3050 lines
1.2 MiB
JSON
3050 lines
1.2 MiB
JSON
|
{
|
||
|
"type": "bundle",
|
||
|
"id": "bundle--317bb250-bddd-4c57-82a3-5a068f5b8d7f",
|
||
|
"objects": [
|
||
|
{
|
||
|
"type": "identity",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-30T08:35:37.000Z",
|
||
|
"modified": "2024-08-30T08:35:37.000Z",
|
||
|
"name": "CIRCL",
|
||
|
"identity_class": "organization"
|
||
|
},
|
||
|
{
|
||
|
"type": "report",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "report--317bb250-bddd-4c57-82a3-5a068f5b8d7f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-30T08:35:37.000Z",
|
||
|
"modified": "2024-08-30T08:35:37.000Z",
|
||
|
"name": "CISA - AA24-242A #StopRansomware: RansomHub Ransomware",
|
||
|
"published": "2024-08-30T08:35:47Z",
|
||
|
"object_refs": [
|
||
|
"indicator--9f8417e3-8289-443f-b50f-4b9814d516a0",
|
||
|
"indicator--9bcf6caa-2f7f-4399-90be-5464af7fffb3",
|
||
|
"indicator--748f48aa-871b-4fa6-ae11-64da0ce5046b",
|
||
|
"indicator--553d71d7-7786-4538-b094-98ea404d48bb",
|
||
|
"indicator--0ac8c1b7-5bf4-4a10-9ea5-287bf9b716d8",
|
||
|
"indicator--1339ed51-87d7-4a2d-aea5-b16ca876218f",
|
||
|
"indicator--35b34378-e9ad-43d9-8bca-fd0563d74551",
|
||
|
"indicator--9c3f0d3d-57a0-4521-893b-fc1f71c0ff02",
|
||
|
"indicator--388d544e-93f7-4d1e-9154-7e55d0e07a1d",
|
||
|
"indicator--ddfe5c42-4af8-429c-ba58-4bbaedab0625",
|
||
|
"indicator--ed4018ac-d765-44d8-aafb-206a9ea92cf8",
|
||
|
"indicator--0b5a3f74-3a76-4ee4-b4a4-8c80494497a7",
|
||
|
"indicator--40a428b4-170c-472d-890d-0cb27e94b646",
|
||
|
"indicator--b52ca8de-3458-4fd3-8636-1be2cd1af1fe",
|
||
|
"indicator--ddc0815e-7b2a-482c-b646-2198d10b43f4",
|
||
|
"indicator--64e6b39c-1dcc-4985-b283-bf1cb9fd593c",
|
||
|
"indicator--3075f2c0-9dd6-4820-a968-d05e8626abb7",
|
||
|
"indicator--9a76a566-7da0-425c-8a5d-51bdb6d90435",
|
||
|
"indicator--859a93ce-4f8e-49d1-92ae-df89b7f89404",
|
||
|
"indicator--84a80386-87cb-4d78-b8e2-b9a0d04022af",
|
||
|
"indicator--a6c4c974-cf9c-4f00-a8fd-2ff625d55ca2",
|
||
|
"indicator--6587a037-f94c-4f14-a08b-5f81f9ef53c8",
|
||
|
"indicator--34e598b3-24cd-4690-988a-b2513388fb74",
|
||
|
"indicator--db420122-76b7-43e4-b1a8-6de9d256dd71",
|
||
|
"indicator--c80ba866-55d4-4477-8019-4484acf55f23",
|
||
|
"indicator--50fb157c-4035-419c-9ea7-6447a7b407e5",
|
||
|
"indicator--355c320e-9f27-4903-a8c5-5a6111305e24",
|
||
|
"indicator--64ea63dd-80c2-467f-982e-6b959e4d32d8",
|
||
|
"indicator--7c27f213-b9b1-42c0-a201-ba55174cb0d9",
|
||
|
"indicator--21b9de99-70a6-486f-be75-b1f7a557ba11",
|
||
|
"indicator--9729de03-5fd6-4489-bc04-d0852f3e77da",
|
||
|
"indicator--1122e8c6-bcff-4e32-af31-4a072a202872",
|
||
|
"indicator--8825cdc8-ec4b-4c51-91db-5c380280532d",
|
||
|
"indicator--3ec481af-b4f5-4cf5-8c89-498095c2d46d",
|
||
|
"indicator--810a68bd-86f2-4aa2-b0e2-df91561aefbd",
|
||
|
"indicator--5d327992-b9cf-420d-b28e-d42d1a14fe15",
|
||
|
"indicator--7168e887-7291-4dfb-9d4a-912a9fb6a22e",
|
||
|
"indicator--8eb59652-ce5b-48c2-b97a-048502e81a26",
|
||
|
"indicator--154720ad-27b0-4874-b825-15c742407d11",
|
||
|
"indicator--1e298817-1d10-4ee2-854b-047814be8405",
|
||
|
"indicator--f0d96598-0ef7-4d23-9b7b-0fec6aac5b3b",
|
||
|
"indicator--90b812fc-3e29-45ca-afa5-988e24533fc0",
|
||
|
"indicator--7ace7601-8fec-4b46-90ac-9937d395ed22",
|
||
|
"indicator--963df56d-8271-4e4e-b629-b0711a7f8f69",
|
||
|
"indicator--de33f108-6159-4577-92bc-ff0a628eba2b",
|
||
|
"indicator--51d3ef2d-d754-4a17-82a8-08a5cd41f666",
|
||
|
"indicator--5e88ac13-5775-4d39-97bb-ae1fb3900acd",
|
||
|
"indicator--450e1e15-ea19-4f2e-81a3-760d237a6f4f",
|
||
|
"indicator--d188dcc5-bccc-445e-9749-16fb3edadbaa",
|
||
|
"indicator--262ee50b-0a57-47f6-842b-a13301103938",
|
||
|
"indicator--543c88a5-cbef-4ac7-9d20-f3b0046fa522",
|
||
|
"indicator--4e62d448-38b5-4d3b-86f3-1be0d863a077",
|
||
|
"indicator--d1825f80-d9e6-4ff4-a45f-aae93d52be07",
|
||
|
"indicator--d8f707e3-843a-497e-bd2a-075075ad6496",
|
||
|
"indicator--2cacc632-ddbe-4e9c-ae27-6589f84bf7b7",
|
||
|
"indicator--ad577292-d9d0-4042-8c43-aa76e45368b7",
|
||
|
"indicator--fc399859-98a8-4cbb-b5b9-845578a6ab9f",
|
||
|
"indicator--5c9df374-ad76-43af-8c96-9948db36d9ac",
|
||
|
"indicator--2736f62e-954f-47e4-b88a-b7c5f09358d0",
|
||
|
"indicator--bde2c0ee-be2a-452a-bf1b-7dcc880bfa1e",
|
||
|
"indicator--12dc6dda-010b-4841-b344-ec8ab4c85dd1",
|
||
|
"indicator--51ef4a2a-b242-4d88-b609-c002e00386d2",
|
||
|
"indicator--63a4ffd4-cded-44e4-80df-aa12d9dab31b",
|
||
|
"indicator--ce0790d7-606d-4c37-896f-dabacb3c9447",
|
||
|
"indicator--d92c5415-7e2a-43ef-831e-540791202372",
|
||
|
"indicator--7968f4e8-f8d5-4ed4-adbd-d186affc40ae",
|
||
|
"indicator--ca71f6fb-4ea4-46b9-8d07-d1a0139740d2",
|
||
|
"indicator--b866b8e7-ddda-4948-b38d-7f0475cabc02",
|
||
|
"indicator--b3769aef-3550-4671-b67b-94a4d4c7f3bf",
|
||
|
"indicator--baf4ea01-b8f9-47cc-ae61-b8ef9b36a4d8",
|
||
|
"indicator--07301903-d63d-42dc-9932-edad812e5aa7",
|
||
|
"indicator--f9fb93a1-1efe-488c-9e5f-f2f5286013fb",
|
||
|
"indicator--0db0ac21-9d65-484b-83fb-83fa3f58aabe",
|
||
|
"indicator--bf9e8ba3-3bc0-40b9-9da0-9edef1248d6e",
|
||
|
"indicator--aff80aa8-02ef-4645-8cb4-13b0aa735461",
|
||
|
"indicator--0b08244b-e363-46b7-b283-2bd8efa5b0c4",
|
||
|
"indicator--ca72dd92-959b-42fb-ad16-10cb124cff24",
|
||
|
"indicator--17c7a152-8d80-4e5d-aebd-76e4cb8575dd",
|
||
|
"indicator--72843adc-2054-425d-8f76-86eb66c52ed9",
