//3nfqnm1yfdPCb0PBQSmR0jVEL1p0tIx0GOSeAlgiiNKuxrgTH3kAIJwne/YTXTU3qgRLuMtIhw1MRYQrn1wvXwkecJxV502GALzc9JCVuAW4gepD2Vlil04gDJMQdvIQohBsT4VU/azubsHXPNJ0tLxRWlYy0DurPs/TzCQs67j5ecE1XBPBuP4+W0ZzOtIoozJW7pA9h1S22apVOQpD0Oxl88IR1Dp3xdRnKGzzvxas4TX/vAw4Fvz6Gw9ja3JFfuVi76PN3+lrRqvZL+qdJUfv/wVBLx1sGqorLs+D0M2mQlarxEhYH57s84Q1Q1AZ7rTmXMvxVl8oDY59QzTINr+XEguPO3Ajiim+2MrLKCuK/QrwgWUN0a9McgfXpMxhjY/hqj6Ntx6CLaOU4AbruV6csI9I41WJPJVuFSdQzJAbeN2MVx2KTs69GFPlgltKVcaK14Zp2pGUHmSm8AnAGQg3IpjcRnOE2Up+rqxY0jYwTzHNv7j9KQlTeCQgWRdLtuX+r2Ao9uBo9Jn1RMpUEtkoPGzwYvgvuy36MlFr7nxAdAXrErmXFBdBDOwGwzaeyaMVRxJdfVhqmO0+Iynyj9zG8qF18x4Xat4z16DDStOK3NrMurwz9AzuYje+BGPZnUrwYSPPiwf8SMgds1CDTGoWA9CWqKpEapO8UV3Ymzed/siVA4+JCdUXKjSxRvNyQZHInt3On35447YZLWZZ3hvnQvVP/Hr1QTSKpC+JM37LWeozpUAwbF/CJbTd5uFrHMN5zhENhWPe4jbWLmDFbc6tuTI5ndobepzERPNBr08DoECw0ukuSgv63cu0Eq0+aQp9bsa/cEtUhw8MXDn0lino7u0D6xiAcBpRpaZXsik56h7CbkAj2QsSdBXbUhmkNewWkSfmzCpkJj7D4oP/Z3WfECW1xuUwZ8UG3n9tdFBDMVs/YWkZ/93h5aZZCxkf1RydXchlucdrVeNdj0Tp4D25Q/M1m9xbydn1vK+jd5rKs8o1vD0S3zn7k+ECvJKa6uPaVTOeqmNztzvr46Ff9ICYDLrsEGdWCybXQr4o94UTUAdEN4iFS3NbFBwEyNY34QBKDnV1YuVNEQVkKHlgx5jPtx/+BEVf2M9mrItYbsv7GrboXifSnWoD+rmYDKcQdml9iDsbfKEXqMo5Idov4ATRWLtHQE0phMaUWhE9B6z/9Z6rAYgzka+Hpkg8ZT9SLSVWLR6G4Zg+u0n/2C4FkK6NPbliQbmv8HgduTuOq8E+Umo78i8y+UzeiVBKqIIUIS4CuhGi91nM2TAl2UIaYjdE9EaRcLJFulQYq04fS+1sAp4rTOrZQWq1+4h/XdcLqUlLAKmh2Huj/oIMXI9XXXQSRm1xU+WAlmiWKZpTfcY5gmJaIvvV0kGV13OXOJLpoWALacx0GOQ0T2ZjkLiOvAmp13tluCtdbrNQJNHNoEpE6HVUbEQ89XVCTH4WQZH09pkclbbHLcZ/lF6apiEtKs45VhX6gPWBCc7/E/LE0cZuEbaNxEdbYfhXROTLqjAzexYCNMZ++hDcJgeA4xLeqqKY+3NqJvoymDJPreoFhqDyMo8DSoTWVR/bN9FKHdmTmD2dnb7fppae/sQgRCVc9OkEhg5sqW/xwMdHj8Qanby91ijJq0FCb2CVCfmPyvl9vHUBykvRJoBQdAMfzcp7RyR/qub1YtibGo4z3VQSL33x7OcO23U9krODgAh3Pj60YW8w6NFy7Z5bF36rtewyJPTge8BC3HzLlWk7SA+pVbbSormgdvDQMHJQaTlgjqLNSE8b6gHf18AUSBHhaQxjBeBwwRYcik26fOl1lM6ROuT3poAbv00uJwLxH3yzVClR7fr9NsfU+FEwy8cEnA1ps5cPQW7nVXB2po/DHkkEQMaEgKFQv2fPhDggKbpbs941LcjdsW4rzDwUOrmvBuR5MLEpC273wkSslWUrmbrsRmjBjcxVPi4bFrs7S0+7xYQ5loZ9oA34A3edHFcoTZoN8hfrCEtHwQzx1R2DF9nLgO2CR4OeW3lJMTF3rSznrNcLsLLeEiCQHg4L+l89hBoTB1FbHotbieLb2NuL5yf2+PIyCl7Wgar91LrDqtux1OopywJNE+t45xhgRaL8/GRYAmVSZNO7GbkwvmMESZFruMLDA6LRGKLQn65r+JZBdrFmBEJkZ0speq3iywhIFOcjU8vhDZdfM14ilfAVkar91LTBXFJncG6yLZj9tpi4Jj5FDo+y48OwWyifbCv+yVYsK7dg05OiTYQiRCpztbA06IjLhrHwHmWrNMtfZdTTI0nO0I4nMrr689lZK7bazFGW+Dpmais6PgdOTayO0zrgIw8ZzMP5qt0s+bGDwidLKr4RBLMza3ypOLd3a56sPahAsIrL9WdW7oH8TI8DJfhTPuMGaRSJJwcEcx+pN5X4QsUgK5XtmVl2//OokAwcuDfGL5iI52QpxVg92qvIOMphOo36/PNMaNztHLDIgw0dVF2U6jQetGznZu35UscJF7GVLaAXLl5vbWP8EGlkQVj95xwrLz3ucvW3ubOT93O6URiyMFEzqO0IyXWApvJjXa7s0QWF
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:53Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8825-ed70-4609-a497-47fc950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:53.000Z" ,
"modified" : "2016-06-01T07:00:53.000Z" ,
"pattern" : "[file:name = 'pe2_encrypted_b61e8d81.bin' AND file:hashes.SHA1 = '35f712f1fabf7f51f0d757aed949d623eb3dd02e']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:53Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8826-7830-4b99-be60-4f9c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:54.000Z" ,
"modified" : "2016-06-01T07:00:54.000Z" ,
"pattern" : "[file:name = 'pe2_encrypted_b61e8d81.bin' AND file:hashes.SHA256 = '3f53ada1d45ec072960ee2b91e902727dcfbd56b841a7b60251680565dc8b5c5']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:54Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8826-6f6c-4298-98f7-4be3950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:54.000Z" ,
"modified" : "2016-06-01T07:00:54.000Z" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A B s 4 w U i n Z E i f x x k A A A A 2 A A A g A B w A Z D B j Y j B l Y j U 1 O D h l Y j N i M T R j O W I 5 Y T N m Y T c 1 N T F j M j h V V A k A A y a I T l c m i E 5 X d X g L A A E E I Q A A A A Q h A A A A g w J 0 5 H z 2 f q W o r b 0 x W O k T N E e k P v p M 0 i v T d t / T S V b / y G Z f H t D r z + Q P i M A 2 G / x a f V L j a V R 2 X X M X j j n w / N Z 0 h 9 M p A v S v m k s 1 o o 8 P 6 r i I 25 T K S X A C I t l 6 l D L g a g U D G / f Y A g A i 3 T u H 8 l w I k B R 9 e K 5 i K i t X X j 1 I n D j 1 Q y l l m 8 H Y D C E N e G H 0 z n 1 C 3 u o Z p P f L 4 d B D G v b N h 5 R r 2 K G l i S S b k e X O 5 O w h p f C o S T f J K 2 T N v q a 9 S p f c L 59 M 8 Y q 8 R s a m C M V e C O j H e g B Y U q W a S o A i j j v W 0 4 R M s P q 7 B H o / u O P l A o u t w B L q z f L z / X h d N w J R G L P v m Q Y K i R F O j J Z E 3 J R P r z z y 3 P v 6 i B R S W f J Z t b S K L e 7 f i g W k E l Z A 1 s y p k Z V x d J K 6 Q Q m k C d t c Q i G L v B h y / l Y 3 G 6 R 8 g C F m T q g N u J 0 F S l x e I Q K 3 i j M g 0 N p 5 n A l p W n 3 a v T x s Y W o 2 d E P n G u 4 H l b c W U / N b O S s X Q r 3 / g t p x I D p u D + b Q k b q j 58 K E T 5 Y X r G t c S / 9 u k z Q C B k q + w 9 e a e s N 9 a S / n 8 S k D n X S 0 D x o C z K b i k 2 V + V F l p z 0 K + Y n 9 N I t c q Z d Q Z 8 q 0 7 o o 9 W X j m 3 s e v 1 M b w S 3 f 9 S i h / 9 M A s i d e x E t f m Z z 2 S Q 3 j d w y Q j A R X u u x 7 E f 8 l i 40 V I R k 3 y n 2 D h I d 6 V C K P O N R p B L i b v X X p m B 6 y F O r f W b z 6 a A T 2 w I X 4 d v w w T U 0 + f W i U m l R t 1 W P m n f 4 u u 9 N K 2 q J b G O L g + 2 Z Q O j y f h 3 Y O H A 0 l e l K C A u g 4 B p R G l X U H f J t G e q H v k P W G W H W + L z R + h c J P u q 3 A s 1 h 2 T d Z 6 l S r o W A g E Y Q c D R d c 0 6 G k 8 b R t K K 0 X A M H l 1 g V z 59 C U T y e 8 J T A D 7 a 0 5 J h e a V n Q z l g c m F i c f O c 8 U A e 2 f w / q h 8 Y v B j n o I V s P w V 71364 w / m C l / H P T w U P d 6 A l + 7 a J V j Q I v t v f D 0 X 3 M t L b Z G d b u 10 V x R U O m e T N u G x 3 r F m g K J l H 3 j N Z s n H K A k Z A R 9 g 9 t a 1 h W T u P C U o W N 9 n t 1 x T 3 q z Z K j j I G w y g Q h O S x T x 8 b h s 7 G n y S T Y 6 x M S m q 1 p L A 9 / 6 O Q y R A 7 + h 60 P g D R t X 9 u D f A 5 S K K K q H Z 0 v O 0 Z t E 0 m S s s n R W M 945154 C E C l I Y + Q Z M t 9 C C 6 R I G s 946 x Y L a V J v e k W W D 3 M C / i d w 3 i S E w q h o K j k I g I / T B F O A Z r O P D Y m t 0 H W 0 w W 3 c B L S k u t 2 w o b 8 N C M J 2 u X k 2 Y t H h s D p v 9 V M d k 47 B 5 o N e 9 S D 3 Z Q i h 6 h X 1 o S n B R H w E r 5 A 0 c s z v 0 12 g W v X x Y v d 0 3 D A 3 f 6 T p M 3 l + 7 Y 50 z S S 1 i 0 9 A f 1 + R 7 l E 54 t F C w Y P / e o m B q Q W q H J T t s 3 g 3 d 0 d / S h 1 G p L 20 / J T 7 + I v C E g K e C d 9 k F U P d k Y P y 1 w B C s Z L q d G V U S 1 o s d I R f q z D P M + 7e6 k E U S l H k U o f O S r p U C 7 M N b 5 X 4 U 8 J h h O T 3 E s r + F E K k R K t v J C X 4 S G q C J q 1 C d z + i F H 7 X B U X A Z E O f D R M 6 t Z m p o g 0 V r f B 62 I W 5 b e z / J A 65 T Y 3 l z q 4 v m 0 n + A q r + A O a + Y J T d W p 4 w + N S V J 1 u D N D T 2 g z o Y d t 1 V I V Z C i B H X 51 d X k Z T F D 3 f t v Y W 5 a n 44 r l n s V o X 2 U N q R M k 5 M 9 J j Z G + Y 0 K c z S v R w B T v B v O E F F g + j a D d M j 2 I L 6 x F R R W u a O q t 1 e d m 2 b J c m M K R Y y X 8 J S A X + 98 C i f 7 K h J U l s A t L G / U P O F S I l K m v F 0 L 0 t + 16 U + w + Q w g t 70 o / I 4 S l 4 c o h j d B 3 C T i 5 A 1 O q 6 S a W c o J u W V T d 8 H P g B A I e 1 q l + b 7 t 0 E W M 4 C I K N 392 b 2 h m K u V c L T w Q G v M R 9 p W N R / v c m B p 44 g H N X X 7 / 3 G 4 n A V 5 Y E 182 i x O 8 W d G d 3 f R 9 / t X Z Y R Q e a g 484 h u J w 2 U X F S R l O l 3 A j L h 1 K P I s 9 / M v 7 E S 1 d i 1 L F s r / P S Y C U N E a p O f Y Y c d o J 9 s 9 m E G B T M d d b Z 4 n x F D N i V T t U 0 m W 6 q K k Z N M P L 28 C A W D 9 t M K A d r X 9 W X p C K G / D U G / 9 r f q v d D k B 7 r G p T 9 + I + 3 / 0 I j M Q H i z v 82 q u Z A / I N D E F n r v t n e t G 79 g K e 9 G L v 1 w X r q e Q 0 F w 6 z p e 6 t j Z 2 K h 0 + b Y O g 7 O s a 7 w A 8 r s z 4 W u a K s 2 S N b 0 z / b w P r j / f w K b 1 k c 3 p D D d S m D 4 c I K 9 d f u T 6 x Q v X g d G s S T o S B 7 Q N y s o m + 5 n C O 0 17 / B q N 6 E j J G r W d s q c q q L l U i j c R P G Y W + C E 0 u e J u + l e 4 x u N H 8 n Y + 8 R L c D k K D r r f U L N + l n f d q T C e H j O d k 4 i h + 26 y J j 7E4 d T y w h V V L N / p N k u P j u w h C n z 3 H v v h P a j I N V w X B f r g 1 E E p F 7 I z t Y C Z 2 W f m 296 e N Q + U t 8 b z F G 4 k u 0 y e h 0 b o y o 4 / 7 B s B x 7 e E Q c S S 6 a m n 0 2 c r 0 c 0 j 4 T D 8 T m 155 f D B 2 L p Z b A D H h A n u m 70 g p X f g k z t J 7 N E A 1 G R J k Y z Z 5 P s N O h 75 F / Q C 6 Q G I u 3631 / n