2023-04-21 14:44:17 +00:00
{
"type" : "bundle" ,
"id" : "bundle--5ee3822c-6828-418c-b619-62de950d210f" ,
"objects" : [
{
"type" : "identity" ,
"spec_version" : "2.1" ,
"id" : "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f" ,
"created" : "2020-06-21T12:25:57.000Z" ,
"modified" : "2020-06-21T12:25:57.000Z" ,
"name" : "The DFIR Report" ,
"identity_class" : "organization"
} ,
{
"type" : "report" ,
"spec_version" : "2.1" ,
"id" : "report--5ee3822c-6828-418c-b619-62de950d210f" ,
"created_by_ref" : "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f" ,
"created" : "2020-06-21T12:25:57.000Z" ,
"modified" : "2020-06-21T12:25:57.000Z" ,
"name" : "Dharma Ransomware Event" ,
"published" : "2020-06-21T12:26:28Z" ,
"object_refs" : [
"indicator--5ee3839a-07e0-4533-8ed9-fe83950d210f" ,
"indicator--5ee395a3-54c0-4f88-a035-433e950d210f" ,
"observed-data--5ee8b501-bf98-4bb7-85ff-487d950d210f" ,
"url--5ee8b501-bf98-4bb7-85ff-487d950d210f" ,
"indicator--5ee38271-b93c-40b2-83ac-4ade950d210f" ,
"indicator--5ee3827b-96ac-4da2-8d46-4ade950d210f" ,
"indicator--5ee38287-bc8c-462b-863d-2f22950d210f" ,
"indicator--5ee382ca-87f8-4144-86b7-fe8b950d210f" ,
"indicator--5ee38314-c71c-4493-ae54-40a6950d210f" ,
"indicator--5ee38343-f910-44d1-b837-fe5d950d210f"
] ,
"labels" : [
"Threat-Report" ,
"misp:tool=\"MISP-STIX-Converter\"" ,
"misp-galaxy:malpedia=\"Dharma\"" ,
"misp-galaxy:ransomware=\"Dharma Ransomware\"" ,
"Ransomware" ,
"misp-galaxy:mitre-attack-pattern=\"External Remote Services - T1133\"" ,
"misp-galaxy:mitre-attack-pattern=\"Valid Accounts - T1078\"" ,
"misp-galaxy:mitre-attack-pattern=\"Scripting - T1064\"" ,
"misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"" ,
"misp-galaxy:mitre-attack-pattern=\"File and Directory Discovery - T1083\"" ,
"misp-galaxy:mitre-attack-pattern=\"Network Share Discovery - T1135\""
] ,
"object_marking_refs" : [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5ee3839a-07e0-4533-8ed9-fe83950d210f" ,
"created_by_ref" : "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f" ,
"created" : "2020-06-12T13:31:06.000Z" ,
"modified" : "2020-06-12T13:31:06.000Z" ,
"description" : "rdp actor login source" ,
"pattern" : "[network-traffic:src_ref.type = 'ipv4-addr' AND network-traffic:src_ref.value = '217.138.202.116']" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-06-12T13:31:06Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Network activity"
}
] ,
"labels" : [
"misp:type=\"ip-src\"" ,
"misp:category=\"Network activity\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5ee395a3-54c0-4f88-a035-433e950d210f" ,
"created_by_ref" : "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f" ,
"created" : "2020-06-12T14:48:03.000Z" ,
"modified" : "2020-06-12T14:48:03.000Z" ,
"pattern" : "[/*\r\n YARA Rule Set\r\n Author: DFIR Report\r\n Date: 2020-06-12\r\n Identifier: dharma-06-12-20\r\n Reference: https://thedfirreport.com/\r\n*/\r\n\r\n/* Rule Set ----------------------------------------------------------------- */\r\n\r\nimport \"pe\"\r\n\r\nrule vssadmin_Shadow_bat {\r\n meta:\r\n description = \"dharma-06-12-20 - file Shadow.bat\"\r\n author = \"DFIR Report\"\r\n reference = \"https://thedfirreport.com/\"\r\n date = \"2020-06-12\"\r\n hash1 = \"da3f155cfb98ce0add29a31162d23da7596da44ba2391389517fe1a2790da878\"\r\n strings:\r\n $s1 = \"vssadmin delete shadows /all\" fullword ascii\r\n condition:\r\n uint16(0) == 0x7376 and filesize < 1KB and\r\n all of them\r\n}\r\n\r\nrule Network_Scanner_post_exploit_enumeration {\r\n meta:\r\n description = \"dharma-06-12-20 - file NS.exe\"\r\n author = \"DFIR Report\"\r\n reference = \"https://thedfirreport.com/\"\r\n date = \"2020-06-12\"\r\n hash1 = \"f47e3555461472f23ab4766e4d5b6f6fd260e335a6abc31b860e569a720a5446\"\r\n strings:\r\n $s1 = \"CreateMutex error: %d\" fullword ascii\r\n $s2 = \"--Error mount \\\\\\\\%s\\\\%s Code: %d\" fullword wide\r\n $s3 = \"-Found share \\\\\\\\%s\\\\%s\" fullword wide\r\n $s4 = \"--Share \\\\\\\\%s\\\\%s successfully mounted\" fullword wide\r\n $s5 = \"host %s is up\" fullword ascii\r\n $s6 = \"Get ip: %s and mask: %s\" fullword wide\r\n $s7 = \"GetAdaptersInfo failed with error: %d\" fullword wide\r\n $s8 = \"# Network scan and mount include chek for unmounted local volumes. #\" fullword wide\r\n $s9 = \"####################################################################\" fullword wide /* reversed goodware string '####################################################################' */\r\n $s10 = \"Share %s successfully mounted\" fullword wide\r\n $s11 = \"Error mount %s %d\" fullword wide\r\n $s12 = \"Failed to create thread.\" fullword ascii\r\n $s13 = \" start scan for shares. \" fullword wide\r\n $s14 = \"# '98' was add for standalone usage! #\" fullword wide\r\n $s15 = \"Error, wrong value.