|
||
|
"indicator--f8131b59-6500-477e-bcc0-afe5b72da54a",
|
||
|
"indicator--bc4f9cf6-0cc2-47f7-a2be-cfa32cc47195",
|
||
|
"indicator--fc7c2ed8-6dfd-4ade-85e4-74dbf2808fac",
|
||
|
"indicator--5ff36800-72b6-410a-8a38-45796c15d91d",
|
||
|
"indicator--6346bd6c-1219-4b2f-9ede-6c279420ec7b",
|
||
|
"indicator--19a486de-c227-49e4-9d3f-f68a11a54f5e",
|
||
|
"indicator--ff9b53cd-695e-4df7-b3ea-5ad7844d820e",
|
||
|
"indicator--775cfc51-0b54-476b-be7d-9a5e4e85cc2a",
|
||
|
"indicator--f55eeae5-4e39-4c08-aa37-835d3e930935",
|
||
|
"indicator--d8a8e30b-412a-4b8c-93d9-e3fe776fa65c",
|
||
|
"indicator--3bb66911-7958-40d9-87a2-2a875b18e785",
|
||
|
"indicator--11e0a379-2fed-4627-ae96-d6ebca0a45c8",
|
||
|
"indicator--67585aa5-af79-4549-9e46-cb4714ecfcf2",
|
||
|
"indicator--b0883d39-d14d-44cc-8030-59d5e2fd5024",
|
||
|
"indicator--3a1c99ac-a57a-439b-8d16-13665a01383b",
|
||
|
"indicator--90d922d7-4084-4d0f-bfe1-ce2e0a322271",
|
||
|
"indicator--06c52109-0e7c-4484-a543-1240961f2f2e",
|
||
|
"indicator--7523ba19-976a-4df1-9406-8013003fd799",
|
||
|
"indicator--20fb95a6-b986-401d-b30f-eacbbcdb5943",
|
||
|
"indicator--1be7517f-01e7-4c4c-9bd3-6a422b2e9527",
|
||
|
"indicator--7ff4da71-e0c5-4ebb-8320-9815bddbc5ab",
|
||
|
"indicator--1887d288-d511-462c-a7ad-0cff9a204216",
|
||
|
"indicator--f8d757c6-6def-4543-9e04-6e174226e300",
|
||
|
"indicator--bc157160-1324-42f9-9d88-8ffb990ee18c",
|
||
|
"indicator--710df6d4-2363-45e7-a703-290d9c479f8f",
|
||
|
"indicator--ef464144-2f45-455d-b7c5-4003ccf1174f",
|
||
|
"indicator--35cfa310-811b-48ea-b867-17e99098b2d1",
|
||
|
"indicator--886fe20f-cd0a-4caf-9a02-e3f212920a32",
|
||
|
"indicator--4143c104-8a9c-4bde-bd9a-599b3c65cd8c",
|
||
|
"indicator--92dda377-34db-45a8-be75-4a0dee8b2f52",
|
||
|
"indicator--973ed75f-241f-48eb-9c4a-79a4284caaa5",
|
||
|
"indicator--4ed6f81a-8b6e-4234-8433-ec4afbf79157",
|
||
|
"indicator--9aaba9d0-17bc-4dcb-b6fa-a98281c5d4d8",
|
||
|
"indicator--e6124b68-6f2c-444e-8945-26d80609a604",
|
||
|
"indicator--5efe6073-eccc-4556-9601-a9c39a814a84",
|
||
|
"indicator--625dae88-7896-4ca4-839d-f68e25a8a2e6",
|
||
|
"indicator--2152142f-9460-4d54-98fa-39852ed5b91c",
|
||
|
"indicator--83060459-430c-460d-8d37-73631836f472",
|
||
|
"indicator--df7d7bcb-0171-42c9-b400-0c892e25bfaa",
|
||
|
"indicator--e8036316-2e9a-4b39-8226-aac5afe6bd83",
|
||
|
"indicator--a8a13368-0670-464d-b6bf-7de2b8cfb810",
|
||
|
"indicator--66d808da-b045-43a4-af50-48dfdf85a587",
|
||
|
"x-misp-object--f0ca19c4-3a2e-48f3-a829-95512862fde1",
|
||
|
"x-misp-object--a89eb75a-7c0e-4ddd-8a88-6afa80638486"
|
||
|
],
|
||
|
"labels": [
|
||
|
"Threat-Report",
|
||
|
"misp:tool=\"MISP-STIX-Converter\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"7e0ace8d-1170-5ba6-953b-07f0edb931e5\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"68936c88-a7d9-5c57-87d5-82cee0258446\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"4980a23b-8576-5f43-919f-be1d65511c71\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"a9732dfc-5d7f-5613-a990-e75667575a20\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"6e60f5c4-cab1-54e7-99eb-e2243d934596\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"8beef3c6-31f3-592a-8f2c-1a35f1454621\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"2d516005-9134-548b-b85f-5f827436dc8c\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"bc83dee5-b6d3-5534-8a27-11345878471a\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"6232b886-5dee-508f-a0c9-6c96ffa34455\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"04ad4243-c5bb-552b-8eca-fa4b48befb68\"",
|
||
|
"misp-galaxy:ransomware=\"ransomhub\"",
|
||
|
"misp-galaxy:ransomware=\"cyclops\"",
|
||
|
"misp-galaxy:ransomware=\"knight\"",
|
||
|
"type:OSINT",
|
||
|
"osint:lifetime=\"perpetual\"",
|
||
|
"tlp:clear"
|
||
|
],
|
||
|
"object_marking_refs": [
|
||
|
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--9f8417e3-8289-443f-b50f-4b9814d516a0",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://samuelelena.co/npm/module.tripadvisor/module.tripadvisor']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--9bcf6caa-2f7f-4399-90be-5464af7fffb3",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/en/d\\\\%E5\\\\%AD\\\\%97\\\\%E5\\\\%AD\\\\%97.resources/d\\\\%E5\\\\%AD\\\\%97\\\\%E5\\\\%AD\\\\%97.resources.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--748f48aa-871b-4fa6-ae11-64da0ce5046b",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/en/d\\\\%E5\\\\%AD\\\\%97\\\\%E5\\\\%AD\\\\%97.resources/d\\\\%E5\\\\%AD\\\\%97\\\\%E5\\\\%AD\\\\%97.resources.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--553d71d7-7786-4538-b094-98ea404d48bb",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/en/d\\\\%E5\\\\%AD\\\\%97\\\\%E5\\\\%AD\\\\%97.resources.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--0ac8c1b7-5bf4-4a10-9ea5-287bf9b716d8",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/en/d\\\\%E5\\\\%AD\\\\%97\\\\%E5\\\\%AD\\\\%97.resources.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1339ed51-87d7-4a2d-aea5-b16ca876218f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/en-US/d\\\\%E5\\\\%AD\\\\%97\\\\%E5\\\\%AD\\\\%97.resources/d\\\\%E5\\\\%AD\\\\%97\\\\%E5\\\\%AD\\\\%97.resources.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--35b34378-e9ad-43d9-8bca-fd0563d74551",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/en-US/d\\\\%E5\\\\%AD\\\\%97\\\\%E5\\\\%AD\\\\%97.resources/d\\\\%E5\\\\%AD\\\\%97\\\\%E5\\\\%AD\\\\%97.resources.