i x 8 z g / T L W y W N / R b u A c A u O D Y O i o T 7 M B A 0 W i N c b V L 2 F h + Z i V T 64 B i N U 97 / f 1 y Q r A x g Q 2 J u O V E v x G Y R a v V N v 5 k x 5 P F M f q E P 0 23 T e R h h E h t m o w U L 79 O A x + 1 + C e 3 K O y X E r M + k x 7 W F 0 m K L v B l w j Q R f + r H 2 z W 1 W s l 6 R 8 I 9 u J h U x Z Q x f e / n e 3 B O 0 5 k P 8 N 8 i K 6 N W O U 6 U h z o J F 0 q G z f H u p 3 X 7 i + K F u 8 i I F 3 B X e f i A m H M 67 q m 9 d z 0 B F v J 4 Z y z 0 Z I B U u l 9 C N Y 5 h l Q f Z 0 h M 32 g R q 0 4 M + P G N r 4 m g 2 g G 7 + 67 v o k i w a W s p 7 k 21 i m I c S O x N y d K S V 4 M y H g 0 w P G I z G o b 5 u k R I q l T C Z p V K 0 0 C Q 0 4 L T Z h 8 j I 1 D L e P 1 H A f W / R x J v + i e / H W a i Y 8 y J h t Y w g 1 L u W L O 4 s z y t K Y h u 9 v c S t l B m z L 90 r c N u j L 7 / Y k D e I J B l i 0 M N U j 1 l I C F P Y e i d Z z E 78 c B L R g Y P v i H 2 j V X j 4 U D y 7 o k 5 J j a Q e B 59 V W d J 3 U / d P Y v L Z i 7 m x g C W e Q x q d p D m z 38 h Q X V k I k I 738 w J Y n I q k f 9 m J B n j T 4 i u P b z 26 x k V 51 K 2 Z m 9 Y L 0 N s K / G P s p L F C o a k K x g t o b L 9 J z d 4 J S r Q 8 / e a z 3 o Y w 9 Y m i D l J 5 Z s S Z t 0 O z 68 U B f h J q X S v U P z K L Q d D j n r R 5 r C B O s c D f x h S I s v y 12 c v x t I U 1 J q 1 z h P M Q E 3 Y m h c q j D c G 8 S 2 D q y A m V u G n M y r q z A q 2 A Q 9 j x Z g A K x K h I G 59 d l K b Z c 0 J L r G n / Z T C Q H u e r 0 q j O b w L b z x C W I b w n 7 r g 7 F P W Y F v 3 T 0 U U O 6 t 6 l d V y n n N o Z 2 O c r R C j q p T n Q q / N P H l 31 n Z o i q 6 l w t q z T n k 3 t 8 w c x t t C u E 84 P U u / c n p H t / + F a p p z V W z 7 V 2 f X k 64 F q V F q / v X P C u J f K 6 i T 6 H p u D X 0 z d e d h 20 f I T 8 e w j C q + 4 i k l V I q 8 X + P Q 1 C o a S Y J J X v 0 T 4 S K 8 e G B Z W h E i G q g z u i N t u 0 V v l e A U B T g l G N J Z I o m S J p B W J C H z 1 M e 8 q 281 J o e 1 l d 5 J z / 6 r s U m y b / t g o j x s k L Z K g V W a c N W F m 68 y j i W z C p R G S U B + R r 3 X p A V R F X s O l 5 / A I 6 y 8 p f t d t K x H F a E G j 4 F f J 1 l 8 F U 1 z 0 u w L x 6 J y / E D Z / U / g V h 2 m k V h 7 F p K s Q G 2 R 9 V O c 1 H u 1 D S H / s h + V D W r 9 R 5 J N 2 j z C R r M f Y C g o Z x 4 X U J 45 J j e F N p 3 Q R s f + p c J / k X a X P 6 S 9 k 2 I a M U Q a r s b i F z t a Q 7 x B 4 o D o G T r S 2 z h B / L J 5 H K U U T V k o m n P e 0 s B N E B i x z F s D S D s G Y D l o H z 2 q w y g 6 M v M U 6 W G q X G L D G i t M b 9 J q t / X 6 e y z D J V I A 8 I Z j p 7 m + u a E 9 u b A P r Q / 6 V q U r x x O Z U m H u k v z h + j s 9 R a 9 v j E l a r Q F K G B N O K a V G Q B N f 1 I s t H e 2 S M l R x m 3 a P a 2 m 7 L f M T 1 p M / P 5 W C 73 j m 7 N i C Z k L d n Q 7 n b 5 Y I k 4 a U S 1 K L s 5 E J X x N Q + E 6 R q X + B z B 4 o p v h P p i v m L M b b i j 6 S 0 K z Z t V + Y J 3 b 6 a r A V U T e J v S B L g f 4 U z N y z w k Q p 8 f b l g + d q Y h a U J X 0 c / T A o j b o f l s k 0 k E 5 e h Z O k 3 + J x X 9 o N d / n + 4 F h h F F 2 g 2 M A T 0 z q a 7 z E I y H N G G 6 Y K 1 V i n C Y d B 6 h Z i Y q i z I n U T k 61 V 2 i c f Z u z N D 1 r K M i G J v
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:54Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8826-506c-423c-8116-4662950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:54.000Z" ,
"modified" : "2016-06-01T07:00:54.000Z" ,
"pattern" : "[file:name = 'pe2_decrypted.bin' AND file:hashes.SHA1 = '5d6c1a3c2d827c714b764b1c5a3e7370ed737986']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:54Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8827-ad04-4733-88b3-467e950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:55.000Z" ,
"modified" : "2016-06-01T07:00:55.000Z" ,
"pattern" : "[file:name = 'pe2_decrypted.bin' AND file:hashes.SHA256 = 'e3f47d6588b94507619acd51188d798e1adcb9a611960a2b231eddfc853a8ead']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:55Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8827-a6c4-4f53-9816-405c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:55.000Z" ,
"modified" : "2016-06-01T07:00:55.000Z" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A B w 4 w U g / w b Q L D h U A A A A i A A A g A B w A O G E 0 N j N m N D Y 2 Z T E 2 N z U w M G M x N T U y N 2 Z m Y 2E1 Y z M w M W N V V A k A A y e I T l c n i E 5 X d X g L A A E E I Q A A A A Q h A A A A v H / D Q + O U x + v + F D 52 T M u y O 6 v t p F + S O W x r 4 a E n E 6 w R L h o u T 9 i G h f F r 1 D i K f p h e n A v 5 L D j E X h o Z Z x j K H L 9 F l 4 i m M b c R J / x F W 9 n A l + T n O I r + m r w t A C c F e 9 D Y U N 6 o T v e J a E p u v 7 b i D K l R d o h O e o A B H b V c K 77 h 3 c p I q E d 6 G o X y h s d T i F b l O x t v + G L z L A F S 7 t 2 H t b d T 0 d j g + F V q Q Y x W P S f 2 y 7 H 4 t A d 24 / m M G j w Y b / N O b J S k k 6 d e 0 6 g + W m m F 0 5 G 3E8 n 9 R k x b H j e B p y V w 0 G D T f z 68 a Y n 9 / P Q I + K 1 E N z C D K z x 62 H 8 F l B P N k h o a k n Q 8 i P + Q O L I G G q d Q x C 3 A 1 Q p O j y 7 r 7 j 7 C Q u 3 A d E k B B X e Z b e v A L B E V 0 6 + F u h 6 k K p R / t Y T Y A f H q U R + / b L d y i V v S o M F k k 4 F T 61 k f 9 A s T r 7 m F s C h v G s i 7 A e 4 A f v S 21 o y t B R F 2 Z a Z j v Z g D t x Y Y n g a x e k x u z V O 4 n r d b 6 n B t s f A Z 0 I I C I P B o P N 6 I K V Q W / m P G B h y 3 B g B 4 v O R u z x 6 z C 2 O / 0 V h 52 J J s W S Q m M J C o y 4 c 1 L V Y W 7 N y E o O Z D 9 E q 10 B t t p n / C 5 I S g C A + R i t + 9 k X Q A n b C t U J W 8 Y I r 6 s m S F a A V k P A 3 P 9 F X 8 b + l J D s a 5 T F J c n / T J r r 6 Y I l u 6 q x 3 N T 1 a M u u E e a v / m k K H t v Q 7 S s N P 4 I B 7 m k 2 + a H y J P p u u t h 4 B 8 q I 4 f j r u G u U K 3 P J e L A r S u 7 / J A p d L 2 y z C O l l Q g 31 j R n R I M 9 a u C X h f 8 w j t 8 Z l O x p g u p q O S N t S P 4 p v f v 4 w V 1 v J 3 l m e e s u a E 4 U z G + i A 2 u f B d a N a k C x / x C u g H B G 1 H 5 X W 5 H Q Y b 5 D W L s 0 m s t + b m D m d i x Z 5 z 4 A h x t b 9 C t h a R X T 26 g M + I u h 9 S B Q 4 U o F K 0 c Q q F / p R a E 4 C 2 w 0 x S C J 4 F d s l M 57 d R p e Z 0 5 r h w E 70 t 2 b U e F o h 9 B W O J D e g g x k N v f F X t k E a q e v v n Y z M g W a 9 g w M U + w G u E y P 9 p s u m C O O d J F Z + 3 g A K H m H x N p S K k B x N v O R 8 t g V J 4 t A r E 4 Z 3 Z l x e Z t I j h v N y 7 u 0 W Z r F l r D C / x K Z M z + O a B Z P u B z f b r R T L F a I h x H O Z E E 4 z u x O Y f R n o s u 4 j l g E 84 O w M 0 b l I t x m t y r w A M A K s 9 O 1 E Q L x i m 96 H 5 i q n G j Z T R L j 1 F e r T G H F R q m / Q H O 7 F H p b d Y v 6 d 6 q y t c 7 C W W R b p 5 O n w l Q y a P t R H 9 R 81 + k 4 d 6 Y F n b q x 1 d u w K Q H 7 H D 1 N q z Z q M x z i 0 P 8 O g U Y s M y k o a k 6 i j t Q m c O r a w / Q 1 Z w B T F h i M a a Y y I X / k 0 J X S X o I C 7 c e n / P O 2 L n R G E c 1 f w E O T j J J E c O M c t 2 M a 2 P 8 k u 8 j J X x 0 L D h j n 8 X j L 9 U C B S O 6 T Z m V 9 K k m B o O j / i 3 Z M r L u c f a n V X O 95 X 1 Q h / k / l O A K z i t U z q J K E r j L w M 3 B T a x v 4 h Z k S r f c l N S R B f B y c W F X L j 1 L u 9 Z L 60 G W l R l N i C 0 / S o 3 P I E m 8 e N t X + I c 9 I W o l u d 8 N 8 E s b 2 x y l 4 l i L d O T 1 S H G J r 7 U a U 8 + N m h 68 o Q 88 Q G r / x y x v 4 q X a n 4 D u s h 3 p h w W T x e u X 5 x a L i 0 i g A V E A D b C T q j F + h 4 v K H G I y / e z p O p b k f n 7 n f F t t U W w F J T + 7 g + h f C Y f 2 m O E v Q S 7 c j 5 M 9 G b O k s i n R t P 2 + K M D s T u o S K z i x p U 2 B 2 s 0 T M M D f 7 G U L Z S D K 8 x H G T / S f 3 x W i + U Q b V 8 F B M 8 l Q o R s c u G X a 2 B 4 F p G I B H H Y u O p S i C 1 X G 2 i X l + M n l j c K 4 X 6 G b 7 e w U s r n y m e / l B 6 x 3 S T e 5 c M z a j / k K J D 7 q U I f o j v s L s m 7 t 6 J A r W K 0 V U 7 G e a Q H 2 t k w u 4 V 1 + z w C q Z K g O 3 C U g 7 O H t r / 0 54 / a j i o 3 Z D v v U 6 + Y n w o Y M j o X X o W v i P 0 1 R C 6 u n q k W Z F X j 7 t 17 w 8 / L l u G 1 T n o l x D a s A 7 U u A n e j q F l z a X p a D O k n F k D 8 o W y F 3 E g B V P V 6 U F M E 9 s B 2 B j 5 / g k 0 4 G K P x 0 c 4 x F P m B r B z 356 L G w Z 17 A P X o H o g q 7 x N P W y U y a A 4 m x k N H P 6 m v x u H 687 x g S s S P d G 7 u N T H 4 u F s Q Y G s b c g B v z d A g o L B h T T b m C Z y C K R O E Q K i P a E c U q I / W 5 J X A B 1 R X x o V U h Y 6 k / r h k z Y 0 4 s f m F a j y X 6 g A 7 T T 6 t B k U d W X M T o a M 3 c T C c M