\" fullword wide\r\n $s16 = \"QueryDosDeviceW failed with error code %d\" fullword wide\r\n $s17 = \"FindFirstVolumeW failed with error code %d\" fullword wide\r\n $s18 = \"FindNextVolumeW failed with error code %d\" fullword wide\r\n $s19 = \"SetVolumeMountPointW failed with error code %d\" fullword wide\r\n $s20 = \"| + scan local volumes for unmounted drives. |\" fullword wide\r\n condition:\r\n uint16(0) == 0x5a4d and filesize < 400KB and\r\n ( pe.imphash() == \"0b0d8152ea7241cce613146b80a998fd\" or 8 of them )\r\n}\r\n\r\nrule Dharma_ransomware_1pgp {\r\n meta:\r\n description = \"dharma-06-12-20 - file 1pgp.exe\"\r\n author = \"DFIR Report\"\r\n reference = \"https://thedfirreport.com/\"\r\n date = \"2020-06-12\"\r\n hash1 = \"2f2e75affe9217c7211043936678fb1777e2db4a8f1986b8805ddb1e84e9e99b\"\r\n strings:\r\n $x1 = \"C:\\\\crysis\\\\Release\\\\PDB\\\\payload.pdb\" fullword ascii\r\n $s2 = \"sssssbsss\" fullword ascii\r\n $s3 = \"sssssbs\" fullword ascii\r\n $s4 = \"9c%Q%f\" fullword ascii\r\n $s5 = \"jNYZO\\\\\" fullword ascii\r\n $s6 = \"RSDS%~m\" fullword ascii\r\n $s7 = \"xy ?*5\" fullword ascii\r\n $s8 = \"<a-g6J\" fullword ascii\r\n $s9 = \"]q)WtH?\" fullword ascii\r\n $s10 = \"s=9uo^\" fullword ascii\r\n $s11 = \"\\\"iMw\\\\e\" fullword ascii\r\n $s12 = \"{?nT*}2g\" fullword ascii\r\n $s13 = \"h*UqD*\" fullword ascii\r\n $s14 = \"b,_f n7\" fullword ascii\r\n $s15 = \"+mm7S%I\" fullword ascii\r\n $s16 = \"+L]DAb\" fullword ascii\r\n $s17 = \"nq0<3AD\" fullword ascii\r\n $s18 = \"U2cUbO\" fullword ascii\r\n $s19 = \";C!|E2z\" fullword ascii\r\n $s20 = \"P)8$X=\" f u l l w o r d a s c i i \ r \ n c o n d i t i o n : \ r \ n u i n t 16 ( 0 ) = = 0 x 5 a 4 d a n d
"pattern_type" : "yara" ,
2023-12-14 14:30:15 +00:00
"pattern_version" : "2.1" ,
2023-04-21 14:44:17 +00:00
"valid_from" : "2020-06-12T14:48:03Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "Artifacts dropped"
}
] ,
"labels" : [
"misp:type=\"yara\"" ,
"misp:category=\"Artifacts dropped\""
]
} ,
{
"type" : "observed-data" ,
"spec_version" : "2.1" ,
"id" : "observed-data--5ee8b501-bf98-4bb7-85ff-487d950d210f" ,
"created_by_ref" : "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f" ,
"created" : "2020-06-16T12:03:13.000Z" ,
"modified" : "2020-06-16T12:03:13.000Z" ,
"first_observed" : "2020-06-16T12:03:13Z" ,
"last_observed" : "2020-06-16T12:03:13Z" ,
"number_observed" : 1 ,
"object_refs" : [
"url--5ee8b501-bf98-4bb7-85ff-487d950d210f"
] ,
"labels" : [
"misp:type=\"link\"" ,
"misp:category=\"External analysis\""
]
} ,
{
"type" : "url" ,
"spec_version" : "2.1" ,
"id" : "url--5ee8b501-bf98-4bb7-85ff-487d950d210f" ,
"value" : "https://thedfirreport.com/2020/06/16/the-little-ransomware-that-couldnt-dharma/"
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5ee38271-b93c-40b2-83ac-4ade950d210f" ,
"created_by_ref" : "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f" ,
"created" : "2020-06-12T13:26:09.000Z" ,
"modified" : "2020-06-12T13:26:09.000Z" ,
"pattern" : " [ f i l e : h a s h e s . M D 5 = ' 1 e b b 6 b b 49 a c 1077 c 5e7 e b a 4 d 56 f 6 a 3 a 1 ' A N D f i l e : h a s h e s . S H A 1 = ' 1 a 37 b b 789 c 7 b d d a 44330 f d 55 a a 292 f 5 f 76 d a d a 5 d ' A N D f i l e : h a s h e s . S H A 256 = ' 2 f 2e75 a f f e 9217 c 7211043936678 f b 1777e2 d b 4 a 8 f 1986 b 8805 d d b 1e84 e 9e99 b ' A N D f i l e : n a m e = ' 1 p g p . e x e ' A N D f i l e : s i z e = ' 94720 ' A N D ( f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A E V r z F D R 5 f g j s R I B A A B y A Q A g A B w A M W V i Y j Z i Y j Q 5 Y W M x M D c 3 Y z V l N 2 V i Y T R k N T Z m N m E z Y T F V V A k A A 3 G C 415 x g u N e d X g L A A E E I Q A A A A Q h A A A A D a v R F 5 o l i c u J E K J O s H D 6 f p S T w 3 N G 7 f 5 i t c s j s b E N p q t m m G p Z o t r p b k l U b q K P w N d 4 E A S C z 8 p R w q T w V R f 6 f 4 F T Y W k z K E R Y Y B m R v L m d 75E4 k 0 W K W i Q c n o K k + D h o k K F 2 I p f w J o q R j z H y H A l N 3 t l s L G B 0 t K e V K 3 F o 5 Q 3 K U W E H Y t i / K C Q P b M i e O E c G f 1 / M y D X H C 2 S p g 7 p p 6 K N 0 p X r 49 o Y 5 z k x J E L h K E C G / z U W n u H h l U b e P 56 g x / i w S 9 a E e H u F r 4 / 9 T Y M 1 G 0 I W 7 O Z X + M Y m n d C I A z Z L R t 5 o W h k E O s T P 8 c a N m 53 n d g Y v l j P 7 F h k I t J z a O r q G s 4 A a V 0 h U X R F 40 + k g 8 N P Y J c g y W h z k P G h K s 8 T J b J F N q i r g H G i 2 b 3 h X b K E r J b K 8 F p T E d / r z j u V W R x b 93 o M p o M 8 z K Z g 5 B 7 + I v D Y p F A J y F S M Y A P / I w 3 J l n n R 6 T H C z x k F 4 A u 7 O y 5 n R E K d T / X h l a g s 0E5 d / A 6 f K 2 + S E I I C A 7 i P T t R y 9 q 1 J s v + n 6 U X l e g F l w D U P 0 H + J E T F d B 1 Y b R N d g g x J b 9 i l k 2 q 8 x T h w 2 X A 4 B R u L z l + s s 1 h o j b z c i M H 3 k U 7 D K g W y v j o G e I m 8 e S x R 9 F G R 1 S l t R c K K