{ "Event": { "analysis": "2", "date": "2015-07-21", "extends_uuid": "", "info": "OSINT Milano Hacking Team malware detection tool & IOCs by Rook Security", "publish_timestamp": "1438347766", "published": true, "threat_level_id": "2", "timestamp": "1438335004", "uuid": "55bb38dc-bda8-4839-8b37-4fe1950d210b", "Orgc": { "name": "CthulhuSPRL.be", "uuid": "55f6ea5f-fd34-43b8-ac1d-40cb950d210f" }, "Tag": [ { "colour": "#ffffff", "local": false, "name": "tlp:white", "relationship_type": "" }, { "colour": "#004646", "local": false, "name": "type:OSINT", "relationship_type": "" } ], "Attribute": [ { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1438333209", "to_ids": false, "type": "link", "uuid": "55bb3919-f5f4-4112-90fb-419d950d210b", "value": "https://www.rooksecurity.com/resources/downloads/" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1438333209", "to_ids": false, "type": "link", "uuid": "55bb3919-5e3c-4275-9953-4568950d210b", "value": "https://www.rooksecurity.com/wp-content/uploads/2015/07/Package_1.zip" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1438333209", "to_ids": false, "type": "link", "uuid": "55bb3919-4efc-49de-8e60-47b4950d210b", "value": "https://www.rooksecurity.com/wp-content/uploads/2016/07/ht_malicious_windows_files.ioc_.zip" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1438333210", "to_ids": false, "type": "link", "uuid": "55bb391a-bdd4-409f-9b67-4282950d210b", "value": "https://www.rooksecurity.com/wp-content/uploads/2015/07/RookMilanoInstaller.zip" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1438333210", "to_ids": false, "type": "link", "uuid": "55bb391a-9298-4e04-8168-488e950d210b", "value": "https://www.rooksecurity.com/wp-content/uploads/2015/07/Package_1.0.1.zip" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1438333223", "to_ids": false, "type": "text", "uuid": "55bb3927-0c70-41bd-8fdc-4274950d210b", "value": "Hacking Team" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1438333380", "to_ids": false, "type": "link", "uuid": "55bb39c4-47b0-4b79-a585-4307950d210b", "value": "https://www.rooksecurity.com/wp-content/uploads/2015/07/HT_Malware_Observations.pdf" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1438333380", "to_ids": false, "type": "link", "uuid": "55bb39c4-6838-418d-8dc2-4899950d210b", "value": "https://www.rooksecurity.com/wp-content/uploads/2015/07/All_HT_Files_Analysis_Notes.xlsx" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1438334481", "to_ids": true, "type": "snort", "uuid": "55bb3e11-bf10-4140-bdf3-41ff950d210b", "value": "alert tcp $EXTERNAL_NET any >\r\n$HOME_NET any (msg:\"CVE20155122:\r\nAdobe Flash Exploit (Memory Corruption)\"\u00cd\u00be\r\nflow:from_server,established\u00cd\u00be content:\"|43 57 53|\"\u00cd\u00be content:\"|c9 66\r\n3d 21 24 49 68 69 69 39 12 61 04 4a 49 4e|\"\u00cd\u00be offset:127\u00cd\u00be sid:9931892\u00cd\u00be\r\nrev:2\u00cd\u00be)" }, { "category": "External analysis", "comment": "OpenIOC", "data": "<?xml version="1.0" encoding="us-ascii"?>
<ioc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns="http://schemas.mandiant.com/2010/ioc" id="7a365842-982f-43b6-993f-2c7db5e487bc" last-modified="2015-07-21T11:20:20">
  <short_description>Hacking Team Malicious Indicators</short_description>
  <description>Contains executable and library files hashes. These files have been analyzed by Rook Security, and have been deemed to have the highest likelihood of malicious use. These files have been analyzed using dynamic, static and manual analysis. We also compared these files against VirusTotal and Kaspersky whitelisting. Hosts containing any of the files found in this list should be considered compromised.</description>
  <keywords/>
  <authored_by>Rook Security</authored_by>
  <authored_date>2015-07-21T11:20:20</authored_date>  
  <links/>
  <definition>
    <Indicator operator="OR" id="7da0cb5c-2d73-44a3-a65d-5392def0f1de">    
    <Indicator operator="OR" id="7ec32a05-53be-4f49-869a-da758f273e13">
        <IndicatorItem id="03fd6096-12ab-4538-be08-72ee4fc3ca91" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Filename</Content>
        </IndicatorItem>
        <IndicatorItem id="fe4650e2-1dd3-4f12-ad11-0bea047dc483" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">MD5</Content>
        </IndicatorItem>
        <IndicatorItem id="3d0d348f-74d1-4bed-8f75-e53fb2a973f8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">Hash (SHA256)</Content>
        </IndicatorItem>
        <IndicatorItem id="d4744169-dc70-4c44-a57b-2d22bc1ec485" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">SHA 1</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="9e1ff222-fbaf-4bf5-a27e-d7bd6c0b7d3c">
        <IndicatorItem id="3de6e5a5-0d7d-4d58-85e6-7e21b929b280" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_final.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="cf64b4b5-9fa4-444e-b80a-5448fe9ffc98" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2a2578d7f22d3b2ee52c5d46bb5fdf05</Content>
        </IndicatorItem>
        <IndicatorItem id="1d377db1-01e8-4ec0-a58f-375e334e50db" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">4d9ced2ee7d979055d33564cfa5a67773e34f3e51d615f162003311c76f51bdb</Content>
        </IndicatorItem>
        <IndicatorItem id="4fbbc046-bc6f-43fa-a895-a7d488b53bad" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0097a9fba6b0bcb09e9473816e51c2c8e48284ff</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="7dab28bf-5dfc-4b72-b139-a5ddfaa121a7">
        <IndicatorItem id="ea24f72a-2e92-4582-8702-31aaef63ec33" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">cygiconv-2.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="4f89bafd-3ffd-490f-a7e4-9de960721121" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">07386293b3ab69dc09ff7382b75c6f4f</Content>
        </IndicatorItem>
        <IndicatorItem id="f323fdce-8af5-453f-981a-2ee1964f1f9c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3476d4368a0e82f27eed752c2ce45dab9ceaf33c7655dd640239d4b54c0137d7</Content>
        </IndicatorItem>
        <IndicatorItem id="83f001c4-9707-40c9-b4eb-969b30f68cc4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0170d2b3ce35883358692c364b7b89e712356aa2</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="5e967c75-d482-40ef-92c5-118131ff1a3e">
        <IndicatorItem id="f90cf7c0-ce67-4878-8d8b-31cb23369f95" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">QDriverLoader.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="7eda9d57-0181-4697-a8f2-01e76f6a69e9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">10bbd73264eb8c5c126eddf1c224d2ad</Content>
        </IndicatorItem>
        <IndicatorItem id="4061788f-fd5c-4a3a-8757-a30b6ece0330" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">622a646311cc4ceec5d9b904fd4e4b5cc27a77b76fbbe2daf00976477241b0e7</Content>
        </IndicatorItem>