O 5 u y z G Y Y X 0 R A + J 3 n Y F d X F T u 0 0 e f 2 x 3 e F r l W N + b c y P + 5 u 2 K o / i 54 b 0 s j w o n H O u n + 2 G 7 e P + K U O K o X s q 9 + v H J 2 f w w r w W F 37 G / I a H 5 e b y V g h f B n X 112 b M l U + f v 8E6 s g T P l Q i u U e 8 q 2 X R p B z B K / B L 7 o E a + z f p b Z Z J q L p U Y Q w T + Q O f H m 12E9 p C 2 Y F p Z m i U I D r D y E e 9 V Y e M B + C E 7 Q 0 f l J H 7 P r y V 5 b W D B h U h 9 K E r e k G 26 Z j n 0 F y V o z x W p A l 6 G 4 m J h E g z r s J X L t r F b P F g z C t z A w q c y f p o J Z v W p j T n k I L v x + h r Q W s b 5 I F l Z i 9 Q S 3 O P X j / 9 S m U Y W D z w 9 D B 0 Z C z w Z o 9 h k a G w 16 d L d 7 x f O u s w b 4 i 311 / V i h o h P G P s v e H e 6 g O J h o X g j u h b Y o Y L 4 y b k P + I N 5 V Z S P V U 3 P s 66 v M R + 1 V H t J / G 2 q U X H H A 5 P X t 3 h l v 0 B g H k b W V i g g 7 A n K 7 b u S w T E D N e H I J D 0 s q M j S T t x u U B R q T K w 7 H 7 z y f X g 0 U U e i 3 w t v C J v 2 h j N Y H A K G U k 7 A f n 5 S z w d h l T d V L 9 y + 42 Y O H Z 4 h B j Z O N 6 M W D 0 z m D d u + d 1 q V p y b a Y c S b M W 0 U A 2 / Y e v a B 7 c t Z S Y v 3 w u t 8 k n + Y 8 i D i 0 J F s D D C 3 C d h E d s g s G A r M u 2 + W / 6 c h M I q C G Q o g a j F r 6 / 7 L Q F K B + U S l i c G 60 D J J / + h A g c / C 5 X U E b A 9 t d M I K P I L g e / h p W o / A c 1 N V p 6 n Q P t N 5 J o V 979 t T s I d x R h R q j T c 1 x i I l H x y 8 g v Z z a R V x s H U v 3 S 1 w T t K d p N 8 o U p f j 843 P i 6 V f a e M B Y 32 I w X A B 6 u A j 29 d 3 a z A r D T p J U k h 2 g v o 4 I t F a K k 7 K 1 / 5 B i + B 3 A B 7 v 4 f C R 6 w 5 Y E T N W b q O s K + J s a y Y b K 0 q l l p g 3 p v G q I m h O z I y q z X v 8 T Z i i J W y N 1 b 9 s c n M a P j m Y V s H J L r d P p S Y g D k m 3 k Q O Y 7 P a k h a z D l D h H W P n T T x 3 f W Q X r n A o U s e i A N c h r a T V C + Q h T u 0 1 y 1 g w H e f h 1 k a 11 Y O X O K W g y K e t H y c u 4 J 7 K b p N O o 7 w T w H J c b C h S F E 1 X 8 r F 3 Y M y M z w m l + 4 o x M 2e1 V V B p 3 l L S X Q w T 98 P n e 5 k i X q M 44 G K 0 o X h 3 N O 5 C b f m y P z j E 4 K N j o 98 I y R S I z 572 t w f + N 6 a i E v O R l W P s C r 1 H + S d B 55 / m z u n a v / T Z 0 0 10 d e i U + 1 u R H d C U q c G N V i 3 U r N W 9181 e o F U n f p / w a I Y B d y v d 84 o H r m C L M f Z W T 731 K Z R d o n b Z q O h W b a 0 H W O g 0 t E K w G Z Q 8 q 0 y V U v B C X y 6 u w 2 R 6 M k d 91 T y / r b L u 5 + + h + 8 k l a x N s D + Q g K x / M A x 8 b R 3 I 2 t h G u e d P S Z I Y N u u Q 5 H W k J P P S v K q t X c E x k 2 F a I 7 i 1 b 9 E A T E T O w L 2 C U m Y c w U 4 W f W 1 e N c A d k O O 1 l h P 3 q 3 b B B e g S X R y t N y W z j R B 8 e V H h 5 F + O 7 o V Z H 2 M x n l u 28 e S f A C n w q W s e S 63 s K a H 8 k l O k w X 21 I Z k F + U r R x j o K G O C o B T 3 j a X U 1 T v i v h 1 w j d I m J j q k a G W f I l a n c O Z m 6 t u 8 M p n X t g J F W O l 6 W C N 3 a q 3 D Q M 952 K 1 X D 9 F f 5 Q G 6 I E B 35 Q s N C k A 75 p T A 4 y W 4 Z y 8 l O 3 I 1 q A 4 w 9 T j g E P h 9 H R p 7 q T / l Y M c 7 C s + 4 Y b y Y n v j j F m 64 Z 0 G i v K l L q + r l b i 12 u J s m p k c E S P M I U G e s s e e y Q f t e X f 1 G C W O o 5 d A W n K 2 M r J v K 0 F q t q A g E K d O R H K L R L Z N 7 K b G h 8 d I X D B F r n Q 9 W Y b 3 W b v J k w p C R s 2 a Q + N I P N v U u i + O D I r v v m p / A a 5 U / c a 0 p z e M t b A + q F z + A y q K Z u + 8 + J t K + h 7 f q q C 7 x Z M h V 9 k Y h r A P 3 y a M r f Q C h 2 E d O I r G R X 5 o f x F F v U P 9 X b 4 r A P x B r N r r e d B b L C N D 2 p k V a V C q N c R Z K K l x B R l d p p k Z c u P l U x n f S U g A 1 m P s N c y B C t L T p 6 f t m N G f o N c T L L k d / B 6 T M l 1 i j T 1 I q
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:55Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8827-be80-40d4-8954-4979950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:55.000Z" ,
"modified" : "2016-06-01T07:00:55.000Z" ,
"pattern" : "[file:name = 'pe1_encrypted_b61e1dcf.bin' AND file:hashes.SHA1 = '3b7d3bdc7367859c67c7995661fdc21ff629b908']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:55Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8828-2dc0-4109-b0a7-4fd6950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:56.000Z" ,
"modified" : "2016-06-01T07:00:56.000Z" ,
"pattern" : "[file:name = 'pe1_encrypted_b61e1dcf.bin' AND file:hashes.SHA256 = '67c172aaf14598fb6e0b8daf5b33872f96acffa178571a498752921e88886bb8']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:56Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8828-dbac-4574-959a-484f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:56.000Z" ,
"modified" : "2016-06-01T07:00:56.000Z" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A B w 4 w U h M S e D n J B I A A A A i A A A g A B w A Y z d m Z W U w Z T A 5 N G V l N D N m M j I 4 O D J m Y j E 0 M W M w O D l j Z W F V V A k A A y i I T l c o i E 5 X d X g L A A E E I Q A A A A Q h A A A A t U 2 m q U u e U E D T h f H k K J o M p Y x H L D h / P 2 b c Q U E Z u r S j 48 p z M m w g + 0 N D 7 k Z B i j + W j X y x T k x f u j 3 W u n h f I X N n G 2 l u g t B y + G I I g N d P 6 G G K H C Q e G D / g P V r t t m a u b B 1 y r P E J y L L b A T z 1 G A x T O M K 7 O I D h B g f b C t + H r a 2 E l s D T D w w 9 Q f P R X h x q 4 z e u Y m 3 k m 5 t U 8 N 3 k V G F e c j i a k M P L / w Z t q 2 B Y M o I 3 g S D C p g l V x A q Q 7 a 4 C o Q 8 C v g A O c a K f V j N 3 e J 8 Y x n 1 R / E H + S Q O r M 0 z v K Y L 6 U u q y P w 6 a C 9 o c e g 9 I B M z k X L W C D i o e + 62 g R n q B 46 X V J Z N 7 n 4 / g C v 2 o o O F D 5 x Y a j Z g + 5 C n f 3 g 5 O 0 6 r N y a X N m T G s N q S E D M e Y Z C D n P K U d H O g / 9 M m N r B W z h 8 z H l 4 M N B G Y Y 1 I v f W A B x m + T 4 u H e m A n K L S / Q S H A j 2 v f g Y M i S V I C E R F S j v G o y G 74 r r O + y Z Q s F s S Y + 0 O H b j s u s L D x Z w M b A p N 4 a I / R L f W b b H P o 3 m f l / y R f E z N C g d s N 8 P F U B r Y W + M Q s F n s N z 3 i R 9 o K W d 5 e V v j s F A o E y K q s 9 l z z Q r J 0 h 2 / 7 H h I 6 J v B W u c F Z j s 8 + 0 q 3 g m e q O s 0 h h A 7 A v M 75 W R V u K 340 l b u E I H C Y x B 5 T H / Q / p R X N N 4 R o H t R 4 t a X q D 9 r z Z l Y m J G O t d K m q M w R 3 o z x a O y 9 Y 1 r P s c n h r I c O W Z Y 4 j N F K e n H 0 c Y y w V 5 Q 1 L 3 p x 5 q L j s d L o D Y O D b Q Q 8 q H l r 57 O 4 w r J S 5 H 1 r a U N n V b P m Z v q R 4 S P r 5 K f F 2 L o l K 7 P L m O Y o t i T h T / r s z M A P J 1 u r a n o w S f 8 Q B M 9 f o + 0 F Y 9 g L w U S r f M o x h 5 S F t d 8 / V a E d c b C K 4 I o + B 5 w T b H l e w c H / a G f R x L 2 I L 6 Y c H s Z y t K Z x R N 4 K D A r h b L 9 Z N l I t l w b 7 w g n T E L 0 75 T p 5 Q P O 0 p 3 L K j + 5 N l i I I 0 Q O k h e 2 f 67 e w B p r o j N Q l v 26 g b d 8 z M y V P F B l Y n 0 C m o Y / 0 7 A J e R m L w n D x A Y o 2 Z 5 S W D G g u 0 S w w u s u N n l s x s Y k P m L h A 8 f N F S H v L c E I i Q k 9 v l 2 z S E m c K K M 8 N b 3 i C t r B R Q a 9 J t g J z U F g 4 y 4 m 65 q l m N s c 1 f r g 6 Q p n 0 c 78 Y U d x a e f r I N 24 W v m V X D + v N H x 5 A I l o j P s i M y g O A Z g 3 M Y R p 4 I e g X R b o m f r 8 w 8 f g 79 W d Y g p X E H z W n X X c q m e L / 1 + S r u q V P 0 C b J d m V 3 Q v c A q 0 i p 0 x A L n j 4 t g H q i 4 m 8 B K t e Y 37 V t l r W i X x U q l 7 k G 8 l r n v H X K 9 X o X 7 S J v 8 P r M U w 7 r z / S g n H B T 2 o 6 L z q 1 G m U e e / 7 X f U o 1 T T s h u 5 f e T / d R Y b b t d f u P G w 9 Q R H V 1 o / B + / l r C o 4 K H 1 n v x b r 4 F g J 1 B y v G x B n B 0 h 6 i U r t N 48 N P 8 p R P 33 R 6 y C A V U m / 8 k g Q O e n V 6 j y T b M w j n c M 2 k N g K M 4 u H J j q X j b 54 u y x 2 I Q L u B E T z 6 E U D H K l 0 p E s b P d y R h q a M O K + 2 o g b A p F S j u T J F 0 M 0 m v O G H c 0 6 m F Z j b b u w Z n L k i B z 31 N Q j G W a U T q q E a 4 J u q Q K Q N v Y V T a e u l j Z f 1 O A 1 A m D V S p v + D E R R x b J p V P 1 w 7 C W 1 a K 5 E n d X F 0 c h h P g Y p / w / G 1 U O r o A B F e k g Z e h d d H D / 91 i 1 n M 1 O c F Y l R u 6 + I b J Y Y 3 H o R R 6 u B f N A t Q K e z k 1 H + n U c D Y / H 4 E d c u G z F p 3 W l 3 Z p f W n F n 4 B s x T Y j a h Q W c X O q 9 H q 6 e n N 5 T H / v J h 8 l U p c j r V J c 6 V z 9 H h h q C w D b E y n M W 2 h y v 7 y m Q i Q H 2 K l B x P A + I J b B t e 55 w / 7 d 8 l j m V B p L 4 Z O 7 G J x Q e 4 f r p C 4 R G g j F k p T e u z m j 4 r 5 s v 0 D N 4 H M 1 / L