f 7 M I C 4 L d q S e T j 0 5 O v + v d C r / 3 T a 7 F X g K I u H 7 g a l P W u 28 x S 7 N h I 2 z i S h t u o 40 Q R / F / P I K Y Q a a C f U p c A 9 N p o 8 o 6 D Y m y I B n L B q I f q o e j t L R n O O W i 6 w u A + t P 6 z U r 7 U G M d f Z H W 2 y Z F h K 4 z 7 c + G B 74 f / r A H H D y 8 l 14 l U w z N 4 a d b Z B b i 0 a v v n F + u C M m H N q k Q P C a C a m k G j N v v / a + d G f J e / e G s u o y I T 8 j y I z C n O k U V l / W l r 6 s w 14 t r 6 S C W T d 3 S 8 v l m r + g c Z k n X 1 X x M T 8 u N u u Y i 8 C A h E l 6 R v e i B r Q 9 z c v I r M 7 F H F f z e P q p Q C T B j r j a y R z N o j n g a L e B S 92 j j J 0 s D s 5 W D / Z 1 H A H 4 w q h 8 j h F 2 z 8 J 4 C v 5 w c Z h 2 a K F G F g k u X o m w O Q W C E R z 0 S Z 8 c k J R / n E M T o r S t Y j I F W F l 1 U P q s v 5 q u S W P i 0 w t F T U j y s K s k E r z y B 800 u / x J u e U 1 h b N + X M P T F X L p t g h 20 U S b 3 O f X R y M y T F d f C q E + c + C y Q o T l N N o m N p p z M J J F V c B M u z c 7 r i y S p c 0 3 h b g I f D Y O c n L m Z B s + e N Z y E D m 0 u H k C D g n U f C s j Y Y s z U R a w J u r 8 m i U s + p C 9 K m n R D a n D v 1 K 0 l k 9 B J h 269 L t J W v g D O p k t x e W 5 w x l e P Y t R j w E z L P b k 2 i F h s T x Y y T u h 7 P q v i O p 2 o b B q G V d d g x c l T P S 1 f Q G Q J q h 8 O y a D w 219 O Z Q h i m 60 v J 2 V v f E E m 5 o 2 y I c z M A / e K w H Q l L J I z V i A g y m 8 y 2 D 8 y e G M x c g P p p 3 Y E e v i r r s U R h M e 8 X z / 0 6 q y 42 l P U a h 0 t z A R 0 A T C b c K O M 2 e d f 7 I V J t j / T Z E y R G M 2 f v C b S P f o 8 v x H 5 n 9 M S z B 996 M E q t C A a G 7 a g r E o q T Q Z V Q L n S s D f S E N L E k J r k y G J s 64 + g d u s a W 6 T b W Y k K c p I / E Y D W y r F V s B e t 9 b P 75 N Z S s 6 l m v 4 y T h r J O l K q a 2 E + X o G a M l G w k A z t j s Z 3 r F r 4 L M Y 59 T 59 n E Q 0 M 9 c B r k g 4 j z u W A q q 14 I p L l C K L L t q 6 / W i T w + 1 p e w K 3 v o E m F x x V p B Q o h F 7 O H M a u 3 b f W v 6 Q C a Q B 6 i i R X 7 z I D n o K O X r k 3 n X 9 A Y U G a U L t l o 7 h p W C E u / I q U y 1 B d 5 z z Z W f y 4 W 549 F j H i s 0 w q e t 6 w D + 54 z D e o l Q j C L o V 7 Q s S u g x v x I M k K 5 Z + X 4 O U 9 O D N A F F a s d Z l g r v O E T N Q d w j t p L + e g B e 8 A R r S V / C o S f L 3 R a w X N + a l R X j f c h + i k 2961 d f O n y S n X b W Z V a a q s n U d Q 3 C 7 H H H G B 4 k q t K n j 5 o 1 k e M 6 P g T 6 P 65 h P J S 7 N c q h T I E l Q y J 8 G X v x q n J n o y p y s g 9 u B w h s j K W Y V c d 5 W K o j N C 0 90 I K N 9 X L 7 C f h x G + p W 5 C T 2 i 9 Z v u B 3 o H g y m I q 9 Z y 2 M 4 K m 9 r I 1 O u k A G v R + 3 M e r e 7 I c k t m t 5 P s t u C l P E O q U n R 9 A A S C L R Q L x j l x D P r d B U X x t E Y q 2 B J 99 r X 4 i W t q G D S N Z Y 3 W d R E B S W w q O N B N s m y f i V 4 B a k D G 1 C Y q y S f G 67 E U Z i p h r 5 L y t y k 8 C E X 2 S 2 a 722 a n v h i + u N n f A s x 1 f j g f p x 3 H h 4 j i V W y D H t h U B 1 B x G L 3 Z a M T g k r 6 L v T n d N w j P k G c j P i X 1 L 2 U e k u A p m b a A 0 O W P q E a 8 R k 6 t U s G U p v y s l / K x X b x F r L 0 L Q M s H t o I R o 1 i l 3 t H C o 8 q b G o S B j k e 9 p k Y L g 9 R Y y + u O X N h r D P u S p h 8 h 3 v 0 / F A t E I g 2 g T U Y v 8 x N B b E G B z 6 K R U G 8 Q C 0 1 E v R g x i 3 G k L r k 0 / P z S G C w Q 62 c + 7 G z 1 e e S D c I e M P d u m h P C 9 j R i N p K T A q Y G T m c U A q N F V Z g G Y 1 y F z h b + W d p D d j p 9 Q O y w + 1 T 6 W V 5 z 0 V a b C e T r 1 X T D y C u O Q A v w H Y 10 w R r w 8 V s i X q Y V Y b 0 b u c a x b M Q + 8 f L K w + 12 w E t Q r h j i T F Y S M G + k 8 / f + 6 s P N o 4 + 863 U H h L N Q M C y l r V b L O p m Z H s z J K b i o C N C i v H i R 3 k Y Q m E 0 e d 1 v X n D + 6 H / 0 D k 6 i s u S S a 9 N x s V 5 F a o W g n 6 V U 8 v X 9 k U 7 y Y h 1 L H 2E5 F p A K d L a 6 s G D q q 9 c M x E D K H a X 5 h B u F j k O y e 7 L 7 C H 4 o 3 O f c F 87 F Z y u e s P S x 3 A F V f P o U D N l G W J H I f D B Q r A l r v l A W d e u A O e r s / W i c S X r o v M i 5 F S j 0 m O J 3 K s P 3 c d A U s R k B f K F T G G Q R X 54 X 68 O + w 3 v M Y I 1 v R l D T d h i m 2 L O A R 6 F h 4 x h l M n m Z 1 s B 1 M I c a T J U w C l 9 R o x t 6 P 2 E Q 9 c a f f d P M h j D 7 F x I i 8 e W R e h g j X m 5 j K N A 5 p P u V J / k X V 3 Y 1 x k + 4 v e J j l j D G 8 K n 9 E v 1 s a R z + b T Z b W f s S u 8 E g 55 Q l J P S F D i m Z f v G 8 Y z u Z d p n 2 + a x C 21 y A r z b G O 6 n c t H J V 6 M F z u 6 g i + T r g 2 I i b L C a a P r D j I g 8 I h + T X S 2 / n Y q v u n K b 5 q e h A W z p g i 7 o r L W 2 w H I l g F m z O C c 2 M z W S G R j k / L e O N n a F I 7 v P n s J V l p H D Q F M t 2 K N O P D V K 4 q 3 c W 52 g v c z A W p 5 o G 8 N + T 5 l H w d o z g n h f p 5 T / 19 J L j B P y b i 4 Q 7 H o s g B M i U P 8 F / c 5 