2023-04-21 14:44:17 +00:00
|
|
|
{
|
|
|
|
"type": "bundle",
|
|
|
|
"id": "bundle--d3e23455-b121-4ea7-84c5-47d67808e7d7",
|
|
|
|
"objects": [
|
|
|
|
{
|
|
|
|
"type": "identity",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2023-01-19T13:59:45.000Z",
|
|
|
|
"modified": "2023-01-19T13:59:45.000Z",
|
|
|
|
"name": "CIRCL",
|
|
|
|
"identity_class": "organization"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "report",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "report--d3e23455-b121-4ea7-84c5-47d67808e7d7",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2023-01-19T13:59:45.000Z",
|
|
|
|
"modified": "2023-01-19T13:59:45.000Z",
|
|
|
|
"name": "Microsoft Office 365 Phishing - hosted on IPFS - https://ipfs.io/ipfs/QmdZDtyPrvVegTU7p6JZ5dm3CoZnH2qdEjTRfsUY8Nncwh",
|
|
|
|
"published": "2023-01-19T14:20:07Z",
|
|
|
|
"object_refs": [
|
|
|
|
"observed-data--776862b0-c64e-4c70-9dd4-ad055acfee15",
|
|
|
|
"url--776862b0-c64e-4c70-9dd4-ad055acfee15",
|
|
|
|
"observed-data--0e67cbc8-3618-437a-8f69-f7d187ac5d96",
|
|
|
|
"file--0e67cbc8-3618-437a-8f69-f7d187ac5d96",
|
|
|
|
"artifact--0e67cbc8-3618-437a-8f69-f7d187ac5d96",
|
|
|
|
"observed-data--4fe65fe6-de75-42c0-8677-603ff907efb7",
|
|
|
|
"url--4fe65fe6-de75-42c0-8677-603ff907efb7",
|
|
|
|
"indicator--e8a0d99b-ec93-4ed6-a2e0-e76e7d9bb417",
|
|
|
|
"indicator--b0c18ac1-4bac-4dff-87b5-02469b41ebab",
|
|
|
|
"x-misp-object--ba88d57f-b0ce-4a18-bd42-2338609a71e5",
|
2023-05-19 09:05:37 +00:00
|
|
|
"relationship--46ef7f45-5aa1-48df-98cf-cf77600bc797",
|
|
|
|
"relationship--747df9b5-a5ec-40b8-840e-0203942e4982",
|
|
|
|
"relationship--a32ff8b7-b880-4b16-994b-178ace888783",
|
|
|
|
"relationship--2e62772c-58e4-4d0f-8f7b-5cb510b02ecf"
|
2023-04-21 14:44:17 +00:00
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"Threat-Report",
|
|
|
|
"misp:tool=\"MISP-STIX-Converter\"",
|
|
|
|
"type:OSINT",
|
|
|
|
"osint:lifetime=\"perpetual\"",
|
|
|
|
"osint:certainty=\"50\"",
|
|
|
|
"tlp:clear",
|
|
|
|
"misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\""
|
|
|
|
],
|
|
|
|
"object_marking_refs": [
|
|
|
|
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "observed-data",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "observed-data--776862b0-c64e-4c70-9dd4-ad055acfee15",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2023-01-19T13:56:59.000Z",