        <IndicatorItem id="09f6789f-4fd2-4c2e-bd76-e298bc92b4ec" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">01c31ede6f2563fc62dca1680e95410de4678d04</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="c6c2aba6-14f4-4d7f-9f62-15a82d7dff2b">
        <IndicatorItem id="8ec560d1-a309-4ae4-833b-95ade0b70d0f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">CHIUSURA.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="a5823fe4-c590-4f20-9e7f-e723c4137ef4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2b42ddd3f6e5db4b2112e68750347dc2</Content>
        </IndicatorItem>
        <IndicatorItem id="277bac93-60ee-4302-9de2-2984b7cd3793" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">65a37da4fd57747c8e73df8f88a7de27b1f3bfc6f0467e45f9241194c4f70954</Content>
        </IndicatorItem>
        <IndicatorItem id="73ebdfe3-d9b1-408d-a668-7efb575fa4f2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">025ca66d2224ca5bdc913503d29878c4846573ae</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="3e2faf88-09a9-4d3b-8ad6-e14382842465">
        <IndicatorItem id="f5efe8b3-673d-4fd3-b4b2-05af247dec87" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">POSTCAUS.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="78ca5de9-d259-4a2c-8d87-af84859e0c39" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2e400c19dd2aa724ce57d723b5cd0e51</Content>
        </IndicatorItem>
        <IndicatorItem id="99be3a1a-6802-4155-8a4a-06a210d40bac" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">8861391b767cb9fa74c442a11edf407acf614b404a5971c6292655fc448a5679</Content>
        </IndicatorItem>
        <IndicatorItem id="2f89d995-7988-44ce-a88b-d55630121b03" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">03c0fe990662abcf32bd2d3d494070366132c367</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="29bbf69b-ccda-466c-93d8-5718492f11e0">
        <IndicatorItem id="62c7eeb0-8d96-4b23-b322-8bf35ea875e9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Mpk.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="fd28be45-f042-44bf-aa5b-4a0a350e25ef" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f713c1e740d67292db2d96c7755a63bc</Content>
        </IndicatorItem>
        <IndicatorItem id="3bd4742b-bd19-48ff-a18a-0bc350675c07" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">9f3673b51a622dbe8ea5f92ad37ff12ed0a03ff5c30a9ca20575dca08c624fa3</Content>
        </IndicatorItem>
        <IndicatorItem id="ae8e2f8c-57cf-4ed7-a03e-35395c76de6b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0540e5eacd37ea3285f8a239dd72e3e7e4faf33e</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a61594cd-5a25-45bc-86ce-fd9ef51b3021">
        <IndicatorItem id="47b421e4-cb7b-4e67-aab1-2d1d21c403ed" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">cygusb-1.0.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="51aade10-9ade-4b1a-adf3-4f79d9158e9e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">3febb273f42e81c95c6611981b696822</Content>
        </IndicatorItem>
        <IndicatorItem id="53b11cc2-8706-4365-829c-44b53f83eb8d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">1e4f59d5541dbcaa4cfeda6943294dc40f425ae3f24764cd3c7d643ff2a7bfb0</Content>
        </IndicatorItem>
        <IndicatorItem id="f357d103-57d7-4d85-b190-73fdee4319ff" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0607db646e4e2f5cd3caa1f833515af1783a6c8f</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2f72ca63-d08b-4b6a-aab3-758a71203b29">
        <IndicatorItem id="4acf2fba-1d08-4dc8-b242-8912a6c84cb5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">bcmhooks.resources.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="f37ae8e6-5220-4128-8359-dafc2cb7ab27" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">8e1a49e6c6f2a6f707b7181f2546eb41</Content>
        </IndicatorItem>
        <IndicatorItem id="35df7a54-d442-4e7a-953e-b847bd2e2bec" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3e0d7773c6261d5f54924febec163163e9e434fe1b6cb59daff06dff190987c4</Content>
        </IndicatorItem>
        <IndicatorItem id="62feedbc-a98b-47f5-af64-0d16070fd358" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0724c43637816b3d39a79bbbe4afe8005c93bbd8</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="4c68a197-6de7-474d-95d3-f7b54a3e8945">
        <IndicatorItem id="708e5acc-1c38-4dba-8d9f-17e1dd259439" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Microsoft Office PowerPoint 2007.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="804ebb6c-8ec5-49e3-8d42-f9ed24696406" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">dfd6d9d5d7074e3d822ee7002a2538b6</Content>
        </IndicatorItem>
        <IndicatorItem id="e730b55a-5de3-4ac9-a87c-d641ee383cbe" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">d70699e40511f4dd459420751e66a2564f050ab17b101ca9955423de2c579fa6</Content>
        </IndicatorItem>
        <IndicatorItem id="a7f206d7-dc86-43ad-8f78-1183bc91fe58" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">076b09d71c5c55e7ae6f044791142470799648bc</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="4cab4d7f-8bf0-4942-aca1-9b48abea879a">
        <IndicatorItem id="472000a7-1ad3-401c-a4b8-ca76a400afec" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_winlogon.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="95061f9a-1d4d-4f2e-b014-80cba9fd4cff" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">5c1215ec7da96f58a1e3e66b60c1d4ed</Content>
        </IndicatorItem>
        <IndicatorItem id="acac6b72-f36d-4395-80e6-e35d91d9f9c4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">2ef643a29808aa6dedeb69165d8682d5a58a95aa68bce856783a2b8dc2d71087</Content>
        </IndicatorItem>
        <IndicatorItem id="5df2ccf7-1b03-4850-96e0-ce1d2ff75a48" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0837b3eed579123555ae09244b3f23aded72b9b4</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="30c6b837-bab4-464d-a4a2-3edfbfcd399a">
        <IndicatorItem id="1b2f7ade-db70-4c8d-8544-b27dd7579ac9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">seg_encrypt.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="73b8d95d-3691-44ca-abd0-7b6f27514b55" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">4b5d19d8a0bc70b2165144cb9be227e7</Content>
        </IndicatorItem>
        <IndicatorItem id="47befe16-0fa8-49e8-a2c6-194b534b9025" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">8306c3a000636a21275774fcc17cd0bf75d1959bd9ea6bdb272666fda8494649</Content>
        </IndicatorItem>
        <IndicatorItem id="dd4e24a7-1ad5-4cbd-a8d5-7e5a0777aa90" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">09920b2f0d20df022da507ab7b334392f7380cb4</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="84a2ad12-41a1-4784-aa50-55bddedb4b60">
