5196 lines
1.8 MiB
JSON
5196 lines
1.8 MiB
JSON
|
{
|
||
|
"type": "bundle",
|
||
|
"id": "bundle--d67bfbe0-e01d-4e2e-8a56-214805d85aee",
|
||
|
"objects": [
|
||
|
{
|
||
|
"type": "identity",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-06T07:48:55.000Z",
|
||
|
"modified": "2024-09-06T07:48:55.000Z",
|
||
|
"name": "CIRCL",
|
||
|
"identity_class": "organization"
|
||
|
},
|
||
|
{
|
||
|
"type": "report",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "report--d67bfbe0-e01d-4e2e-8a56-214805d85aee",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-06T07:48:55.000Z",
|
||
|
"modified": "2024-09-06T07:48:55.000Z",
|
||
|
"name": "AA24-249A: Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure",
|
||
|
"published": "2024-09-06T07:49:36Z",
|
||
|
"object_refs": [
|
||
|
"indicator--e4d79d5b-0f18-4425-aaff-8ad4a76965bc",
|
||
|
"indicator--d200de3d-892b-4cc5-acb7-5b9483a87558",
|
||
|
"indicator--dbd63fee-b773-44e2-8f5d-a86bc605c493",
|
||
|
"indicator--79464528-6363-47d6-b916-2acad6b1967b",
|
||
|
"indicator--aae7a7d1-0efc-4214-879c-c5bb0ae26af6",
|
||
|
"indicator--ef02798e-12ab-4998-b06f-a5560e7e5a66",
|
||
|
"indicator--16387805-2b0f-437f-8626-6b9288d077c4",
|
||
|
"indicator--84fee704-e245-4bc0-8367-3f595c80492a",
|
||
|
"indicator--ebd1e153-de64-4b1e-bf20-2a905d976b9b",
|
||
|
"indicator--6263e5f1-8aab-4ca8-9964-37153d0d835f",
|
||
|
"indicator--42d0545e-8f58-4e14-b422-ce7a4814fab5",
|
||
|
"indicator--d78f253e-bcc2-465f-99e4-edb709de3f08",
|
||
|
"indicator--2c737bec-16c5-4941-8fcb-abaff31fe732",
|
||
|
"indicator--b4d30160-f19c-4e65-97d5-31ddb50abc3e",
|
||
|
"indicator--ee69c3df-c937-4d55-9262-08ce29a20a7a",
|
||
|
"indicator--2fefe355-31cb-4629-86d1-25c8bf649a09",
|
||
|
"indicator--5b9125b1-5e5d-4979-8db7-640dd0edb400",
|
||
|
"indicator--7bcfbc3a-4c9c-4ff7-b386-3675e604872f",
|
||
|
"indicator--1ed0174d-a046-449f-8cf5-f2adb538c862",
|
||
|
"indicator--65d74122-9806-4072-a07b-a782cdb29920",
|
||
|
"indicator--86043c21-e0ec-4aa4-9776-38d6d3f54dd9",
|
||
|
"indicator--5c37afeb-578f-492b-977b-21fd0ed1ce14",
|
||
|
"indicator--0125fa07-459a-4303-94e7-c6a3ab0fa616",
|
||
|
"indicator--76983bd5-1263-43f1-948f-dbbc1c68f993",
|
||
|
"indicator--8ebbd796-e691-4a77-91ad-ed23578798de",
|
||
|
"indicator--4492d66f-71f9-4c8c-8db1-d15c409e6537",
|
||
|
"indicator--f3a3f4f1-c776-4ce4-b6d3-215710582bd0",
|
||
|
"indicator--cee06014-e20d-4604-acdf-70f064ccb078",
|
||
|
"indicator--f16ba0e3-9c09-4381-9528-53ed7ac15119",
|
||
|
"indicator--c782c58f-0860-416e-990f-eb3966dff5fd",
|
||
|
"indicator--341b14db-37e3-4597-9e20-94cd26e8b5e6",
|
||
|
"indicator--84b269d9-399b-4b56-a0ec-8fa36b910b64",
|
||
|
"indicator--1396ca9d-4c4c-4fa1-9ccf-284c5dc1b2af",
|
||
|
"indicator--e3cd4b8b-8cdd-4ecd-89ea-656a80d02eb0",
|
||
|
"indicator--3b86b9fd-1252-4562-b03d-2e04d1962a87",
|
||
|
"indicator--b34015c1-842a-4239-a9cb-b93c5b618627",
|
||
|
"indicator--cb9275b4-9e07-4908-a02b-20ff23ecf33a",
|
||
|
"indicator--65c5ef28-1e3b-44b4-bb6f-40352dd6e48a",
|
||
|
"indicator--84f3dd6b-9f19-44c1-af63-b3df7315de9e",
|
||
|
"indicator--028cae65-31c0-4e35-bc5f-fc44a06a8fdc",
|
||
|
"indicator--971ea537-49b9-47f7-aa3c-4b069e937f48",
|
||
|
"indicator--75afcfa4-d56f-4a6d-83b4-20998a206056",
|
||
|
"indicator--5f5d6811-6362-46b9-a72c-a3feabede57c",
|
||
|
"indicator--6f44b2f1-dec4-4eec-89b5-3c605f3be0cb",
|
||
|
"indicator--ea33e6fe-d2db-488b-ae4e-21f0bb3d854b",
|
||
|
"indicator--d4a14fa6-d863-4409-ba49-d9fd8307aa89",
|
||
|
"indicator--5ea01eea-27f2-4594-abee-672ad5e38b05",
|
||
|
"indicator--49995268-a9b5-4296-a1e1-ed68bf2e4789",
|
||
|
"indicator--80e9623d-7e43-46a7-84b8-9e0ee4b5af82",
|
||
|
"indicator--e00d7787-021c-44df-8be8-37b0031f260e",
|
||
|
"indicator--22cf353b-1896-4d8d-8ca5-ead2e033dfb2",
|
||
|
"indicator--a33130bd-3ad2-4697-9890-4e2be951c1e9",
|
||
|
"indicator--d889113d-a8d0-470b-a609-3bec93bae1e6",
|
||
|
"indicator--f7388f34-1830-407b-9353-1e49540add16",
|
||
|
"indicator--b8839abb-9d28-4697-af69-48d67e96a5d2",
|
||
|
"indicator--cccef14a-c480-4a0d-8d68-f3a15d300380",
|
||
|
"indicator--87d9dc0e-3a5d-491b-9578-22cb9c0d0edf",
|
||
|
"indicator--f92297f3-d860-402a-9435-d71a88b58a5b",
|
||
|
"indicator--b7bcc0a9-e052-4b49-88a3-6bc2774ee335",
|
||
|
"indicator--a3e81f0d-e045-49a7-8ebc-2ce9531cc720",
|
||
|
"indicator--a67cf1aa-6079-42a5-bd77-49ee050c3216",
|
||
|
"indicator--1d61dad5-71e8-4ee1-b8d4-cda09c070039",
|
||
|
"indicator--173119ee-711b-4cf5-8615-bde343ecaca4",
|
||
|
"indicator--e724aa55-de70-4c7a-a791-c34479314cae",
|
||
|
"indicator--85c8f694-4185-4627-a6c7-be965878edae",
|
||
|
"indicator--29abf48c-a628-4d19-939a-5bbae672d694",
|
||
|
"indicator--c18cde77-f736-44cd-a2a4-a7f44807b3c1",
|
||
|
"indicator--048b7124-c527-41e7-9edd-4ff1263c3b6e",
|
||
|
"indicator--6986a8fc-f8ea-4e3b-8dbc-0ab19b4f160a",
|
||
|
"indicator--dcb5c48c-4b54-463a-9f79-d588a08caf0c",
|
||
|
"indicator--df45d9b1-6794-4745-a364-99267de3c6fe",
|
||
|
"indicator--17d4d0c8-2671-47e2-94ad-94e15f94059f",
|
||
|
"indicator--fc3fa43a-0d9d-4bbc-b4e2-6d1bd71fcfca",
|
||
|
"indicator--4fb60f8b-6d92-460e-8846-42fe50019713",
|
||
|
"indicator--916dea47-465e-4b18-a2b8-a643f35d6a67",
|
||
|
"indicator--086d9462-83c2-4c34-8311-83d6507395a1",
|
||
|
"indicator--fa73a2df-eecf-4e1b-8a8a-09ef22be8e57",
|
||
|
"indicator--fec4f9e8-a4fb-4fa6-9d1b-ca779679dbd5",
|
||
|
"indicator--8d54312e-2c13-47ab-be31-4e0fd42f16b5",
|
||
|
"indicator--09ddd38b-27b8-4873-b641-2b654cf35544",
|
||
|
"indicator--c05d7456-72fd-4ff2-9137-311ac5783fde",
|
||
|
"indicator--27063176-a2bc-46c7-89db-b01e662c1345",
|
||
|
"indicator--6f2c8464-bab4-4722-a4a3-16e24117cc76",
|
||
|
"indicator--954cfc41-4031-4460-9684-51c22d935c54",
|
||
|
"indicator--7def6d2a-4598-4cc0-8790-4e691fb831b4",
|
||
|
"indicator--f397e000-7d05-46da-9d70-a9f65bedea34",
|
||
|
"indicator--2461f554-82c8-44fd-a6fa-ffd565d733f1",
|
||
|
"indicator--0273104b-e0fb-47c4-a8f5-7355b57565b3",
|
||
|
"indicator--ac14c670-634c-4229-8b13-bd572a0ab45a",
|
||
|
"indicator--c461aadf-2b11-4405-982c-86a150531bab",
|
||
|
"indicator--7e326bdf-0224-486d-ab78-884139b8ce1a",
|
||
|
"indicator--9872cc0c-af66-43de-aad8-7064de07d04c",
|
||
|
"indicator--650062ce-3490-43e1-b9f8-5d60e67bd3cd",
|
||
|
"indicator--b3c044da-a5e6-4ce0-8ac3-c340e514da10",
|
||
|
"indicator--ce239e3d-2f3c-44b7-b043-66aa37545096",
|
||
|
"indicator--ce9ea643-0fab-4e2d-94ba-98779dcb1d00",
|
||
|
"indicator--a7fa2017-94cf-4a95-9d16-27b3468397d5",
|
||
|
"indicator--17ddd8b4-7f8a-46ea-9458-a99cd57319ed",
|
||
|
"indicator--e3867e98-784e-4976-ab3c-384fe37733ee",
|
||
|
"indicator--7281a17b-0e66-4e00-9718-800a9d8da6ec",
|
||
|
"indicator--4092fbde-df88-478a-8fcc-57457c8276b8",
|
||
|
"indicator--0ff224fc-f3ca-4e3b-aa4e-b82da3fd79da",
|
||
|
"indicator--e4139b31-64f7-47a5-86fb-b419398b5c5c",
|
||
|
"indicator--3909e442-be38-4e98-919b-88b537e093e2",
|
||
|
"indicator--d6d0ba98-fac8-4dc4-bc41-c5e01e406ec5",
|
||
|
"indicator--30081114-c827-4109-affd-c60971086205",
|
||
|
"indicator--563718cb-9d8f-4ab0-b8ec-0022d77ba1a0",
|
||
|
"indicator--4b7bae0d-8f8e-4675-aca7-a3f770f0a18e",
|
||
|
"indicator--1dfee9f0-6557-41eb-ac11-3eb882ac2813",
|
||
|
"indicator--4bde370f-bef8-475b-9879-b46e524038c2",
|
||
|
"indicator--e59e8107-1983-4286-beba-928290528ba3",
|
||
|
"indicator--078b5b12-8036-4216-8cf3-5dc5542f4ded",
|
||
|
"indicator--3460cfae-957a-4aa3-be2d-5090bc8b66b0",
|
||
|
"indicator--63dd4894-a056-4a7b-9bb4-a69c9d4d3d17",
|
||
|
"indicator--2bbfc56d-3da3-41aa-b4de-e37f373efd7c",
|
||
|
"indicator--83fc4d37-b08a-4961-a44e-484c93534f69",
|
||
|
"indicator--1b29c353-0228-4fda-9b4d-aa3bfe56b035",
|
||
|
"indicator--791096f0-6cb0-4766-9b0d-477f781bb317",
|
||
|
"indicator--1c82a716-832f-4f03-8f77-ca3f86a25d99",
|
||
|
"indicator--57ac15b9-249c-4ac9-8d7d-e5a4eab46174",
|
||
|
"indicator--747f670a-4ba9-4cd5-8680-3607b8a33f5b",
|
||
|
"indicator--e6977878-8f62-4141-9116-d444a6f68586",
|
||
|
"indicator--9fc03b83-56d7-4d98-af98-6a89d240d102",
|
||
|
"indicator--0f8d37d1-c54e-4514-a5a8-39ccd34f9ea3",
|
||
|
"indicator--ae01811a-2cc8-4b54-8f5f-bc3d0638f023",
|
||
|
"indicator--01860414-eb4f-4d89-9ece-ef1d85b56658",
|
||
|
"indicator--5ed49f3c-2c7e-4c3d-b9d8-1d05d2f1a91f",
|
||
|
"indicator--05bb2494-eb7a-4ada-b948-5fa896837b35",
|
||
|
"indicator--0ffeaa0a-b3d5-427a-813e-66c279b94a1f",
|
||
|
"indicator--4df248e4-c491-48a4-8294-9be67e4b30c0",
|
||
|
"indicator--6f9ef797-bf7b-4ac1-89f6-98adb0ea6918",
|
||
|
"indicator--0c45962b-3242-4bcb-821d-4b8c663d8404",
|
||
|
"indicator--bd1c2ee1-8c63-4867-a85e-03d59045fcb6",
|
||
|
"indicator--fb7a494a-a0f1-4a77-9f41-f12a5600b607",
|
||
|
"indicator--f4fd2e9c-4700-41ac-ba00-f8971fab3117",
|
||
|
"indicator--012d93e3-ae29-4e61-bd55-2c38a33dbcd8",
|
||
|
"indicator--d82de68b-4555-48d7-832f-6fb0dbaaed83",
|
||
|
"indicator--ff08bc0b-86c5-48dd-a6ba-886aa7e26f47",
|
||
|
"indicator--4ab89aa2-eb6e-4ca7-aa45-4ead9f893679",
|
||
|
"indicator--7d517f54-eda9-480e-8c63-bd959eff0b1c",
|
||
|
"indicator--08bb0f87-cdda-429b-8e10-eadca0bdf8e2",
|
||
|
"indicator--b9301e51-88a0-4b3b-9ced-381fd33f331c",
|
||
|
"indicator--b6b22511-4344-4605-8be6-e98cdc9475e1",
|
||
|
"indicator--fb19330e-2a03-4e57-8424-9ad5c6bbcfe2",
|
||
|
"indicator--31e51fad-79ef-4cca-b31a-108b889c546c",
|
||
|