|
|
|
|
"modified": "2023-01-19T13:56:59.000Z",
|
|
|
|
"first_observed": "2023-01-19T13:56:59Z",
|
|
|
|
"last_observed": "2023-01-19T13:56:59Z",
|
|
|
|
"number_observed": 1,
|
|
|
|
"object_refs": [
|
|
|
|
"url--776862b0-c64e-4c70-9dd4-ad055acfee15"
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"link\"",
|
|
|
|
"misp:category=\"External analysis\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "url",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "url--776862b0-c64e-4c70-9dd4-ad055acfee15",
|
|
|
|
"value": "https://lookyloo.circl.lu/tree/4ccf341f-233f-4cc1-b427-abc19f967726"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "observed-data",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "observed-data--0e67cbc8-3618-437a-8f69-f7d187ac5d96",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2023-01-19T13:56:59.000Z",
|
|
|
|
"modified": "2023-01-19T13:56:59.000Z",
|
|
|
|
"first_observed": "2023-01-19T13:56:59Z",
|
|
|
|
"last_observed": "2023-01-19T13:56:59Z",
|
|
|
|
"number_observed": 1,
|
|
|
|
"object_refs": [
|
|
|
|
"file--0e67cbc8-3618-437a-8f69-f7d187ac5d96",
|
|
|
|
"artifact--0e67cbc8-3618-437a-8f69-f7d187ac5d96"
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"attachment\"",
|
|
|
|
"misp:category=\"External analysis\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "file",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "file--0e67cbc8-3618-437a-8f69-f7d187ac5d96",
|
|
|
|
"name": "screenshot_landing_page.png",
|
|
|
|
"content_ref": "artifact--0e67cbc8-3618-437a-8f69-f7d187ac5d96"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "artifact",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "artifact--0e67cbc8-3618-437a-8f69-f7d187ac5d96",
|
|
|
|
"payload_bin": "iVBORw0KGgoAAAANSUhEUgAAB4AAAAQ4CAYAAADo08FDAAAAAXNSR0IArs4c6QAAIABJREFUeJzs3XmYJVWdIOxf3KxiKfatWEr2YqdEWRQVWRXcFxy7XWjpHrVt7dYenbEXnRlHe1One74ep7tnbJfWcYFxQUUURDYVsZVFaAUUFwRkE5ulKQooKm98f2RlklmVeaPynow8EXHf93nyObcqMyJOnDhxIuL87jlRPHz3XWW0Wj9p6bJs9u43PX9VqvJfVCxfFFV/QZtV1o/E4195/tS9/szqLt+26xe93FlIlHb9Sz/+aeXX7LOn3vOjXL/qfotPweT2ucX73ggdL8Cq+pV6/c197qW3L2n73/HqswnyFkC/4fePdZ9/dd9/VuWv6vxP3f+6yy9d7u2nKTPXn/Tjm7f808/fwff/Td//3Nd/0uRvP9Oev9PV239R1b41//pGnUa9/7CK8um2sZrb37q1O/cAAAAAAAAATBEABgAAAAAAAOiIJbkzADCXuqeQMUUNADSP6zOQi/YH5ub8gNHl/AdoJyOAAQAAAAAAADrCCGCgsVK/YVgURdb1AwDzV3V9dv0F6qL9gbk5P2B0Of8B2skIYAAAAAAAAICOEAAGAAAAAAAA6IjWTwHd9JfQNz1/VeqeItcEIXnVPYVLv99PWj5V3effqJ/fVUwB1Gzp7Xva+us+e1LrX2r7OPD3xeTfDL996LK6rx+p53fdy1dJLZ6m71/XNb38Rv3+ue77h1R1P7+N+hSfqfvX9PM7VdePf25trx9Vun5+tF1q+ec+ftqneuk/HMwrBrut7ffHRgADAAAAAAAAdIQAMAAAAAAAAEBHtH4KaKA+uadwAWiqlPax3CAFmI/cUzS7PwQA5sv9AwAsPiOAAQAAAAAAADrCCGBgTr6hCTC7ukcAV43gA0ZX3SOA614eABg97h8AYPEZAQwAAAAAAADQEQLAkKw/ZArAKCqmffm9V7YzBQAAmI+yGC5timHzP+opAPk0YArowcGwpk9B2/T8VarIf88ULBX6kRYAHvwdjNQpcvp9weZBctfu1CmOqlqf3O1T06d46pV5z49+0e3vYFUd36qjX1V/Uut/av1LXr6cuALMlUZZRlFERBlZ0iKKgfnrVxyByuPf9tun7BeQxALMvgP1qrz+Vex+6vWz/van6v6xcgVpy1e24HmnkK5ef9LqIavUKdo3YQs1rz9Ravs84g1A3e1rbpXtf+bs90e7+kVZ9AcGCvvlxDPe+keSGWlE+vFLrv9F7kDq4PJrchqxEOdfWv9p3XL3b7Vd6vFre/mP+v43Xb+yAauIr1V1T1Qev7Tj2+3eZ6hVf5bP80kFZwFG2eQ9ZNvSCCOBAQCATTM9EDhMEDH3dxdT8z/qae7jBzDKBIABAAAAAAAAOqIBU0ADw8o9xQkAAExX9xTaqZr+igoAYOG5/gMwiowABgAAAAAAAOgII4ChxYwABgCgSVJH2KTe36au3wggAOge138ARpERwAAAAAAAAAAdIQAMAAAAAAAA0BHZp4DOPYVt7u2nSs1/b8SnOEkrv3KDdGOpU9C1vX6SV+oURnXXP1MwQXMNOj/LqH8K19y0P+1WffzqrZ9Nrz91n5+524fU9c/n/nxyX6fvc+X2G14/aLfc5x/k1PX63/bn56IoIgZkscn3J9W9f+1XVT7p9avLpZe//o66ul8h03Sjvv9tV/f13QhgAAAAAAAAgI4QAAYAAAAAAADoiOxTQEOXmeIZAACY5P4fAGib5ClmFygfAMyPEcAAAAAAAAAAHWEEMNQodQSwl7ADAEB3uP8HANomfQYT9zcAORgBDAAAAAAAANARAsA0QL+l6XS9IdKFOv1yl8NClF+K3PuROS1GNAWSlcVwaURE3xe4AQCATVCUG3+eT1qUE88iwz6/pKYbfmb+ch8/gFG1AFNAD+6MT58iIk3u7VdJzV+v9VOE9WNQgGuifPoRMVw6UTyDAmhFwvYnFQN+BgeC0w/f4PJrdhqRHgRv8/73Y+L0H75+R5QRZX1pEb31/45a0nLy/JwjLaf+fpb8RUQRY9FmvcmyGFLuAFzdU1hWLZ+6+82+O6hfWUzUoV4Ml7b97qNK5f1ZYgVK7YxIniK2yHwGZO6NGfUpduve/9TrQ+7nt/lsf/Jv57NMZekn7n/tx7fWtdev6KfVz/GKEkit300/P0iV9w42d/2pen6p/fzo+OU/9/GtvP70y4ljUMas6aAAcK7A4SgFEuuuP/2pfpw5q0BFOj7kchOqHn96vcH9k2XmSpB6fEb9+afKqL+iZdT3v26p/bdV/ceV/acP331XYgsvAJxitAPAswUEZ6r7Apf6jt68r9GuLr/mSym/Luz/aEsOgMTShclIS+UOAFd9gaPpN4jNvjuo1+S5l1KHmn58my57ADi3zB0o+dvPvOoufgGuvASAB0utnwLAubefpmz79VMAOGn5tmv6/lUfn/Gh1z1KgVjq0avoOmx6ADhV658fMxv18hv1/c+tV/X9torjYwpoAAAAAAAAgI7IOXwRapc+wpd69SPteyhG/wIAAAAAw6nuHzYCEmgnAWAgM0FcAAAAAACAhSIATKeljgA2xz0AAAAAQDdV9w8vUkYAFph3AAMAAAAAAAB0hAAwAAAAAAAAQEdUTgFd/RL0qt/Xqzp/eaXmr+lTEKftX7lBuviaXr7d5/2/AE3k+sggyfe3oX51WWr7kbp8058PUzW9fW57+Vfmv6L4U/e/7eVXpar+dn3/c2t6+Tc9fwzm+NBlbe/fz31+