        <IndicatorItem id="d3eb7457-d7b8-4d60-a961-3b1c7057ce84" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">peutil.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="bbe37a85-4db5-4150-b31d-125d6a84efcb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">365bf9ae89eebc67a34e09ad07ebf166</Content>
        </IndicatorItem>
        <IndicatorItem id="563348d0-0708-4ea9-b763-847098fee1bb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">314211107852b35dbf7d2abc54581aadfce1ddf79e1930bb44e37ea4af338541</Content>
        </IndicatorItem>
        <IndicatorItem id="0e96e30c-d059-4a99-b9cf-31f1bf78b1a6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">09a77488453f586ac03782a539225487c44c3a30</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f76da59a-e45d-4c4c-98d3-533c9723fcc1">
        <IndicatorItem id="6f01cbcc-d4f9-43ab-a56a-f11807bee48b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Microsoft Office Excel 2007.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="cd0e4509-d5f4-4808-b913-51c080bb6a12" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">710cdda3bc6ff73c2399d0a718c9fbe8</Content>
        </IndicatorItem>
        <IndicatorItem id="fd38f292-2166-4322-8510-c50e15c1e047" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">8caa3a2f4c39992952cd2bb38bebadbbee5fb68114500e37832221d4e59aea30</Content>
        </IndicatorItem>
        <IndicatorItem id="31fad87a-4a49-4ee3-90a1-2a743bbfb718" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">09b49ee08641e1d18532a67acc09d98a1b708545</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="c22f23e5-55e8-4f0c-9c39-ef4e4f8ed470">
        <IndicatorItem id="8ef9db5a-8157-4116-8e61-162a2b6e159c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">BackupPlayer.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="7e08db63-1016-45db-af89-97bc72da0c7e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">ee49e261fe226f36a1cec2b0ae582437</Content>
        </IndicatorItem>
        <IndicatorItem id="5dbf642e-df75-4816-a3fc-6829c527b0d4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">5993a690c5131cc9269b72a5a6d8f0f6d5c4ed5a4f51418c0018a72105fe361e</Content>
        </IndicatorItem>
        <IndicatorItem id="1a079ad8-3b6a-4566-afe9-5ee9b7a579b7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0a2be6fe113db2b1d05cb9f45cd90cf04f53f126</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="38daee54-7dd1-473a-9abc-9ab1e4e520a3">
        <IndicatorItem id="5ff88bb0-3309-4c03-b7da-362dcd01c4af" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">OIS.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="0db109a7-293f-459d-a5ef-d00d2a01314e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">94bac050560b074bf7f48dcc282ab7ff</Content>
        </IndicatorItem>
        <IndicatorItem id="786c5766-5cee-4eb3-99e4-596e298492c2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">b0d3aad477487039fbe9a33a66bd3654fb17f8af731c965d78977ebeb20392a8</Content>
        </IndicatorItem>
        <IndicatorItem id="86cd92ca-d8ed-42cc-aac0-53fc0e3a87b7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0ac7f04dd08120e93ea449b49eb8e557a5a2ef22</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a9a4a597-332a-41f2-a3e7-7d9d244436e7">
        <IndicatorItem id="7b44ee9c-6d77-481b-a3fe-f30c53f568ee" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Themida.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="64ee491b-c518-4483-a403-6681fa4d302c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">37b5ee810eee08eb46da2d4d1710262f</Content>
        </IndicatorItem>
        <IndicatorItem id="027df668-27a2-490f-b40b-62e10afcbc0d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">f3fc6d8ed53b5be3be601281848d26134fa85ba4737ab69b13a50a3a8dd523cb</Content>
        </IndicatorItem>
        <IndicatorItem id="179259b2-ee11-4640-9536-5211fc0f39b9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0ad4455380b6c2224bf6d0d5112653db2e05ab28</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2c7091fa-7a60-4e69-8616-74c20df793e5">
        <IndicatorItem id="31b7bf62-d64f-4a70-9e56-bae3c565e788" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">besx_upgrader_5.0.4_mr8.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="fa837395-d2bd-43a7-9c5b-0c2e88f16157" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">4e90a964036aa157b6ecf47b3e4a7363</Content>
        </IndicatorItem>
        <IndicatorItem id="87f99bbd-5022-46bc-a61c-be38f750837d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">29720f3bd8b01e49a2266c89281a2cba78d5e417d11859ed113acfd2ce627f27</Content>
        </IndicatorItem>
        <IndicatorItem id="14a6fde9-0064-4186-8a0d-2a61b3cd57c8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0c51c76c4508ed0a4e8ecd397e850701c5f4d82e</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="6790e537-8eb0-4663-99e8-f8e7aaa7ccd8">
        <IndicatorItem id="1f8911be-2eb7-4008-8768-ec027bd5a2f7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ldid-cygwin.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="34c82991-614f-4c07-940b-93423f6afa9a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f244e28e40f924b0d719e8d611dee760</Content>
        </IndicatorItem>
        <IndicatorItem id="ed936977-308e-408a-8cac-4ef7bcedfadb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">afcab14b17a685f51809883bf501e8429152414b8f93a041eefa01e4d2d015ef</Content>
        </IndicatorItem>
        <IndicatorItem id="80d4eb55-955c-4743-9c80-9aef4a737056" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0d29d6b51761711968d2a0a21d9e62b2b5edc143</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="1d9147ed-3e78-45e7-ba25-349589361995">
        <IndicatorItem id="365b7f83-ca33-4471-830c-b471db486a59" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ConnCheck.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="972e5d6a-4c76-40e5-beb6-ea14e648e42b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">4129265bceaca9a9c804a586c5446c15</Content>
        </IndicatorItem>
        <IndicatorItem id="4547e918-b6df-4480-9025-a6ed3e6adcc1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">25e4376ebb9d3aa7f35aacf9298416e125d02bc6c180a78e749d46c1669ae886</Content>
        </IndicatorItem>
        <IndicatorItem id="1a083bcb-5292-4ad9-93bf-8fa031ed82d3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0e3c510285ab43a397da8fb611c75ede08cbb353</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f6771325-5f6f-48a8-82c5-9124d6f0a58d">
        <IndicatorItem id="35b16d7d-aa26-4455-b7c1-d0781449ca56" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_doc.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="e3b21831-27da-4049-9da6-5d24e3042819" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">0be0c072cf2a885d77886705e24e08d8</Content>
        </IndicatorItem>
        <IndicatorItem id="8340ef87-1f8d-4093-b85e-025fa10fe959" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">b924993e72cc8fd0b505e95cea5e8b09d17d2a15c9d9ebc2b0c32843edcd40ee</Content>