"indicator--f55dd154-c819-48e8-af95-8a3a6c598158",
|
||
|
"indicator--adf7457f-75a7-4c70-bf38-32a5f17b28c7",
|
||
|
"indicator--9735b359-67a2-4921-8f4e-0bef0a83ce73",
|
||
|
"indicator--83cd5ade-209c-41a5-bb19-33768efe19e6",
|
||
|
"indicator--72febe90-22b8-432b-b825-bbb840ebe07d",
|
||
|
"indicator--273d289e-3124-4d8f-91f8-a0ea37b5d744",
|
||
|
"indicator--1207700c-abca-4f4b-bdcc-4e1761913214",
|
||
|
"indicator--0419067d-ad28-4706-a017-25969d67328f",
|
||
|
"indicator--0580b905-8022-41ae-a4f2-bbb3f9ef83b9",
|
||
|
"indicator--8602ba8f-7158-42a5-a629-32d0ed3c27ef",
|
||
|
"indicator--316a71af-6b75-46e2-ba77-6801f2cb6497",
|
||
|
"indicator--5d516549-e05f-44c5-8f51-837c53229eff",
|
||
|
"indicator--ac4dc844-a4ed-4d31-a196-8e2e28e86c02",
|
||
|
"indicator--66ddfef2-0de7-4469-97ef-90be5dd1aa61",
|
||
|
"indicator--aad8c2fa-b5b6-45e7-a954-2426db987af9",
|
||
|
"indicator--c44b0a77-8d94-4b6b-9863-7607b65237ab",
|
||
|
"indicator--a467682b-8390-4502-9cc4-70bb332e569b",
|
||
|
"indicator--7ebda806-74e0-49e0-9746-0dee98c9ca2a",
|
||
|
"indicator--15777c0e-1b11-40ca-a3da-e9eec41e0946",
|
||
|
"indicator--95c78c9a-98e1-4cb1-9a4a-45956d3c5628",
|
||
|
"indicator--891b311d-58c1-4e90-b329-35de69333ddb",
|
||
|
"indicator--debcfe37-043c-44b7-b86b-ecc0ce889d5f",
|
||
|
"indicator--2c18b530-e166-4f99-bf0f-3805b95608ea",
|
||
|
"indicator--1f657c53-754c-4adb-945b-78f39060d8de",
|
||
|
"indicator--e805eda5-9ebd-4523-864b-0af05828b1c9",
|
||
|
"indicator--58497591-5993-4c93-8fc5-1173daf43782",
|
||
|
"indicator--1b21652a-6f34-43bc-9b61-334826b22f5b",
|
||
|
"indicator--b740d5a1-9153-45c8-81f2-0950d39d6a14",
|
||
|
"indicator--7199a781-3a71-4301-ad10-407b5e9fbaa7",
|
||
|
"indicator--6dab9927-451f-46cb-a5a3-876f381ae1e4",
|
||
|
"indicator--32933f91-47f8-4ffe-8b4b-1452040c87e9",
|
||
|
"indicator--ce473a0c-acf3-497b-bf35-cf534a1b69fa",
|
||
|
"indicator--2d170d33-aca2-4cfe-94a5-7fb0182c71e5",
|
||
|
"indicator--e582ce35-ccd7-4582-9d2e-cd953c3e6090",
|
||
|
"indicator--841c42e7-de66-49c8-ac04-141fe28d21bf",
|
||
|
"indicator--4dfa7787-900b-4c3b-aa03-1a5be6c44375",
|
||
|
"indicator--d56d107e-abf2-4a7f-ba35-0c8d6f8330df",
|
||
|
"indicator--bf03694c-665a-4145-930e-7c218915ae22",
|
||
|
"indicator--060ea156-0eb5-4f95-ac8d-7b2502fb92e7",
|
||
|
"indicator--99b93ad5-38af-4534-a43a-f0f48080386d",
|
||
|
"indicator--ad9882f2-73a8-4ee8-9933-01c00d70c9a1",
|
||
|
"indicator--c8c23229-d10f-45d9-80b4-30691f49e9b0",
|
||
|
"indicator--e49afa4e-ab00-4def-b732-bd8b77301f9c",
|
||
|
"indicator--ad79ab5b-e77e-400b-9903-7c37dbd711ad",
|
||
|
"indicator--c53c4b11-22d8-45f8-abdb-62a102dfd0f3",
|
||
|
"indicator--9356204e-b184-489e-ac87-2ad76d12f9bf",
|
||
|
"indicator--6a89f90e-176f-48f2-9b00-07d7ca24890d",
|
||
|
"indicator--a489adfe-a6b6-4890-8f35-ca25c35c82d4",
|
||
|
"indicator--981b34f3-18cd-49a6-af3f-8b91618ae731",
|
||
|
"indicator--a3a725cb-3205-4867-a8b1-44f3106cb138",
|
||
|
"indicator--d74d9dae-1d82-43fb-9a61-00b8153938fe",
|
||
|
"indicator--b0cd44ba-3d9f-425c-8bf2-3ec7efe6bb5d",
|
||
|
"indicator--994089df-40d9-4ca1-b834-6d05829cf31b",
|
||
|
"indicator--fea555f1-2e49-4c87-9005-9493f4e46d82",
|
||
|
"indicator--1d29024b-9099-443c-af91-3b831562902e",
|
||
|
"indicator--5c918e3d-fca0-4cbd-8327-a7968237a2c3",
|
||
|
"indicator--6971d11f-4641-4a6f-9d6d-cc032f5fdeb9",
|
||
|
"indicator--7c18bc0c-21c4-44b4-b89b-4280be7eec4e",
|
||
|
"indicator--82f83bb1-8e40-4ec0-83f0-5bc9c3aa476d",
|
||
|
"indicator--dfcf55fb-9c49-4cad-99b3-86ebad50f186",
|
||
|
"indicator--ae8445df-cd98-49d6-bb60-3f2dd3def234",
|
||
|
"indicator--1768da67-e65f-4bad-8744-12a90e2e3300",
|
||
|
"indicator--7b213df7-fb1f-4ab2-8d90-b3ca6b6f94a6",
|
||
|
"x-misp-object--c015fd65-073d-4519-bb64-d652be3f1d97",
|
||
|
"x-misp-object--c81a4e0d-b5d6-4779-9299-a85efdb5c03f",
|
||
|
"x-misp-object--ef754d1a-1b71-471b-b4c8-c7b200dc0fb7"
|
||
|
],
|
||
|
"labels": [
|
||
|
"Threat-Report",
|
||
|
"misp:tool=\"MISP-STIX-Converter\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"7e6945c5-7f3b-55f6-bcb7-fa324c6bdaed\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"cfbd0546-fbbe-50bc-9839-f5942a2351aa\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"5831810d-b580-5f7a-a1e7-faed4d1a563f\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"486b67c5-001e-5f63-a107-32fc8a0241d3\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"8853f41e-8f72-5458-ab93-952f356cfe5a\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"e50f5d5e-71ea-562f-a620-81b1959d12bf\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"0dfcaefb-2c4e-5c91-a456-1f99d838489c\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"29a2e23c-a528-5a0b-9951-62f952c61a41\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"72daa13a-e9e7-5e55-b00e-33bd4b388780\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"f5c5bb0a-b069-5007-81ce-a5237603e5d2\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"fcee58e5-5ecd-59dd-b6f3-a2ca3773d319\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"5204f946-8433-5ec8-9191-7befc4fabd19\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"e3483879-54f7-577e-bc58-ff095f52940a\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"9ee6c31a-4150-5379-b985-e326e66af3ca\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"e6927ba4-7209-5b63-a292-b0debffe25ee\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"9c5bce7a-fd1d-5dce-8baf-50b158ddd0ef\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"d4702430-9466-5d8a-8c61-df2dda91d764\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"b3d2e49a-5e0d-5874-abe5-7056de875f42\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"ddbb1e82-5ec2-58f6-a798-21a99cdd86bc\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"819ae972-e7cb-50fa-951f-39f313782283\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"6c1fac21-26db-5cfa-b85b-b35035980c89\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"ffdadad3-c8d6-58e2-b167-f7d519a773d2\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"ebcb5766-2582-57d4-abdb-217f7d3cf6bf\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"65b221c8-e332-5ee8-9690-df517ca14b0e\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"a4c3c998-327a-5e05-8a71-274d32a0fc61\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"8cc97e25-1098-5b49-a89a-b227ac8acfb6\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"deaa17ef-2126-59f8-bfda-8ad576e9f255\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"02af8157-334a-5ad7-95da-71d2da89b995\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"5e84e7dc-47d0-5cbf-a650-10b7f0cfba02\"",
|
||
|
"misp-galaxy:stix-2.1-attack-pattern=\"ee63b40a-73ae-5655-a319-f550fe7da87e\"",
|
||
|
"type:OSINT",
|
||
|
"osint:lifetime=\"perpetual\"",
|
||
|
"osint:certainty=\"50\"",
|
||
|
"tlp:clear",
|
||
|
"misp-galaxy:country=\"russia\"",
|
||
|
"misp-galaxy:intelligence-agency=\"GRU (Russian Federation)\""
|
||
|
],
|
||
|
"object_marking_refs": [
|
||
|
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--e4d79d5b-0f18-4425-aaff-8ad4a76965bc",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '59da31da4db1aa5f9a5c7c0c151422c8']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--d200de3d-892b-4cc5-acb7-5b9483a87558",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'ddec2d79f460a881849037336ba8968f']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--dbd63fee-b773-44e2-8f5d-a86bc605c493",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '64b9feeccf6c183b9f7138f8fc53acbb']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--79464528-6363-47d6-b916-2acad6b1967b",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '993f01861aff306df44e6475f7886f37']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--aae7a7d1-0efc-4214-879c-c5bb0ae26af6",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '143594597130e301499e5940a5fb798a']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ef02798e-12ab-4998-b06f-a5560e7e5a66",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '6a4fca88ee36fecc5113e188cc39d25c']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--16387805-2b0f-437f-8626-6b9288d077c4",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '56e0446a6d7175a0d09110bc483ddbed']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--84fee704-e245-4bc0-8367-3f595c80492a",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '2128361d8aaae1225d50c9add32006a1']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ebd1e153-de64-4b1e-bf20-2a905d976b9b",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'b32e14a9b7de6c92cd16758fa6e23346']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--6263e5f1-8aab-4ca8-9964-37153d0d835f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '7fe7f33d9b5dbdf3d032d2a10e39f283']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--42d0545e-8f58-4e14-b422-ce7a4814fab5",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'f34f60375bebad861a35b7c4bb0fa1c8']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--d78f253e-bcc2-465f-99e4-edb709de3f08",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'cd62d4a178705b2b90a8babd8613df93']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--2c737bec-16c5-4941-8fcb-abaff31fe732",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'e1a