w P 12 K G I k Q / 1 g H F 2 m x m R m C F E S N 3 z E Z Y G v 1 b l k P s 3 N E x h k 8 W s O N 0 h k 8 l H 9 s O h r K u 1 J g i R e 5 w R + y w d U / W 0 i Q T p Q c y q n m H e D I L k D a i g f / j B g J 9 j 8 U c 70 g j M Z I / F Q D s P j j f I 0 8 e W O a / 7 B Y S t M m 4 C t 5 z k 0 Z W D n 9 i D b Q T h W K j 9 v k 5 u j 7 B C 2 N 81 V v N R t d e T T V m z Q X 3 P w n u 8 + N o M a U g W p 9 Q 81 R X y d d N 72 h 8 j h t 7 F V k y 5 C d H V J M 9 t S K S / m 2 w 4 m O + q D V 1 F c 1 G g k s X r N 6 z Q K e N f / 7 B M u 244 V Z d P 3 O F q z t 1 l z + d 7 y 8 m c 3 E V s 9 L n 3 + x / a D g g e m 3 p U 2 P 8 N a O Z x X y o 5 l b u a g R G P j g Y k + H C h 7 L F T + T p P J Y s N K X j 0 o H P O M / i 8 p n d 6 J Z f W 0 I 3 T o L x 3 V S k 4 K K 6 y i 5 s E l E N c b 6 S e 0 x z I w u f 1 C A x I j z G N l J m K T D 1 N N G N + A B L q L g N 6 / Z J 8 w W 1 a 9 / M V b A X H v 0 4 Y F j n 9 C N I q U S t A g P F P u V F z r g G L y E w 6 M k A r S c g 7 T O l z 1 d v A 33 j O s o D F U 2 Y v / X o W 1 q I I y B k j g D s U 5 m j 8 G Z 461 K + 1 o W 6 w S z D 0 u J d Q M I x R e r y C X G J y X k R + P f / C 8 M 7 r u u D 1 k E G r r 6 F g x T X U Q N 7 h J A x b r d 6 c a L O C A E E X z j m R S k 5 z 9
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-06-12T13:26:09Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5ee3827b-96ac-4da2-8d46-4ade950d210f" ,
"created_by_ref" : "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f" ,
"created" : "2020-06-12T13:26:19.000Z" ,
"modified" : "2020-06-12T13:26:19.000Z" ,
"pattern" : "[file:hashes.MD5 = '9b0d6df42f879ba969f82c7a0ab48bc6' AND file:hashes.SHA1 = 'b5d6f94f270a02abedc7484dc7214d15d2cee99e' AND file:hashes.SHA256 = 'e25245f98a23596e03e51535beb0f73c000de63e473580c4c26e7b8b01b4e593' AND file:name = 'closeapps.bat' AND file:size = '3611' AND (file:content_ref.payload_bin = 'UEsDBBQACQAIAEprzFA+CgJcPwMAABsOAAAgABwAOWIwZDZkZjQyZjg3OWJhOTY5ZjgyYzdhMGFiNDhiYzZVVAkAA3uC4157guNedXgLAAEEIQAAAAQhAAAAJGTC79urpRw78MMkXDoxs1DaeVy8tRk/4oYMpKdycWKBNJN8TUNryHLM7/8gwj1QoI5Tt2OIP3kWNi23M43QA8kU9VSMOeMSibp6MQR+a7E9sgvfo/i4lLDBbB3qeYCmPcWwJyMeGNqb/mZbgtIdN1f6OZ1VO23stimt0tAZ1los6ZXF6f+bB8v7qSLwou86fycGoNVyrVE2iHzPI2wGBz9qZpGxpocViMR5wyRiIpD+HGo5xoilm1fK6U0ulu+XbF3CRS+gr3n2//3rEea3IuOWsPu6k3bqlRbi0gjurvRR52+oPWk9aSw4pwFkF6VEoJZrv3PVm8ThtT6kjS4JJIOvEMIWpEKZ7iJq0CmUQ0bbkR0AlMbP2Z+jklgsISlJKPIZyzh02MmIJHyf4ZOaUmaBs8c0+WG7n+IgjHfEJx6IjIiYmdAh+XWsSV8irPoLwh3RTaxDlq3Hl4QDAXa7UKF02GdJBFWmiw11EwlsBciBBtrIBthn21jnqaI+ifXrUA6W8/K7eXdp7dZ9+Q6AiX93SMdAkkNvL01V1bIuYmGbWCOMLMUchWX6wkOuvuBilB7QxvqGeQ1LA/fRQdDV7942+SUFL909wpdQMgK1fjB8M7vcIOVcxRo/Rb+8JrFShbukz2ysfOZGbOBVgBI4vLIAayiL99DIJaq6PopCGlOUT+ndLhzFIKJEp8KueNrnfnwCk9EBgBw1S0QccUY1v2lBNLntfYa6Ux8s4hZuTi6/rGuxcFfTRYFmvR+T8B/kne3jwTqpw2oAOCtT0eair+1QeqLTrdrTFccfPvZdKAjlfUvAxG5Ys2vxLhmlW1L62ZwqxMBhPpbUPgM9kvFHe3T7t/lPkxV0ssbkPX88SsdRS2KA8NdsPDUegCduVhF50rOHtrwGKX/9tfJxAXorUovMgIBvmdfv7mU/RdYXPnxh+PoPnntdG/0bWNy87BZIStT7Lb6mkY1Zy4Q5koezywl9jdDBjH4fsNzRUlJ8RRIoVjK/bQB4TmwXnIzt3aMgpapsfEInFS9fZrn7DAM1gRmHEtlPF4fX1gadl0sa1lvaphsO187KgtNSxqMNuYQs1CH65hoquvfLUVbEX3abUEsHCD4KAlw/AwAAGw4AAFBLAwQKAAkAAABKa8xQRYb6PBkAAAANAAAALQAcADliMGQ2ZGY0MmY4NzliYTk2OWY4MmM3YTBhYjQ4YmM2LmZpbGVuYW1lLnR4dFVUCQADe4LjXnuC4151eAsAAQQhAAAABCEAAAD9KdpzjSYt6QvioyAnChI5W73UEcaTWAMHUEsHCEWG+jwZAAAADQAAAFBLAQIeAxQACQAIAEprzFA+CgJcPwMAABsOAAAgABgAAAAAAAEAAACkgQAAAAA5YjBkNmRmNDJmODc5YmE5NjlmODJjN2EwYWI0OGJjNlVUBQADe4LjXnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAEprzFBFhvo8GQAAAA0AAAAtABgAAAAAAAEAAACkgakDAAA5YjBkNmRmNDJmODc5YmE5NjlmODJjN2EwYWI0OGJjNi5maWxlbmFtZS50eHRVVAUAA3uC4151eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAOQQAAAAA' AND file:content_ref.x_misp_filename = 'closeapps.bat' AND file:content_ref.hashes.MD5 = '9b0d6df42f879ba969f82c7a0ab48bc6' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected')]" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-06-12T13:26:19Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5ee38287-bc8c-462b-863d-2f22950d210f" ,
"created_by_ref" : "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f" ,
"created" : "2020-06-12T13:26:31.000Z" ,
"modified" : "2020-06-12T13:26:31.000Z" ,