        </IndicatorItem>
        <IndicatorItem id="b9243ed3-40f3-4a1b-b6df-f2020551e8e9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0e6ebd6d90cc59eb572762afaca548dcc63397d8</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a6782ab9-2431-4f69-a7be-78439acf8a39">
        <IndicatorItem id="efd1477f-8fae-41b4-8aab-61a6b4c00acb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">UFED_Physical_Analyzer.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="9b820942-7a32-41e9-854a-f770b337aa59" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">4e0f4146a22ee299cb3722f24f13af93</Content>
        </IndicatorItem>
        <IndicatorItem id="6fdf6c0b-4f3b-478f-ac5d-893c5aa2f409" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">477f1f7dfd4ec43da8b3ebfd162812208ea085edf3259ba1e8b0b551825004b6</Content>
        </IndicatorItem>
        <IndicatorItem id="18fc8b44-51c2-4ec7-8193-4d4f3f008542" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0ed9a779864333b37ed3ed697b185ab39ee9f544</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f4978a33-7a2d-45e4-8848-1cd881375344">
        <IndicatorItem id="603dc789-ee6b-4fbc-9b70-3723337ae57d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">cyglzma-5.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="8e78d731-11cd-41cc-9d26-b067f5835786" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">88f9a2235d3162aa2ce322320025e207</Content>
        </IndicatorItem>
        <IndicatorItem id="cbd850e0-d3ee-46ec-90fe-664a4f2b878d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">6b48e56098976fc5b5eaaf5f43f5c9a39295095e352cbd784b00b55eafa5d355</Content>
        </IndicatorItem>
        <IndicatorItem id="292bc712-0d95-4dc9-864e-331ff7c9dafe" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">0fc9171b5404816c5753080b78f2af31ba023611</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ac5010e9-e8c1-4881-bac8-a679ccdb6261">
        <IndicatorItem id="58feff7f-9823-4c2d-bf9f-4cf6e28d7f69" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">EMUDOPEN.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="e9f85a86-df9e-4721-98e0-cff4622f78d6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">0a83534af3f8d44217b5e8847e36fef8</Content>
        </IndicatorItem>
        <IndicatorItem id="aff03452-4044-46c6-9ec0-6bd929bac29e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">7dcf83c5af0991d927c8caa9bc1424e541c966de37aab8845e4e11dddfeabbeb</Content>
        </IndicatorItem>
        <IndicatorItem id="9cd88c7a-6209-4a3b-99ac-6ec7fdc3b7a8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">10b65bab3b5215955b076ea1a54d89afb8bc6431</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ef455858-2d80-4abb-9750-8799352a6db2">
        <IndicatorItem id="fcd259c9-925b-41fc-8b2c-4dd74277dd8d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">vector-default.exe.dan</Content>
        </IndicatorItem>
        <IndicatorItem id="29ac23d2-eee9-46e1-b8bd-b0e48144bcec" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">158105fd8f227ab0a2e3440724520275</Content>
        </IndicatorItem>
        <IndicatorItem id="c9b39760-748c-4a7d-a61d-57352b7b0ae2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">d64a0092cf3b55f68c671d462be80241d3a45b75667bb29f624f52aea7f1246f</Content>
        </IndicatorItem>
        <IndicatorItem id="138d4e73-a86b-40cc-a0d2-c42dc34c3f6e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">11662f991e15213c282357723bcc49059f6c55f2</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="948efbd6-0d14-4fec-8c53-ba4cb705f2b6">
        <IndicatorItem id="337d3393-3972-431b-999f-94f268f3910a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">core-scout-win32.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="5ca6c134-549c-4af7-89b1-c78fdce60599" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">84964d5410d6c7754e36e7592334df5e</Content>
        </IndicatorItem>
        <IndicatorItem id="38d47efa-0e22-4f2d-aef1-ccdc619e77d5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">da07eca4cd4cccc81d9418fcc796d28bc95756c8d6d4ad9503effd12b6c0aef7</Content>
        </IndicatorItem>
        <IndicatorItem id="db127a92-a48a-4553-aa68-18adba1b7282" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">11c87f734bce1fec82087fd16e568472e960fe17</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="17f8f305-130d-4379-9d3f-be09bf0b40ed">
        <IndicatorItem id="68448d31-1910-419e-907e-6fcf09fb8d9d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">codec.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="f03cbf6c-8c93-4dd8-b30b-9b023c213073" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">48d638a3194f8740d9f05faf62670ff9</Content>
        </IndicatorItem>
        <IndicatorItem id="914b45a1-673c-4aa2-9a24-c7ade8284ed3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">fb3b9464e866b35b3d7a3b506f967b32e1c2015e0703780c89993ce6d50a0ea6</Content>
        </IndicatorItem>
        <IndicatorItem id="dffbdc1d-0c44-4111-ac3f-6c95430334c4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">1351e784ebdffacf0fd143c07581136e94ca2319</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="fddf8713-df1f-47dd-99c1-5088b74d440d">
        <IndicatorItem id="0a48c8a5-4caa-4c26-95c8-409b2ddf9c3e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">CALCOLA.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="cbfe8ae8-5b3e-441d-aba0-f4870dd86f75" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">42cd6d2dcff23995d4008625fb702b20</Content>
        </IndicatorItem>
        <IndicatorItem id="ba7ffd47-77c5-4473-8e24-992fda128442" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">51816c81180eadfcdba84be0285d256ad650dd6eec131f94e1c1957623d7e9bc</Content>
        </IndicatorItem>
        <IndicatorItem id="9679925c-eaf7-4d1b-93cf-639cd2235866" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">1372e653874a767f800e77f682604d65396f314c</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="1ac32076-ede7-438b-ad72-52f1fc19ef2a">
        <IndicatorItem id="8078dfc3-b29e-4fe0-aedf-c7c79d670a6c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Carte.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="3f9681d4-abe4-4d51-9003-d0d6badd4952" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e679c556ee24d30acdff97a24e5b5a10</Content>
        </IndicatorItem>
        <IndicatorItem id="26891248-bb74-4e8d-8665-091e4bd9685b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">6ee1da63a3d5a55c66df408c2c0b57fc5bae064778cdf1845bc00e44021c290a</Content>
        </IndicatorItem>
        <IndicatorItem id="8d94c0bf-897c-41eb-b2c2-e5d6091acf10" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">138e1f98351a111a489ca5e8d7761ef125cfdac9</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="9d411ea6-e775-483e-9210-3941b1175376">