15bc13157134f542cd9c55c742460']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--b4d30160-f19c-4e65-97d5-31ddb50abc3e",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '791a81f31a8e7090a7d5417451e09efa']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ee69c3df-c937-4d55-9262-08ce29a20a7a",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'a1b509254a0a1daa7e00d279ec974461']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--2fefe355-31cb-4629-86d1-25c8bf649a09",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '5c9e2195d10375b746b6717fdb47b5b9']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--5b9125b1-5e5d-4979-8db7-640dd0edb400",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'aecb57e20d2c0b0d9fece2cbcbcc3459']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7bcfbc3a-4c9c-4ff7-b386-3675e604872f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '80f0ee332a452172533ad8863bb3bc63']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1ed0174d-a046-449f-8cf5-f2adb538c862",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '2b39eab325906b0a3ab7e584c3d67349']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--65d74122-9806-4072-a07b-a782cdb29920",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'b7c1a8d39f46eaf52be90e24565dd6b0']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--86043c21-e0ec-4aa4-9776-38d6d3f54dd9",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'd06761b2cff86035a4838110ed6ab622']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--5c37afeb-578f-492b-977b-21fd0ed1ce14",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'd40195a444526eafb0db56d95bf8655d']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--0125fa07-459a-4303-94e7-c6a3ab0fa616",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '7234da8ceafbe6586469f18c03cc1832']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--76983bd5-1263-43f1-948f-dbbc1c68f993",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '1c85c0d044ac837e8939564afac1eb32']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--8ebbd796-e691-4a77-91ad-ed23578798de",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '58e879213d81333b628434ba4aeb2751']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--4492d66f-71f9-4c8c-8db1-d15c409e6537",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '562c337b8caca330da2ea6ae07ee5db6']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--f3a3f4f1-c776-4ce4-b6d3-215710582bd0",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '422437f326b8dbe30cc5f103bde31f26']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--cee06014-e20d-4604-acdf-70f064ccb078",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'd034fe4c71b16b6d331886c24fef2751']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--f16ba0e3-9c09-4381-9528-53ed7ac15119",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[url:value = 'https://cdn.discordapp.com/attachments/945968593030496269/945970446149509130/Client.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--c782c58f-0860-416e-990f-eb3966dff5fd",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[url:value = 'https://cdn.discordapp.com/attachments/888408190625128461/895633952247799858/n.lashevychdirekcy.atom.gov.ua.zip']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--341b14db-37e3-4597-9e20-94cd26e8b5e6",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[url:value = 'dns.test658324901domain.me']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--84b269d9-399b-4b56-a0ec-8fa36b910b64",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '81.17.24.130']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1396ca9d-4c4c-4fa1-9ccf-284c5dc1b2af",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[url:value = 'https://nssm.cc']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--e3cd4b8b-8cdd-4ecd-89ea-656a80d02eb0",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[url:value = 'https://3proxy.ru']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--3b86b9fd-1252-4562-b03d-2e04d1962a87",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '194.26.29.251']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--b34015c1-842a-4239-a9cb-b93c5b618627",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '194.26.29.84']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--cb9275b4-9e07-4908-a02b-20ff23ecf33a",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '185.245.85.251']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--65c5ef28-1e3b-44b4-bb6f-40352dd6e48a",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '185.245.84.227']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--84f3dd6b-9f19-44c1-af63-b3df7315de9e",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '179.43.189.218']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--028cae65-31c0-4e35-bc5f-fc44a06a8fdc",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '179.43.187.47']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--971ea537-49b9-47f7-aa3c-4b069e937f48",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '179.43.175.108']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--75afcfa4-d56f-4a6d-83b4-20998a206056",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '179.43.175.38']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--5f5d6811-6362-46b9-a72c-a3feabede57c",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '179.43.162.55']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--6f44b2f1-dec4-4eec-89b5-3c605f3be0cb",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '179.43.133.202']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ea33e6fe-d2db-488b-ae4e-21f0bb3d854b",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '154.21.20.82']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--d4a14fa6-d863-4409-ba49-d9fd8307aa89",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '112.132.218.45']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--5ea01eea-27f2-4594-abee-672ad5e38b05",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '112.51.253.153']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--49995268-a9b5-4296-a1e1-ed68bf2e4789",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '90.131.156.107']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--80e9623d-7e43-46a7-84b8-9e0ee4b5af82",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '79.124.8.66']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--e00d7787-021c-44df-8be8-37b0031f260e",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '46.101.242.222']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--22cf353b-1896-4d8d-8ca5-ead2e033dfb2",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '5.226.139.66']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--a33130bd-3ad2-4697-9890-4e2be951c1e9",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '1cac5c0cb8801e8730447023270d8d56']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--d889113d-a8d0-470b-a609-3bec93bae1e6",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'a9c9c0be8eca3b575c24da0fcf1af1a9']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--f7388f34-1830-407b-9353-1e49540add16",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'af277ae0fbf6cc20f887696ea4756d46']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--b8839abb-9d28-4697-af69-48d67e96a5d2",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '9d7ab8b0aa669125d9a5adc4f46c56f3']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--cccef14a-c480-4a0d-8d68-f3a15d300380",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '755dac7edd17fbf5b5c449dd06c02e14']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--87d9dc0e-3a5d-491b-9578-22cb9c0d0edf",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '251f3a4757d9e4de0499cc30c0bc00a9']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--f92297f3-d860-402a-9435-d71a88b58a5b",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '28d571ddb5c04d065dfe1be9604663ba']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--b7bcc0a9-e052-4b49-88a3-6bc2774ee335",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'ca43a241042b5fcc305393765ae18e69']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--a3e81f0d-e045-49a7-8ebc-2ce9531cc720",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '1e22d64f263e8ea4b2d37dcd9b7c3012']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--a67cf1aa-6079-42a5-bd77-49ee050c3216",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'b0d0a23766fa64ece9315f37b28bb4c0']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1d61dad5-71e8-4ee1-b8d4-cda09c070039",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '94bf96b76c2a092de8962496ce35deaf']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--173119ee-711b-4cf5-8615-bde343ecaca4",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '4e9c55c6fe25d61ca4394de794546fab']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--e724aa55-de70-4c7a-a791-c34479314cae",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '3ccf799ff208981349cee4fb1a1cf88c']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--85c8f694-4185-4627-a6c7-be965878edae",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '96964aed18f65a7