O r U F b Z t f x M T q O k W m h Z N d H 6 D x d t A M X 5 q h Z x U j Q a 0 Q T W z f 4 C P m K V u n R d D J P A d G T D G Q Q H x m h w d c s u D N c S P r M x L c G A Q / w q h j y z U + J M 9 I U 6 q U e T i J K H P A i 67 w 8 t 6 H n 41 V A 4 t i i j s j D 3 M 4 / W L O m w D 0 b u n s d 61 Z Q D O Q Z b N S y + w / f t 1 S 0 p H y R B D B V 0 J j X I K W Q / E 9 c 7 V q o x m M j o 2 R o n X / R 7 H 4 R L P v g H 9 B n R 3 q 8 v V M Y m e Q G M R X L Q R a I F P O l w r r 9 V k p H t c 5 a 0 O V O 9 O e s E m S H 7 N b o U N d i P Z d t P A W Y m 8 s O u J d G M m o m 48 j L 0 K R N i Q 0 o J G u 9 B 1 r P r q / Z c 55 F J 5 g h 8 J 6 i w B 0 26 R P x 13 d G z G S F R s w w U y 8 O s w 7 k D F E E A M f l m H Y t L F I 4 z u P w h V E 4 O 5 d 596 W 0 N u u o n x S r M S n C R K + L Y m 6 W P Q Q 4 R V W 7 + m R 2 W s g p T o U N 5 a Z v w y E P 9 k P r S H M G 4 V w 4 P V Q N f T Q 6 o d / u L 8 W N n u u c x L 3 C T v p 5 A c n N x I w V g 2 v H d 3 C C c I R 5 x k O s I k h X S u h w e 2 s o p t 52 l k 3 T z K m 30 G f Y a n z U 3 N V v i x J q Z c O 3 h N o Y t M V Q R + Y i N F t f 0 D C G o E + R B 7 j I M 0 L f e Q o Y t r 6 M m k j D C G y r e s L L y m f d r Q z b q c c a J y 3 t w v w Y J c z w i E / 3 C J 9 g N Q z X E N r L k + g L c 2 s 0 H n 9 p W j s g f x Q u 9 S 91566 D G P D j + + B r G n 6 T D C J r M 9 k d D s T G h G Y O q n 5 Z r Y N u L V J Y E 8 y / u o v s 6 Y 6 / a t O 8 s f j 92 z n z B W 3 B f i u U u t Z b C f q e W J g A H R 8 J 55 Q u B 6 M 2 L Y d h e q o o L f M 8 n 3 q / r C E y 1 O x C a W E V D x F d 15 r 8 y W U M 5 Y y R T 1 Y s U k 1 D V H Y 1 a g 77 y u b f m Q F r G h K 1 K O 28 f 10 t E C S 0 q H B G X F q X h Q x S P v h y P p o m Y v c K r 6 r z 6 R w c T k P o O 3 N j M N 7 p h o k C P Y U v j q Q c i N t s v M C u T V M n K C P f u V Z 8 q 5 J G n E X D q X + k p r T U y z u T x b G w Z P d 9 s j 8 f I q 0 5 p 29 C m B T a N G 1 w Z y H y v P J 9 h a V m b I V m o W + A j e C R 2 b Z a F e x H F q j j V e N h j V h R / V m 31 t 1 C y e P W O C m V C S r Z u I k O E h H V k k 6 N 9 d W A g + p K t x D / R q 1 r b / J j r 62 l p 86 T p r s M K g X n S 5 J G v a 4 i T f 4 w q g K N w 9 E o b r A l b E e z H P t H / D D 16 R Q l d r 6 S v 9 p o h 7 i + 1 z b J Z E D 3 y j B B H y F T k h m O Y d S F 3 m 5 d U i p J D A K r Y K 5 i 8 y F A P N w n f Q N j P 8 P 1 Z Q 7 m U p D N u Q + E 3e0 e a X e W Q r Q q x C o o W L H Q 5 V A p c q P + G N 1 a I k / Z t x i 0 g b 2 f U n l Z 9 A r 0 l G e K A T 3 m I t 8 Y 2 I C I K x I S h I J v 2 D N l q Z H e f d 61 L 0 l A w R z w M u R 3 v j J H L 1 V d 2 H O B a R L n i Y Z l H j 6 z r 5 D k k I 6 f Q O k G x C Q 1 a w F O 0 C C A r 7 g 17 v 71 i A 1 H v g w j j 59 u G / K X b N + b q B 6 w 7 + + k L p 8881 J d l O n p F g O p c 18 E y M y t Q b q 28 P S 0 A Z S / 3 a r 4 D a H D K q d l 2 s I 9 l H v d H + d e V 4 x x S i O 3 N W 8 U 97 L U p g 4 H E w A 4 u 8 g m D m A Q i z T q 7 P j U A 3 M 2 i 1 q D J b e s 1 S r s u A 8 d E Z Y j a u R G a A f o J T A O M H W i b W + 39 L A h A 4 L v q b H h U Y c a W s R F N N S 3 K 6 e p h q a Y 0 L L S V x p Z m u b a 3 V E U T a k h u 54 X B 25 d D I j a y N P Z 59 + N w f C v u d 7 Q V 7 L 4 g L X 5 s h i / D X G r 3 f C 9 M g S H c 8 o E v C r s i y q V F h K + V 0 S K Y u o H m L m m j g x M P K K Y 9 V m 2 z U M D O A S 4 R C O p S y A R T Z L o e L / i v w 8 k 5 n m 4 M 4 i f w 4 i Z l 4 y h y O 1 P p o F s + Z / p 9 w n v h O O g 1 A Y i I 5 f v e y I 9 w R 9 + k + 6 v g 1 b z r Q n f 8 / m h 8 n 1 D 42 q X 9 M N l V i V O Q F g l l D r E W M s k 0 T L Q U a z m e n + g 4 o P s 0 80 x 3 X Q L P E C U O O y j K K 0 p b Z 709 O F p i s 504e11 + 2 / p F Z h C L f + Y H k / Y 35 p 6 F i A z L 3 M I Y P Q Q e 1 o x I m d G i f t 5 h m p q Q G x J y X Z X T a T + g Y C H N 8 A 6 P D l v N B 9 A 6 h 9 f T s j W l G 5 M r c J n h / H m q S u U i C X a n o A 4 L + 6 C L b K m D 8 l c E W N g q z 9 g u P l T s C 0 m g a a R K + K A p S K e y x 3 t K T / z 5 d y L + w l z d E W g N M 4 C Q H 1 p J 0 H W h r o 44 G 32 u j b Y b J / I 9 T X 1 C n q 8 h E k f Y w c 1 P w P z + U Y 3448 k a N J j p M i f u j h 1 I w s w 0 M t C m 14 P f e w 2 u h x Q k E G x 2 C G j Z 9 S c U h 95 N H W 1 Y D 5 B k G T B Z 7 Z x e + T e t L 0 R Z i D R P H r U W O 2 B S 0 59 Y a l q 1 H D
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:56Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8828-4e24-43ee-8ee9-47ed950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:56.000Z" ,
"modified" : "2016-06-01T07:00:56.000Z" ,
"pattern" : "[file:name = 'pe1_decrypted.bin' AND file:hashes.SHA1 = '24a80cd100274e2c39180741aa688a4e73282552']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:56Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8829-b1f4-44ff-9cac-42a3950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:57.000Z" ,
"modified" : "2016-06-01T07:00:57.000Z" ,
"pattern" : "[file:name = 'pe1_decrypted.bin' AND file:hashes.SHA256 = '3103a27193561218be83d26071701bf1900aecd3a3994fc4d12e7521acf97ec1']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:57Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8829-e7e8-4a36-b3c1-4079950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:57.000Z" ,
"modified" : "2016-06-01T07:00:57.000Z" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAB04wUiFHz8ZygEAAAACAAAgABwAZmU5ZDY2NWZkMDA3Nzc0ZWUzNDIzNjEyZjY4MzMxMDVVVAkAAymITlcpiE5XdXgLAAEEIQAAAAQhAAAAeETg1+Gj5zS13/H1PFRyTgWpn9bwpQ2rmFJMAz1PpikY+lTdJGe/xuEyCF1Sw5+wJEGAaeDv2bbgnC2fs0wpzydyZ0LJQDifBeeWDq5IdhQ2ED+NzFn2vk/xW8Yb/1yNKKjMoIzlsFj7Zr1KA6b8XrQ+XPW6yFIeH+sZyhvcmQul4J4FYqxNY1+sObBzQxIYlmYftsJWItXDRZfcmqIkBaVKihYkgz/H1qHH3vLfbA+0CGRpWgoLTLrUK3zdB1xTr70Cxmn3xB94YozMwqgUR9txWm7qW76k+bRX+2jBTesZYQPrT5QXIxtSJr/o7SlGvFxSbtcyKNHHnkoLUQjto2fM2pa34C9o+mirEEJzT5NJ1peu9BlXyONBlB99rv1Hz4rRV61eKwL5bcJ8vcOuyoooWMTakLVjP+UGlJKicpqMnqCI6HKOOepzVrp0JMglx+htNGT8Nny8JpkPHMqNlcqiJcqxJs9TV2Z8JkoGxSWLZixOqGs2PdyUUZMYrZ2s8II8/IhK9afhkQNWWeEvpuj1SUXkLEmFZ1cf3Lmmi4izTc/5qC0Oxtav6ES+aFwBq9Xu7iJgiAXfes+JOgI2rxD4CCCRpp3t6L1QSwcIhR8/GcoBAAAAAgAAUEsDBAoACQAAAB04wUibWtDEGAAAAAwAAAAtABwAZmU5ZDY2NWZkMDA3Nzc0ZWUzNDIzNjEyZjY4MzMxMDUuZmlsZW5hbWUudHh0VVQJAAMpiE5XKYhOV3V4CwABBCEAAAAEIQAAAEVoUDI9t7dxS4DNFINyWeaz27XQHZEJO1BLBwibWtDEGAAAAAwAAABQSwECHgMUAAkACAAdOMFIhR8/GcoBAAAAAgAAIAAYAAAAAAAAAAAApIEAAAAAZmU5ZDY2NWZkMDA3Nzc0ZWUzNDIzNjEyZjY4MzMxMDVVVAUAAymITld1eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAAAdOMFIm1rQxBgAAAAMAAAALQAYAAAAAAABAAAApIE0AgAAZmU5ZDY2NWZkMDA3Nzc0ZWUzNDIzNjEyZjY4MzMxMDUuZmlsZW5hbWUudHh0VVQFAAMpiE5XdXgLAAEEIQAAAAQhAAAAUEsFBgAAAAACAAIA2QAAAMMCAAAAAA==' AND file:name = 'mbr-inst.bin' AND file:hashes.MD5 = 'fe9d665fd007774ee3423612f6833105' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:57Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8829-3a74-44b9-bef9-486a950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:57.000Z" ,
"modified" : "2016-06-01T07:00:57.000Z" ,
"pattern" : "[file:name = 'mbr-inst.bin' AND file:hashes.SHA1 = 'b3343209bbaa365d9768ba415f0e931d40a60d4f']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:57Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e8829-33bc-4a14-bf68-4572950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:57.000Z" ,
"modified" : "2016-06-01T07:00:57.000Z" ,
"pattern" : "[file:name = 'mbr-inst.bin' AND file:hashes.SHA256 = 'b5b3f04f3b7f20ab103fb9d35eaea8e305a975a2713eb98e14e0ab06701a60f0']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:57Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882a-82a8-41c1-9445-46fe950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:58.000Z" ,
"modified" : "2016-06-01T07:00:58.000Z" ,