        <IndicatorItem id="e49ade9f-7ad6-4cc8-9a88-cad0b29df217" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcsmobile-2012013101.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="d384ce93-ae26-428b-8d65-0e02e98da7dd" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">0df77ac381a54c34bf3f12d13f516be1</Content>
        </IndicatorItem>
        <IndicatorItem id="92d0bcad-8048-4b9d-915b-e03ca70435e4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">5e75e0babe92f1a7691a43641fadb7be84d4d273b8bcc6cce5dfeb5523a6b709</Content>
        </IndicatorItem>
        <IndicatorItem id="45d87268-1ef4-4940-8ce4-f1bbcb85cd0e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">13b20e7945eb7342540b5fab2eb2f03063518239</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="0f6dce4a-213a-44da-933e-60801f2d2530">
        <IndicatorItem id="a29e37fb-97a9-4668-9be2-b4746e2d584e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Core32Dumper.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="6f05f1fc-f7a4-4a58-bfd9-3f2eef66bf00" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">38bd6cd2b91810c30ceb661e54032f5c</Content>
        </IndicatorItem>
        <IndicatorItem id="f096956e-08a3-4be2-937c-75d48dd6bff5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">92af7c751d9353ceb1b449bb6ea1a29c7a68a5bd2344759ad1c974ac5c63dee6</Content>
        </IndicatorItem>
        <IndicatorItem id="cb707d40-64eb-422f-b63f-ae64015c43ef" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">158be9f90b5f37590808e0c97323b6476d4c9f9b</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="cf9c9d4d-7095-4df9-9c88-fa668f8bdf31">
        <IndicatorItem id="eb30a61c-76be-41b8-9e36-b162eb693537" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">dsa.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="6ef50b33-6d54-4e93-b112-c570d3b45da5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2d0cdf0e4ae6976dde895d66aadf7c1e</Content>
        </IndicatorItem>
        <IndicatorItem id="54fee32a-671d-4498-8e91-3df98d87feac" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">d38a068de0cdd67f0825c31e62977231bb1f287a8c39c148beaecf9c93f31605</Content>
        </IndicatorItem>
        <IndicatorItem id="96d98ab2-2b82-4e7c-b603-b41ba7c4a062" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">16af6adc3087258d33136a140d024e4e507c2389</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="840cf07f-e03f-4ab6-950f-9e25c6dd1ae1">
        <IndicatorItem id="5e5c07bf-4dec-4025-a8f3-e18b0d31d476" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSDB-2008041101.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="28f399d0-1f8b-4295-8e93-b14d1ddbedb9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f9799175290f28ec2c1c7b2598307bbe</Content>
        </IndicatorItem>
        <IndicatorItem id="322cbc16-8c26-478f-a9ea-d10ef883f7f9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">91583788c81ef48567671b8173c31b826b8f3e20cb40b8bdd7a528093ec7c717</Content>
        </IndicatorItem>
        <IndicatorItem id="42c978a3-a34b-43b8-a743-d7d7fea3f1e2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">17895ed9f472bf3c2300da2d300e6a38d7b1d0cb</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="26130c2d-3acb-435e-bf7b-abf92cf6faac">
        <IndicatorItem id="3ebdc8bc-5577-43fc-b22c-d393887113f1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">cygcrypto-1.0.0.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="2b8cfd96-5265-40cb-8aaf-cdb0bae8d653" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">7bde415017793b4fc3b16caa0f640967</Content>
        </IndicatorItem>
        <IndicatorItem id="78a62ad9-772e-428d-954d-cec1e82f7bf6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">129c045ef072adab8457f6c90a57ce947f2792a09c02b451d416f988994869bf</Content>
        </IndicatorItem>
        <IndicatorItem id="86ef3a02-269a-44c9-a597-6d53a2229b16" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">1a4ad7a57276dfd24d31fe5cebd7385e8269f5f7</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="86b84159-895e-4dba-9aed-6497c19b992f">
        <IndicatorItem id="459741e1-466a-4c2b-915c-6b9b8184c2f4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">VMWare-workstation-7-keygen.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="833e9c05-78c7-4707-86df-7b00c437c97d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">309ad3a96832730545d1ff1f4fdd8de2</Content>
        </IndicatorItem>
        <IndicatorItem id="d75ed8b7-859e-4a59-9ffa-556928114d23" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">0a5c0224092468a4669f04721e291e3e89653d1ecf436c5c4dd7f1f8df4d0ff7</Content>
        </IndicatorItem>
        <IndicatorItem id="d2d8e876-1332-4909-ac71-25a72be72156" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">1b8f53c2ee42fff1f333223e82d3e538792b9778</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="0aa46847-12ff-4596-8ff0-b62583e8d85d">
        <IndicatorItem id="03e35e72-734c-4dd5-8691-65e97b58d9c7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">pcf.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="61fa8c22-7a76-4d10-be0e-0dae74246d59" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f7133f6037738c9c0ade22104349e8bc</Content>
        </IndicatorItem>
        <IndicatorItem id="2bc17f79-70e2-4f38-b73a-6bbbd3035069" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3d8a446c2da93d0c909caf9724ad452c66c944cf71f582a9b5002e9b2cc67793</Content>
        </IndicatorItem>
        <IndicatorItem id="a719265a-90eb-4b2b-9948-fad02ed60f0e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">1ba03151aee8276e95666df59e36506a9136634d</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="3f85500f-37ce-4e5c-a8c4-40c0fc912c7a">
        <IndicatorItem id="f1d24ef5-130a-4119-99d3-172d864a77ca" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">dualshield-hotfix-DUAL-341.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="5b013ff9-0f58-4c4b-a9cd-3562c8cabf03" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e599f11de0752ea0cd026594700c7b10</Content>
        </IndicatorItem>
        <IndicatorItem id="dba095e7-b850-4157-9442-49df33a68f94" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">dcb06dce6163b736ae1623365c1023bebb9915d09da1097931952472ab1d02fa</Content>
        </IndicatorItem>
        <IndicatorItem id="5a349392-f3b1-46bb-8711-a928d584ae52" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">1c7c5e90bf3434d3d3757b96b516c61404f422d3</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="0ef4ec49-cd38-462d-9087-c752124e2a7f">
        <IndicatorItem id="318199bd-c369-4da6-a7e7-f476ce80ac46" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">cyggcc_s-1.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="14c19552-9e71-443e-a687-fc9f4fb0bb21" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">b517ea5d532c329d82bd0bb8a8239c21</Content>
        </IndicatorItem>