acae632f358a093f6']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--29abf48c-a628-4d19-939a-5bbae672d694",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '09a2d85e809d36bff82bd5ab773980a3']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--c18cde77-f736-44cd-a2a4-a7f44807b3c1",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '5eaa7e812733a5c8cda734fab2f752d5']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--048b7124-c527-41e7-9edd-4ff1263c3b6e",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '569c1d31f4c7ec7701d8e4e51b59fe85']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--6986a8fc-f8ea-4e3b-8dbc-0ab19b4f160a",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '246f31c86bbbe7f65c0126cf4a1a947a']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--dcb5c48c-4b54-463a-9f79-d588a08caf0c",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '0a2affa6d895baab087b84e93145da35']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--df45d9b1-6794-4745-a364-99267de3c6fe",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '3fe96ff4a5ef0f5346ce645a2a893597']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--17d4d0c8-2671-47e2-94ad-94e15f94059f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '540ee8e39150c539fea582b0e77be7b0']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--fc3fa43a-0d9d-4bbc-b4e2-6d1bd71fcfca",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'd43446b4a22a597b93b559821ee5ac9b']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--4fb60f8b-6d92-460e-8846-42fe50019713",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '69e58c5ee69f5e5e8a58f4afdd59adfe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--916dea47-465e-4b18-a2b8-a643f35d6a67",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'dea3ae8225913dd98148fc86cfc3bcbe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--086d9462-83c2-4c34-8311-83d6507395a1",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '246d9f9831b125ea7e6ef21bc4c8a0ca']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--fa73a2df-eecf-4e1b-8a8a-09ef22be8e57",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'e21fe98cc8866c0eeecf3549ebcec751']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--fec4f9e8-a4fb-4fa6-9d1b-ca779679dbd5",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '41871fef433d7b4b89fd226fe3a1a2c0']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--8d54312e-2c13-47ab-be31-4e0fd42f16b5",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '9f11e915be5c0d02a3130329cf032a28']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--09ddd38b-27b8-4873-b641-2b654cf35544",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '03af632aa6f87bf9dd4364ee3b612cbb']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--c05d7456-72fd-4ff2-9137-311ac5783fde",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'd0b00a6c83ce810ec2763af17e8ab1c4']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--27063176-a2bc-46c7-89db-b01e662c1345",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '77aa3f342a0d69fda67c853bcc004d48']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--6f2c8464-bab4-4722-a4a3-16e24117cc76",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '5d063eecd894d3d523875bc82ef6f319']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--954cfc41-4031-4460-9684-51c22d935c54",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '9935a86108e3ae3f72cd15817601dcc6']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7def6d2a-4598-4cc0-8790-4e691fb831b4",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '552d9b79cc544fc6c3e8aa204dd00811']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--f397e000-7d05-46da-9d70-a9f65bedea34",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'ad0ca738aa6c987e4ee1a87ff2b8acd5']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--2461f554-82c8-44fd-a6fa-ffd565d733f1",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '4c19aeecbfca13b8a199703d8b8284b9']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--0273104b-e0fb-47c4-a8f5-7355b57565b3",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'cee5acbfef7e76f52f40b8ae95199c50']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ac14c670-634c-4229-8b13-bd572a0ab45a",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '54a9fa9eb337a3b5ca7b0fa4553e439d']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--c461aadf-2b11-4405-982c-86a150531bab",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '95cf2a5a24b0d33d621bb8995d5826bc']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7e326bdf-0224-486d-ab78-884139b8ce1a",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '343b140977b3f9b227e7e5f82b0fadb5']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--9872cc0c-af66-43de-aad8-7064de07d04c",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '981160dee6cd25fb181e54eca7ff7c22']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--650062ce-3490-43e1-b9f8-5d60e67bd3cd",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '6c152774f6894407075e6f0a2859bbae']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--b3c044da-a5e6-4ce0-8ac3-c340e514da10",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '6859fe5a3eead00a563cd93efcc6ea96']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ce239e3d-2f3c-44b7-b043-66aa37545096",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '99305ce01cc2d0f58cd226efb2de893f']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ce9ea643-0fab-4e2d-94ba-98779dcb1d00",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'd6b41747cb035c4c2b08790cd57f0626']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--a7fa2017-94cf-4a95-9d16-27b3468397d5",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '6e1394938c2fecad2d4f5b3bcf357ec0']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--17ddd8b4-7f8a-46ea-9458-a99cd57319ed",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'de276cf07ccffa18d7ffc35281bca910']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--e3867e98-784e-4976-ab3c-384fe37733ee",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '7d3b529db1bd896d9fd877b85cafdc64']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7281a17b-0e66-4e00-9718-800a9d8da6ec",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '9b2924c727aa3a061906321a66c9050c']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--4092fbde-df88-478a-8fcc-57457c8276b8",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '2b2509c6ee46d6327f2f1c9a75122d15']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--0ff224fc-f3ca-4e3b-aa4e-b82da3fd79da",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '32db8abce1618e60441f5c7cf4be0d22']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--e4139b31-64f7-47a5-86fb-b419398b5c5c",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '332b7f6662e28e3577bd1b269904b940']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--3909e442-be38-4e98-919b-88b537e093e2",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '1934e2ebc64d41e37ef53ea0c075e974']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--d6d0ba98-fac8-4dc4-bc41-c5e01e406ec5",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '0e6374042b33d78329149a6189a7cb46']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--30081114-c827-4109-affd-c60971086205",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'cc4a9db6f250114e26d8d9ba6ab46bc9']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--563718cb-9d8f-4ab0-b8ec-0022d77ba1a0",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'da4d81f9ef3b25ea09f34481d923dd9d']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--4b7bae0d-8f8e-4675-aca7-a3f770f0a18e",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '77675a24040f10c85112d9a219d5f1c7']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1dfee9f0-6557-41eb-ac11-3eb882ac2813",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '85afdef18d65b0518d709a5a324ea57a']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--4bde370f-bef8-475b-9879-b46e524038c2",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'e2cc52273d56ed66c800a726760c1ed0']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--e59e8107-1983-4286-beba-928290528ba3",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'a5494ffd9efb7c3df59c527076a05e62']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--078b5b12-8036-4216-8cf3-5dc5542f4ded",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '0dc5ac12f7690db15c99eaabc11b129c']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--3460cfae-957a-4aa3-be2d-5090bc8b66b0",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '9657c2ef6ed5229740b125df9ca6c915']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--63dd4894-a056-4a7b-9bb4-a69c9d4d3d17",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '673586594242d99ab02118595e457297']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--2bbfc56d-3da3-41aa-b4de-e37f373efd7c",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '8a2ba7f9cb6f65edf65dbe579907551e']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--83fc4d37-b08a-4961-a44e-484c93534f69",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'af85885a74cfe099676af542dcdc5741