"pattern" : " [ f i l e : h a s h e s . M D 5 = ' 8 a d d 121 f a 398 e b f 83e8 b 5 d b 8 f 17 b 45e0 ' A N D f i l e : h a s h e s . S H A 1 = ' c 8107e5 c 5e20349 a 39 d 32 f 424668139 a 36e6 c f d 0 ' A N D f i l e : h a s h e s . S H A 256 = ' 35 c 4 a 6 c 1474 e b 870 e e c 901 c e f 823 c c 4931919 a 4e963 c 432 c e 9 e f b b 30 c 2 d 8 a 413 ' A N D f i l e : n a m e = ' E v e r y t h i n g . e x e ' A N D f i l e : s i z e = ' 1668200 ' A N D ( f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A F B r z F B p l H U l q 5 I K A G h 0 G Q A g A B w A O G F k Z D E y M W Z h M z k 4 Z W J m O D N l O G I 1 Z G I 4 Z j E 3 Y j Q 1 Z T B V V A k A A 4 e C 416 H g u N e d X g L A A E E I Q A A A A Q h A A A A g L l Z d t U m 3 K l H 9 f A x z / A u K u y 8 i + y 7 W f g 3 F Q 3 t d I K S v B G b G W m 4 U I p R / I h C C 57 I S f V 14 P d B k q 3 t 5 w S z P 44 A z 25 s 8 P x c o 0 u H 8 e n k G r + x X c I Q P Q q J Z j q e c 6 M g U W 6 a 38 Z R u 4 O U c O S J d 3 + r 3 j e m I J + x T D i s N V c K T v S 16 r 8 U D / y 2 Z m f l V x h S I B k o w 7 L 9 M B 4 t 6 o A 6 j F 78 N d r Z u g f A g r o 8 q Q f r 87 h G R 23 k j Y O 7 b f 0 3 o g o T S 7 x w 0 + O V 2 K L 9 n k n B L Z K v 1 / L p z / J 4 B C t i m + 6 B h e n q P f c M J 9 u S a r P 7 m a P f d P p T A 0 T L 155 O 2 f O Y 4 s F Z 79 A K Z U R A U c g 6 X 0 f h T 9 G f m z q A p W p 89225 h O 6 + 8 J K / 39 h E f X r O Q i + r i W j u 9 i 6 B Y 4 V k O O t 4 V H s 9 M R k u l D X x K l C b 1 v 9 L 0 o i I / b Z 2 U j 1 r D Y s h k y P d n V t Z M V i r 1 f K w w V J W L H o 7 D i 6 + M I R T S x m c s z K I Z k B o j J P 7 M w k 2 B q J y / H A w v P G u d o 6 / r X A 7 y 8 L 1 + m j p 80 q b b V 8 X y N Q k G L I v n w B G h T W W z V 7 j 76 b 2 r 865 y y 5 r S c A Z C Z f 7 X g 8 A q a 4 a O C 2 V Y I y 2 I r 8 d H B K t m u Y s a q Q 50 J M C W R j w c B j S S S 7 Y L q + + M x q x 6 K / B q 6 P k c G 0 2 p h n P d Y + G f 2 p 4 Q k 21 g 1 p H l L 7 + B W 13 r k g J 9 d y m D G R g W B j V 8 R 3 C w S / q b M + W W F R M I I U l T V N A r x 7 + j T w O p o 3 N R p o g w F I D 5 / l 6 z i u n O 0 X X O y Z H m M 77 P m 8 H 9 w e 6 x c 796 u j B E + j B r F C a g e O z g h R t / t M H b 7 Y O u m h J W H 0 G W V A W Z h A l 7871 b h E e T k D 6 P X + m D 5 w t q R o 3 Z O W l 68 R S 14 K G M I / a T D d r 7 p H z 8 v a G Z h a p O m B 5 X Z H W x 1 h a A R z m S t 8 v p C T B T 9 t I S v + o E g 1 p O b V 3 v 7 p P q N k Y d y 5 C e L B u 2 a k 314 p 8 M S a k f h 6 u R o W i r r I J V x G 52 v m F C N J k b h Z 39 q s Q O X 6 S O J J B L o L j d C k 83 C x 1 o R N y F f / A q Q 5 n J E 95 Z X H a + d p k J 5 W d 0 m 9 r F z d W l N N W H F k V y q m z l b + g y z V I P B z d N u c r M 7 F W P 8 R W K Y d q b A 87 c N Z v D h / F 9 A z O y + P b m b N w F J y m y u x c W 0 8 K 7 + D G X b K B n s k K V Z 0 W R h 77 g k k 4 n 3 c B X + Y F 0 X r X F 6 y Z / V 5 Y u 6 c e B S 4 Z F Z 0 0 d h / j i D L Z P B h F L a M H N s C 3 d U 1 E I X j P p A / Z 4 u l u q m j 9 w T Z 3 K o n a I b e D C k 3 U R D i J H t H E J p p 9 o j b j I s C m 9 q r W p y C F E z m c F l 0 C L n S q 5 k z u 7 x L w 4 L u R a S K L o l z d n y Q t d 92 D g Y 3 M t m B 7 J U 6 y K t v y V N 6 m x W R Y Z e e t R y A V 115 R D c u S o c G d 7 K e 4 P k P + W d 6 S X I 4 t j H b 0 9 Y 3 M c s y n E F 1 J X 11 + 68 R 2 l 2 G Y S Y i K 4 g v d c 0 p 0 C 3 P x z k 815 C n 3 U o m O L N Z z S 4 v w O S M B 33 w 91 O z G E A P Q 8 + y + n j H 9 Y Y Z K g 8 M V b x m J 8 n y Q I J 8 a 6 b Q 7 Q z W M e A X 26 G l w T / l a v r J L x z H K I X D r s z T 3 A 3E7 s a r n 1 V m 0 z L G N U 4 e a S v d 9 f F I 1 Q j r I m A 5 s g S D R D d I D m V W g g m 6 G / l T R u N 3 Z I v u t A i k Q j V 2 O B t G t 5 m p T 4 D D q F 33 h U K Z g m L P / w U 5 f w 6 B 8 J 33 u U 3 k y U 5 s t i Y 8 m x l x h D Y j Y i P q i c D u + H 9 R 0 S / 8 X v x s i G W J K k z h W n O a V X S s Y V e t e r X 0 6 h h D p 8 z H z U b J w 2 z R P W v H + c D D C F X / c L p 5 V Z Y D C X a e c p M p C S b D F G w z 3 O 21 m v v Y Y K y n G c f j P c j 1 X x y 98 A q u 7e3 x j L I g w d y i 1 V W e F h A 3 X j e E x m M 6 J X n q J U R j P / 6 c s y v L j t V 8 m X l C c V m a g 2 U p 1 k f O W j O j J g / q 5 b j r i P M 12 z Q e + y t Y u 6 i J 15 k D z y 4 p n 1 X M t r f i N P S v 4 S t i V P T x l z s T z e m / j i 0 G Y n / z 4 M B E F X n 63 C U l K I L L 1 + e j G j k k H J N G B g g d V r 6 e g j L + o D b l V 85 i z B M G R P P L s n x r F C G w t 68 r I G 4 u T K 2 k 8 c p T a L x a 9 W u t r V H 6 l I / M 8 m n 2 D K n H I t 9 L g z E G S i T x 7 q W i P e l M V W h 7 n g f w G o E 0 I T q l E p f 9 M L T 43 S + 80 s 7 G l T w 2 B I A P K n U 6 i 4 R j n 1 c d P p u P v N e u / 69 h M B 5 W 20 / G n 7 o m J + 0 k L h U n 7 P W A F p f V D D o W H R H o 37 y T p A m t h 3 T E V c + g u J d I d 6 h x M z J s q L g 8 u r s 9 y D k 4 n E l b n i 5 + l 22 I 7 p 8 u y E s + C 2 X K y I K A 6 V o 3 B d f 1 d W r e + p W x s z C e E 0 g 2 k 3 N E 4 T G B q + 5 Y q m C c O m 5 N + k I y R L F / B T G S 2 h f r m B G 8 F 0 C p Q d f s c j O 84 M 0 A V D j 56 O b X 8 I e d Y P k 832 s + a 0 u b 3 G 5 D 9 f S b w U j S N / X W X j w T V o R 5 P D s L J c 27 S T 2 Y A m N F a S s f o M V x Q I 0 1 D P + Q + 2 l + v e W l d z r I R 3 d J p B u 4 N 5 X M Z Q A 0 B 1 D 7 W i M h k F m N 8 y + / v A / L R b L a q Y P M J x f m N 0 m G n j p W X I M + H I w V Z h u L 4 a 5 E U m 3 p x B S Z o o f d s L E E P C x c i N F U R I 63 z E K n V K z 0E8 B L R D D K O J o 5 l E