        <IndicatorItem id="da65a89d-32e6-46c6-9949-8442ccb4de3b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">bdb971f13959add3ff1f61c2e1ac4368f7a706bec401b8bf81904b27fe6e59fe</Content>
        </IndicatorItem>
        <IndicatorItem id="04f881c0-c43d-4f8c-bea3-d1c2b3f862b8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">1ced2955164b7492fd6ba609c504cfd5107aa98d</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="77b34410-0779-4974-a1b3-0074963d5f8c">
        <IndicatorItem id="ca7c66d5-304a-47d1-84d0-d8255859662c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">uTorrent.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="892894b3-b616-4f1a-855b-2ca2a500d39b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">432f4e8794a2ea8a64e4c75ea80b790e</Content>
        </IndicatorItem>
        <IndicatorItem id="2bb41df4-ac44-4ee6-a104-9c7497d282b9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">d94b971cecd864fe6153ebe94a775157f3cdb69e8ad802eb78cfc0136737c0f2</Content>
        </IndicatorItem>
        <IndicatorItem id="f77b3f29-afdb-4f8a-a4d5-7907958e2e43" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">1f78800e17ecf9535eb695b5665f1da4258be70b</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="5ea83a80-92f8-4347-bfc7-e69e0f082bb6">
        <IndicatorItem id="b6ca0baa-862c-47d7-820d-5c1ecc63b1d5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">OfflineInstall.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="e248bcd8-6c23-4e3f-862f-ec671fc67c64" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">0a403c78075cb35602a3bcbd93f18f99</Content>
        </IndicatorItem>
        <IndicatorItem id="caffadfb-1bb8-431a-951d-990593234f97" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">23fc75c4cc154a74aeeff9c7729295b7436d26bb6a0292627120782fe698b18a</Content>
        </IndicatorItem>
        <IndicatorItem id="76a66dd1-3afb-4d2f-99a9-a8ba743ffe43" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">1ff40a24c1f9d5a09b0b882ec4ec7228de6f437a</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="37b2e0ab-cb2e-4cdf-a75d-e4b523e6a7ae">
        <IndicatorItem id="6e9f007c-bd41-49a3-ae40-3a3d2b745aab" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_dell.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="9a1c23b9-25fd-4dc0-bf3b-cd7c202cfb04" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">652a5cd27ff8966d26db94bb394ce4d1</Content>
        </IndicatorItem>
        <IndicatorItem id="45b626ce-46f5-44bb-8684-81217fed2f89" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">b6d736a68360253a94cc89bafbfa3141c382079d3e74346b12251da26149d1c3</Content>
        </IndicatorItem>
        <IndicatorItem id="4722f478-257a-411e-a998-79481c3b899d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">21b5f25b33e6db635ecc245291b092748d075719</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b9f75329-cfed-4460-b3c5-30f8b66039bf">
        <IndicatorItem id="97001908-3b35-441b-ac43-b73e3709d83b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Sierra_Wireless_Software_Suite_Light_Installer_v1-1-5.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="916524e2-4f82-4df5-958b-ef9cf804fdf3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">81b9f49f11d4cab2cb68ead87a017d36</Content>
        </IndicatorItem>
        <IndicatorItem id="5b13612a-c6f9-42f4-a85c-9f020b0858f4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ff156bb8efa93bcd15fd0d49fc154dc43835e1b66f7226dd27b66bb67622a516</Content>
        </IndicatorItem>
        <IndicatorItem id="f4d5adc2-b517-46a7-bacc-7cc24fb77764" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">221a77832f5b39e0e5c4d7099e4d96c9ba6c3bba</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ae2df506-29fd-4e62-bea9-69dc0940377b">
        <IndicatorItem id="6aa38d67-4137-4ede-a92a-13b3a471d190" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">BusinessLayer.resources.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="c29daf01-4202-4268-b9ff-2aa74d0d3832" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">357df22e4e92681e4f7fd0168caf51ae</Content>
        </IndicatorItem>
        <IndicatorItem id="a43aa07b-dbae-416d-ba31-8a6c73242892" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">1c83f67e338502f500d131e6f69c40a23ba4cf94e38e050de578733cd397126b</Content>
        </IndicatorItem>
        <IndicatorItem id="c2731ec2-a5c9-4d5a-97f0-e76ccc243756" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">224aa1856ead0722c5d5287b46dd32d1fb111371</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="bd412947-630c-46f2-bd07-98099af3216a">
        <IndicatorItem id="2e7649e1-ce5c-4496-ba45-73b7ef7a3020" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">cygssl-1.0.0.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="4ad87982-f03d-44a0-b632-1e3fe983691d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">3c8fa6759db3772f109b6e9860fcdc93</Content>
        </IndicatorItem>
        <IndicatorItem id="9b3f4cb2-9ab8-48ed-a8ae-e0cc1ad8a816" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">9581e36c5a55faae049a89fcfa584cde4fa7294b156e31de3e1a33035f4df3a4</Content>
        </IndicatorItem>
        <IndicatorItem id="f76fc727-3a58-4c2d-8f6a-1f31739077de" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">22e1893d9da4fe32aa5abe60f14dad6e52c45095</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="8a6ad82c-4f22-4e01-9f21-37c9c94cfa92">
        <IndicatorItem id="023a9112-8022-41ab-976f-ff8c699c7f4b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ida.4.9.rkpo.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="572f987f-ff79-4997-a189-79e8d4918c7a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">92a05da3047dd74826e09acc2692fe57</Content>
        </IndicatorItem>
        <IndicatorItem id="095074ea-1e76-4f5f-8e5e-1c798ca28ec4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">cfa438d2d1426c983134203329e30ac92a4c5f6170e1687dc287ecf67ef53404</Content>
        </IndicatorItem>
        <IndicatorItem id="fa424b92-1663-4ce9-b8f9-63a2d52eb8eb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">23442e4cee456a1571f65c75e0e53c388e194d7f</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="8e1c94fb-ee67-4fa0-bf31-1e7a3da8b24e">
        <IndicatorItem id="8c62f1aa-335f-4f20-b941-dcf2b3704a59" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">MODUNAME.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="3c849da1-154f-4307-a73c-07fc8b4cd6e1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">c36d60abed084c6d61741b08ff6681df</Content>
        </IndicatorItem>
        <IndicatorItem id="7e3dcbff-e0c7-4685-9b66-e4399c83ddc0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">a1eae49b5f732a7ceef30fa8aa1218c9c97e6436bfab5555ed79e4b29b0fda83</Content>
        </IndicatorItem>