']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1b29c353-0228-4fda-9b4d-aa3bfe56b035",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'c265188fdadddb648629e8060601dca7']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--791096f0-6cb0-4766-9b0d-477f781bb317",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '683546b9171a1ea284a96d1b45d1d823']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1c82a716-832f-4f03-8f77-ca3f86a25d99",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '3bcff990faacbebb8fb470dfe03e2543']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--57ac15b9-249c-4ac9-8d7d-e5a4eab46174",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '47f4534da421daf8089cf34d53f6bb6e']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--747f670a-4ba9-4cd5-8680-3607b8a33f5b",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'd8c04ecd646a1f8537a59f63518ef3c6']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--e6977878-8f62-4141-9116-d444a6f68586",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '601c12596dfea84c2113ae5ee59a52ec']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--9fc03b83-56d7-4d98-af98-6a89d240d102",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'fa97dbe84ce7717b754795fa89f13dce']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--0f8d37d1-c54e-4514-a5a8-39ccd34f9ea3",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '2e035360971a817b854d7d5a2b008717']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ae01811a-2cc8-4b54-8f5f-bc3d0638f023",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '875f9200b49db08c33962b0a6bd05ab9']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--01860414-eb4f-4d89-9ece-ef1d85b56658",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'f8ffd1eab6223e31b15d0fd6c3c0472e']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--5ed49f3c-2c7e-4c3d-b9d8-1d05d2f1a91f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '0adc2530cf348c0a3d53a680291a3d67']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--05bb2494-eb7a-4ada-b948-5fa896837b35",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'd973210977957209f255b58eb1715b12']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--0ffeaa0a-b3d5-427a-813e-66c279b94a1f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '7e0c42d33921a89724424f17c97037bd']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--4df248e4-c491-48a4-8294-9be67e4b30c0",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'e4634ef9bfe7b598b857ad997445b239']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--6f9ef797-bf7b-4ac1-89f6-98adb0ea6918",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '911c7e82f32f78577dcd725a7adb114d']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--0c45962b-3242-4bcb-821d-4b8c663d8404",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '5c3b0040e2dece6e17093ae607b79044']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--bd1c2ee1-8c63-4867-a85e-03d59045fcb6",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'fc418fdda06ce5982153766dcefb71d9']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--fb7a494a-a0f1-4a77-9f41-f12a5600b607",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '9152c9de57b5647ee4ab3dff551dc8dd']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--f4fd2e9c-4700-41ac-ba00-f8971fab3117",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '5b884f15dc9b072d7bbad9ec2b249f38']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--012d93e3-ae29-4e61-bd55-2c38a33dbcd8",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'ffa68749aa3fc6495e2c49b01d964339']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--d82de68b-4555-48d7-832f-6fb0dbaaed83",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '1220b580cef1bf22351e271773945d20']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ff08bc0b-86c5-48dd-a6ba-886aa7e26f47",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '8cfef66b390f08bdbfd940922cf51650']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--4ab89aa2-eb6e-4ca7-aa45-4ead9f893679",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'a66b3b22a3619f739b197d0d443b700c']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7d517f54-eda9-480e-8c63-bd959eff0b1c",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '032f5642d4fb2fdd74e6f20a13c57746']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--08bb0f87-cdda-429b-8e10-eadca0bdf8e2",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'c9d1677f4f89b95b41591b23a1dc1a63']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--b9301e51-88a0-4b3b-9ced-381fd33f331c",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'fba76f4eb2e7a2eb17193bebe290a198']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--b6b22511-4344-4605-8be6-e98cdc9475e1",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '0e03103e8110785156105946e48ea9e0']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--fb19330e-2a03-4e57-8424-9ad5c6bbcfe2",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '8d3d4d702ba6b4be2766a41bfe5ff76e']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--31e51fad-79ef-4cca-b31a-108b889c546c",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '2b5f159f022109a8de1bc5dd9e3138a0']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--f55dd154-c819-48e8-af95-8a3a6c598158",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '19cb20c4e7dbfe15c1aa284752d0fecb']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--adf7457f-75a7-4c70-bf38-32a5f17b28c7",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '4bce4831b1dd71f19c55b3e3b5e99856']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--9735b359-67a2-4921-8f4e-0bef0a83ce73",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'eef2363744345741e09fe5380eeb4df3']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--83cd5ade-209c-41a5-bb19-33768efe19e6",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'f4f4e55a00d2f3a433c9e5624285ac1c']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--72febe90-22b8-432b-b825-bbb840ebe07d",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'df4f856f783d23fb01af1e0e64bc0e20']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--273d289e-3124-4d8f-91f8-a0ea37b5d744",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '7a70d5fbbafe3454b76e3ad2f009618f']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1207700c-abca-4f4b-bdcc-4e1761913214",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '4d8343c40be53d6521244fe74393d937']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--0419067d-ad28-4706-a017-25969d67328f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'de1bf141976776becd376a0dac400df6']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--0580b905-8022-41ae-a4f2-bbb3f9ef83b9",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '2ca6bcf16ee4293a771a1cf7b7b9ee49']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--8602ba8f-7158-42a5-a629-32d0ed3c27ef",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'a905d620717f75751aa94ceb88995dbc']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--316a71af-6b75-46e2-ba77-6801f2cb6497",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '955e4c198ee58e40fe92cb74ceefdf00']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--5d516549-e05f-44c5-8f51-837c53229eff",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '5f4df6dd8e644d59eaf182e500b5e7bf']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ac4dc844-a4ed-4d31-a196-8e2e28e86c02",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '8633bd2bbbb5da22c3f8751150186c42']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--66ddfef2-0de7-4469-97ef-90be5dd1aa61",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '08dfebc04eb61c9a6d87b6524c1c0f2e']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--aad8c2fa-b5b6-45e7-a954-2426db987af9",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'f73d203bdf924658fd6edf3444c93a50']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--c44b0a77-8d94-4b6b-9863-7607b65237ab",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '7f84263fd24f783ff72d5ae91011b558']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--a467682b-8390-4502-9cc4-70bb332e569b",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '4074798a621232dc448b65db7b1fdd66']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7ebda806-74e0-49e0-9746-0dee98c9ca2a",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '179.43.142.42']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--15777c0e-1b11-40ca-a3da-e9eec41e0946",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[domain-name:value = 'interlinks.top']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--95c78c9a-98e1-4cb1-9a4a-45956d3c5628",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '179.43.176.60']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2019-03-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--891b311d-58c1-4e90-b329-35de69333ddb",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '7c8cb5598e724d34384cce7402b11f0e']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2021-04-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--debcfe37-043c-44b7-b86b-ecc0ce889d5f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '78c855a088924e92a7f60d661c3d1845']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2021-04-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Payload delivery"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"md5\"",