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--9c3f0d3d-57a0-4521-893b-fc1f71c0ff02",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/en-US/d\\\\%E5\\\\%AD\\\\%97\\\\%E5\\\\%AD\\\\%97.resources.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--388d544e-93f7-4d1e-9154-7e55d0e07a1d",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://188.34.188.7/555/NEWOFFICIALPROGRAMCAUSEOFNEWUPDATE.INI']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ddfe5c42-4af8-429c-ba58-4bbaedab0625",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://40031.co/npm/module.tripadvisor/module.tripadvisor.js']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ed4018ac-d765-44d8-aafb-206a9ea92cf8",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://40031.co/npm/module.external/client.min.js']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--0b5a3f74-3a76-4ee4-b4a4-8c80494497a7",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://40031.co/npm/module.external/moment.min.js']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--40a428b4-170c-472d-890d-0cb27e94b646",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://40031.co/npm/module.external/jquery.min.js']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--b52ca8de-3458-4fd3-8636-1be2cd1af1fe",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://40031.co/npm/module.tripadvisor/module.tripadvisor.css']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ddc0815e-7b2a-482c-b646-2198d10b43f4",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://samuelelena.co/npm/module.external/jquery.min.js']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--64e6b39c-1dcc-4985-b283-bf1cb9fd593c",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://samuelelena.co:443/']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--3075f2c0-9dd6-4820-a968-d05e8626abb7",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://samuelelena.co/np']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--9a76a566-7da0-425c-8a5d-51bdb6d90435",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://samuelelena.co/npm/module.external']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--859a93ce-4f8e-49d1-92ae-df89b7f89404",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://samuelelena.co/npm/module.external/client.min.js']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--84a80386-87cb-4d78-b8e2-b9a0d04022af",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://samuelelena.co/npm/module.tripadvisor/module.tripadvisor.js']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--a6c4c974-cf9c-4f00-a8fd-2ff625d55ca2",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://samuelelena.co/npm/']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--6587a037-f94c-4f14-a08b-5f81f9ef53c8",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://samuelelena.co/npm']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--34e598b3-24cd-4690-988a-b2513388fb74",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://samuelelena.co/']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--db420122-76b7-43e4-b1a8-6de9d256dd71",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://samuelelena.co/']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--c80ba866-55d4-4477-8019-4484acf55f23",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://samuelelena.co/npm/module.external/client.min.js']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--50fb157c-4035-419c-9ea7-6447a7b407e5",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://samuelelena.co/npm/module.external/moment.min.js']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--355c320e-9f27-4903-a8c5-5a6111305e24",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://12301230.co/npm/module.tripadvisor/module.tripadvisor.js']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--64ea63dd-80c2-467f-982e-6b959e4d32d8",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://12301230.co/npm/module.external/client.min.js']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7c27f213-b9b1-42c0-a201-ba55174cb0d9",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://12301230.co/npm/module.external/moment.min.js']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--21b9de99-70a6-486f-be75-b1f7a557ba11",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://12301230.co/npm/module.external/jquery.min.js']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--9729de03-5fd6-4489-bc04-d0852f3e77da",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://12301230.co/npm/module.tripadvisor/module.tripadvisor.css']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1122e8c6-bcff-4e32-af31-4a072a202872",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://i.ibb.com:443/V3Kj1c2/1154761258.png']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--8825cdc8-ec4b-4c51-91db-5c380280532d",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://i.ibb.co/X2FR8Kz/2113791011.png']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--3ec481af-b4f5-4cf5-8c89-498095c2d46d",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://i.ibb.co/V3Kj1c2/1154761258.png']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--810a68bd-86f2-4aa2-b0e2-df91561aefbd",