        <IndicatorItem id="e183cb1b-0050-4c2a-baae-62f58533d21c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">23ba80af8dfb460b579b46309f4b7f0de53bbdd4</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="0cc170b8-1e98-4a4f-8f2c-4a07325c7e93">
        <IndicatorItem id="9340a045-2bea-402a-9dee-0121196e9665" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">idag64.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="fbaad4a5-d84b-429d-989d-a4de05e2625b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">48dd7a0dbed1258be15e6b857f75d763</Content>
        </IndicatorItem>
        <IndicatorItem id="707792d4-a5c1-44b8-b7e3-bc199b20f663" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">7d805fc7c5f667a3825d0bee1f19d9e048a18b91c64af71e14b78ffddb5bb31e</Content>
        </IndicatorItem>
        <IndicatorItem id="4bdbd747-143d-4518-8784-b3dec213c76f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">25acb56944c7513f843a26e7649c3a564d934e3a</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="1fdfa9ef-6943-481a-8333-b5de498da11e">
        <IndicatorItem id="a930afd4-9883-4550-86b0-2173bc8066f3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">DemoPrj.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="5f27062b-5dc2-414a-89ac-c7b14141b0b6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">6551a3789e12c4013ebc282bfa2a353a</Content>
        </IndicatorItem>
        <IndicatorItem id="80909d75-cd09-4785-9ecf-ac682878d02b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">57797d9c4740cca49aabe0187bb38607e2c157eb800c6794bb64e2751f5fd967</Content>
        </IndicatorItem>
        <IndicatorItem id="79e0fed3-625a-4149-bb8c-03b0369dff62" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">26768956ea4ee5a12d744d78710903efe0fc2959</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="6615782d-75dd-4c31-9b02-1a61ece21753">
        <IndicatorItem id="27232b41-928e-42c9-8f94-5dd3a4e062a0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSCooker.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="11e34580-5726-4e3d-a4a6-de6a8362ab81" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e3bd52648f653b38d75d325f2c205130</Content>
        </IndicatorItem>
        <IndicatorItem id="e3c80d98-4a1d-46f5-81dd-1576a9949d8b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">79deeb5af79f9a48cbbbb37400b940dc1e709230d0b176669bc1d095c4bedca7</Content>
        </IndicatorItem>
        <IndicatorItem id="0e59afbb-7c3e-4f8e-b7cd-0e45f7bd55d1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">26f87e87c78f075ff69aa7de4f6c50f97f499ab7</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="8598a138-e92f-49ba-b885-8c309030e094">
        <IndicatorItem id="84802bc9-bde4-4274-aaa8-3f1d8d7bce88" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">packer32.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="71605063-ea8f-49a4-8c5d-5474b0f045d6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d54de20c9ea82ce5e212ebcbb25f8093</Content>
        </IndicatorItem>
        <IndicatorItem id="0dcd4756-f154-40c6-ade9-718cbcc7c453" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">bb2e56e22ec4fc86f70ca44b847cf03763ae4f7a5877993c3dc03dccbfa8c4d8</Content>
        </IndicatorItem>
        <IndicatorItem id="fa22af45-5eda-43da-89a3-5a86eaa1800a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">272d783cb0bdeb6691758e1f592fd532319820c5</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="58a90cd5-3309-47ea-a339-149841305e67">
        <IndicatorItem id="39002ef2-8174-481c-b5be-69d39081c121" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">MSACCESS.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="56224b9b-16d5-404d-93ac-7245978a0ebb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2e6707641e23e18134e93e3c4f51c840</Content>
        </IndicatorItem>
        <IndicatorItem id="4e4ccb4b-a336-4033-beeb-9e4c1f22acbf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">71864e38545034655c934d46f6b50485cb3d605ad39a7c3889f7d3816440bf1c</Content>
        </IndicatorItem>
        <IndicatorItem id="14dc5b10-f599-4c28-9ea2-6132eff9acab" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">275c5629439be1efa5f586b0bde9f447b85be829</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="c4d42390-0ab5-4c48-a586-fe05c72fc0cd">
        <IndicatorItem id="8b367c73-0255-43c9-9c37-90366a57bb2f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">CALC98.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="b50ea4f5-6bd5-4077-ab68-bc1febcfd49a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">fff3802c3834a700a0fff78c39bfbd4b</Content>
        </IndicatorItem>
        <IndicatorItem id="9bf5252d-f202-46e5-8e95-9d655e125ed3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ec716cffd1650cea61d6536c2f4c52a7819990737b0ee619dbe3953d6d9debaf</Content>
        </IndicatorItem>
        <IndicatorItem id="a7c46115-3ef7-4b78-b6dc-9674a57d7fbb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">27de1373351c992bfd7cd9a21af8b0bd2da02749</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="20ea9485-3c09-40d2-8188-91ddb572cb1b">
        <IndicatorItem id="980fdaa5-8a2c-41a2-be20-b39c50ff7849" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">microCadCamSetup.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="cf096a8f-e0b4-4600-9ea0-694a52284625" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">081b26d9ca74faae821e0b2eb2bb1fc5</Content>
        </IndicatorItem>
        <IndicatorItem id="382eac27-69ac-429b-af71-83091edd1201" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">4ae1e35dc83825dc81e886b7597f00781b184be4fa288a8aa7a3c0f62a526387</Content>
        </IndicatorItem>
        <IndicatorItem id="8a258482-8f2b-479e-885d-49b6c15db715" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">28fb3ef8f16da864f44529f1fa09872af6b7e858</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f7f7c504-1a08-478e-8d71-59790e255ab9">
        <IndicatorItem id="f02b704c-14bc-4c3a-9808-206ee3bacda8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">GucciSpy.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="af09d36a-fd2a-4ea9-ac87-865a1422ac36" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e3458decc7cc44759cb5f06453dcbefc</Content>
        </IndicatorItem>
        <IndicatorItem id="91e36d30-2d08-4917-afb9-a5c55d888478" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ddc857de7180ae0d54d793509bfda9671bca5123f74791b1d8291d68d05e44eb</Content>
        </IndicatorItem>
        <IndicatorItem id="b53a989e-6eac-4910-95e2-4f0084bf1bee" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">293c4de4c53db68b82195d73ec093da149cd8b08</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="c74312ac-1b37-4111-b72d-062fc7907fea">
        <IndicatorItem id="41e16d87-cbe8-4319-aed0-a6de0b402cd7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">e2k_owa_pdf.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="354f111a-4d24-4ea5-967b-2a1642fb923e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">42341fbd8807373a3122ad5f69147f16</Content>