|
||
|
"misp:category=\"Payload delivery\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--2c18b530-e166-4f99-bf0f-3805b95608ea",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[url:value = 'https://cdn.discordapp.com/attachments/928503440139771947/930108637681184768/Tbopbh.jpg']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"url\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1f657c53-754c-4adb-945b-78f39060d8de",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[domain-name:value = '3237.site']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2014-11-22T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--e805eda5-9ebd-4523-864b-0af05828b1c9",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[domain-name:value = 'smm2021.net']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2014-11-22T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--58497591-5993-4c93-8fc5-1173daf43782",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '111.111.111.111']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2014-11-22T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1b21652a-6f34-43bc-9b61-334826b22f5b",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '45.141.87.11']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2020-03-28T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--b740d5a1-9153-45c8-81f2-0950d39d6a14",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '194.26.29.95']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7199a781-3a71-4301-ad10-407b5e9fbaa7",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '194.26.29.98']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2020-08-02T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--6dab9927-451f-46cb-a5a3-876f381ae1e4",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[domain-name:value = 'nssm.cc']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2021-05-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--32933f91-47f8-4ffe-8b4b-1452040c87e9",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '62.173.140.223']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2019-08-07T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"ip-dst\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ce473a0c-acf3-497b-bf35-cf534a1b69fa",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[domain-name:value = '3proxy.ru']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2014-05-23T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "Network activity"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"domain\"",
|
||
|
"misp:category=\"Network activity\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--2d170d33-aca2-4cfe-94a5-7fb0182c71e5",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'f772f5c65d65412f61ef5f2660e33ceb' AND file:hashes.SHA1 = '892be61f0cf68425e42efda9aa31f0e14bc963b5' AND file:hashes.SHA256 = 'eab7c6ef336c0fe2e0d15e2ccfe851f7ee172bdc14cee2d25e1c245e9034279d']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--e582ce35-ccd7-4582-9d2e-cd953c3e6090",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'afbb9459d4a0f60d7ffb3b3532d11bc2' AND file:hashes.SHA1 = '91f7690be7d36bde7537193987610848289e0f56' AND file:hashes.SHA256 = '3c02aeeb57d3c64feae109f50a89774111a443142859891bae4fb2f469fa0466']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--841c42e7-de66-49c8-ac04-141fe28d21bf",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '29d83f29c0b0a0b7499e71e7d5cb713f' AND file:hashes.SHA1 = 'd33f12dbcdd427c527a8285fd9ab0c848051288b' AND file:hashes.SHA256 = 'fd4a5398e55beacb2315687a75af5aa15b776b5d36b9800a1792ede3955616c2']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--4dfa7787-900b-4c3b-aa03-1a5be6c44375",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '9b1191f1ceddf312b0d609cd929c6631' AND file:hashes.SHA256 = '0dd61a16c625c49ffefaf4ce24cabf9a074028a06640d9bbb804f735ff56dfa3']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--d56d107e-abf2-4a7f-ba35-0c8d6f8330df",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'de85ca91e1e8100a619de1c25112f1a5' AND file:hashes.SHA1 = 'd2d96f0d819abd771617e806994effc180c7438c' AND file:hashes.SHA256 = '489ab4819830d231c3fc3572c5386cad9d18773a8121373ea8174de981cc9166']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--bf03694c-665a-4145-930e-7c218915ae22",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '5a537673c34933fc854fbfb65477a686' AND file:hashes.SHA1 = '7070b7e9d537c96a2218b3907b05af2d7378661c' AND file:hashes.SHA256 = '35feefe6bd2b982cb1a5d4c1d094e8665c51752d0a6f7e3cae546d770c280f3a']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2014-11-22T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--060ea156-0eb5-4f95-ac8d-7b2502fb92e7",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '764f691b2168e8b3b6f9fb6582e2f819' AND file:hashes.SHA256 = 'aa79afbf82b06cda268664b7c83900d8f7a33e0f0071facba0b3d8f7a68ce56a']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--99b93ad5-38af-4534-a43a-f0f48080386d",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'eac0ae655d344c25ff467a929790885c' AND file:hashes.SHA256 = 'b9e64b58d7746cb1d3bed20405ef34d097af08c809d8dad10b9296b0bebb2b0b']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ad9882f2-73a8-4ee8-9933-01c00d70c9a1",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '6154760e602bd71192d93f72fbdb486e' AND file:hashes.SHA1 = '50566fdea2f4b8a3466427f9c6798dabe2587823' AND file:hashes.SHA256 = 'bc2e7451995e188f50581efb2b564dfbc5b593f57f7b52072eeba235a0861670']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--c8c23229-d10f-45d9-80b4-30691f49e9b0",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '394e056cb6cb732dfd5e0d45d3dae938' AND file:hashes.SHA1 = '731dab83ef1d02203db64fbefbe59f3791db1e21' AND file:hashes.SHA256 = 'aa212493331277dd28a8b9b2f535c7b719ff9c6d4ccad121fd0a59dcb78697d9']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--e49afa4e-ab00-4def-b732-bd8b77301f9c",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'dd2431b1f858b4ca14a4ea05fb8c4a06' AND file:hashes.SHA1 = 'c3181fd7cb463893fc73974acc0016605d90ef6c' AND file:hashes.SHA256 = 'a05f2999844495bffb3405b1db2d1927e5237e61d71edb599a5fa64e3e575856']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ad79ab5b-e77e-400b-9903-7c37dbd711ad",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '58dc7c9577ff90a046359ca255c0c9f4' AND file:hashes.SHA1 = 'f6acdc16c695c3c219116aea3d585efedcafdab5' AND file:hashes.SHA256 = 'd3a80ce2fded8144d347ee0b42c18ff6ad8cb386c3a2fc884ef2348afe7633c9']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--c53c4b11-22d8-45f8-abdb-62a102dfd0f3",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '869742fb9db71fdb66f00528fe2966ec' AND file:hashes.SHA1 = 'db370ee79d9b4bd44e07f425d7b06beffc8bdded' AND file:hashes.SHA256 = '7f8d4a36d05b60f0dd986a3bbde1be34b10a2d80297d1ae28d3fdaaa914fb8bf']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--9356204e-b184-489e-ac87-2ad76d12f9bf",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '9345425cf07b4c39a80cd8540e08bfde' AND file:hashes.SHA1 = '2e113050a81bbd0774db7e86fad4abd44e5b6ec2' AND file:hashes.SHA256 = '4ff07f308da5b18f4a71ef09eea3f3c968683c93e8aa55d3f03975207e3b19ce']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--6a89f90e-176f-48f2-9b00-07d7ca24890d",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '9c695be3703194fdb71c212a0832bcf3' AND file:hashes.SHA1 = '88c76d31b046227d82f94db87697b25e482eb398' AND file:hashes.SHA256 = '3de02a782987b4463e02dda90df57a06fb0022eb8840a17c4c812631705ebf7c']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--a489adfe-a6b6-4890-8f35-ca25c35c82d4",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '9606b4720a0e73ef1f00505a11aab2f7' AND file:hashes.SHA1 = '27c176bbd3e254d5e46ccb865d29c8c166ba4a9f' AND file:hashes.SHA256 = 'a5833236a73c66add109c8b53adda6f998bf92d63955fa06787d66d670d7889e']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--981b34f3-18cd-49a6-af3f-8b91618ae731",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'd33f608f561096be24cba91797e0da2f' AND file:hashes.SHA1 = '90fa56e79765d27d35706d028d32dc5be7efb623' AND file:hashes.SHA256 = 'c27a3b0ffaba2258d66d595c5478f12ee8a107cd590132a4a72d8bfdaf486fc1']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--a3a725cb-3205-4867-a8b1-44f3106cb138",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'dc795cb9290b1bc0b7fb1ce9d6ae7c93' AND file:hashes.SHA1 = '5fbd9bd73040d7a2cac0fc21d2fe29ebe57fb597' AND file:hashes.SHA256 = '887936dc1db271c6970ca78f25c4eb62d3816761b675db2cf4a46645c98a5fd9']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--d74d9dae-1d82-43fb-9a61-00b8153938fe",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'b85538f665fdb6c8d9a74f2df7369832' AND file:hashes.SHA1 = 'fb83899dc633c59a8473a3048c9aacce7e1bf8d8' AND file:hashes.SHA256 = 