N / y N c D z X I O B w 23 u b W Y B I c 8 M q T c V 3 u g 6 b o a 6 k m K X b y 1 P f i A F L G L U v 77 c + h L 1 I o / Y J y K v t F V i u N o i J w g V 6 c E v D 8 w C H w n I H a W d w h Q j z h 531 o R 98 S 9 G 0 N 9 u o x 3 j 5 s G P X k B m L C Y x Y j e E C 9 H f p n k a 1 l T j b 1 S G 6 L w k f 7 X b y o k w D 5 e E j l m o Z 6 V o w g k m K C W 0 m 66 Z p V 9 o j 0 4 w H 4 w K U s O 1 i 0 C D S 5 d w y 363 / 40 V 5 q / x y S G V p K 7 I w O D E v F 0 D X n z z M d 0 F X P Y P 24 c T 5 j Z N x n K X d K S Y F V P x F 5 D N x D l f K j x d B h A 4 x 4 s l L i c j h U O k c 7 w R B 7 D W k W Q 1 Y C z u D u k 7 E c 6 + N 1 z e y M R o U K o k s m W r o w / F g l q Z g 4 x 6 L e z k u H D B / F I I Z x 3 r O b B y w K K K 8 k E E F o T v N D J i G F K E j K q 6 T U U y l M i z A O w z k R E r Q F I + A w K N 0 A r R 2 g G w j h 7 x / j g I b e A t V Q v A N 7 S K o c t D I R 8 d e c 4 y 6 C g U 59 d Y U P I V J 1 Y S O 75 T 7 k l n B t w N g J o f U o s p i v 8 q Q m n W r / w 1 + / R R D + e j Z R O / l f l 3 C H N n I A t s T V U P b A + x a j O E C h Z F M b F T e 1 D t J M 9 R T V 8 w e A W x v k F I Q u g v k y Z j X F j B I O x 6 W 2 y p d L 299 K F Z m H M s V i C h r c K B 9 X a E s d 9 K 3 L B 3 g v 2 l H N s E 9 Q b H R T i 36 O X Q K A k L D J 48 b D i 9 R 6 l j L j B m o 4 D p c K n o S H b b B m q D n K H 33 J i N k S 0 p 1 I 4 P 0 f P l 21 E V q q X K Q 7 r 0 P n 7 w C 4 H t 2 s W z 4 R r 8 + 7 b r X F X F p d + o h o + R g J J F + O S g O I X Q r a 3 Y 4 d 28 G b y 4 j d p J O b H X P x Z o i K 81 l j c E Z M 0 0 E Z w U 56 Q l R t 9 N C k i q F h K t e g 4 t w + w U q t r Y b e s e F + N 0 g T r Y 8 L J U M 3 O o V F x 47 / f s q c e B V u n d z j K 0 N 7 v 1 E L D R e I W 1 T R 1 g 4 a + D T + o Q N V Y v G I G t U 9 w o a K u g u 9 R F l R n u 0 5 C k g x A 1 o M / b n 4 x y W z o d + C E 7 e + j Y O 7 b s U q F F F m L b K + c T O W Q O U B U D l V w C b N z g e h t j B s b a s f e v i 3 x 5 r x Z 3 g z P A j N j a c 2 q 7334 H u 2 z B F v A 0 4 S 7 M J G I I w X T a F N L 9 q l 4 / X v 6 F w n z 4 O 9 n R M W v A r 5 s L / b q c P Q k 4 a A n x 8 r I m T z S o M H r r F p A T S f 2 V o r W u E b F g N X J n T P j h H N 6 Y Q q W h y P G f v J P I j s 9 E g c o U t u 1 U G N + + u w 1 I / M / C g 5 j K 4 B R H + S q o V G q / j 2 d d o H 0 7 d N h Z y 7 Y M s A K c d F j + V t z 6 d L B Y h d M C I C v E k U E q 6 g / W o 8 k / n T 8 L T y G t d d S U e s l W T 9 p
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-06-12T13:26:31Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5ee382ca-87f8-4144-86b7-fe8b950d210f" ,
"created_by_ref" : "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f" ,
"created" : "2020-06-12T13:27:38.000Z" ,
"modified" : "2020-06-12T13:27:38.000Z" ,
"pattern" : "[file:hashes.MD5 = 'fb9c610ba195f9b18a96b84c5e755df7' AND file:hashes.SHA1 = '5e4f2074850cce0eab4d6165807e86c88b5b8c0b' AND file:hashes.SHA256 = 'e17ca6c764352c0a74e1e6b80278bb4395588df4bed64833b1b127ea2ca5c5fd' AND file:name = 'LogDelete.bat' AND file:size = '63' AND (file:content_ref.payload_bin = 'UEsDBBQACQAIAHNrzFAT3/k6RQAAAD8AAAAgABwAZmI5YzYxMGJhMTk1ZjliMThhOTZiODRjNWU3NTVkZjdVVAkAA8qC417KguNedXgLAAEEIQAAAAQhAAAAkJAWEDFbPYZ2o3WgIF6QJ8CFWZ5A8i3V8Wgfc5l9GFagLS9/8geHrmjx5zmDQoFwbvW3G0sOFzHgyvkX4q2yNZ1w7R4OUEsHCBPf+TpFAAAAPwAAAFBLAwQKAAkAAABza8xQ/TRUNRkAAAANAAAALQAcAGZiOWM2MTBiYTE5NWY5YjE4YTk2Yjg0YzVlNzU1ZGY3LmZpbGVuYW1lLnR4dFVUCQADyoLjXsqC4151eAsAAQQhAAAABCEAAAALb0KLMLoBXwW8baPXrym/BpzCqab++U/FUEsHCP00VDUZAAAADQAAAFBLAQIeAxQACQAIAHNrzFAT3/k6RQAAAD8AAAAgABgAAAAAAAEAAACkgQAAAABmYjljNjEwYmExOTVmOWIxOGE5NmI4NGM1ZTc1NWRmN1VUBQADyoLjXnV4CwABBCEAAAAEIQAAAFBLAQIeAwoACQAAAHNrzFD9NFQ1GQAAAA0AAAAtABgAAAAAAAEAAACkga8AAABmYjljNjEwYmExOTVmOWIxOGE5NmI4NGM1ZTc1NWRmNy5maWxlbmFtZS50eHRVVAUAA8qC4151eAsAAQQhAAAABCEAAABQSwUGAAAAAAIAAgDZAAAAPwEAAAAA' AND file:content_ref.x_misp_filename = 'LogDelete.bat' AND file:content_ref.hashes.MD5 = 'fb9c610ba195f9b18a96b84c5e755df7' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected')]" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-06-12T13:27:38Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5ee38314-c71c-4493-ae54-40a6950d210f" ,
"created_by_ref" : "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f" ,
"created" : "2020-06-16T00:21:07.000Z" ,
"modified" : "2020-06-16T00:21:07.000Z" ,