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://i.ibb.co/v1bn9ZK/369210627.png']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--5d327992-b9cf-420d-b28e-d42d1a14fe15",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://i.ibb.co/SxQLwYm/1038436121.png']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7168e887-7291-4dfb-9d4a-912a9fb6a22e",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://i.ibb.co/p1RCtpy/2681232755.png']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--8eb59652-ce5b-48c2-b97a-048502e81a26",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://i.ibb.co/nbMNnW4/2501108160.png']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--154720ad-27b0-4874-b825-15c742407d11",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://i.ibb.co/HK0jV1G/534475006.png']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1e298817-1d10-4ee2-854b-047814be8405",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://i.ibb.co/Fxhyq6t/2077411869.png']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--f0d96598-0ef7-4d23-9b7b-0fec6aac5b3b",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://i.ibb.co/b1bZBpg/2615174623.png']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--90b812fc-3e29-45ca-afa5-988e24533fc0",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://i.ibb.co/4g6jH2J/2773036704.png']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7ace7601-8fec-4b46-90ac-9937d395ed22",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://i.ibb.co/2KBydfw/112882618.png']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--963df56d-8271-4e4e-b629-b0711a7f8f69",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://grabify.link/Y33YXP']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--de33f108-6159-4577-92bc-ff0a628eba2b",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://temp.sh/KnCqD/superloop.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--51d3ef2d-d754-4a17-82a8-08a5cd41f666",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/xwenxub285p83ecrzvft.exe.Config']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--5e88ac13-5775-4d39-97bb-ae1fb3900acd",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/winnlsres.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--450e1e15-ea19-4f2e-81a3-760d237a6f4f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/WINMMBASE.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--d188dcc5-bccc-445e-9749-16fb3edadbaa",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/WINMM.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--262ee50b-0a57-47f6-842b-a13301103938",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/WININET.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--543c88a5-cbef-4ac7-9d20-f3b0046fa522",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/winhttp.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--4e62d448-38b5-4d3b-86f3-1be0d863a077",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/webio.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--d1825f80-d9e6-4ff4-a45f-aae93d52be07",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/USERENV.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--d8f707e3-843a-497e-bd2a-075075ad6496",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/urlmon.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--2cacc632-ddbe-4e9c-ae27-6589f84bf7b7",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/xwenxub285p83ecrzvft.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ad577292-d9d0-4042-8c43-aa76e45368b7",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/TmsLA6kdcU8jxKzpMvbUVweTeF5YcR.exe.Config']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--fc399859-98a8-4cbb-b5b9-845578a6ab9f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/SspiCli.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--5c9df374-ad76-43af-8c96-9948db36d9ac",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/msi.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--2736f62e-954f-47e4-b88a-b7c5f09358d0",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/mshtml.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--bde2c0ee-be2a-452a-bf1b-7dcc880bfa1e",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/IPHLPAPI.DLL']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--12dc6dda-010b-4841-b344-ec8ab4c85dd1",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/information.INI']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--51ef4a2a-b242-4d88-b609-c002e00386d2",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/information.exe.Config']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--63a4ffd4-cded-44e4-80df-aa12d9dab31b",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/information.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ce0790d7-606d-4c37-896f-dabacb3c9447",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/iertutil.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--d92c5415-7e2a-43ef-831e-540791202372",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/en-US/d\\\\%E5\\\\%AD\\\\%97\\\\%E5\\\\%AD\\\\%97.resources.