5t7/VG0//qlGff+brur4GAEMAAAAAAAA0BECwAAAAAAAAAAdUTkFNDRZ7iksAAAAgGqe3wEAYPEIAAP5FIkdAKV3CAAAAAAAAEwnAEyrVX2D2EvGAQAAID/P7wAAsHi8AxgAAAAAAACgIwSAiYh+pnTDzyl6GdJeTOS/C+UHLVT0J34mP88nhRE2ffb9XjlcCgAAsBimP79Mfp5vymgri8ffIjdqKTDalpTleO48DFQ1RVBuqfnrZZ/iaHAAc2L/+hExV9obuPympXOrniJqbP2nXkQUc6RRU5or8Lvp5dd47kZGWvKD2FRQNyKiP880Isp2fwcqNRBX9tLOv4ZfnqlQlOuvlHOlMfj3fc13rbo+BWaZeA9TtXT95dfu45N6/W367Vvq8TdF7WBVe19VPn03EFnl718ZXD9qz17iBsqWR5Jyt1+pzy/N7r2sX9Xxqz6/U/uQ8j4/Dxv4nUybfv9CvaYf/+ECqf2kQGy/nOhJL2K4tFcUSQHgouH9X12//677/qvp5dP141u31P63Ys1dtzf6Djb/A8pg7Q4AVwcSc5d/9fZzvsa6Q4FYaKPEAGaUOduP/NIDwIOXb/oNXLPvLvIbdPwmD70g8PCqOqAaf/5kvj8UAM6r6x2oOijq1fYAcNuvfbnb77bregC46fVj3B38QM0PAOfrOzMikrZLvf/s9TN/gSPx+uP+e7C2l0/b8990zf76BwAAAAAAAACbbLSHP5Fd079hCgAAANB2Te9/qcyfAUIAAPNiBDAAAAAAAABARxgBTFbm+AcAAACoV9P7X6pHAOsfAgCYDyOAAQAAAAAAADpCABgAAAAAAACgI7JPAV05xUvLt9/sKXTKDdLF3n7+8qmSu/yqNL38gO7S/nTboOtfGY5/qraXX1X+U++vK8sn8/MD3db28xNor673j6VK7V9Kbd+bXj5tV/f9Y1mWSb137g/IKfX8qLv96vUGjzGse/ttjz+kqv35u2Ztz3/TGQEMAAAAAAAA0BECwAAAAAAAAAAdkX0KaNrNFDgAAAAANJn+K4B6aF+huYwABgAAAAAAAOgII4BJMuovWQcAAACg2VJHqOnfApid+AA0lxHAAAAAAAAAAB0hANwJ/SHTDT+n6GVIezGR/2H3PzXd8DMMK8f5s5Bamv+iP/Ez+Xk+KQAAALBoymK4dMPPMGrKYvjzJzUF8qp9CujcLwGvnIKgYvm6pyhIL5/JAGg5RzoZJI0B6fD5K4qx9Z96MVGas6VRU9pfn79B+z847ZXlREBnjrQoe+v/HbOnudV
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "observed-data",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "observed-data--4fe65fe6-de75-42c0-8677-603ff907efb7",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2023-01-19T13:56:59.000Z",
|
|
|
|
"modified": "2023-01-19T13:56:59.000Z",
|
|
|
|
"first_observed": "2023-01-19T13:56:59Z",
|
|
|
|
"last_observed": "2023-01-19T13:56:59Z",
|
|
|
|
"number_observed": 1,
|
|
|
|
"object_refs": [
|
|
|
|
"url--4fe65fe6-de75-42c0-8677-603ff907efb7"
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:type=\"link\"",
|
|
|
|
"misp:category=\"External analysis\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "url",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "url--4fe65fe6-de75-42c0-8677-603ff907efb7",
|
|
|
|
"value": "https://urlscan.io/result/f221789b-1eee-4f30-9c25-16779e0f505d/"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--e8a0d99b-ec93-4ed6-a2e0-e76e7d9bb417",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2023-01-19T13:56:59.000Z",