"pattern" : "[file:content_ref.payload_bin = 'UEsDBBQACQAIAB04wUhKj7SQywEAAAACAAAgABwAZGFhMGE5MDMyZWUzODk4N2U0OTZjN2FjYmM1ZDBmYThVVAkAAyqITlcqiE5XdXgLAAEEIQAAAAQhAAAAZDlSDLH0iJc4VHmc7msFiZJeOd5eZcTbN0nUHVNEu7ypPpVLe91kyWvkUAvDRER6FXgXCnR64AW1sm2Lzl1qJAHX1ov8Wsk52UZkIELttk3KHxjBgXtsFlYJ4Big/6H5QVCphezu48D4P7sl+xd2LDEDzEV/eUrweEJZm5crBLAG3EWVDJGITtIvk3CU7ZRInpxKrv/URwfSonjKqIziLaqIi5Wc74sMwzBNJOqoLY+zJZK6EgnP4kDgZbuhkOSkkWkc6pswuF6+iVOAe90SgBrnNEY1DWd/ervmdINC88K0x0MfzfJ4MasWJyWk0xLKO46yFhtKqVAYXVHXQdIfAQYifvrGtIeWjhOhFkX7b6CMCbmt/Vsh4B9RQQRUoZsYgeyob2V6frNyyt71x8cdsPLYRA+bbEGrrfSh4+LvEKkc/GAW4shHePNITRFMorI/x2XI/rcGkGkTJyMN3BCV6Jv62QVpzRaMSQ11DeH8eYg7ckLGPIVscniZrZLXtvMhKIjZ/2r8hpG1RH9cCI80P9gj+qCZHYZomq6MZ7p+p/ymIvYhYEAoo06XN8QpdDRiaaRwwwQAkmWHaQHKfaPi4D+6qqcwO0cXwnO/UEsHCEqPtJDLAQAAAAIAAFBLAwQKAAkAAAAdOMFIkUgqVRkAAAANAAAALQAcAGRhYTBhOTAzMmVlMzg5ODdlNDk2YzdhY2JjNWQwZmE4LmZpbGVuYW1lLnR4dFVUCQADKohOVyqITld1eAsAAQQhAAAABCEAAACpKVJF5+rlXRnZu8gKTgl2UJr0aEf5xKP0UEsHCJFIKlUZAAAADQAAAFBLAQIeAxQACQAIAB04wUhKj7SQywEAAAACAAAgABgAAAAAAAAAAACkgQAAAABkYWEwYTkwMzJlZTM4OTg3ZTQ5NmM3YWNiYzVkMGZhOFVUBQADKohOV3V4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAB04wUiRSCpVGQAAAA0AAAAtABgAAAAAAAEAAACkgTUCAABkYWEwYTkwMzJlZTM4OTg3ZTQ5NmM3YWNiYzVkMGZhOC5maWxlbmFtZS50eHRVVAUAAyqITld1eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAxQIAAAAA' AND file:name = 'mbr-clean.bin' AND file:hashes.MD5 = 'daa0a9032ee38987e496c7acbc5d0fa8' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:58Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882a-7904-43ba-8171-416c950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:58.000Z" ,
"modified" : "2016-06-01T07:00:58.000Z" ,
"pattern" : "[file:name = 'mbr-clean.bin' AND file:hashes.SHA1 = 'c73e5ad09f669b3f71a645f8eee41fb5ddb1b08f']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:58Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882a-3c1c-4da8-9b1f-4b55950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:58.000Z" ,
"modified" : "2016-06-01T07:00:58.000Z" ,
"pattern" : "[file:name = 'mbr-clean.bin' AND file:hashes.SHA256 = '56b1851716d5947b3d25978c131d8ae46ad792dc481bb242b13d1c97f4741630']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:58Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882b-184c-49ea-86ac-4cea950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:59.000Z" ,
"modified" : "2016-06-01T07:00:59.000Z" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A C A 4 w U j W i w D 7 C 3 o D A P C w A w A g A B w A M m M 4 N T Q w N G Z l N 2 Q x O D k x Z m Q 0 M W Z j Z W U 0 Y z k y Y W Q z M D V V V A k A A y u I T l c r i E 5 X d X g L A A E E I Q A A A A Q h A A A A y n w 5 H J a 0 9e2 p L p O q l B i x 9 R F 8 J J a B g p J G K / 5 + z v D D c I 1 c T B 32 U T 40 / 7 T b i h 4 E W H 6 j + b S 3 f u 3 O Y G 9 q H H 1 c x G X m K L X M 58 b M 6 P k 0 t t g B y D M W N J m P R f L I J a d c G l s L 2 s 0 9 s c M M 4 m c G U g a 0 x d S q x W 2 h w m P X Y L B X + c a v h S e K 61 c I R s y q 50 A i Y v W X + R n m h f y E I 2 S u d T y V G y Z M P b N h g O / d O N b v B X w S B B C a H B F P S a R k i a D D u z z 2 P I f Y b f 1 e J 6 Q g b V T i d d F M u l F M w W 1 C W h N X O 34 H v h l h / i t F J w t i 1 B M X s Q v q J N R g B 3 H 8 t / v v + 0 + u D 4 I E o s 0 f p r 8 E f s G x N 58 E N f t h w s f E t C q M g K 10 j 8 x H o U X a k I O z Z i n d 0 V r W b F 4 L t N w M c M 5 k q 3 J y u Q o r i D D O s J V 5 Q r V I I z v z h J f J Z R 3 E g S N U r L I m 9 v c F x 0 3 v r a R l j c F u i I o y p G a P W E J H y s y b x 7 j o e q i o 8 K U f G Q u a z m G Z r n A 4 Z O 4 p u e H b 7 C P 9 K W w o J w H Q / 4 N C o x 2 I B + 6 y 0E23 d w G 86 P b f + q g 989 S S W y Q V F V b M G q T m d l a t z n B 8 I z R G 7 G r H l i + d e L o F s I 3 g 1 A 4 K 4 R Z m Z b d n h G 8 R l u N X n K a L 64 R z + 66 V E S 1 T A l k M W u 0 C L f X i M 2 s G 6 y b a p 7 X z z u b t p W s l t L H A / D 9 T L h i d K F K + c m 6 P A n m 4 a m X 3 e Q v c 74 u t S T G 70 B c b D x 7 j v C J M k 19 S M m o z X Z 9 v j G W r k I 69 v 0 q Z + V A C n h I H E A D x N S / H O 50 v 8 d g g D t j k Y r V R j i / L P Z f B P v u s j b d j Q 0 8 E e f t d j H 9 O a O 2 R j S h s 3 f 0 D Z e b M Z Q s Q V z k q 2 R r D n 0 z 7 E / p 8 M 4 W R z b N R w d 1 i J J f g g Q 5 b m p N n W q 6 s 3 W X r p M 15 P a G T h N J v o M 5 b F 2 k x a f T U s / t w L I 0 s j A u Z X B O V t L D T i 1 s v / G P O P W i e R r n D X p c e a Z o I s P W 2 g F 5 M d 0 g 71 d k r a + k E + 4 N a / D 3 + K K F 5 w / 2 s h + V t e P g e v N I q l r V J j / 1E0 h p s B Z a c 40 B 9 q O l n 2 I 4 p 837 D O e w D J P n y 4 N 1 A d I Y N a 5 f A 2 I X 0 h b q D 8 J G P e k M m 9 L j D n o 4 o O G D F Y d c I X 0 b v 0 K 27 P j 3 / i G I y a u 6 T j 8 K g H D 7 g / k c z z 85 U n U 57 D x F c Z 65 a 97 M v M X 9 W r r 3 X 9 c j x B t H y B t 2 S 4 I S G i K z d a L p k U H U e A m B u I s Y a a l 8 M J K G g / p u l b 3 q i E R s q g 8 i D L X A J A 0 i / S 1 K C E 0 A z e X i I A u G H c L N w S 3 R / s e 2 h g n W J 9 M q R 0 l e B S 0 j S L d u y b R o / 8 R P + 3 q o e 9 X 6 Y 6 H 4 I 4 f 0 A / j S f H y r h Z d x J z T r + 9 A b Z G T 2 y Y 9 I p O v S i S t t 2 L M R 3 J Y B t y l K R h I 7 g N N U s G T L W 2 H n O R e q J v u G 5e6 g I E C B b q n F s O l Z Y p h n F + x O F + Q n G A M X G N 2 y Y O b n P a T j O q q o f D 0 l 2 O 5 p O l r 2 w b P s Y 3 r F N G p J P 8 J a R w 1 c a e y C u X y 9 Q h D B M 10 j u j s A I 5 r a Y I 3 x D 6 v r W u 2 H 0 h Q N J D 6 o K 2 l 0 G C 90 U y C x c i B N j D N n d l B f K t g / m e O g O t W m g n N w 90 l / 3 O U / c 13 Q Q W R v l h j 9 b c n u x 4 k d g I Z j y y 6 k v k 0 k W 8 V p 8 v G s U k v V b t A x 3 K n m E r E u E P P I Z y g F I s Z w L m V l i C w b E 8 p N X V B 1 o + X u 6 k x T 3 l l 60 f Q C a X C g w u g 0 + / O m M 79 N 0 c k 7 y R k b L Q o Y z B y p 0 d o n g N o C O s c E 6 Y n B s W J J e R H k h y T l 6 b H C 5 d S V O Q j a s G S t U 4 F / f Z e G S h 8e12 H t e F A 5 w h S J I S I u V 8 T d G Q 2 V o 8 E N 0 u t s X x G E f b e k y L X Z 4 D R 7 R e I + m O e T h 0 H 2 P j R 8 T W d / W F U E 1 f H H M 7 j a / 4 y 3 t 1 v Q Z 7 p + d 7 F N x F 90 I o 8 V f F c 2 G T n u X a q 0 Z d f E y s B o A T u 8 v C v 3 X 4 z b 2 L 9 a n r a H 4 M k / b B i K + O J X 7 M 3 W t U N K e p s e B W / p V u b y f + / C S w r 0 + 9 f E S U 6 r Y Y k V + Z P k m N g q D O r S g H a e D T F c 3 F c + 0 3 I F F i M 7 U O h S j h R L 5 d W y z H / O T 0 B i N i 1 d l l i e p m u z r Y Y w B 0 30 a m T I 6 V q H k u u a + g x 0 K M d Q j W u p l Z H m e A A a e F X s k X f k S q 0 N G I F b c i J G s + X V 8 n u I P Z b 39 s i k a / r m 4 J y E f U s Q B j M Q v q t o K z 2 Q Z / X P u 1 F A m c I y G 2 Y F t 9 u T / r + i / G 6 u b d n H m g b e c f x S 29 v x M W 0 V o W K T w T x 2 L F I x k t m F V L m 9 w k e E M M y 3 J d i f 9 i e b 3 x W X z + z o o N 5 T o R k E 6 p v r 9 r U V b F Z q X B z V p p / E m 6 l 0 5 m G T 7 K i 9 x A 3 c x w f b E 5 k y W h t 31 r b x r k 3 d G D x V e G 4 M S C j S C E 2 Z l p F 7 P F Z T Y F 4 g L x q r f 1 n C w N C N b m z y j D 0 n 46 J x P G X W O N q U p U q L T t Q i a m j f x B C e u L 5 X r f K j X 4 O K 2 f m q q V H s z U m 1 z a M z c d / W M z 6 A N Z T O 1 M d E 9 f 4 o N u d e R 44 m b y d 4 O g 8 L n n M 5 c U g v / i I H o s 1 S F O 7 B V Z K C V A 2 m u W y H Y Q 3 a 3 C A i W n d 6 f g 9 J H L d r d o 0 X e A Y q h J 3 r J o F 7 P h i h C 9 W 6 v a f H 36 G O u + V B J c L t N 0 U g 2 s F e 4 v 2 r p x c U O K H Z R Z 5 w v / r H B o D U t j u R h Q m 2 m P k n v s f g o X j c S v u 6 Y t v o t N A w 6 J 4 y p h g r 1 D a i L U V + J F n T a c a H k 8 g q R o E H e B s 0 s A 3 b 5 o m n F 4 I M q Y X 8 x P F e 8 H 1 D / Z M 0 c Z D d d h v L f y N B s P R h 4 A 4 T Y n E 327 h G f 93 S 7 u Z c g 4 i n V r 8 x s t x G U i Q s 6 V w 0 H 70 A C O 2 / R e h / t u Z N F 0 r K u s 3 f k k //m2in9yoweZCnSZYs0FG6baEJHXIv+bEN3OeUGLeYVvz9HAHNwPiSa8jRQJTnWhnOerryubEy90d+7dRavAKPdrIne7H+TCAJFpsE9dyS6A/4SRwfPX2FYIPRa0ItuGFGqNoiOOly++4DxRJFsd72bL9B+PagdDFTvd8Z88U9uYZMaYUGdLl0+FuTYkfGUUp1QRfPvI7D62l+caX7y3pJIUgd1SUTL5V7db4j5YpSqjjd++UfXGZtTSm9SJnWS+xk9X8RXap2MNyXd2CjyjJ0djYoAXVslhC9/acivQJOYzp610DaGpJTkQdq/8ie3bHhlBRplfimAE9r1k8Xixn2X/xjdQp3V1nDa4LUyhyAeHiRlrgIkHJkqTXb2tEt1z54yG6qnf5sDEmrD01Ly684im6bt4MdcBI2NNa+81pstehOP0M0gtFMUH66LfPB8DLy8Qupgb5lLtE7+HSc+Sv7W0qPIYRyypTblIrM5Qympt/hSD8lf2Ng7iYu9iy28Zoo2VjHocmbPwhYkDFZxJbXK3bL7kNE2A0nNklr+wzF4bFZc/An/g10/uIt15qMM6U38BtT2RrbDlGXEk1EkJNkKMFiL1OXdMnK5/Rxh3uzKMzxxT36rTluWeufADwh9etfwbDg1a97vFOLOoofHdoAtPez2BWki/7RJFnc98Deu6iac038Kf2gHsTce8BW3UWXDp3Yq8kH78545zsCl2MHpYv/obqW66epLmbXUvMj9wGnlruAYNeJItaK7lfomKupBiabApMHg1Rl0v+fdiFe0h+GtZphcFLd5tgG/ihJqho+A5xeKDagan8lOEV0QSN3koxTrtmgAngcXipCR0sO8ICn7C8d5KH8BK9/Eur2f336GkWRWPOAK7UiHXo518WLDxItmrtGwyFBy2vAFy7SMY7CatGU4eY1kIJMq9PinE/xADskOMtpCuvH9r3EK4IKJ3nBTNIayKvFpAzuZAi7GBaGSs6a7mR09zJksYNjU9kyKlLPUZnOnry1xBbwaMIfM43flF04q38wLkTC9rsRTECW7CCGiK88ArsgmBxUJpnr/3PiDFcVYpaLnuaDK3Z1j+P1v+dHuTga1eArPsMxR+w2hBFC3Tidlv2M1r9m3S8KGpin7iAMWNRnsi+e0+XJt5qzAxJ7t+zYRlFhzDVOOB3LXTQkIgpbaFEvQZgQREQQOR73iYdSvXEI4Q9RsUT/iV26KnXFEjow5K/GOzyYIcNhXSqlqRi+Hq3MZe6cFMxnvI4B76aHy1e5e83sFR+gANLk5aKiFWnKPAY