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7968f4e8-f8d5-4ed4-adbd-d186affc40ae",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/en-US']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ca71f6fb-4ea4-46b9-8d07-d1a0139740d2",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/en']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--b866b8e7-ddda-4948-b38d-7f0475cabc02",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/DPAPI.DLL']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--b3769aef-3550-4671-b67b-94a4d4c7f3bf",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/cv4TCGxUjvS.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--baf4ea01-b8f9-47cc-ae61-b8ef9b36a4d8",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/CRYPTSP.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--07301903-d63d-42dc-9932-edad812e5aa7",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/cryptnet.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--f9fb93a1-1efe-488c-9e5f-f2f5286013fb",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/CRYPTBASE.DLL']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--0db0ac21-9d65-484b-83fb-83fa3f58aabe",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/Cabinet.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--bf9e8ba3-3bc0-40b9-9da0-9edef1248d6e",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/bcrypt.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--aff80aa8-02ef-4645-8cb4-13b0aa735461",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/ambapdf.ico.DLL']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--0b08244b-e363-46b7-b283-2bd8efa5b0c4",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/AmbaPDF.ico']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ca72dd92-959b-42fb-ad16-10cb124cff24",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/92.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--17c7a152-8d80-4e5d-aebd-76e4cb8575dd",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/9.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--72843adc-2054-425d-8f76-86eb66c52ed9",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/8.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--f8131b59-6500-477e-bcc0-afe5b72da54a",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/7.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--bc4f9cf6-0cc2-47f7-a2be-cfa32cc47195",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/6.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--fc7c2ed8-6dfd-4ade-85e4-74dbf2808fac",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/5.exe.Config']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--5ff36800-72b6-410a-8a38-45796c15d91d",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/4.exe.Config']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--6346bd6c-1219-4b2f-9ede-6c279420ec7b",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/3.exe.Config']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--19a486de-c227-49e4-9d3f-f68a11a54f5e",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/2wrRR6sW6XJtsXyPzuhWhDG7qwN4es.exe.Config']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ff9b53cd-695e-4df7-b3ea-5ad7844d820e",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/2.exe.Config']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--775cfc51-0b54-476b-be7d-9a5e4e85cc2a",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/2.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--f55eeae5-4e39-4c08-aa37-835d3e930935",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/12.exe.Config']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--d8a8e30b-412a-4b8c-93d9-e3fe776fa65c",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/12.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--3bb66911-7958-40d9-87a2-2a875b18e785",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/10.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--11e0a379-2fed-4627-ae96-d6ebca0a45c8",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/1.exe.Config']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--67585aa5-af79-4549-9e46-cb4714ecfcf2",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/1.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--b0883d39-d14d-44cc-8030-59d5e2fd5024",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--3a1c99ac-a57a-439b-8d16-13665a01383b",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--90d922d7-4084-4d0f-bfe1-ce2e0a322271",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--06c52109-0e7c-4484-a543-1240961f2f2e",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://188.34.188.7/555/NEWOFFICIALPROGRAMCAUSEOFNEWUPDATE.exe.Config']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7523ba19-976a-4df1-9406-8013003fd799",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://188.34.188.7/555/NEWOFFICIALPROGRAMCAUSEOFNEWUPDATE.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--20fb95a6-b986-401d-b30f-eacbbcdb5943",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://188.34.188.7/555/en-US']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1be7517f-01e7-4c4c-9bd3-6a422b2e9527",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://188.34.188.7/555/en']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7ff4da71-e0c5-4ebb-8320-9815bddbc5ab",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://188.34.188.7/555/CRYPTSP.