"pattern" : " [ f i l e : h a s h e s . M D 5 = ' 597 d e 376 b 1 f 80 c 0 6 d 501415 d d 973 d c e c ' A N D f i l e : h a s h e s . S H A 1 = ' 629 c 9649 c e d 38 f d 815124221 b 80 c 9 d 9 c 59 a 85e74 ' A N D f i l e : h a s h e s . S H A 256 = ' f 47e3555461472 f 23 a b 4766e4 d 5 b 6 f 6 f d 260e335 a 6 a b c 31 b 860e569 a 720 a 5446 ' A N D f i l e : n a m e = ' N S . e x e ' A N D f i l e : s i z e = ' 128000 ' A N D f i l e : p a r e n t _ d i r e c t o r y _ r e f . p a t h = ' \ \ \ \ % U S E R P R O F I L E \ \ \ \ % \ \ \ \ D e s k t o p \ \ \ \ O c \ \ \ \ N S . e x e ' A N D ( f i l e : c o n t e n t _ r e f . p a y l o a d _ b i n = ' U E s D B B Q A C Q A I A J p r z F B 8 p e O K D Q Q B A A D 0 A Q A g A B w A N T k 3 Z G U z N z Z i M W Y 4 M G M w N m Q 1 M D E 0 M T V k Z D k 3 M 2 R j Z W N V V A k A A x S D 414 U g + N e d X g L A A E E I Q A A A A Q h A A A A D r 51 G E T U X 5 g G 9 y c 4 d x K a W g p R o r k A 0 + Y Q C y C F B l V T t U s 60 T y s W k q e V 8 q 8 b t e Y w U k 9 T D P l D o m c M e F W p B b U q c N 8 G l A l D J Q i B 84 p H F N M 5 o l c X F J B i J U o h t S P s X c n D G W b O u 2 / 4 f z M 8 k k 6 D o J 8 o L Z 1 q p 5 w n y i A T w 2 g k w 42 k Y b K f p Q U q u k 7 O b x 6 m S + u V 0 37 G R o 1 N g J + d H J l w Q 0 L V j T Q g F E r j e b g R i 7 V p 4 Z p / o + k 3 a k Y c A 15 F e v y k M M Z 2 k M W S + 2 m I y U l W 5 A x Q s e C 0 P O v Y S a G q 16 M x 7 s T J 1 v 4 M J b F b l p B i u f d D a D J C L c w H e Q U E a R y x F t l w G c A X A j B S Z 9 S y b w 0 b t 4 u e 6 E e X R Z L h 9 D u p n 4 m L g s I j u l N A L c X 6 i u 90 W h N L Y E e L 5 B f o W x b q 0 38 G v m G d i 8 y u u C b + e L K p u h 0 / A x 1 m 4 D 0 i f o p + V C I B s 71 g Z i D R Z o Y E a B Z + b D v H F 6 U e 7 a j 0 P K O 7 d A z g d A J n S 4 Q y J + I 4 K r L z 8 o 9 J f 3 f B j H X W y Y P n 9 f u V n U p g 8 Y W R s y J 0 a s f B f m q X m n J H 4 h t b h G u x 3 y s m 0 6 W S H e U X k e P D x t X p O o b j C P K A e P S y m 3 t h l v r B w t r k 5 f 7 K V m O T J 7 P q Z 1 p P d r h n + g 4 S t I l E m + 8 X 0 w z W 9 + H 1 o G W x 7 E N g m L g g v k z 1 e c d F x t M 9 z d F C 7 B a y v y H H y w G K / s m F o O 7 s w B 5 T 2 q F e J K V i G o n V u 8 d 76 j y u W F G u w N 20 l F n G t Q r d / 2 X p K e v d 8 O v / 2 j Q 5 H P j q 41 N T 4 A J m P r j d 0 I T g Q 77 E n F g a t O 346 Y K u v o S r W y w S W D e i w q m I N O 9 k M l I 9 D e V d 0 9 A W Q G K 49 A M M / 3 t s W H 3 X V v 2 F u + I j e M c p G D N 87 F 0 V v b p l G 2 I t K U L 517 f K 5 q q Q 6 R D f C 3 s P B 5 M 1 S 8 N 0 1 H H X e 8 b x / x 0 a 8 h g w 6 N R W M g Z 9 O x T Q S z b 9 E Z 3 x s T I N t g H 3 I N q W m b R p 5 + 8 m 8 j M Y 5 L / u I 9 w f X X K L k f d d 9 B k J 3 + M i Q y e / H Y I U C 5 U i V D 3 X 5 K x s b Z R L b l a N v n n 2 x 9 z b n w b I J z Q 1 O u 80 l H u 8 c z C J K j 14 G f 5 Z L 1 Q 2 f i + j j M V w e x f 0 M 0 i W + M Q e 5 n S D s i v x l B m 0 s g R R R Q / X 7 U U h Y t D 73 M g V f y j w 5 x F v y 4 v t G m c B 9 t f + x A i H a C y w 910 s c 6 y m C e + z w U M 6 G P C R r e F q 2 P h 352 z K W n 7 x A n 1 N s e P D o G 6 Y Z O G r e j t k e X l h m i F u u w B x + F A k N l F a L n 0 M k y y L S K 4 h L 7 L 6 G b 5 t Z u g i p B R X M o z 6 t l R I o Z V v A T M o g P x l Y H 1 o 6 i z a h R m n 0 h 8 f X c z 3 L f f i + n 8 q F w q O 6 Z J Y 0 32 g a o A r f Q Y Y z s t r K 2 m P 6 L 7 S T 15 j S D K T W + m X M J o S u 6 T + r N H O Y C 0 N E 3 I e r a I j P S i W u W J 8 p u s I A J l G m 8 P L K k w L D D n v w 7 B t 9 q Y c y X v S I 7346 G 4 P 43 e a x a A N 3 + t 1 P 1 l 5 s 9 Q 57 B S l I X G W f e e g W p 8 E Q n G d O b s t 2 e v r s 0 v 1 h X r Y 9 k K q c 3 D w T t s I E y k A K c d T W g h R L 9 d R g Y V w z d 32 Y F 5 K s T 1 c r C p 1 F S t I b h W 2 h K P y F V S a 0 O + F R p a q Y 3 V 6 j g a l j n o c 8 v X 9 w 5 Z z w f u 0 2 C 1 Z c 4 v M t h h g 0 K m U g Q f E a 0 z D 754 B D G O T m x v + I 7 g I A 33 P E R Y 8 N 7 C g I D n m V D 3 S i J R s n x U r X y z w I V H v 3 y u o t c + i L T 8 Z H M O c s O z z V 4 S f f 3 P 4 N w J Q R u 6 S N 5 g u D m m N T 4 O 8 X S D R G 3 s a S i D 2 j O r z 7 I 4 W p 2 / L 1 H c f h P 26 a E p A U V 6 A h t b Q R m i w F r i t 6 V O L i p 3 O Y A c w O h r i Z J c f 2 / W H K b x g Q Z 4 + h / 15 x v J a 94 I y N S u 9 z s d 5 r V L O O u R 3 i j r J C S N 47 h p a k O g r P m s X a T H n t + a / 4 Q E n 5 R 1 k H W w I k X K g z / n E A E q p Q 8 l g g V 8 a d M i F O + 721 F O x q d R j W I V 4 W 2 w C 56 x s 9 A S 9 y f u 5 d c n J i l N D N l D z N Y k m / M R K R Y J J 3 q 22 R 0 f G M B I B a 62 K 4 v m Y p o G d r s 2 z E U g B 8 K f l x x l m 6 Z 4 j x Q I p 5 m M T 8 n r Y Z / a B c s V 8 R I Q H S N p o g O N S K B C q y Q o F H + v 51 l 8 o d T B m C r O H r i Y k u / x w c t Z + S e 6 n p K 4 k C k B s 7 J 8 A h j O p h u 6 X W P l c z M Z T b Q m k W i p S P m H I R r C J f T e A v j z D d o 4 X a k w m O s u u f 963 i 8 x w q O 8 I S n A t L U J j c l X d S / r z 9 P Z H v 1 H 9 y L r 3 K F g k T P I G V Z 4 C 5 x h 30 G h n e g B K R x Z j u / m l O 1 w L c q G K r s Y b f g L t 51 g t j g f h b 9 d D 6 r q 7 h G 39 T o I D n A a Y E M l 6 e w Y L G r i W R o U W J e L Q E U 5 A / Y V X l L 8 w 4 k b 0 n i e j K 8 X 67 b Z i / B F Y K v w F C f D q N 9 Z A Y V A P O 4 x 9 r p i 7 X M E 0 o N 0 9 V L