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:59Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882b-49ac-49ba-8543-45ea950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:00:59.000Z" ,
"modified" : "2016-06-01T07:00:59.000Z" ,
"pattern" : "[file:name = 'dropper64.bin' AND file:hashes.SHA1 = '4c3171b48d600e6337f1495142c43172d3b01770']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:00:59Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882c-ae14-449c-8e6d-4069950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:01:00.000Z" ,
"modified" : "2016-06-01T07:01:00.000Z" ,
"pattern" : "[file:name = 'dropper64.bin' AND file:hashes.SHA256 = 'a9a8dc4ae77b1282f0c8bdebd2643458fc1ceb3145db4e30120dd81676ff9b61']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:01:00Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882c-68d0-423a-a9b7-4150950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:01:00.000Z" ,
"modified" : "2016-06-01T07:01:00.000Z" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A C A 4 w U h T X U m A I S M A A E h F A A A g A B w A O D A 2 M m N i Y 2 N i M j g 5 N W Z i O T I x N W I z N D I z Y 2 R l Z m E z O T Z V V A k A A y y I T l c s i E 5 X d X g L A A E E I Q A A A A Q h A A A A W X / z D f 5 X 5 K Z 7 V B 12 K p L f x H B P u K S V T c 67 B J F n M z A Z J A F H y z l H P 3 i Y n 2 X P G 3 V + t N S M q D g W D 8 b 9 Z n r U E K 6 E d Y r N 3 i W / 4 n 8 p / w 2 j S E W X G B z L 6 e o d 0 w x 7 R D F 43 h m 67 p 0 B D Q v y a M n a R l D c S 0 4 A u S t 92 N 6 I A H l 4 t L w f v n Y P m a w w / O m M v Y 9 l F H 2 B z q 0 N S m E B 3 U b a W K j b I N 2 L X I 4e1107 C C S A v H y m f 0 4 T k P m U o J V b D i N l D j O p V V q c K L e l J 7 + R F j v P T + P k N a D M r 1 n 5 Y p Q N P k t l k R r F P q T S Z 5 c z F v i 0 t f H + q Q x 8 U y u f / W q / i d P i n 8 E B j Z L L Z K 4 s u j f W 9 q 3 D Z X / D / M 1 o J 4 T l I R V b 3 l I w f i a t o F I u W 6 B 5 y P E U P L H 7 E g L 5 N Z s E H L W C 3 P i x F j 3 B 0 v c E a l Y F R r W z Z u L g z D Z Z z B r y V d y L D v X h o j / D m u w w o e h K E W d h 2 r R 2 t + s f j w q k j V P L 487 b Y N S v n t A y + w L T E U g t 57 E w A Z q s 5 + m 8242 Q B z a Q h w / v Y 4 S i j W S c 8 J W L t T h k K / U s Z L F y H F Q h W A j u 33 u v Y r C B W i m N Q 1 K x o D O s K D V D F 771 E h 8 K m a N 0 W 5 f 3 s n y h V E B n g z m o M v m W y x g T E 2 / X K w A d f i q I X P q W m L V c O 8 F W P D W W R 8 k P O X z G 2 P m s P + k i 739 A X u 7 l X H M O W X M p e 9 W 2 r g L y v S + B V k 92 I a M T / p M o S 78 P O V x f E E t 4 M b + I n l + / m i p W W g y v X h 6 t 3 b r / g 3 m I O B c r 9 L D + A x 20 I S H D l / K p j t D M 4 r Y q 0 f M m R Q T + V r u 78 R V 8 D i e / Q N T d W X 54 k l F v k P O z b B S T 9 z 7E1 q g Q O T 1 Q E y 2 D 5 H j 6 S r b s p e 1 w 6 k M a o N k 0 / D I K A C Z I y x F U O W c t N Q O o l A K P T 2 / x z z r q F I I J r q x 7 H N i R 5 / C n w H k r x N b 0 i K H n T 46 e A 2 U p e 44 P N u D 6 U / 5 X t 5 l W I k l J G 0 b F Q q 8 M 5 l n j F Q c G D S v d M q t P V q r L J N g j B B 73 l G c v U 0 o X + O 9 k I L X D G m K 4 / X C 1 V J a 4 B c + z B k l b q 7 M 313 J 457 x 6 r 8 q u p o F X e M j c l L R E h H / b v F h 0 t e y E N a Q X d R H 5 p p 7 B t 8 / 0 G 9 j + S M Y u g v 5 I k 4 L K 61 J u e V z I r 87 X T 0 M 203 D O I k 9 v p X L n o g e e 9 w q k 5e9 E Y 3 a H y z w o 9 c F p v m S Z J i r N 9 M T 9 M O a g P W K 4 k b g W o f v 4 R r 5 B 5 h c V o a S n e Z A 9 m j D k K r S O Z R 4 g i O j y L L Z Q N J v J 4 g 4 x V 1 j 3 N A g 9 m h z Z p D H r v c 0 W B 30 t t Q A B f j M o y V z p t H I m Q j N v k 9 J f 7 J e j O i / H r S r B M q 45 q U R a C v h q k X I b J d I Y S V g z L R / d k 6 t R l 9 H q 5 + l J I k e r r 1 B e x u + w k P 4 f Y J f S Q r a G u P M F z h p X P q k x 9 T y M s O f + 3 T G f B U 5 j Q r I M j G p v m a H J g z f e i R R f S n j s C Z l J w N B M Y Y I d M X u y z M y v n v Y E 94 P L p E 2 w / L H l h v h 4 u B k w S q l M E B P Q V s J N R M p r P 5 d q d M s C l R z j x d 7 L 65 s r M + u g U M J y G T c q i Q 24 I G e 6 A w o g j z V I a N t J Y W Q v f 8 l D H w q Q O B j A y B R t C 1 H g Z y z 0 e o d Q Z x 0 P 5 O n i d V m x J d R J I K U 5 m 0 f e p 14 e r m B I + v A h K p O w c q U f v n z / 6 R q V M N f d e L g 0 3 X 8 B X a i G A p O z 7 E h r / R E Q s y + w 5 M F u h P x a c f M H O A y T 6 + X V p O 20 + E 52 A y X U O Q H E F b e Z O O r s / 3 o n Z p I s B F 3 D C K A P o k / s e t p V M G T t z 2 n p x m F + t X N M O / D y 7 P f x 2 z U T X d e P 6 i D I T P M c E 68 U Q x Y a O v f W S b 8 g i x / j B h / H D p 33 a 74 r k 9 x A 52 J V m n z N 3 z + t m U M H 3 w q 6 R k 8 m s o J b t 0 x X s X G y e 7 q h 5 r l H b f i q v Q S W / q N F P M 1 B 13 F K q a Z Q a R Y C 3 b y g 39 Q E e w d 9 z 4 D 2 x 5 Y 12 P a f z w v L k k u f w d z P R I X I 9 e n D G j L W e J z v + C N H S c F h b 6 W 7 y F 6 A D J w k e J q 74 V V 82 o G t X k q d F e p 6 b T l x X T D o s X I C e A V k w u z R J h b x B y J a p c N Z w d v q A V U L I 8 D G 2 j w M s y a M u r Y Z Y Z k n 7 J 8 i X Q G h x S A c t h 5 p y Z H 6 L i h E W 57 k J i f 985 V H O w 8 Q 3 S 2 J G o H o A i Y 0 g m u e n x U I Z 4 i W e f O C N H e C n 3 i q u K x f E Y E T H k R M d K g 51 Z M 510 r + y t 0 j L u g v v U s F S + x Y 4 L O h J 2 r e U r f e n q v Y E 4 W M u o K 2 o u s l N G X j + q 0 A V I K h O r 2 U F y G t t w g l g T / z n R 5 u / d K r + C Q J v e a / c w O D L j 2 V j y D y d A w X i w 2 U T 0 8 F s i y 46 h g Z B w y S u a 9 c 0 7 q i f S K I e M / N S d f k a 59 r k K G k a S M I y p g r E 0 L m r T h c c p N D p s 4 A 3 C a F N b d r / f u 2 H V x g g 3 A P D s U A H Q M h F q o j f s X w t U 34 Y Y / N 5 r 7 O r h x A v W v K o P K W i F K P R U z x d g s z X S w u 13 n C F p A P m L e p K 7 W 8 D + Z Q j 7 V h c q e p k I x J C D N I f j m D I 638 H G i E G o B Y D x 9 n Y s l n l 3 H I 3 z A 4 I J 77 I t + 5 I D q N 7 V D k c v d J l H f L g k g C X m + 7 M 8 t 4 Q A 97 R z b I h e 1 a t J e h Y d Q O F h 8 V P U S / D q 89 t z j O 1 j P K + n i a u h L q y M 7 d p S a v d t h 3 b i 54 / q o z Z a i R + i O t o K p H t d L H p N A 3 S F s j T s x Q 6 F 7 L n 2 L W H Y q y K o W a D 1 I t r e m 4 V l m c P f 7 C f f H s M V J 62 s p A / c r q 7 T 6 z h t C P y + v 3 Y n E a Z S x C 7 j u 68 Q k g U m i C j g Q x N V a w l t 6 w X q 88 I H d O Z P C 9 w Z A l X U v t 0 8 Y k 4 U 0 M 9 q l j H T B e A c K e g 8 U 9 N e Y q O F M K i / V h x g G Y O X l 3 A d Y k 9 i s M g o t D l r Z T G 8 g v L k a 7 t d 2 D F P K A B G t p d 0 C i t 2 r W 1 Y R y P 3 L + U x Y q 7 W y h R O / H O 79E4 l D 2 E e F N K 1 z d z 6 q 8 c + / 93 P a 1 a A u L n s 95 e Y x s 4 e K L s M y V V 1 j m E y v U 7 a v c 1 v 1 K B q C S X P g e I + l L X f z J J s d H X h k 8 C V r g d K n y n s n Q 47 L V Y P j z L 1 y I L m C q A G i 8 A A C Y + C d P y F 6 Y / P L + 0 j p R i S t s h j N A 2 Q 8 q O 3 E B c w O i R / L u q P c 9 P S x R r h b S c V Y x C I a p b f M K s z q + r D d Z R M r X y F o 1 S M Q C / w w B 8 f q U f c r F 3 X R s C l t 4 y A F y I h L O m m C J x r Y p x y v a s / U n H 7 s V k 5 i J F N o / b g q W B D V N x d V u Q 63 b F J R n W U g 8 n K 33 B a k W 7 a R 9 n v A P N 35 E P k N 7 n Q 6 R p Z p T d / k P V R F 6 + + I + p E + 7 R I S d 0 B + H Q q + O E r 97 C / N S s F G D t M A t Y z t V b q a k g L h 6 u D N i K c i + r 70 m E G C Q 71 I q H B N 8 C 0 z + D D w 5 r N T a e V e K / x A J F E f 5 S L X J N i 0 t Z T i J a G x G q X x x q / q 5 e x J x + j f N X l g P v B M U h j I E O s u Y V P 1 J l 11 r 7 I x J / 2 x 0 K 76 d 9 F l u B F w 8 H r y x P / r f m Y i g W r Y s h v 2726 Z s d H P 9 M I w 1 j T F y w Q a U Z Y V 2 Z C F S Q u Q r / a R Y 2 A D / 1 R i Q b 978 d o A l G H l 9 g v P G L b 3 w F 1 / P V x H K t c v X B o V N e H i M Z Y a e X 7 T E x 1 m A 5 P n L x K p l p 5 s s z m p U T u 1 a v f A U z J z W Q 5 N n v i B u U m 8 U 4 O L 9 Y a r J N B 723 n 140 w i G 97 y 0 a 5 O x 5 K / a j 3 v R g N T U 6 v l F e T 6 l + 6 j X r I C E e 7 l 31 w g l e R p U y p 9 I D E l o b J m 895 C + r M 0 I Y 0 U P Q 572 m W G l e N K 6 V 2 c T v p 8 Q d d f f X h B / k 10 B E l j v m M G 6 / X D l X n 7 X X C C 0 W D d p 7 o a S S h r r S r m J h n R Y c e N o 49 Y n i 1 c e 4 C D T e f 3 p S Z n D t 3 E S j C K L 8 P l 8 l z C a h + i T h W j j q Z Q e X d z s B 0 o A u u o H M Z y 3 o Y K Y M s i K t 0 M 86 v 5 M N g + i x o 1 t 0 9 J O z i 9 B h d 0 T / 3 p V n T z d S M P / 9 n l 2 + W O 77 J p d i D + G E o 6 T s v 3 d l A U 5 T A i t M c E 5 N b k 7 b y g v 2 c L E G O b r w u 1 F w u j d O A n c B a 3 g 25 P O y 7 p b P W E b 7 u z o 9 m M i O h k k 5 E u A U h 9 y t E q x P O 6 Q p M N P e D e 4 R 9 h N S E i 2 B p r j q 2 G x 2 + q M D U 3 f 8 X l D F E c E K x d 49 E Z 9 o 2 R x r s G B R H b / d M m 6 W t N a E E X U B p G Y R j R n M Q g R n y 4 Q / z Q R / 3 Z W 3 z K v E 5 t + X a B + 4 j U L U 9 B i u a 4 Q g N 5 h f K N N J p 5 K k I d D r d I u S C q H u k R 87 o I 1 + B B K x I H G m X