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1887d288-d511-462c-a7ad-0cff9a204216",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://188.34.188.7/555/bcrypt.dll']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--f8d757c6-6def-4543-9e04-6e174226e300",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://188.34.188.7/555/amba16.ico']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--bc157160-1324-42f9-9d88-8ffb990ee18c",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://188.34.188.7/555/']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--710df6d4-2363-45e7-a703-290d9c479f8f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://188.34.188.7/555']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ef464144-2f45-455d-b7c5-4003ccf1174f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '193.233.254.21']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--35cfa310-811b-48ea-b867-17e99098b2d1",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '193.124.125.78']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--886fe20f-cd0a-4caf-9a02-e3f212920a32",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '193.106.175.107']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--4143c104-8a9c-4bde-bd9a-599b3c65cd8c",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '45.134.140.69']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--92dda377-34db-45a8-be75-4a0dee8b2f52",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '45.95.67.41']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--973ed75f-241f-48eb-9c4a-79a4284caaa5",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '8.211.2.97']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--4ed6f81a-8b6e-4234-8433-ec4afbf79157",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'https://samuelelena.co/npm/module.tripadvisor/module.tripadvisor.js']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2023-09-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--9aaba9d0-17bc-4dcb-b6fa-a98281c5d4d8",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '188.34.188.7']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2024-07-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--e6124b68-6f2c-444e-8945-26d80609a604",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[email-message:from_ref.value = 'brahma2023@onionmail.org']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2023-08-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"email-src\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--5efe6073-eccc-4556-9601-a9c39a814a84",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/5.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2023-08-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--625dae88-7896-4ca4-839d-f68e25a8a2e6",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/TmsLA6kdcU8jxKzpMvbUVweTeF5YcR.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2023-08-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--2152142f-9460-4d54-98fa-39852ed5b91c",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/3.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2023-08-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--83060459-430c-460d-8d37-73631836f472",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/4.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2023-08-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--df7d7bcb-0171-42c9-b400-0c892e25bfaa",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '89.23.96.203']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2023-01-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--e8036316-2e9a-4b39-8226-aac5afe6bd83",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[url:value = 'http://89.23.96.203/333/2wrRR6sW6XJtsXyPzuhWhDG7qwN4es.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2023-08-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--a8a13368-0670-464d-b6bf-7de2b8cfb810",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[domain-name:value = 'samuelelena.co']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2023-09-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--66d808da-b045-43a4-af50-48dfdf85a587",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-28T15:32:35.000Z",
|
||
|
"modified": "2024-08-28T15:32:35.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '45.135.232.2']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2017-10-19T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "x-misp-object",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "x-misp-object--f0ca19c4-3a2e-48f3-a829-95512862fde1",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-30T08:21:42.000Z",
|
||
|
"modified": "2024-08-30T08:21:42.000Z",
|
||
|
"labels": [
|
||
|
"misp:name=\"original-imported-file\"",
|
||
|
"misp:meta-category=\"file\""
|
||
|
],
|
||
|
"x_misp_attributes": [
|
||
|
{
|
||
|
"type": "attachment",
|
||
|
"object_relation": "imported-sample",
|
||
|
"value": "AA24-242A-StopRansomware-RansomHub-Ransomware.stix_.json",
|
||
|
"category": "External analysis",
|
||
|
"uuid": "d9d6f328-5d89-424f-bcaf-bcce5894baa2",
|
||
|
"data": "ewogICAgInR5cGUiOiAiYnVuZGxlIiwKICAgICJpZCI6ICJidW5kbGUtLTVkZGQ5NmNiLTk1OTEtNDdlMi04YTg4LWRiMjRlZDliOThmNSIsCiAgICAib2JqZWN0cyI6IFsKICAgICAgICB7CiAgICAgICAgICAgICJpZCI6ICJsb2NhdGlvbi0tOGYzYzM3ZGEtYWVhYi00MGI0LTkxNDktMjQ1ZGYzNmEzNjIyIiwKICAgICAgICAgICAgInNwZWNfdmVyc2lvbiI6ICIyLjEiLAogICAgICAgICAgICAidHlwZSI6ICJsb2NhdGlvbiIsCiAgICAgICAgICAgICJjb3VudHJ5IjogIlVTIiwKICAgICAgICAgICAgImFkbWluaXN0cmF0aXZlX2FyZWEiOiAiVVMtREMiLAogICAgICAgICAgICAiY3JlYXRlZCI6ICIyMDI0LTA4LTI4VDE1OjMyOjM1LjAwMFoiLAogICAgICAgICAgICAibW9kaWZpZWQiOiAiMjAyNC0wOC0yOFQxNTozMjozNS4wMDBaIiwKICAgICAgICAgICAgImNyZWF0ZWRfYnlfcmVmIjogImlkZW50aXR5LS1iM2JjYTNjMi0xZjNkLTRiNTQtYjQ0Zi1kYWM0MmMzYThmMDEiLAogICAgICAgICAgICAib2JqZWN0X21hcmtpbmdfcmVmcyI6IFsKICAgICAgICAgICAgICAgICJtYXJraW5nLWRlZmluaXRpb24tLTYxM2YyZTI2LTQwN2QtNDhjNy05ZWNhLWI4ZTkxZGY5OWRjOSIKICAgICAgICAgICAgXQogICAgICAgIH0sCiAgICAgICAgewogICAgICAgICAgICAiaWQiOiAiYXR0YWNrLXBhdHRlcm4tLThjN2QzYmE2LWQxNWMtNDFlYy1hYjUyLTkyNzNhYTNhY2YwZSIsCiAgICAgICAgICAgICJ0eXBlIjogImF0dGFjay1wYXR0ZXJuIiwKICAgICAgICAgICAgImNyZWF0ZWQiOiAiMjAyNC0wOC0yOFQxNTozMjozNS4wMDBaIiwKICAgICAgICAgICAgIm1vZGlmaWVkIjogIjIwMjQtMDgtMjhUMTU6MzI6MzUuMDAwWiIsCiAgICAgICAgICAgICJzcGVjX3ZlcnNpb24iOiAiMi4xIiwKICAgICAgICAgICAgImNyZWF0ZWRfYnlfcmVmIjogImlkZW50aXR5LS1iM2JjYTNjMi0xZjNkLTRiNTQtYjQ0Zi1kYWM0MmMzYThmMDEiLAogICAgICAgICAgICAibmFtZSI6ICJQaGlzaGluZyIsCiAgICAgICAgICAgICJvYmplY3RfbWFya2luZ19yZWZzIjogWwogICAgICAgICAgICAgICAgIm1hcmtpbmctZGVmaW5pdGlvbi0tNjEzZjJlMjYtNDA3ZC00OGM3LTllY2EtYjhlOTFkZjk5ZGM5IgogICAgICAgICAgICBdLAogICAgICAgICAgICAiZXh0ZXJuYWxfcmVmZXJlbmNlcyI6IFsKICAgICAgICAgICAgICAgIHsKICAgICAgICAgICAgICAgICAgICAiZXh0ZXJuYWxfaWQiOiAiVDE1NjYiLAogICAgICAgICAgICAgICAgICAgICJzb3VyY2VfbmFtZSI6ICJtaXRyZS1hdHRhY2siLAogICAgICAgICAgICAgICAgICAgICJ1cmwiOiAiaHR0cHM6Ly9hdHRhY2subWl0cmUub3JnL3RlY2huaXF1ZXMvVDE1NjYiCiAgICAgICAgICAgICAgICB9CiAgICAgICAgICAgIF0KICAgICAgICB9LAogICAgICAgIHsKICAgICAgICAgICAgImlkIjogImF0dGFjay1wYXR0ZXJuLS1kMjRlYWZlYi1hZGU2LTQyNDUtYTJiNS0yNjNjMmEzYTdiOWEiLAogICAgICAgICAgICAidHlwZSI6ICJhdHRhY2stcGF0dGVybiIsCiAgICAgICAgICAgICJjcmVhdGVkIjogIjIwMjQtMDgtMjhUMTU6MzI6MzUuMDAwWiIsCiAgICAgICAgICAgICJtb2RpZmllZCI6ICIyMDI0LTA4LTI4VDE1OjMyOjM1LjAwMFoiLAogICAgICAgICAgICAic3BlY192ZXJzaW9uIjogIjIuMSIsCiAgICAgICAgICAgICJjcmVhdGVkX2J5X3JlZiI6ICJpZGVudGl0eS0tYjNiY2EzYzItMWYzZC00YjU0LWI0NGYtZGFjNDJjM2E4ZjAxIiwKICAgICAgICAgICAgIm5hbWUiOiAiQ29tbWFuZCBhbmQgU2NyaXB0aW5nIEludGVycHJldGVyIiwKICAgICAgICAgICAgIm9iamVjdF9tYXJraW5nX3JlZnMiOiBbCiAgICAgICAgICAgICAgICAibWFya2luZy1kZWZpbml0aW9uLS02MTNmMmUyNi00MDdkLTQ4YzctOWVjYS1iOGU5MWRmOTlkYzkiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJleHRlcm5hbF9yZWZlcmVuY2VzIjogWwogICAgICAgICAgICAgICAgewogICAgICAgICAgICAgICAgICAgICJleHRlcm5hbF9pZCI6ICJUMTA1OSIsCiAgICAgICAgICAgICAgICAgICAgInNvdXJjZV9uYW1lIjogIm1pdHJlLWF0dGFjayIsCiAgICAgICAgICAgICAgICAgICAgInVybCI6ICJodHRwczovL2F0dGFjay5taXRyZS5vcmcvdGVjaG5pcXVlcy9UMTA1OSIKICAgICAgICAgICAgICAgIH0KICAgICAgICAgICAgXQogICAgICAgIH0sCiAgICAgICAgewogICAgICAgICAgICAiaWQiOiAiYXR0YWNrLXBhdHRlcm4tLWVkZTE0ZDY2LWJlZjgtNDBiMy1hZTE3LTMxZTA5NGUzY2RiZSIsCiAgICAgICAgICAgICJ0eXBlIjogImF0dGFjay1wYXR0ZXJuIiwKICAgICAgICAgICAgImNyZWF0ZWQiOiAiMjAyNC0wOC0yOFQxNTozMjozNS4wMDBaIiwKICAgICAgICAgICAgIm1vZGlmaWVkIjogIjIwMjQtMDgtMjhUMTU6MzI6MzUuMDAwWiIsCiAgICAgICAgICAgICJzcGVjX3ZlcnNpb24iOiAiMi4xIiwKICAgICAgICAgICAgImNyZWF0ZWRfYnlfcmVmIjogImlkZW50aXR5LS1iM2JjYTNjMi0xZjNkLTRiNTQtYjQ0Zi1kYWM0MmMzYThmMDEiLAogICAgICAgICAgICAibmFtZSI6ICJDb21tYW5kIGFuZCBTY3JpcHRpbmcgSW50ZXJwcmV0ZXI6IFBvd2VyU2hlbGwiLAogICAgICAgICAgICAib2JqZWN0X21hcmtpbmdfcmVmcyI6IFsKICAgICAgICAgICAgICAgICJtYXJraW5nLWRlZmluaXRpb24tLTYxM2YyZTI2LTQwN2QtNDhjNy05ZWNhLWI4ZTkxZGY5OWRjOSIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgImV4dGVybmFsX3JlZmVyZW5jZXMiOiBbCiAgICAgICAgICAgICAgICB7CiAgICAgICAgICAgICAgICAgICAgImV4dGVybmFsX2lkIjogIlQxMDU5LjAwMSIsCiAgICAgICAgICAgICAgICAgICAgInNvdXJjZV9uYW1lIjogIm1pdHJlLWF0dGFjayIsCiAgICAgICAgICAgICAgICAgICAgInVybCI6ICJodHRwczovL2F0dGFjay5taXRyZS5vcmcvdGVjaG5pcXVlcy9UMTA1OS8wMDEiCiAgICAgICAgICAgICAgICB9CiAgICAgICAgICAgIF0KICAgICAgICB9LAogICAgICAgIHsKICAgICAgICAgICAgImlkIjogImF0dGFjay1wYXR0ZXJuLS0wMWI2MTY1My
|
||
|
},
|
||
|
{
|
||
|
"type": "text",
|
||
|
"object_relation": "format",
|
||
|
"value": "2.1",
|
||
|
"category": "Other",
|
||
|
"uuid": "d99ff78d-cf0d-45ef-82d9-e64dc57be59a"
|
||
|
}
|
||
|
],
|
||
|
"x_misp_meta_category": "file",
|
||
|
"x_misp_name": "original-imported-file"
|
||
|
},
|
||
|
{
|
||
|
"type": "x-misp-object",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "x-misp-object--a89eb75a-7c0e-4ddd-8a88-6afa80638486",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-08-30T08:23:40.000Z",
|
||
|
"modified": "2024-08-30T08:23:40.000Z",
|
||
|
"labels": [
|
||
|
"misp:name=\"report\"",
|
||
|
"misp:meta-category=\"misc\""
|
||
|
],
|
||
|
"x_misp_attributes": [
|
||
|
{
|
||
|
"type": "link",
|
||
|
"object_relation": "link",
|
||
|
"value": "https://www.cisa.gov/sites/default/files/2024-08/aa24-242a-stopransomware-ransomhub-ransomware_0.pdf",
|
||
|
"category": "External analysis",
|
||
|
"uuid": "f63f57ce-87d0-4db3-a01e-e5e609b02194"
|
||
|
},
|
||
|
{
|
||
|
"type": "text",
|
||
|
"object_relation": "summary",
|
||
|
"value": "The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the\r\nMulti-State Information Sharing and Analysis Center (MS-ISAC), and the Department of Health and Human\r\nServices (HHS) (hereafter referred to as the authoring organizations) are releasing this joint advisory to\r\ndisseminate known RansomHub ransomware IOCs and TTPs. These have been identified through FBI\r\nthreat response activities and third-party reporting as recently as August 2024. RansomHub is a\r\nransomware-as-a-service variant\u2014formerly known as Cyclops and Knight\u2014that has established itself as an\r\nefficient and successful service model (recently attracting high-profile affiliates from other prominent\r\nvariants such as LockBit and ALPHV).",