|
|
|
|
"modified": "2023-01-19T13:56:59.000Z",
|
|
|
|
"description": "Submitted URL",
|
|
|
|
"pattern": "[url:value = 'https://ipfs.io/ipfs/QmdZDtyPrvVegTU7p6JZ5dm3CoZnH2qdEjTRfsUY8Nncwh' AND url:x_misp_host = 'ipfs.io' AND url:x_misp_domain = 'ipfs.io']",
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2023-01-19T13:56:59Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "network"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:name=\"url\"",
|
|
|
|
"misp:meta-category=\"network\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "indicator",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "indicator--b0c18ac1-4bac-4dff-87b5-02469b41ebab",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2023-01-19T13:56:59.000Z",
|
|
|
|
"modified": "2023-01-19T13:56:59.000Z",
|
|
|
|
"description": "Content received for the final redirect (before rendering)",
|
|
|
|
"pattern": "[file:hashes.MD5 = '4a6742b13afe1d19b88536343b78fd87' AND file:hashes.SHA1 = 'a34625a53e22cd534f0777ec29ad30856c033590' AND file:hashes.SHA256 = '3f643e84717df8b6ff354e68426e2f85acbb4c5a2872c009461c850249d0a336' AND file:hashes.SHA512 = '2738198956544cfb635e61b18179af7b69bb99d2358c9a232ede5c0c02816fc7212077ad4708cd1640253f65c28c4707df2101388d76c2da9eb5c21079721535' AND file:name = 'QmdZDtyPrvVegTU7p6JZ5dm3CoZnH2qdEjTRfsUY8Nncwh' AND file:size = '275937' AND (file:content_ref.payload_bin = 'UEsDBBQACQAIACBvM1a4hNrwm5IAAOE1BAAgABwANGE2NzQyYjEzYWZlMWQxOWI4ODUzNjM0M2I3OGZkODdVVAkAAytMyWMrTMljdXgLAAEEIQAAAAQhAAAAYMSMx6P1QNrczmkB9fVEtKAlzaL19eXkCYkmPw/pUk2PXlm9NnRpX31aFa8jHv+sCkpoR5GV6QwKI4JUThx8U5Dta+CZV22IB0CGC98rrO+wzYzuq8aK7OZYJxjeXIxCbrdSq0WYHFPw2nQGz7c3h1n1R7MNer26AW/Ga7QPlKNSz8cNOW3jl24f17B9yfy7rm9aVnEn/cwuMGfMnRHcuPCH457PpYbjb4nv5rFNp+az4oOiZrZKWlRCCQyxbnrt8+joIoS/227u2wrN0xvI+2S/Wx5f1BbSaV8zSkUjTOTHfw3pPczfMrGptjwmZmolRJKDGO7jTp3RPFh5c0d5tF3kA4c/q71uCCvK+h2hsPTKyTyDbHKsY3oIi6I36kcC1PU5/yo1XOabAnbaMavXAPIYgkNgBtV/DfGxYoAPYLsW00p+hyVdBVltq40aQW34RMndHMWLlmfVnUwvk+i7+4uDYwB4bJ4Gj0nbKrlEed+xGYurra0OZ9fCD/lLDQ0yaBDrI6jCPA9D6hKtmZi+0p7c73F5pmwPztw+t/hw/iGo3OgcyS9FlmlH4u66JFkuFY0X8THtn/x8IOcyQmqj2rM6YFKqpaTSe7yzHJZ+D4CJOkcakddum6RPT3cY/vI+CnoPEacG54f+NouWYUE9PC0DQznJSFUYGXbT66LOaeBvz7cdWTCQt4k8fOmS11qZSexm0mWZaJXSuDsrqNh8AJgloinAPLwHUaFzaTH+mhaVe3WANYwtbSdaaXu66pRSFR7o5MOcgXi8rT9aIgy3gwm+gX5LUF9CBys0WnderJt6GxkFO70DEnBk464Su18BbO38vp70hRiuaS6ukHH8pParHwlLjpbx++Vs8XU8oSaZpKHS5bJcPI4A0fySNh2AHCgX4uphLuPRbpDVM9oy955GU4ft0jD/VcrY+3xmq1QM6uc/nQLMwDrtAjJGmTM1FpONDjzmAhJjZKaFEwGP8nqxIl6gKnrbqUdGE0mw9r92Oc5sj1E1xbMbR5cY/yk5GOgi6lM2Gzf/u+DhuEq3wjqBTBUF76EyrW1/mKgU9UGWfnwAZ/d9/hlKwOgq9emsJLDNLRm6bJe+NxpF5IKfhQS/cdZ+gayYAva+py1uou2JG2lRH+XwX77NfYcA2tUDXiodVaDJnVQprXBhwOHGJnkh6Z7OO8e8U8UGAfmzeJA5Z4AL8dKijoK5HvvJDl/6odQUAqmK6Hl70N1daSCDblpssxrHpWRjRkQNR7/ZkNUkFjT00sJvd+c+NxFKegK9aLauxDbIYhqfopb+o6Yn+Zwxc6M5B6TozVU/Sz7q7rNCjHyB/ulRiBQzLV9IklGHshsAiy/HjxaGf7SRt5A0JOgY6tcKhJxeZzHyAB2EDop7qzV0bfk6Ewd1B59ap51A1eAp4sfFO6yE9zK4FKT42phUCcCN0/PidtqdTsip5Dr3oNZRFe6qAbNA9+0AEXv1mwW3wSCkg3ZKhyEoUoOhfBp4sVRr/qTjDWzqJSN4wykG0vC62QeYnaTARN4zQZV4XaZYpHm7hnNzJGlVeOkvgADXzC9HaUKsTv7WS/5G/FXPQpe1/pZVQNL/ENDxvO+lPa/hMHdLCDVMn9u/9pp1WZ804RvkPTzxCgqZJ6MMNkn5wzHSxD/6vHXVO0BhIt5uyzMl5mFy4uo1vgKAB0uHLmkbnMsGFKi7AJGUUHFayP3onxtZWogioI4hPQCMHiAzcWnkhEPtTVnpIkPcpJrRe/348TPqf2uarpRYu3ked4towuNmuaXM+mNvZM/To71st2UvwXI21AJeJIawp22f/5j59FgnI7A46lCGw3P8o6a4MpCfEVmOVBBB40R+6Zau0mQZmvPdf6d0mDvVNqcXpMKOBJifEnUWbSJrZ0jwldIdQTVvOpq1dvnafB1jE6qDQB+QZXG5geyhE+37uTv6PwBmvg1p2MXeqixtSBt2SyakhieHTvKj1iQpoUDC5HEWU6TaZaQY7y3YfpFv2T1tujb5eTGZWAQqLfIJm4aGrqQgShCAjYpSScNGErthNPXEOGZKbWL4QRqX3ReeC5V++UdHjcpiJf6s/thRxOB2+kAS4cG8NIfV3rCsleLFGfxYcY3cYtvdQCVTBghdt1I3w9oGQahqN77OsUpujg/s7HSVbfwGHXHB46D3sciPGgb3W+tuFD2OzckhoTaQ2tYGjKJEx7MMij0VD8dq++WnAdIOtuAGaJxE2DVnEETh42fVFYEEeXTzfXlgBacKuOEczMcAM7aKOHV6e3Rip2s6YJ+Ob+GP+dmWgG3NVr/gCXDmRi1uDcdkJGt9tTZt3QsCF7iiik7E5M/xis407y8Fym38C+jQX+BnhkquvDYHYAewkSIm3QFDesOXlU7jHZ0HYonoKepIODQ9gqdcpdBHwPTKwefYbBgTcV5ryIHkQr5z7ke+vJW7HpUNrKJ6J6qyvWvVGpby4AYSfarvpClY4Hnx6yQVE37EMS1d3+FP22aa7Y1fnnJhPCUSSWEoX+iVGQB0/Bl5/IiMKuje1WONXAcX93qyEkOz4cjB8wuFD4MVlTraSx+J/Tj40jIEI9w93YPaq0VIF6Zz6OnComy7mO2zSWeUfXtF073YXRQCS2YzfTAVa5GahoKLhpUj49gbxfmOOnE0Hvrz6jvVoqJg5bU7JsXz4SLWLaa5vkiYbifPSH6G9A8VYEqq5CyRKkiOZQA5YA0IR4fHx57wfHSop+Jjt4W9YIg4av6tPeGBcVbFrC3aTgP33stjTYS7qGMLvn0D/H8SfcldCshFnvUm+bWUvTe5nXHoEHBPkg4pqoTWoc26+lmprAcYIxzOYNg6b6JJve1SP5OzmKboT9JyipQLEYJW0Bf30QrmUH+XRw5bA0il9viauLjBdR9Gt6uzQbReH2dUPbCUU2TtGAzsoxRQil/BB0GB2Tr9bfMh3MuANkZpS1m2Qscxka4AjQU/LGyD1mYLx4mA22SwW7aqb/RBR/KK6+tLVe2YjB2wMiXNcRx0pAgl6N1C3aTwMdyvJqX1TvXbk29CLcQLZz9/TzTB5aHfqhE4GQsbp3RB2IUK6cJ2LXJMGu+Dsx90WbZTjRhyoLDjy4pdG7JkKzd2hKH79p6Uz44MOmavLuJfLA3WIbKDUA3JesatUbgkCb7a8PPLJ/ADA8Jvo4aFHOF6v6Ca0Rp7H2AS7ogG9az5BOJKMGjHBwNwAW+QZIsDbTaZheXenVX0KAXrPaxq+AV/Hf6R+BQXsA5P2+MqUjhUqLBvdmlBPAW/zWMi+4VU8UqbYsrpOy34f+TFVBudptRWmpUsiimnEZfj9oMS5ZBHNduyqwt+1ceHmSEBTRFEOO+fQu5jGAs0o6kOmXvN5bAHXG9MHtb5ky4YIKJNm9KczuipNoA5DB2kO05mdqIYlOqlVMBNSRct5hlhdKLwTVb+cIHYcoVs5l5hOXSVoIMTL0TC
|
|
|
|
"pattern_type": "stix",
|
|
|
|
"pattern_version": "2.1",
|
|
|
|
"valid_from": "2023-01-19T13:56:59Z",
|
|
|
|
"kill_chain_phases": [
|
|
|
|
{
|
|
|
|
"kill_chain_name": "misp-category",
|
|
|
|
"phase_name": "file"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"labels": [
|
|
|
|
"misp:name=\"file\"",
|
|
|
|
"misp:meta-category=\"file\"",
|
|
|
|
"misp:to_ids=\"True\""
|
|
|
|
]
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "x-misp-object",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "x-misp-object--ba88d57f-b0ce-4a18-bd42-2338609a71e5",
|
|
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
|
|
"created": "2023-01-19T13:56:59.000Z",
|
|
|
|
"modified": "2023-01-19T13:56:59.000Z",
|
|
|
|
"labels": [
|
|
|
|
"misp:name=\"virustotal-report\"",
|
|
|
|
"misp:meta-category=\"misc\""
|
|
|
|
],
|
|
|
|
"x_misp_attributes": [
|
|
|
|
{
|
|
|
|
"type": "datetime",
|
|
|
|
"object_relation": "first-submission",
|
|
|
|
"value": "2023-01-18T22:30:44+00:00",
|
|
|
|
"category": "Other",
|
|
|
|
"uuid": "de3c316a-bf5c-46d3-8b85-143e4cf8d2f6"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "datetime",
|
|
|
|
"object_relation": "last-submission",
|
|
|
|
"value": "2023-01-19T01:34:46+00:00",
|
|
|
|
"category": "Other",
|
|
|
|
"uuid": "9cc3674d-986d-4049-9e81-0c1059fd4d49"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "link",
|
|
|
|
"object_relation": "permalink",
|
|
|
|
"value": "https://www.virustotal.com/gui/url/a72ed654133ffe6c54396fd873f306b0603dc05a5cea655c5fe0ac482f6ae546/detection",
|
|
|
|
"category": "External analysis",
|
|
|
|
"uuid": "9c78188f-b439-4416-90af-d950f6284c6b"
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"x_misp_meta_category": "misc",
|
|
|
|
"x_misp_name": "virustotal-report"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "relationship",
|
|
|
|
"spec_version": "2.1",
|
2023-05-19 09:05:37 +00:00