'b72e8c0e4291e85ad683d6dcba449f18eacd31e8e5395c7064dcb05077db4a06']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--b0cd44ba-3d9f-425c-8bf2-3ec7efe6bb5d",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '618d62dd95fd9aeb855fe2ef1403dce5' AND file:hashes.SHA1 = 'b5e3e65cd6b09b17d4819a1379dde7db3e33813b' AND file:hashes.SHA256 = 'fae14137605c6a173eaca1e89ad92961e6cb2b66b924087f2f109c0ab38a0d71']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--994089df-40d9-4ca1-b834-6d05829cf31b",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '3907c7fbd4148395284d8e6e3c1dba5d' AND file:hashes.SHA1 = 'a67205dc84ec29eb71bb259b19c1a1783865c0fc' AND file:hashes.SHA256 = '34ca75a8c190f20b8a7596afeb255f2228cb2467bd210b2637965b61ac7ea907']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2014-11-22T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--fea555f1-2e49-4c87-9005-9493f4e46d82",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '8744cec7547b1e73705c10a264e28e08' AND file:hashes.SHA1 = 'd4851eb90fc4ba627b6ce633c40852b963a1b555' AND file:hashes.SHA256 = 'b7b76f3fe12e12b8d1d34dcd1a53ab18223ec10a5a7549b2db4cde5d84c8970d' AND file:name = 'Ofewufeiy.dll' AND file:size = '438272']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2021-04-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1d29024b-9099-443c-af91-3b831562902e",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'de1f9d1f0336ddcff832ad3900acd2f1' AND file:hashes.SHA1 = '7631b43feb02fb8dc97401e82a1ec5c7d970a055' AND file:hashes.SHA256 = '2880f3c707dff1de85e6b9a7e7154648e2e1df535647c0917e8fb4ea0fe9fd20' AND file:name = 'de1f9d1f0336ddcff832ad3900acd2f1']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--5c918e3d-fca0-4cbd-8327-a7968237a2c3",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '974e7c0b3660fbf18f29eac059f85ac0' AND file:hashes.SHA1 = '80abdc5c36eb4a2745783e6590a13d92497c8513' AND file:hashes.SHA256 = '163932f1d39d2ae140bcf89aee6d514f65902ce8b4d46c7061c1cc94eb2a25b2' AND file:name = 'de1f9d1f0336ddcff832ad3900acd2f1_reversed_974e7c0b3660fbf18f29eac059f85ac0' AND file:size = '1772032']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--6971d11f-4641-4a6f-9d6d-cc032f5fdeb9",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '17fc12902f4769af3a9271eb4e2dacce' AND file:hashes.SHA1 = '9a4a1581cc3971579574f837e110f3bd6d529dab' AND file:hashes.SHA256 = '29ae7b30ed8394c509c561f6117ea671ec412da50d435099756bbb257fafb10b']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7c18bc0c-21c4-44b4-b89b-4280be7eec4e",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '6eed4ee0cc57126e9a096ab9905f471c' AND file:hashes.SHA1 = '4f06d376648def0bb8a325e70046a5030d2cb1d1' AND file:hashes.SHA256 = 'db5a204a34969f60fe4a653f51d64eee024dbf018edea334e8b3df780eda846f']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--82f83bb1-8e40-4ec0-83f0-5bc9c3aa476d",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'e61518ae9454a563b8f842286bbdb87b' AND file:hashes.SHA1 = '82d29b52e35e7938e7ee610c04ea9daaf5e08e90' AND file:hashes.SHA256 = '9ef7dbd3da51332a78eff19146d21c82957821e464e8133e9594a07d716d892d' AND file:name = 'Frkmlkdkdubkznbkmcf.dll' AND file:size = '280064']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2014-11-22T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--dfcf55fb-9c49-4cad-99b3-86ebad50f186",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = 'b3370eb3c5ef6c536195b3bea0120929' AND file:hashes.SHA1 = 'b2d863fc444b99c479859ad7f012b840f896172e' AND file:hashes.SHA256 = '923eb77b3c9e11d6c56052318c119c1a22d11ab71675e6b95d05eeb73d1accd6' AND file:name = 'Tbopbh.jpg' AND file:size = '280064']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2022-01-13T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--ae8445df-cd98-49d6-bb60-3f2dd3def234",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '14c8482f302b5e81e3fa1b18a509289d' AND file:hashes.SHA1 = '16525cb2fd86dce842107eb1ba6174b23f188537' AND file:hashes.SHA256 = 'dcbbae5a1c61dbbbb7dcd6dc5dd1eb1169f5329958d38b58c3fd9384081c9b78' AND file:name = 'stage2.exe' AND file:name = 'Tbopbh.exe' AND file:name = 'stage2.exe; Tbopbh.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2014-11-22T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--1768da67-e65f-4bad-8744-12a90e2e3300",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '5d5c99a08a7d927346ca2dafa7973fc1' AND file:hashes.SHA1 = '189166d382c73c242ba45889d57980548d4ba37e' AND file:hashes.SHA256 = 'a196c6b8ffcb97ffb276d04f354696e2391311db3841ae16c8c9f56f36a38e92' AND file:name = 'stage1.exe']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2014-11-22T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "indicator",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "indicator--7b213df7-fb1f-4ab2-8d90-b3ca6b6f94a6",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-05T12:42:42.000Z",
|
||
|
"modified": "2024-09-05T12:42:42.000Z",
|
||
|
"pattern": "[file:hashes.MD5 = '896e0f54fc67d72d94b40d7885f10c51' AND file:hashes.SHA1 = '5d60c8507ac9b840a13ffdf19e3315a3e14de66a' AND file:hashes.SHA256 = '5e0f28bd2d49b73e96a87f5c20283ebe030f4bb39b3107d4d68015dce862991d']",
|
||
|
"pattern_type": "stix",
|
||
|
"pattern_version": "2.1",
|
||
|
"valid_from": "2021-04-01T00:00:00Z",
|
||
|
"kill_chain_phases": [
|
||
|
{
|
||
|
"kill_chain_name": "misp-category",
|
||
|
"phase_name": "file"
|
||
|
}
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:name=\"file\"",
|
||
|
"misp:meta-category=\"file\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "x-misp-object",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "x-misp-object--c015fd65-073d-4519-bb64-d652be3f1d97",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-06T07:44:41.000Z",
|
||
|
"modified": "2024-09-06T07:44:41.000Z",
|
||
|
"labels": [
|
||
|
"misp:name=\"original-imported-file\"",
|
||
|
"misp:meta-category=\"file\""
|
||
|
],
|
||
|
"x_misp_attributes": [
|
||
|
{
|
||
|
"type": "attachment",
|
||
|
"object_relation": "imported-sample",
|
||
|
"value": "AA24-249A-Russian-Military-Cyber-Actors-Target-US-and-Global-Critical-Infrastructure.stix_.json",
|
||
|
"category": "External analysis",
|
||
|
"uuid": "ed2d4f7d-7a83-430d-ae23-b577eb3c8765",
|
||
|
"data": "ewogICAgInR5cGUiOiAiYnVuZGxlIiwKICAgICJpZCI6ICJidW5kbGUtLTA1ZTFjNTQ2LWYwMDMtNDE4Mi04NDA4LWUwMzI0ZjM2OGQ4YiIsCiAgICAib2JqZWN0cyI6IFsKICAgICAgICB7CiAgICAgICAgICAgICJpZCI6ICJsb2NhdGlvbi0tMjVhOWVjNDQtOTYzMy00OTJmLTgyOGYtNTliNDcxODkxOTdiIiwKICAgICAgICAgICAgInNwZWNfdmVyc2lvbiI6ICIyLjEiLAogICAgICAgICAgICAidHlwZSI6ICJsb2NhdGlvbiIsCiAgICAgICAgICAgICJjb3VudHJ5IjogIlVTIiwKICAgICAgICAgICAgImFkbWluaXN0cmF0aXZlX2FyZWEiOiAiVVMtREMiLAogICAgICAgICAgICAiY3JlYXRlZCI6ICIyMDI0LTA5LTA1VDEyOjQyOjQyLjAwMFoiLAogICAgICAgICAgICAibW9kaWZpZWQiOiAiMjAyNC0wOS0wNVQxMjo0Mjo0Mi4wMDBaIiwKICAgICAgICAgICAgImNyZWF0ZWRfYnlfcmVmIjogImlkZW50aXR5LS1iM2JjYTNjMi0xZjNkLTRiNTQtYjQ0Zi1kYWM0MmMzYThmMDEiLAogICAgICAgICAgICAib2JqZWN0X21hcmtpbmdfcmVmcyI6IFsKICAgICAgICAgICAgICAgICJtYXJraW5nLWRlZmluaXRpb24tLTYxM2YyZTI2LTQwN2QtNDhjNy05ZWNhLWI4ZTkxZGY5OWRjOSIKICAgICAgICAgICAgXQogICAgICAgIH0sCiAgICAgICAgewogICAgICAgICAgICAiaWQiOiAiYXR0YWNrLXBhdHRlcm4tLWRkMGZlYzAyLWNjNWYtNDVhYy1hYjk1LTFjNmIxZmZlYWJkMyIsCiAgICAgICAgICAgICJ0eXBlIjogImF0dGFjay1wYXR0ZXJuIiwKICAgICAgICAgICAgImNyZWF0ZWQiOiAiMjAyNC0wOS0wNVQxMjo0Mjo0Mi4wMDBaIiwKICAgICAgICAgICAgIm1vZGlmaWVkIjogIjIwMjQtMDktMDVUMTI6NDI6NDIuMDAwWiIsCiAgICAgICAgICAgICJzcGVjX3ZlcnNpb24iOiAiMi4xIiwKICAgICAgICAgICAgImNyZWF0ZWRfYnlfcmVmIjogImlkZW50aXR5LS1iM2JjYTNjMi0xZjNkLTRiNTQtYjQ0Zi1kYWM0MmMzYThmMDEiLAogICAgICAgICAgICAibmFtZSI6ICJBY3RpdmUgU2Nhbm5pbmciLAogICAgICAgICAgICAib2JqZWN0X21hcmtpbmdfcmVmcyI6IFsKICAgICAgICAgICAgICAgICJtYXJraW5nLWRlZmluaXRpb24tLTYxM2YyZTI2LTQwN2QtNDhjNy05ZWNhLWI4ZTkxZGY5OWRjOSIKICAgICAgICAgICAgXSwKICAgICAgICAgICAgImV4dGVybmFsX3JlZmVyZW5jZXMiOiBbCiAgICAgICAgICAgICAgICB7CiAgICAgICAgICAgICAgICAgICAgImV4dGVybmFsX2lkIjogIlQxNTk1IiwKICAgICAgICAgICAgICAgICAgICAic291cmNlX25hbWUiOiAibWl0cmUtYXR0YWNrIiwKICAgICAgICAgICAgICAgICAgICAidXJsIjogImh0dHBzOi8vYXR0YWNrLm1pdHJlLm9yZy90ZWNobmlxdWVzL1QxNTk1IgogICAgICAgICAgICAgICAgfQogICAgICAgICAgICBdCiAgICAgICAgfSwKICAgICAgICB7CiAgICAgICAgICAgICJpZCI6ICJhdHRhY2stcGF0dGVybi0tYmU0ODIyOTgtNWI5Yy00MDkwLTk1ZmItMDI2MzI5M2U3OTcxIiwKICAgICAgICAgICAgInR5cGUiOiAiYXR0YWNrLXBhdHRlcm4iLAogICAgICAgICAgICAiY3JlYXRlZCI6ICIyMDI0LTA5LTA1VDEyOjQyOjQyLjAwMFoiLAogICAgICAgICAgICAibW9kaWZpZWQiOiAiMjAyNC0wOS0wNVQxMjo0Mjo0Mi4wMDBaIiwKICAgICAgICAgICAgInNwZWNfdmVyc2lvbiI6ICIyLjEiLAogICAgICAgICAgICAiY3JlYXRlZF9ieV9yZWYiOiAiaWRlbnRpdHktLWIzYmNhM2MyLTFmM2QtNGI1NC1iNDRmLWRhYzQyYzNhOGYwMSIsCiAgICAgICAgICAgICJuYW1lIjogIkFjdGl2ZSBTY2FubmluZzogU2Nhbm5pbmcgSVAgQmxvY2tzIiwKICAgICAgICAgICAgIm9iamVjdF9tYXJraW5nX3JlZnMiOiBbCiAgICAgICAgICAgICAgICAibWFya2luZy1kZWZpbml0aW9uLS02MTNmMmUyNi00MDdkLTQ4YzctOWVjYS1iOGU5MWRmOTlkYzkiCiAgICAgICAgICAgIF0sCiAgICAgICAgICAgICJleHRlcm5hbF9yZWZlcmVuY2VzIjogWwogICAgICAgICAgICAgICAgewogICAgICAgICAgICAgICAgICAgICJleHRlcm5hbF9pZCI6ICJUMTU5NS4wMDEiLAogICAgICAgICAgICAgICAgICAgICJzb3VyY2VfbmFtZSI6ICJtaXRyZS1hdHRhY2siLAogICAgICAgICAgICAgICAgICAgICJ1cmwiOiAiaHR0cHM6Ly9hdHRhY2subWl0cmUub3JnL3RlY2huaXF1ZXMvVDE1OTUvMDAxIgogICAgICAgICAgICAgICAgfQogICAgICAgICAgICBdCiAgICAgICAgfSwKICAgICAgICB7CiAgICAgICAgICAgICJpZCI6ICJhdHRhY2stcGF0dGVybi0tNmY3N2YwNTgtOTJiNi00M2E0LTgwMTctZjA3MWY5ZGQ4ZTc4IiwKICAgICAgICAgICAgInR5cGUiOiAiYXR0YWNrLXBhdHRlcm4iLAogICAgICAgICAgICAiY3JlYXRlZCI6ICIyMDI0LTA5LTA1VDEyOjQyOjQyLjAwMFoiLAogICAgICAgICAgICAibW9kaWZpZWQiOiAiMjAyNC0wOS0wNVQxMjo0Mjo0Mi4wMDBaIiwKICAgICAgICAgICAgInNwZWNfdmVyc2lvbiI6ICIyLjEiLAogICAgICAgICAgICAiY3JlYXRlZF9ieV9yZWYiOiAiaWRlbnRpdHktLWIzYmNhM2MyLTFmM2QtNGI1NC1iNDRmLWRhYzQyYzNhOGYwMSIsCiAgICAgICAgICAgICJuYW1lIjogIkFjdGl2ZSBTY2FubmluZzogVnVsbmVyYWJpbGl0eSBTY2FubmluZyIsCiAgICAgICAgICAgICJvYmplY3RfbWFya2luZ19yZWZzIjogWwogICAgICAgICAgICAgICAgIm1hcmtpbmctZGVmaW5pdGlvbi0tNjEzZjJlMjYtNDA3ZC00OGM3LTllY2EtYjhlOTFkZjk5ZGM5IgogICAgICAgICAgICBdLAogICAgICAgICAgICAiZXh0ZXJuYWxfcmVmZXJlbmNlcyI6IFsKICAgICAgICAgICAgICAgIHsKICAgICAgICAgICAgICAgICAgICAiZXh0ZXJuYWxfaWQiOiAiVDE1OTUuMDAyIiwKICAgICAgICAgICAgICAgICAgICAic291cmNlX25hbWUiOiAibWl0cmUtYXR0YWNrIiwKICAgICAgICAgICAgICAgICAgICAidXJsIjogImh0dHBzOi8vYXR0YWNrLm1pdHJlLm9yZy90ZWNobmlxdWVzL1QxNTk1LzAwMiIKICAgICAgICAgICAgICAgIH0KICAgICAgICAgICAgXQogICAgICAgIH0sCiAgICAgICAgewogICAgICAgICAgICAiaWQiOiAiYXR0YWNrLXBhdHRlcm