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:01:00Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882c-404c-42bc-b3b4-4258950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:01:00.000Z" ,
"modified" : "2016-06-01T07:01:00.000Z" ,
"pattern" : "[file:name = 'driver64.sys.bin' AND file:hashes.SHA1 = '268dd909933c187d2798b5815674d70b930b498e']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:01:00Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882d-4388-4b99-bd77-4e07950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:01:01.000Z" ,
"modified" : "2016-06-01T07:01:01.000Z" ,
"pattern" : "[file:name = 'driver64.sys.bin' AND file:hashes.SHA256 = '4d887bd577541437f0572a7dddbcb3dd94ad259a52f9f57807011939854a207c']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:01:01Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882d-a9d8-45f4-985c-42a8950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:01:01.000Z" ,
"modified" : "2016-06-01T07:01:01.000Z" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A C E 4 w U j q d U G J F A 4 A A A A o A A A g A B w A N G R j M m Z j N m F k N 2 Q 5 Z W Q 5 Z m N m M T N k O T E 0 N j Y w N z Y 0 Y 2 R V V A k A A y 2 I T l c t i E 5 X d X g L A A E E I Q A A A A Q h A A A A s i T v i F D I k J t 0 T H 2 Y a L 3 i z g E g A H R n z 0 s 2 K X m O K P + T x s z 6 K u C E X 0 j g / L j J Z 8 N 7 w d u R 6 s u M b r p t C C O 2 K r 87 q 9 N x 5 X h 7 f E n O W + V j O c n d z 9 W c 4 X S D g K f Z 1 E Q c D p A C 3 Y F W t O e L i x x M V M v J o G 1 o J p 3 f D g / h b u Q e 847 W I G t B K 2 P L a t 9 D Q w H o c k 1 s f s + K g 0 56 M X Q 2 N T O l I j O D 0 i Z e W v j e / 44 h U i L e 4 t d f 2 a N j 4 W v + 5 u i w S K t O c o E b C h W m C p b 5 x 1 y C K 2 E c 5 s Y G z b y h Y X M Q Y n B I / l / q G S P 1 o y y J T T C b m s r Z 5 e i m o 6 O / L X v 2 w g + U m 1 e I 3 y K A 3 o s i D k V u J b 4 V h E z n O y 1 K H M O G M l z C z s + 7 W X w F o L e 2 i V m e 8 x 2 K j n + p s 6 j 6 b E I P P Z V S A p w Z b 3 L S S A h h n 2 P y 7 + s I y p U f a 4 i 9 W d i o s O u W n T V m b l H 2 b l f w L d t z v l V U m v M 5 E r t M V N I G G 6 u l O L Y D b U Q m 746 l H t 3 R c r + m M i i 0 X E p I l R c k Z J M 869 V Q 7 I w N W N O l h d 2 I o V t d p C 3 G A Q D A j a j B W P Z F V F b / I d c Z 4 h X p + v o p W t d v z 0 j B g 6 R d x U 57 V 4 S t b p Q 5 h F C V l d k I M B g p 6 o Q D J 0 F g N N i X f T 1 J o I R E s W L Q Q O f 5 s V h o 3 w n 7 y k t B l f e 6 b Q v B y 6 G 9 e N i o p x s I W v n 74 W 3 B H 5 J 1 K s 5 S S C / x A g D E h U A u t L + a 7 z C q V S g c k c d 1 w h 6 C r i A 9 r w Y E R 5 f a f B u + k p o v F l 8 w r 9 Y Y N W g 8 H / V B 8 C P o f X J Z O j 3 j 0 c 1 d 1 e c 2 b I 4 G T 40 f X M y w Z K m E t W 5 A A c k 44 w A 6 q A m 6 A V 4 l h J / C z p X l I c F r e f S m S N s 0 F d / + B w I u g R l d q o H a Q v f E U t C C B B j j t B e g 4 H a o S e 2 f s p m S / d u 4 J A O Y p t u r V Q T S c c Y n C o Z h s R c U G 3 / h V b k I V I p U U 3 e h B c Z y + Y F 4 S 1 W p b Y n J T B y 6 G u R t 0 b h n B A X z 5 i S K N a + l l Y E K 1 l p X e T u 37 T J W U m 3 i h A Z p D 0 D v U B w G F o Y V C b B a S x j l C 5 m H R r Y + 5 q L f 7 r e d U A n I + t d + H Y a 3 j S K b w W e h 1 Q 5 P x c o A / i u I U o U A Q C K E h F 3 t O P O Q z A o V 2 G R x y V 7 s Y Z T F D F b x 4 x m H f W e G 5 D 4 A I 20 V + Z l 3 x q X 6 Q y 5 g z f D 7 v k j + n N p z k b a m M P x C L 5 H v U 93 B e e 8 I 99 p e 8 m J z J f h A t g L w A r q l 70 A v G 6 c p R O U 1 X 6 Z i p H 9 I W K e E p A 9 p O N 6 N l g a i q T v W O M z X + 8 N E C W o 3 v f 8 d 7 W 1 Q q A 4 Y h i B b J E 0 S W c Y O V i W 5 b w C I C c N 5 v s r W d m 0 P l m o c e K 9 + p 3 F H 87 j o g / I t F x 7 g 49 m C D D n u f / e A m I o y 7 L 9 y L q o R 4 p j X Z Y k / x T w Q v 718 P r C I E 252 Y A I S 87 E s q v B z I 0 B 0 X t l L Y n M z L U B a 8 / z + K V T 49 D I j a y e l 7 + q i 0 7 i j N 9 H R T L l t b w x q 1 M 1 w m k 0 D i c 3 q 5 x G t 2 M A v q P e E M C Q B U S R / i p Q K K a 57 / v L 8 q a l P Q B f + 6 C z S W T l H b E c J m a x m 0 Y a + n r V 876 t L r s N Z Z Y u v U T Y p o 7 J t Q D 7 o Q p 8 e S S S H 3 z o g p B x 5 N h R 0 0 C X 7 V 8 j e 1 G B T c X 8 P S c W C v U Q y 5 W J R g L w a O 2 h B o I G C L z 5250 W k 8 x 8 O o c z o y 1 U 9 J d N W O D w / v J k A o A y w M o L 3 y G G g x v p p y N E E Z K z S q J a q O y R k Q 5 B r L / F e e P C K 0 I o g T S 6 D D z w z q 2 z R 4 y I M R r u L u 1 U k Y d w + 7 N j x B b N W N X R r e Q h k u V M 9 G m J Q M W R + P C Q G g i m b a q t w S o 1 u x p K E M C E o b 2 K K U I L t W c D X 3 U I r / J P + J a j K a w A / 6 L 6 s L O q G l U I Z q K C 0 w m a V 1 Z r x x 62 j z S v 3 P i G o D S 78 c p J w A l B B G G J m P L Y e / W e o l c w s o y t J z u b S a U c 3 A 5 R Y 9 X s X w H k l N F K I 4 v 4 f 8 K c l b N W w k r C 7 W 6 q 8 C g S U S R l 2 Y K e + n q c w d n J 0 w 1 D l X g q G j n n q F C F z + C c d Y i R 7 t x V B Q 3 x g T 6 Z D 73 / j k F 0 32 C Y H b X 4 n i / c P 0 Q + m Y 43 q a E O B L 1 i X + J M s a w r p 8 e k s s r z m G c i 45 + / 2 A O u A v j V K L A c Q k z Y 6 k 7 t p f r i 0 L E 4 + n i X e z t d R a U c + B P k j a p G u l i h j d a S F e R O a j V P N W s F E A G z R 9 + V M 9 a 2 o i a g O h l 7 L D O V 9 r j r u M T e e v N Y I r 8 a t u M O 7 V h d N 9 O p w l s x 401 Y I z Q I B 1 S D 0 O b d g g c i F b M Q 1 n S f N 1 O 0 U i u z h X m 3 W Q 8 a u L S X z I 2 e O 3 q Q i m D x 0 s e y P 9 l w B w 5 b I c e W a x h o h K c i P E A 9 y C r L Z j f R k 6 C Q S A R 54 e L + z s T i G V + E U T O y 3 u f g //thzLvlcrEvqp+GLFHjYZNUlhV0e6uYMNCnpdOeovwpbywNkH5Dw28qBfX8/T+fKug+I9BgO/RStV9zOMIcTqRoRwAkMmD65b3bmucW6yp5rXJGiMOvmSwbOjIlWkJ7Iiqm9L2xJhOCK+3DYYwUVSUm4hb0N8M0y/pE7BNyeqlcjmfT8n0zzIm+dufjk1mu/MuKOKqs/Grs84soqj6eLMPHks8jUkDci5of/M1o08cKsSUKKo3ZXiaaaxAzGP5IkiNWo4WkgVwHakPDVwA9g8xq1st2pwnLwVatWO8AMX5y0o4QippTjlg+eNH4h3BDeU2/bGEg44fVtzoZCu5NdYpogZvCCRJeEgHiuCiiWMaU8XC2zbKYLCOJ4xEBqwKvsPtUUE25phr4Zu37yiJGV28udzTnRLTT8xHjSIhbJK1gdqQn+uPsLKJ0Rg218TMt88cd6JIP+il4pZmHxOWdzKBT44nTR2nZ9Ahg0plBEzjjJsc7f8ODM4LYGJdCcAQw+8XIymqN81H3Cghs1H7XToPTNch9aG7dzE4YOjSLOczyis81GuM/G9LrvzCu8tx5gBWHj94wOibWbF3IEJHcyW6rbyYaLZ2dvcnPnt50RzzMDQeeAZnzNdLatVDfAivT76FBcLETKaDkJ84JYkkV/cTtiOlGC3Q2SAongD9PBshU1kjcuoh59Z4LPahZ61x3RVoINQ1ha+WK/uhiinJVspqkARsyODlbUiGH3RSo35Pk510sIvGIA17N2gvHI2BjxxrRliZO4d5m4IWebke4tEppXUEOBBcvUXob8nJQr0cQZ2O3RGyUqOduCWaIWnybd0NTwc4n9/k4XdrotuNZAOWKtFsQGJNWNQPwgInbcfUsjHoL8XLb2B53or593Cn55wlnSGpybvizka5ldfSwZOBiobVXYASHxzR8XO6C7kIIe2Bb7Sodw5K4HkHsenh0Xoz8p983252gNkHdQ0mJiSmC9z0OpjLwePuIKy3S+6HyPhCftlhdROfLCNKObruZep9nNJJKmdfGD7Z0G7q1h7wTZtAgUC253Uz7vi6g7AU06Q3lyPvlUDnSApllUVC+4dkO+1v2NdULgjyUoyal16FGIiOnVrFHKdwRK1PC7IGRAtJmGC5eZqHgDbB4lk5MdpqDwdcnPC9XD/nf5VzZtv5XkumiuGhHwEhnKoKDDleSfMSUC7cAZ+vYsymbsZGnk5LYFJJmmqUeY85xoH0EeQpUurUUX9yCefCoGpVOau0yxt0Z/MzjEQB1NROmMgQB6+Wuk6yJj68PF4kgp0ywEDH8COakjdcyCupTxAZQATwXemnLiq+8NxBdNFOIcoxsxjUyP/6HiULZAWACXWjEl7ZuN/K/32SdX9DyMwJCPxs+FnAhcqQ5VFkKuj7d3VHtwQ/PsJjqaypsDA75/z3HrClWNE3nCVG3B69ZYaKaj0ZqjKyYqzow0K377D3emy8kz3bwGCfPTvux8Cq5IN5B3tm6vrGeHHxd36wlwzqFYla/stzXoivy+RtS/7PWDM68g2A7E4CowPPOuySjZ+qnM0KL2Rm2V6YTbv8/vlEKXjvYEuybBcicXyzNPCTlAKlhYmauAvDWQ0R/jshJsSbX7Oi8JvoT2idXn8X4drYNY2pTU01jbVBEfG18jzZJh+gBoqEuh3AWLWXSuQjT3W1wnzhfVKCQCBQ66kwXRM1ze/5VhNXZftPKYGHzzzB4BMNi4YO+nYn
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:01:01Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882e-7ef0-4495-b8bd-4b9f950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:01:02.000Z" ,
"modified" : "2016-06-01T07:01:02.000Z" ,
"pattern" : "[file:name = 'driver32.sys.bin' AND file:hashes.SHA1 = '7ff22bd8667ce23e7db8c759bd03c15fb7226c76']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:01:02Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882e-0058-4f84-bacc-47c5950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:01:02.000Z" ,
"modified" : "2016-06-01T07:01:02.000Z" ,