|
||
|
"category": "Other",
|
||
|
"uuid": "695b93f7-31a9-4b62-8245-3006051a83e4"
|
||
|
},
|
||
|
{
|
||
|
"type": "text",
|
||
|
"object_relation": "title",
|
||
|
"value": "AA24-242A - #StopRansomware: RansomHub Ransomware",
|
||
|
"category": "Other",
|
||
|
"uuid": "d332b82e-c897-4b6e-bcba-a3d87224a3ee"
|
||
|
},
|
||
|
{
|
||
|
"type": "text",
|
||
|
"object_relation": "type",
|
||
|
"value": "Report",
|
||
|
"category": "Other",
|
||
|
"uuid": "138fc15f-8a67-4c52-a29c-5530684db097"
|
||
|
},
|
||
|
{
|
||
|
"type": "attachment",
|
||
|
"object_relation": "report-file",
|
||
|
"value": "aa24-242a-stopransomware-ransomhub-ransomware_0.pdf",
|
||
|
"category": "External analysis",
|
||
|
"uuid": "8e215cdf-4b70-4907-be01-edfd1a3bd1f5",
|
||
|
"data": "JVBERi0xLjYNJeLjz9MNCjI0MTAgMCBvYmoNPDwvTGluZWFyaXplZCAxL0wgNzIyNzYzL08gMjQxMi9FIDI5MDk5Ni9OIDI0L1QgNzIyMDIzL0ggWyA1NzkgNjc2XT4+DWVuZG9iag0gICAgICAgICAgDQoyNDQ4IDAgb2JqDTw8L0RlY29kZVBhcm1zPDwvQ29sdW1ucyA1L1ByZWRpY3RvciAxMj4+L0ZpbHRlci9GbGF0ZURlY29kZS9JRFs8OTQ5OTA3Q0RDN0Q2QjY0Mzg5OUFGMTMyRTFCOTAxMUU+PEQzMTdBNzcyQ0RGMDc5NEVCMzgxNkQ5OTc4QzgyRURDPl0vSW5kZXhbMjQxMCA2Ml0vSW5mbyAyNDA5IDAgUi9MZW5ndGggMTY1L1ByZXYgNzIyMDI0L1Jvb3QgMjQxMSAwIFIvU2l6ZSAyNDcyL1R5cGUvWFJlZi9XWzEgMyAxXT4+c3RyZWFtDQpo3mJiZGAQYGBiYGC5DiIZ14JIJn0QyR4AZk8HkaxqYHYoWI0WWP0qsMh7MPkfRLJJgsWvgtXPApMiYPV6YHY/iLReAVazEkQyhIFI/s8g0j8BSDJ6fgWx3WtApOFhEGksCjYfhBjTD8LdxqigCGKrZIJIZbAClp8gUv0O2OVGIDWF90Bs4Swg+WetBgMTIwMnWA3QRQNG/mf4ee01QIABAPrHHMMNCmVuZHN0cmVhbQ1lbmRvYmoNc3RhcnR4cmVmDQowDQolJUVPRg0KICAgICAgIA0KMjQ3MSAwIG9iag08PC9DIDcwOS9GaWx0ZXIvRmxhdGVEZWNvZGUvSSA3MzEvTGVuZ3RoIDU4MC9PIDY5My9TIDU2Mz4+c3RyZWFtDQpo3mJgYGACog8MbAwMvGUMwgwIIMzAChRlYeDoMHBkEeRkEQAJsgg4AlH3Vod3LAwNDB8KVB4xRrhOfan3h/FKgkkNYzBQCfMWhuUMGi9YLJiyFriYcFxq5BDQmMPy70DOC9Z/1eESx/RSZIrnvCmacnzvSyTbGAW0e0V+CnqairI4tIv8FA5MdRRQPLorsn+iqVjYzBdsL104ItvtvNJ9XTMiBJnkXroq/NScayoWWuDC9dJVafGTZSVXQqsOCijmrSh+4uuaDVSza6H/RFPtEKDiV2tABmZd3SLIJPZqjZ3LlbDdjgLKT3wdXDh+CgcIMgFFWByAFgHdsGrDT+EgoKyi+67FQHPC1gDNATK8DgKlgMpA3IXngcZGSC8VUEyDuAfktsDzk2ZeDgxtFFB8NyUY5JjIABcOkEsaGASV0js6OhoYzNIrOjoYGIBkAwOTkjqQ0wEKrXKwpIiLO1iAUVAEIiAoWg6iGMRByhkFQcobGISUwILlHQzsFXAqDWwigyBYCkgC2SBC0BwszFgOsccdbACzMZjLClRAdhwCpX0ZOGaBIk0FiPXB0RfCIMjwtrGewSPBV4GDgzmCYw3jbIarjYYOExRcEtQYmDM4yqxDGFc1MDRefvLgkCunzIKEe0YHGa5JznawLvxzUWFF1wZ2L7UOpvcySU1OBy96MmUwJzDu4tkpLQo03Ir5+ga2BUEmbPfgySWCgStqDijZAN16DkhHMnDFZQFpcQaGfiO4qiIGbqZWiCrGxwABBgB6gOPgDQplbmRzdHJlYW0NZW5kb2JqDTI0MTEgMCBvYmoNPDwvTGFuZyj+/wBFAE4ALQBVAFMpL01hcmtJbmZvPDwvTWFya2VkIHRydWU+Pi9NZXRhZGF0YSAxMTIgMCBSL091dGxpbmVzIDE0NSAwIFIvUGFnZUxheW91dC9PbmVDb2x1bW4vUGFnZXMgMjQwNCAwIFIvU3RydWN0VHJlZVJvb3QgMTg2IDAgUi9UeXBlL0NhdGFsb2c+Pg1lbmRvYmoNMjQxMiAwIG9iag08PC9Bbm5vdHMgMjQ0OSAwIFIvQ29udGVudHNbMjQxNSAwIFIgMjQxOCAwIFIgMjQyMSAwIFIgMjQyMiAwIFIgMjQyMyAwIFIgMjQyNCAwIFIgMjQyNiAwIFIgMjQyOCAwIFJdL0Nyb3BCb3hbMC4wIDAuMCA2MTIuMCA3OTIuMF0vR3JvdXAgMjQ3MCAwIFIvTWVkaWFCb3hbMC4wIDAuMCA2MTIuMCA3OTIuMF0vUGFyZW50IDI0MDUgMCBSL1Jlc291cmNlczw8L0NvbG9yU3BhY2U8PC9DUzAgMjQ1MCAwIFI+Pi9FeHRHU3RhdGU8PC9HUzAgMjQ1MSAwIFIvR1MxIDI0NTIgMCBSPj4vRm9udDw8L0MyXzAgMjQ1NyAwIFIvVFQwIDI0NTkgMCBSL1RUMSAyNDYxIDAgUi9UVDIgMjQ2MyAwIFIvVFQzIDI0NjUgMCBSL1RUNCAyNDY3IDAgUi9UVDUgMjQ2OSAwIFI+Pi9Qcm9jU2V0Wy9QREYvVGV4dC9JbWFnZUMvSW1hZ2VJXS9YT2JqZWN0PDwvSW0wIDI0MjcgMCBSL0ltMSAyNDM5IDAgUi9JbTIgMjQ0MSAwIFIvSW0zIDI0NDMgMCBSL0ltNCAyNDQ1IDAgUi9JbTUgMjQ0NyAwIFI+Pj4+L1JvdGF0ZSAwL1N0cnVjdFBhcmVudHMgMC9UYWJzL1MvVHlwZS9QYWdlPj4NZW5kb2JqDTI0MTMgMCBvYmoNPDwvRmlsdGVyL0ZsYXRlRGVjb2RlL0ZpcnN0IDIwNi9MZW5ndGggMTUxNi9OIDIyL1R5cGUvT2JqU3RtPj5zdHJlYW0NCmjenFhZb9s4EP4rfGxRZHkfAooAdtwk3jZNECV1F0YeVFtNhNqSYauL+t/vDCnZltY3AkaUOBc53xy0UCoijAilGeH+yYmS+BSEywgn8CYNThQRzuFEEy0VTgwxTuDEEhP5iSOOea4IxBlkMyDYRPjNcMIjiRIM0iqLM5BunMYZSIwsmmA0kYIhCQiQ0hMbS2DiORxRzHrJEZjqDQE2ZeF1yCOmYDuPL0Paz8fpn3RMe+m/2Sh9vOkSwZAW9oIEHz/STj8mP5PJIqXdO/q1mE+TCb3qEP4Xo/cP1cr9wx3hNO6Qcv47pfFdsvgFpHlKn5azlH76U97EZVKmdJR4vmIW+C4vT5UfXk9TcD8fp/Msf33XH6d5mZXL9/Qxfc0W5Xz5rjMufqTvafx7NpukU1gmLBi1GOELZ0zTq34vTks4E4EYeKRXyew2zV7fSmIZg4MLpBdCMHo9SV4XRNHrIi+73eLPkPnvhHMuvbAXv3SdTLPJ8l28nP4oJu/Dp2ySogcl8zrw09dkmtKvneeHu/sPgfTuyS/E5TwtR2/1YeGnQTBIgUH9Mplko07+OkkJo3GZTr8Rq8NBISkaPM9mZTGn36t9aBZ23U0WKZL8TysewXIBovr5zyKg3Z9Ev/dU3PR7d8mM1odLewPcKWvpCpGBTPHvHyXaAsxIgnaJtXV0MOSCDSEeXl4uL4c+jCog7rQuuGCcwCnC8iKEHKr6lI+KMXh+ZdzF7Uo9amT0qXjOMyBK0b1e09qUTSBEWm343Ri79ruUvPK7FGvHX3CIdFyDwxAK+Ruuv54n+a9JlpObonzLRqRbFL9aQBBNIPz9+H3QH3yoGQPfBfKdiwmzFxMqkk1M7DFgdc6DLO/ki2z1fp3NF+XVWzKvz6YJCOe3+CWpaLhVa/dAIvHmbXqIq6aHQN+4fFsMhcaoYUQ79LuFgAMPEe445ErpB64iVT0QjEh9zKh5gvRKh8LsDokdkqW2ETGQprVyEEnOzw1WB+CRVhEjIBdHjDioHAZrAIBCQ+bHp4G8oDFDQ3I3DPRJC3QgC/aggV6LsAdfVvw+IFbxP+QipMXcr6EAIZ2EFRWBbAX2wjoOzYBfom6wU4kgF4oB2i7hO9YTCTbjGhY3A+8K8Kq4huda37F//mxBJ45wVuiJUyRYK18akRe5zYzLzUbkCV1FXmQ2Ik/D+eEaVGY4ZeBvRF5nniXtnGubofbl9rn/Of7gKS9C6JyceS+4qOIsEvtzL4+acbZd+5khZlgrxJTZH2LS7Qgx61qOklL64d0OqzjHJw7tE3D7fz3Yiq6WxRngDZ
|
||
|
}
|
||
|
],
|
||
|
"x_misp_meta_category": "misc",
|
||
|
"x_misp_name": "report"
|
||
|
},
|
||
|
{
|
||
|
"type": "marking-definition",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
|
||
|
"created": "2017-01-20T00:00:00.000Z",
|
||
|
"definition_type": "tlp",
|
||
|
"name": "TLP:WHITE",
|
||
|
"definition": {
|
||
|
"tlp": "white"
|
||
|
}
|
||
|
}
|
||
|
]
|
||
|
}
|