|
||
|
},
|
||
|
{
|
||
|
"type": "text",
|
||
|
"object_relation": "format",
|
||
|
"value": "2.1",
|
||
|
"category": "Other",
|
||
|
"uuid": "872f2361-c641-4db0-a671-53f6f45f91f5"
|
||
|
}
|
||
|
],
|
||
|
"x_misp_meta_category": "file",
|
||
|
"x_misp_name": "original-imported-file"
|
||
|
},
|
||
|
{
|
||
|
"type": "x-misp-object",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "x-misp-object--c81a4e0d-b5d6-4779-9299-a85efdb5c03f",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-06T07:46:08.000Z",
|
||
|
"modified": "2024-09-06T07:46:08.000Z",
|
||
|
"labels": [
|
||
|
"misp:name=\"report\"",
|
||
|
"misp:meta-category=\"misc\""
|
||
|
],
|
||
|
"x_misp_attributes": [
|
||
|
{
|
||
|
"type": "link",
|
||
|
"object_relation": "link",
|
||
|
"value": "https://www.cisa.gov/sites/default/files/2024-09/aa24-249a-russian-military-cyber-actors-target-us-and-global-critical-infrastructure.pdf",
|
||
|
"category": "External analysis",
|
||
|
"uuid": "5ddcb4a7-2610-457b-aa83-2707a391faa8"
|
||
|
},
|
||
|
{
|
||
|
"type": "text",
|
||
|
"object_relation": "summary",
|
||
|
"value": "Russian Military Cyber Actors Target US and Global Critical Infrastructure",
|
||
|
"category": "Other",
|
||
|
"uuid": "05e1f9b0-d784-40b7-a7be-3274ad23c51e"
|
||
|
},
|
||
|
{
|
||
|
"type": "text",
|
||
|
"object_relation": "type",
|
||
|
"value": "Alert",
|
||
|
"category": "Other",
|
||
|
"uuid": "9e961ccb-2c9b-4e5b-8092-09ae661ed9ca"
|
||
|
},
|
||
|
{
|
||
|
"type": "attachment",
|
||
|
"object_relation": "report-file",
|
||
|
"value": "aa24-249a-russian-military-cyber-actors-target-us-and-global-critical-infrastructure.pdf",
|
||
|
"category": "External analysis",
|
||
|
"uuid": "0c4ae0c2-61a9-458b-b85e-075dbc54f90f",
|
||
|
"data": "JVBERi0xLjYNJeLjz9MNCjM4OTkgMCBvYmoNPDwvTGluZWFyaXplZCAxL0wgMTA1MjA4My9PIDM5MDEvRSA0NjIzNTcvTiAzNi9UIDEwNTExODYvSCBbIDU1MSA3ODldPj4NZW5kb2JqDSAgICAgICAgDQozOTI5IDAgb2JqDTw8L0RlY29kZVBhcm1zPDwvQ29sdW1ucyA1L1ByZWRpY3RvciAxMj4+L0ZpbHRlci9GbGF0ZURlY29kZS9JRFs8NTM2ODJGNEJBMEY5RjQ0MEI3OThCMDYwMjlFMzQxOUM+PDRFNzIyMkIxQzVGOUZGNEJCMEQxOEQ0RDZBREFFMDU1Pl0vSW5kZXhbMzg5OSA1M10vSW5mbyAzODk4IDAgUi9MZW5ndGggMTM1L1ByZXYgMTA1MTE4Ny9Sb290IDM5MDAgMCBSL1NpemUgMzk1Mi9UeXBlL1hSZWYvV1sxIDMgMV0+PnN0cmVhbQ0KaN5iYmRgEGBgYmBg1QGRDGtBJNN6EMnmD2ZrgUgWCzB7NpgMBZHM88GkHljWBEyygEhGiIgnmNQGmwwmrVeARcLBtoSBSF6wve51QJLRuxDE9ksAkZasIFKuH2xaLkg2fC7Y3tsgtoIikPx7QZqBiZGB/xTYNAbGASD/M3x++QYgwABUIROVDQplbmRzdHJlYW0NZW5kb2JqDXN0YXJ0eHJlZg0KMA0KJSVFT0YNCiAgICAgICAgDQozOTUxIDAgb2JqDTw8L0MgMTAyNS9GaWx0ZXIvRmxhdGVEZWNvZGUvSSAxMDQ3L0xlbmd0aCA2OTAvTyAxMDA5L1MgODk0Pj5zdHJlYW0NCmjeYmBgYAKiKwysDAy8OxmEGRBAGCjGxsDCwHHBSaBFkQFEcACJRA4PAR6gFoH7fgmeLVyOjRYO4kdYkhsWXxBYA9Ql68C9pZFfQO4FyySGNQzSmkzmDOI/WKoY5T5IujDbMG6PENJgkldwFOAObJQXECmLj2voEhCQZuJTsJBg3MOgqJA9V9zNMHnBMcNzxdMlD16dk/bkoKZXzAGEswRaRBaeK2QJ8nV15HB013gu4KpyJUSoSSAyrgHMLv3gJBDUbnlE0NNUlEWRdZp6F5gt24KmJvDU1MdzHEUmB4YDzUmteC7k6w5idD6e42mqWAK0pTKuAyjoGtsi0CIW0VeocgUHA2jX5CBRRw1FVhm4YwLhLvSCCgINLJ4DcZJcOMRJoiWCTkKBp6rU+RyvXGoNCQFLLQKaFhieCGRPfQGyokzAXSBgaZXSYoiWMklGjYCWqQ8fFTwR9dWIdXVwAnqqYzHYIzccOQK5ppkvAqtUKRMASiWB/OURCzQNaGwAqqdEgAyg9mCgqxg5HP2AdiEpSwI5IwIUICD1Hg4MgioVHR0NDIzuYIpBHEK5gLgdDAyC5WCKQQxEA8UFxSHiTMYQAWHzCpBm4XKwrJI5RDd7BRrJbFoOkwBR5shWMpeDDVSBGMgoCDILbLUQxG6wlQwMjEJmYIkGmAzIWWYwTSIwEXWw4nKwoDrYfKCdEAE4g1EJ7BoRoP0NtEnsQCOyGXhm9gNpGSBWAyfwMAYhhjCH+AnMAcyPGCY68H/gVWG8wfC9weoBcwLzZ4avDrYBbz2YGYEqTy+UWeAlLdzU3PWh5AmjuOjEAxIh9fp30zyE2WI+cOr4PmIwOaLjwL6H4Q5vV4NxACwHlTLwffoCpIFGsL0D0mUMfD8fAWlVoIgMPJ/NZRDgdICoYvgMEGAAW0syvw0KZW5kc3RyZWFtDWVuZG9iag0zOTAwIDAgb2JqDTw8L0xhbmco/v8ARQBOAC0AVQBTKS9NYXJrSW5mbzw8L01hcmtlZCB0cnVlPj4vTWV0YWRhdGEgMTU1IDAgUi9PdXRsaW5lcyAyMDQgMCBSL1BhZ2VMYXlvdXQvT25lQ29sdW1uL1BhZ2VzIDM4OTAgMCBSL1N0cnVjdFRyZWVSb290IDI4NSAwIFIvVHlwZS9DYXRhbG9nPj4NZW5kb2JqDTM5MDEgMCBvYmoNPDwvQW5ub3RzIDM5MzAgMCBSL0NvbnRlbnRzWzM5MDQgMCBSIDM5MDcgMCBSIDM5MDkgMCBSIDM5MTAgMCBSIDM5MTIgMCBSIDM5MTMgMCBSIDM5MTQgMCBSIDM5MTYgMCBSXS9Dcm9wQm94WzAuMCAwLjAgNjEyLjAgNzkyLjBdL01lZGlhQm94WzAuMCAwLjAgNjEyLjAgNzkyLjBdL1BhcmVudCAzODkxIDAgUi9SZXNvdXJjZXM8PC9FeHRHU3RhdGU8PC9HUzAgMzkzMiAwIFI+Pi9Gb250PDwvQzJfMCAzOTM3IDAgUi9UVDAgMzkzOSAwIFIvVFQxIDM5NDEgMCBSL1RUMiAzOTQzIDAgUi9UVDMgMzk0NSAwIFIvVFQ0IDM5NDcgMCBSL1RUNSAzOTQ5IDAgUj4+L1hPYmplY3Q8PC9JbTAgMzkxNSAwIFIvSW0xIDM5MjcgMCBSL0ltMiAzOTI4IDAgUj4+Pj4vUm90YXRlIDAvU3RydWN0UGFyZW50cyAwL1RhYnMvUy9UeXBlL1BhZ2U+Pg1lbmRvYmoNMzkwMiAwIG9iag08PC9GaWx0ZXIvRmxhdGVEZWNvZGUvRmlyc3QgMTk4L0xlbmd0aCAxNTE1L04gMjEvVHlwZS9PYmpTdG0+PnN0cmVhbQ0KaN6kWG1z2jgQ/iv6mEwH9C5ZNx1mIISETkh7IW1yZfjggpt4QjAD7rX597cr2YApL4Ubj2xZ2tUuq+dZr5BOMsKIdJITEeFTEK4MdiQRSmBHEeEUdjTRmmPHEMu8sCWW+05EIuVlHOGcOegpBgs5XEBxwq3AWViPR5HvwepcSOzB8lr5nibCRmgAHWAGvVCWSBnk0I7Gm3JECY6zmhFlQGPg/WfkjkjrWNGJ/Mjw/XvaDKLwRlt9eO/Ddf82S2grm4+TOX0grNEoXgYox4b0mnbpXTLKB8K6umPglalDnCJZjyJJlK0r54a0/+NbjgvdpNOXsGRzOs3yRgOtdvvkezxZgJkevc3mr/GEXjQJrzP68VMx8/FTj3Dab5J8/iOh/V68eAHRaRLWuvyVX/XzOE/oKPZ62Szo+fU/orvp9OmsO06meZq/nYPDT+kin7+dNcfZt+Qc3JvNJskrTOMvRJ8WI3yJnKMX3XY/ySEy3PrIXMSz6yR9es6J1Yq2kyBZE5zTziR+WhBFO9k0b7WyXxAjHCdcaodrDf1MJ35NJ29nD+DSGNriPIymkwRBADBBKzh0G78m9Pbx4v7+/t1Suga+/5jEcy/Rz+dJPnouo4ZDD8E3xRjt5vEkHTWnT5OEMNrPk9cvREcsxAxl0fl5OsuzOX0sf5OQPgCteJGgyG77GJe3BSzanX7PAg98eLrt++yq2+7FM1oGnLYfCGfgUdVo4AwqlfAAZRRBB8XKTfow4JIPlI6Gw0Zj4AlWIPawm2GDxjFEGOQWgZVo83I6ylB06WXteukHmoY4ZZ+nKQgluC2eJCuf1lHiDFtDhTF2hQopS1Q4s4JFTQjt5yAqwHLQryCjM4+nL5N0Sq6y/DkdkVaWvVRBImQVJF9714+dL+9KxaBXQ72AgSPBUuMlXKzZixbldBUtBx1ZRh12qjldpMv3Tjpf5BfPMaBCbMFJYMVNXMhwwVebBSnBO7m+X0JV9wvsjfPnxUD4/Lb9OmZOGzSgrSHsf1za/y68a1GMKFWVENw/JXww4M4sSIhiTgk9XMchZ2odiJabNSAKXQCxCG8AojHazxEB9PQLVJDYnKfxZCM/uSr0Li/7D48377xk7/7ErBRFe2GmuavCbMPoiaBSrAoqkNmLKSZ3YMpGlX1wLjq8DZV8oOHb4rfBfylA/9AuCL2RAL52+sA7L1kLET56M2pcFNvhxHHbsd36qbsijqW62bktu8jsZ/C+S2ZzHJI63K0QvuGb4Xydptr8Jvm71Ab5Qcc3tuqj3WUf1sCG8/iM4Au71PH2JI4wttJiwTLD3kZq0GYnJiHJb0sNUObiXJkatDkISl4F5c3X697dYwGLVjYZH4Sk3ZEfuD
|
||
|
}
|
||
|
],
|
||
|
"x_misp_meta_category": "misc",
|
||
|
"x_misp_name": "report"
|
||
|
},
|
||
|
{
|
||
|
"type": "x-misp-object",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "x-misp-object--ef754d1a-1b71-471b-b4c8-c7b200dc0fb7",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2024-09-06T07:47:05.000Z",
|
||
|
"modified": "2024-09-06T07:47:05.000Z",
|
||
|
"labels": [
|
||
|
"misp:name=\"report\"",
|
||
|
"misp:meta-category=\"misc\""
|
||
|
],
|
||
|
"x_misp_attributes": [
|
||
|
{
|
||
|
"type": "link",
|
||
|
"object_relation": "link",
|
||
|
"value": "https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249a",
|
||
|
"category": "External analysis",
|
||
|
"uuid": "e46251d4-652a-4100-94d0-ff204026f66c"
|
||
|
},
|
||
|
{
|
||
|
"type": "text",
|
||
|
"object_relation": "summary",
|
||
|
"value": "The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and National Security Agency (NSA) assess that cyber actors affiliated with the Russian General Staff Main Intelligence Directorate (GRU) 161st Specialist Training Center (Unit 29155) are responsible for computer network operations against global targets for the purposes of espionage, sabotage, and reputational harm since at least 2020. GRU Unit 29155 cyber actors began deploying the destructive WhisperGate malware against multiple Ukrainian victim organizations as early as January 13, 2022. These cyber actors are separate from other known and more established GRU-affiliated cyber groups, such as Unit 26165 and Unit 74455.",
|
||
|
"category": "Other",
|
||
|
"uuid": "1ca91bb5-3f5f-497b-bf19-8f55d72c1cf4"
|
||
|
},
|
||
|
{
|
||
|
"type": "text",
|
||
|
"object_relation": "title",
|
||
|
"value": "Russian Military Cyber Actors Target US and Global Critical Infrastructure",
|
||
|
"category": "Other",
|
||
|
"uuid": "fdf0898d-d55e-4744-a92b-2bb4ae57c8cb"
|
||
|
},
|
||
|
{
|
||
|
"type": "text",
|
||
|
"object_relation": "type",
|
||
|
"value": "Alert",
|
||
|
"category": "Other",
|
||
|
"uuid": "2eadb775-b12f-40a0-bd72-6a8909d957ef"
|
||
|
}
|
||
|
],
|
||
|
"x_misp_meta_category": "misc",
|
||
|
"x_misp_name": "report"
|
||
|
},
|
||
|
{
|
||
|
"type": "marking-definition",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
|
||
|
"created": "2017-01-20T00:00:00.000Z",
|
||
|
"definition_type": "tlp",
|
||
|
"name": "TLP:WHITE",
|
||
|
"definition": {
|
||
|
"tlp": "white"
|
||
|
}
|
||
|
}
|
||
|
]
|
||
|
}
|