|
|
|
"id": "relationship--46ef7f45-5aa1-48df-98cf-cf77600bc797",
|
2023-04-21 14:44:17 +00:00
|
|
|
"created": "2023-01-19T13:56:59.000Z",
|
|
|
|
"modified": "2023-01-19T13:56:59.000Z",
|
|
|
|
"relationship_type": "captured-by",
|
|
|
|
"source_ref": "indicator--e8a0d99b-ec93-4ed6-a2e0-e76e7d9bb417",
|
|
|
|
"target_ref": "observed-data--776862b0-c64e-4c70-9dd4-ad055acfee15"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "relationship",
|
|
|
|
"spec_version": "2.1",
|
2023-05-19 09:05:37 +00:00
|
|
|
"id": "relationship--747df9b5-a5ec-40b8-840e-0203942e4982",
|
2023-04-21 14:44:17 +00:00
|
|
|
"created": "2023-01-19T13:56:59.000Z",
|
|
|
|
"modified": "2023-01-19T13:56:59.000Z",
|
|
|
|
"relationship_type": "analysed-with",
|
|
|
|
"source_ref": "indicator--e8a0d99b-ec93-4ed6-a2e0-e76e7d9bb417",
|
|
|
|
"target_ref": "x-misp-object--ba88d57f-b0ce-4a18-bd42-2338609a71e5"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "relationship",
|
|
|
|
"spec_version": "2.1",
|
2023-05-19 09:05:37 +00:00
|
|
|
"id": "relationship--a32ff8b7-b880-4b16-994b-178ace888783",
|
2023-04-21 14:44:17 +00:00
|
|
|
"created": "2023-01-19T13:56:59.000Z",
|
|
|
|
"modified": "2023-01-19T13:56:59.000Z",
|
|
|
|
"relationship_type": "loaded-by",
|
|
|
|
"source_ref": "indicator--b0c18ac1-4bac-4dff-87b5-02469b41ebab",
|
|
|
|
"target_ref": "indicator--e8a0d99b-ec93-4ed6-a2e0-e76e7d9bb417"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "relationship",
|
|
|
|
"spec_version": "2.1",
|
2023-05-19 09:05:37 +00:00
|
|
|
"id": "relationship--2e62772c-58e4-4d0f-8f7b-5cb510b02ecf",
|
2023-04-21 14:44:17 +00:00
|
|
|
"created": "2023-01-19T13:56:59.000Z",
|
|
|
|
"modified": "2023-01-19T13:56:59.000Z",
|
|
|
|
"relationship_type": "rendered-as",
|
|
|
|
"source_ref": "indicator--b0c18ac1-4bac-4dff-87b5-02469b41ebab",
|
|
|
|
"target_ref": "observed-data--0e67cbc8-3618-437a-8f69-f7d187ac5d96"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"type": "marking-definition",
|
|
|
|
"spec_version": "2.1",
|
|
|
|
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
|
|
|
|
"created": "2017-01-20T00:00:00.000Z",
|
|
|
|
"definition_type": "tlp",
|
|
|
|
"name": "TLP:WHITE",
|
|
|
|
"definition": {
|
|
|
|
"tlp": "white"
|
|
|
|
}
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|