T E f d o u / h v o b u T O d s q f s Q d N G 7 e H T / y A t T 1 v M y Q Z F A K F l T S M Y 4 g Y t D j v C I y z p 4 O F 4 n t e d f S y c C Q 722 f 1 a + 1 P + W K a a R + 726 b R 0 5 F B + E L h n b T v G 3 r r 37 r j t 9 o b + g R X 2 s n a 4 u 7 a s z X D q P p S W l l x t s y d g c y v J z 3 g x 4 B y H V K x 77 G E J F C A D l S 6 V i P H I 8 J / e m / n n Z Y 1 n N W 0 Y E W Y z 6 k Z t I l 2 L G J q h Y H W / j S D V R J w 53 N 5 b D + U t h A C j m n N L 3 A e 15 I N 6 y 2 / w 0 T M s g u j 7 V E n g Z L C O + T l Z 4 i 14 R B N I s 6 f q 7 c Q c d o w M 1 T G s H 5 O p n b c S K 5 p F G c p u v 3 e R 9 N n n H m R W X p d L h z m Z S l d w c J u F V 9 / u y v u T U S s 0 r u O L 2 W T S y h P A d r i R y A D S 7 a 73 m W 2 D I G k y D l 3 X d I J U X k 4 B H V Z s k f 7 c t 4 T t o R 3 d Y 7 c W 3 F q 3372 q y r 2 A u S g 0 b 3 u p G 5 q k c B y / 23 x H e x e e X r 57 m w B C 37 c d 8 R / w d D Y K e V s / 1 + K 28 g 2 E W / L z S H M g J 5 U 9 e x V G C M E 8 W n k 4 h o Z N k k 8 F G 6 d k Q p 4 c B G J X v J 92 Q y Y 6 I 4 u t V B e G m g D 1 G p 0 9 q s s w Q I O r O y X b G y n a H 2 V n L X 0 Q w h X O Z E g m 1 W 6 G C C P Q i Z C U B U T + K 194 b t e 2 R k I w A T / 5 B i W j 6 J P F E i a m m v L J K D Y G y 659 k x n I y v U g 5 r / x i m O R 4 j p o 3 q L w u C y A l c 9 H o j F 8 R E f u L q J b b V C W p A J q 1 x 3 g v R b D U U g U 7 n Y Z K E E m G Q O Z r T F O z G 51 I v g e 0 t k K C v b n v a O D w s 98 U e n R 5 o t 1 D s V U 4 a j s s 7 e / 6 X f H x d h x N X r s u B P Y S 4 C d 1 X W c 7 P r 0 K + e j M n 7 y Z E O K D 4 G t z C r D O q r O L q V F h L L Q g 0 7 W 0 d P X o a R s K T J m 8 J o I z D V o k q E A X b C o 0 5 e z D 7 w y 5 Y M 1 + N 7 b t N + z W 4 f E z / w V 539 e I U L J R L j / 7 L J R R f e r 8 w M F 8 A j a I i I 3 L K 1 f W 8 n a 2 t c g s 63 H B 79 d S 5 x D T p B E h 8e9 L s m a 5 x t b t 6 B P x T M H G U d M g I 9 H n x Y V V 9 e I 4 i b x j D h q h 1 m K n e T o y + H T 6 I W B H E t T a L c d V W q K E 1 D r H R l Y J y K K w d 8 j f X 9 n U A g o N J V 2 s h v S J i D + C 3 U + Q d D 2 i F s e b 7 O l 9 R m X 4 X 1 L z c A V V B 2 m s 2 q I U e P 7 + k B r j e 6 D T E Y W j q p o S k H J Q 1 s j 7 + 4 n y o 0 Z B j Z P c b X 61 Z t w 9 T 6 A r V G r w b I 7 Y M m S u U Z 9 f H D E G x 6 A f x C W n r 8 K 3 / L + g b f M p X r Z g r S 1 Q q H W d g + W Y h i b k 8 J Z F 9 A d 5 z w m g P 5 H m E q i S a X G P V / Y w 3 W X + / 12 f b O F C t X t J I a Q z s c s b N M X y U r a O l v L D c / t T V 4 c E N m D u f d 2 s X g w u W u y s + i d 9 Q Q S A o X v W o 6 P d U K 7 Y w B 6 D w X Z B 3 J n d +
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-06-16T00:21:07Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "indicator" ,
"spec_version" : "2.1" ,
"id" : "indicator--5ee38343-f910-44d1-b837-fe5d950d210f" ,
"created_by_ref" : "identity--5e9e5d86-5b94-4ff6-b07e-4e3e950d210f" ,
"created" : "2020-06-12T13:29:39.000Z" ,
"modified" : "2020-06-12T13:29:39.000Z" ,
"pattern" : "[file:hashes.MD5 = 'df8394082a4e5b362bdcb17390f6676d' AND file:hashes.SHA1 = '5750248ff490ceec03d17ee9811ac70176f46614' AND file:hashes.SHA256 = 'da3f155cfb98ce0add29a31162d23da7596da44ba2391389517fe1a2790da878' AND file:name = 'Shadow.bat' AND file:size = '28' AND (file:content_ref.payload_bin = 'UEsDBAoACQAAALRrzFCwl2wlKAAAABwAAAAgABwAZGY4Mzk0MDgyYTRlNWIzNjJiZGNiMTczOTBmNjY3NmRVVAkAA0OD415Dg+NedXgLAAEEIQAAAAQhAAAAxkuUBupOxYH1WPeLxc8qnjJZJAGL5FaJbdlEpu7iMW3IJ30qHl9suVBLBwiwl2wlKAAAABwAAABQSwMECgAJAAAAtGvMUIIXyqcWAAAACgAAAC0AHABkZjgzOTQwODJhNGU1YjM2MmJkY2IxNzM5MGY2Njc2ZC5maWxlbmFtZS50eHRVVAkAA0OD415Dg+NedXgLAAEEIQAAAAQhAAAA5snHYoa6G1Xvvc31fr846Fr/w0SoO1BLBwiCF8qnFgAAAAoAAABQSwECHgMKAAkAAAC0a8xQsJdsJSgAAAAcAAAAIAAYAAAAAAABAAAApIEAAAAAZGY4Mzk0MDgyYTRlNWIzNjJiZGNiMTczOTBmNjY3NmRVVAUAA0OD4151eAsAAQQhAAAABCEAAABQSwECHgMKAAkAAAC0a8xQghfKpxYAAAAKAAAALQAYAAAAAAABAAAApIGSAAAAZGY4Mzk0MDgyYTRlNWIzNjJiZGNiMTczOTBmNjY3NmQuZmlsZW5hbWUudHh0VVQFAANDg+NedXgLAAEEIQAAAAQhAAAAUEsFBgAAAAACAAIA2QAAAB8BAAAAAA==' AND file:content_ref.x_misp_filename = 'Shadow.bat' AND file:content_ref.hashes.MD5 = 'df8394082a4e5b362bdcb17390f6676d' AND file:content_ref.mime_type = 'application/zip' AND file:content_ref.encryption_algorithm = 'mime-type-indicated' AND file:content_ref.decryption_key = 'infected')]" ,
"pattern_type" : "stix" ,
"pattern_version" : "2.1" ,
"valid_from" : "2020-06-12T13:29:39Z" ,
"kill_chain_phases" : [
{
"kill_chain_name" : "misp-category" ,
"phase_name" : "file"
}
] ,
"labels" : [
"misp:name=\"file\"" ,
"misp:meta-category=\"file\"" ,
"misp:to_ids=\"True\""
]
} ,
{
"type" : "marking-definition" ,
"spec_version" : "2.1" ,
"id" : "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ,
"created" : "2017-01-20T00:00:00.000Z" ,
"definition_type" : "tlp" ,
"name" : "TLP:WHITE" ,
"definition" : {
"tlp" : "white"
}
}
]
}