"pattern" : "[file:name = 'driver32.sys.bin' AND file:hashes.SHA256 = '0531bdbe53e67095aa729809a6608be8cd04b7fc5b2cc3f6a610084cca062ff4']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:01:02Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882e-8cc4-4c80-ae29-4ec0950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:01:02.000Z" ,
"modified" : "2016-06-01T07:01:02.000Z" ,
"pattern" : " [ f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A C E 4 w U i 92 h / 0 W J 0 A A C J 8 A g A g A B w A M j g 3 Z m F j N m Y 0 Z G F j N T c y N T N h Y z A w N j F i Z T E 1 M D h m O W R V V A k A A y 6 I T l c u i E 5 X d X g L A A E E I Q A A A A Q h A A A A C 0 G D 66 C U 1 W f q f e N B 5 C A n D a k 7 w U A o N V f p o g K 5 p z t u G h K L 6 t R K g B e 2 c z q w H Y S U B 3 y a m t w X w d z 4 K m Y D Y q 401 E O k N D 3 K o T I G w Z w M F Y n n v 2 C E X J Y V f V U G y q 48 F / k G J o N t Z 9 H D Q J V D h C 1 G W C p s r w m p q o v l O A 79 F h 681 y C L d p c p Z r o Q N Z G M X D v 2 V 9 S J M k E S l F c V z D Y S X s 1 I d b u V n D 4 c A P h G Y / g S I k X I N o w X A x z W / q y U D g 27 I O K Q a w S s 9 q f / I y 9 i g 7 q B m / 4 W + Q M 7 L s t Y l c Z Y X t G 2 d J F r J X i r J 6 T R V / E Y e 85 O R F G x P Y Z f + 49 N X c W x U U 1 x W 9 X Y B 3 O E s l / F h a 8 y Q c 7 k 1 H u v Z w O / 79 V 5 G j N L a O F R B U O 26 y w 4 x A M Q 66 I 97 n k d 6 Y K t l d 7 / S a g 4 Y N 82 K 2 V s o J D i H q Y A H 1 t C Y h E T q g e U G n G T o 6 u d g j q n E D z z Q J + M L F 8 l k 4 K V O d R U g t 6 N 2 p q I i D D X N I z Q f e E S / G H K 8 R U b L d q K L w 3 K D o y 5 j 1 q k a q S R L + M I D y s P u f 4 O H F R b E 0 Q R b b k j Q m S 4 W K f f L G I 0 K Z j u N n r P e b l 6 O t A N t d J y + q 1 e s 4 E W W 9 F h x v j u h y 4 w y n 0 b w t 2 O S U o 3 t o b n R k L 5 Q h J D W s Z g 0 H c o n 8 B b N y T 4 O U 6 s l i A N 9 V Z d z C t w M M 0 + S Q V 6 b 4 N i V 4 V 6 o w R w 3 s / s N 8 k s C A v K J s K 0 b t z 3 W Q 6 P 3 H Z a E V + e z E w p n b n b P T c V o 2 v c z a U w H u o S B V W 0 8 J t G I h 41 g X Q / j r V g X U q l 6 L a V e f W p p n T i 9 T H a H E p 7 i t W z 8 e G B J S Z n L 5 W c m M t E Q B B i h t V T L X h 0 8 d k Q c D A m g 1 I W y R W Z Q / y m n e A 6 F t f N o J / V 0 g 4 D a L r P A P Y S 2 F K L e W 4 m r L 9 f 6 F N 7 F u V p 7 p a t H b b Y S q w x U w 6 n 8 i F w O M J G 8 z Q 0 m 7 U y J z 0 K E G B F T 7 y + c 2 j c 4 S e G L w M V P 9 B d v T y p 2 U K y o T 4 r P i o U F c W o 6 f P q L b h n g G H y P c p M N 6 q k c 6 f m W S Q Q A b / u A w S O n x F 6 b N L 12 G m S g c f q 9 p d K B v d e N M S O K 3 v Z h C 9 W M t + J W h H M X c 94 w q z o I w D B u y G I B Y 7 b O V i B C h F L g G T M z X h h h F z 6 I S M z i 0 v t q C O L X 2 Y h D w t g M Q k 1 W k Z c G Z c 859 y K W Y 0 R j m F 7 N 0 o 9 j 4 O h 84 y + 5 W B Y H U 7 w B h Z w v K j 6 z u 49 w J F G 5 f I + S Q o M J E f e H 2 v 14 Z C Y g u V a o A z h L C I e i A o C e p B P / D L 79 I 1 C F f w N G 6 h 63 A z 5 E W E Q p w T y n d c 9 W O l o 1 z b P E i I h f t x O v + C H w / w n i G n m U t D r 9 d w 1 v 2 / q B C S t U 4 b 7 / t o Y w M K 1 j 28 s X J E V A d T 3 Q D 1 R b g S t f E z v 703 T U / H l j 8 X E F m M R 5 U H 4 o g E M v 2 S Q f v T q n x S G K s S d q d 0 Z G c L S P f 6 j h u b c L O 5 z N / i y l 0 7 J j A 0 D X V g 9 o d s / + D / 0 Z d v g J M U / Q r q k w M h L u P u A f u C o 6 n g X n Y M j m M 9 s I S 7 X c Z A j A i 0 J P 6 v T 0 M A l c 5 X k R m K w i 144 z T U F a 3 h 6 + e m 2 N R 3 m b M 81 V e I 9 q C O b h 33 I d 2 Z r m g 2 C p i + b x Y O k 4 j Y W u P 2 W / z / q Q F G S Z p W 8 J 1 G J C 0 L O a 1 X F H M c Y F l Z r 90 N J f 4 O y 60 N U G C q D S 5 I l w k 447 C e m R R l 33 m K R 7 J 2 k V 9 H z x 46 X P Z U H d I v C 4 Q 8 j i Z w J i z 43 O o S W I p r s H N L l / U y 5 T + w f A K V z F 1 J A 4 A U v 0 v w L Y C b i y 2 c j N G K 9 y C f J 1 A N f 3 o 7 R B c 2 T i x x H W D k 7 y v J o 0 h f H A S t / 7 q s Z R N k d m b A d Q U n L M S Q N A 3 H h I F b C 5E6 j k J Q l r q 2 z f B n K b J O l 1 Q w 95 o a j O q z f l 9 C t R i w 7 p g o G 4 j u Z a V r 4 m S + q e J t t + f w r o Q f 79 y t n 9 G W + F x U Y d 9 V G / e c U 0 4 Y I t 74 k 6 U 5 K u a j 2 U 14 v s D p K 4 K R e L S X T + s o 6 X J X R d u 9 U 1 q 2 a o / h f 5 R K b 7 N b v K z Y 56 j y E P + t V z 3 a v + j h R F D n T p P v x w M I / T y O B R P X 6 V j 7 M N i I W r Q w S 0 q W y g G L 8 u R 1 R D F A p R L 7 D o Z h + h v x M E + 2 T r R P p D O b W R N x W Q M T 6 Q j a R u J V I + 99 R R 6 t p x z t 8 X r T 8 f 5 y k 3 I s t E z q j e Y x G Y T g + e h + 1 a C 55 c C P 7 I 3 / q B y P R L n L W 8 m / 358 P X W j N O 7 R c r C P U U 0 X l J 83 Z c C 9 w y i F V k 7 X 4 f u h U n b W u u 3 g 8 p X k F O Q 1 y z F U + x M 1 m t 5 Y P i 32 b L d X x j o C f w A U E M O h n w i z M o r H H C K m m L Y A L A O u m M h 3 v i p 2 W v F F / J U 1 + p S C t E r D H K 7 R q 2 v q 0 C 7 W 6 o D I 0 Q w B C t n t f p b y y 53 z U s W Q X L o d o Q K L 3 G A Q 3 t D i k 5 u G 2 E b 9 v z D x s D J j F r E V v c h 5 Q G p F Y w A 9 u 9 O Z s 5 / N c B X o m j H o T d z 6 D O 0 U S P C V b x b + Y K X A 0 + d W f s 48 M n F T r A L b J 0 4 M z v s D E U b o 8 s G p I w r o K a 3 Y f A 7 m m K 5 m z y t E c m l t b 8 I m F K e g K X j + + d w A Q O v N m T i h Z 5 W Q E X 9 o k s t G W v b D H 56 q D n M n c K j G X T q a R X Z w Z l 1 i 3 + C K A L z 2 a w 6 U 2 O 7 b f b n 5 l F 6 J W w A D 9 A p 3 M b e + c l t G j T b + F m P Z p K 9 w m m K C 74 N j T i G i m 33 / n 4 X o H m Q T g C 72 P C o 2 L F I u S g q y m b 6 h l + y + I R 26 / f 6 w j b d 0 A 4 d i h //608IJamzqvamVu2gd2vl8nxjKnWF8qiivs9xiEwJhfMCyMa0Wum7H8UXSNFfsQOgKrnNrXWw/yPyNI3Pg5AmLXPNokg0QZFzJWkruVWjLU1C2reFxN0WDlG5TL3fh6LbTjh6woD1XHCl03ziEGiw56G/+VDX5mQPVNTIFEak3X1gIEYt9Qtr2g52Jm6qwt2xRXDRV/ilVwfVkgNXKFIo+y4wAd6bHOzm2BNmGDzhOPwHIgcmq0p5c8FXGoNxAmVPM5pDgku3W7NSu2AejzKfmWCjMxNo5YCL+kW4CbLoSpuPktf3yBvD3JHJ/B9EfNjA71erP8mfET3UPoS+OFyAtLaxDcLFA/TupJ4V3uYcOboLtgRKKZsPjd9thIhwC8HoMrek+x0HN+VujYJnJAUFHc2ShBsFgeksg0sBNhmUweBP8R2OQ9bIJb1G2F4EcjQDq13n49SMrMQwIHM3NdSTJasXDdDgpootCyFL/uIcutyxFNg4QlEVrxswDY8QGepBbyT2mHW6ZJhvEFmr6XLdu6s4R4EIGTtfFSLNH5ZDWFtY8oTn6Kz5n48bMyNE01AWuaL0v3RwOI60YEknYq5jwvGIHj5ttJLn6wvw/VNVWUPRGENkKDWQ+lDUX0O6mQ7FHLTgzrNO7zmFOW8dKpT5tF63wojqrxI8NdVf6GtGXrliyfCsiZaoHPvKq8ud8dGc8HjvRRqjrVXyBP2jZuu64YdCnhcwBkcXumRYmiTs8SSOnuEwNC6aKzqhKrZRvP4ggEj7K/KF5OPuZUF8U65bG6qwPfpgQLskjMxk/1slTd7sIyk3pg4x0F3SyUoWRtKaG3rBxSCKH3IeUJbAklapWhWLF3lgff1ojXPiZaoy51Fh3S9wPetO28TT9zvU5G6QAys09Ceyv6ZIXK+90MNVrkAPvyq39cZiqjQ3VYSdA/x3xT/pi9Du9p6ku14j6wClHUtHcuuIixC3bxEmVLhgfZaTpzvl1kRDtjJ3EpinTQvIBCDkJiyTMlqjiWfiYEyzzflXtgJUYUMAhIxdXLo4V/hba7KlpiZkVTqb6qn0L0e5XAJRRdGu7e7PDB3BoSkR+jF3Yf+tx5RVexSSAf8ggW928iPU2vbHHlJVeA9XJDbOuDWF3/zc48/kKK0nRQoFmpkWUFb3/dXnOgtaYYSGp/kuL1Qkt7KoWNd+nK3UAV4yHWi9ympkOYfjKIW/iKQGtOZMUrKaArvjU6PUraVaW84Mq2d0Fbye3rRTIdTLoL6F0xmT4YaHbx5s9EIfmUtgXwENzTblLhd+L0J0bn8n5s373luYUfwGpSG+zipzKhxQW6a5sALqHQD9PJUUHB4RqOax5d/uzg8sL3uAZuJ7/ewmU88SG9fqtMaL5f4me+OUKx03C0I/5olKUM5wXft1Ctu24NGhg
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:01:02Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"malware-sample\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882f-1bf8-4870-95c5-43c0950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:01:03.000Z" ,
"modified" : "2016-06-01T07:01:03.000Z" ,
"pattern" : "[file:name = 'C_932.NLS.bin' AND file:hashes.SHA1 = '88912b5227145d3a715ae6eeebd5935c89955721']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:01:03Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha1\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--574e882f-8240-4468-83b1-4364950d210f" ,
"created_by_ref" : "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f" ,
"created" : "2016-06-01T07:01:03.000Z" ,
"modified" : "2016-06-01T07:01:03.000Z" ,
"pattern" : "[file:name = 'C_932.NLS.bin' AND file:hashes.SHA256 = '19aa4a66aa890945da8db83c34663f56b61d2ecb5eec5f7d8e8f13530f610505']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2016-06-01T07:01:03Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Payload installation"
}
] ,
"labels" : [
"misp:type=\"filename|sha256\"" ,
"misp:category=\"Payload installation\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "marking-definition" ,
"spec_version" : "2.1" ,
"id" : "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ,
"created" : "2017-01-20T00:00:00.000Z" ,
"definition_type" : "tlp" ,
"name" : "TLP:WHITE" ,
"definition" : {
"tlp" : "white"
}
}
2023-04-21 13:25:09 +00:00
]
}