        </IndicatorItem>
        <IndicatorItem id="611c1a8f-7d66-4b71-8be6-c35f9c9de63f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3833e00748827cc78010c7f8fbab07d3badd2513ff087d89ea8b323b5c97cfeb</Content>
        </IndicatorItem>
        <IndicatorItem id="6d8e4266-9969-4f01-bdef-2fe46b0782ba" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">2ba4f9dc2dbc2257e36276c539d415f468db5cf3</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="9519de52-5c02-475b-b786-38a69a5be03f">
        <IndicatorItem id="74eaee82-b94b-42ce-83c6-f63ec1e38305" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">besexpressx_5.0.4.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="500ad43a-7f5d-4ac4-8d5e-948466029a43" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f512a7826046ed3711f52a59abbf2a76</Content>
        </IndicatorItem>
        <IndicatorItem id="0f11b359-04b9-46f9-8db9-d0e8bf9fb284" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">c2cfe41365a5ab251090b5f4583ae234f3445c626bcb85ef45ac5d63973c5964</Content>
        </IndicatorItem>
        <IndicatorItem id="6ec2d370-d352-47e4-9c92-e4e3bc6429ff" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">2c8e4e7de83adbe512377e5496f90277099f3837</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="90fa9dcc-a9f1-4b0e-bf8a-f077700b7593">
        <IndicatorItem id="aabc909c-1187-4c63-9882-275113d1289c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Microsoft Office Word 2007.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="03f20012-874e-4647-ad48-c2b4243b45cf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">cd3614092135f8f6c222d6010a3130d6</Content>
        </IndicatorItem>
        <IndicatorItem id="2391254a-8354-486a-bda4-9b7ff30cb5c9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ffd49343ef5d6a77d30c9e9678079d48285e82d9537abe4f12ccebdd5caea23c</Content>
        </IndicatorItem>
        <IndicatorItem id="29066f8d-a6c0-47e9-9083-7428c822beaf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">2dc37aa7241c408b01bd1a5e69ea151c295176e2</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="91692301-3273-4661-8f5f-a874308500cc">
        <IndicatorItem id="2926e9ab-0a2d-4e8e-b5df-7489f80d9401" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">WDSOleDB.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="1ebc5c5a-a417-4482-95ff-892020210361" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">b1417cbfb402e47599e9c4830cd27081</Content>
        </IndicatorItem>
        <IndicatorItem id="740527cd-e3c9-4eac-9997-42745e94d6a7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">199291791ccd7ca5bed11be7b50ca72750d9d78e30694730f159729a4835f5c2</Content>
        </IndicatorItem>
        <IndicatorItem id="a6b6bbd7-adcb-44d1-9313-31f1acabe2fc" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">2e8c0e4d6bda2f784c1dbfaed88319e79ce336fc</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="56bd121c-c28d-4140-b546-3cacd4806580">
        <IndicatorItem id="3d7292e8-1bb8-45b7-8b8f-feafbda3f63e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">kis14.0.0.4651it-it.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="db39780f-668e-4c7d-976a-dac8415e2491" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e3b3919d8ed1399a113d8a3c5a1586f9</Content>
        </IndicatorItem>
        <IndicatorItem id="34f27427-c7d3-4da6-8f4c-d3b4cbed7006" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">e827ec9a1b0acaf346aa98dd77ea61479ff6cd89bb631e7dbef6ead3b5c59bc0</Content>
        </IndicatorItem>
        <IndicatorItem id="a95f20f7-b835-499d-9657-96be72605fb5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">2f02b5736f9fe8987607885bce0fc28fc7ea922b</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="3738cbeb-e0cb-436f-99bc-6fb4d63a65d1">
        <IndicatorItem id="9a16acd9-0ad3-49a1-9f70-10b8fd4616e3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">insert_cert.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="c3c56601-a258-4b42-a9a1-182e93315a11" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">68cd61eefa0e6a7a6b36fb359bdd93ae</Content>
        </IndicatorItem>
        <IndicatorItem id="591bfc3a-74a5-482c-bf1b-0d3ebcfada72" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">b785b107632a3b8e9070a5a9a610202b46d916709f6b969b30c5d3375a2f38e7</Content>
        </IndicatorItem>
        <IndicatorItem id="cb02b143-7dd2-4c22-b3ca-1b544072d8f7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">2f4e851d21c45e9b0a77a9cd9a0d5500a7740395</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="e0b565ef-0732-4436-b25b-e19d3411cee4">
        <IndicatorItem id="a93d3ce6-c49e-44a7-aaf0-27a1f0a9b90f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">pomf166.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="20e5e237-d39f-4faf-9096-e4ace8c16ca1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">56fd59bf9f93ab512cfb0822e20dc157</Content>
        </IndicatorItem>
        <IndicatorItem id="e583f5e5-8bc6-43f9-9dd6-30e2d24e8cb4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">f82c4673a15ff6c5806f54811c4e782b595a0a445476c3ccdbdc4cd200bfe36e</Content>
        </IndicatorItem>
        <IndicatorItem id="acee8983-c761-4bff-ae3f-ff4a22eab8ed" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">2f9a28719745d1f95818c424bef3bd202f4172e9</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="d1701079-618a-4774-81a9-09dc07df1458">
        <IndicatorItem id="b9325c73-84c6-4d35-9c0c-0f0a725f9830" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">TAGLI.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="564bddd6-c8d7-498d-8d17-0fa1b4be0dad" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">bcc6501b750ec5cbd558a11ad4445bda</Content>
        </IndicatorItem>
        <IndicatorItem id="bd4eb5cd-d921-4acd-9e7f-0a6e0fc2caff" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">40977ce5c1e3a5296f4359d30a9a9518a83259410bdc6a568cab2e0c30311c8c</Content>
        </IndicatorItem>
        <IndicatorItem id="f42d8bc0-91dc-4f5f-981e-00ef0a94b092" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">31a89ea1c539f710189ec4bdccfb8baf68adc352</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="59850ecc-0905-4154-b524-b33b41e42569">
        <IndicatorItem id="15e238a4-a304-440d-8f5d-c1a98518e5ba" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">9DmX3bPh._Kj</Content>
        </IndicatorItem>
        <IndicatorItem id="aa1a980b-5dd4-4d41-9c4c-488a4791a929" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f27de7b44ae44588445238ef441c9d99</Content>
        </IndicatorItem>
        <IndicatorItem id="3ca73dac-7691-470a-bcf9-26de1d45e79b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">14844c483d486348f598f31956aa13e50f3fa85320287d91815be3a611c8f1a1</Content>
        </IndicatorItem>
        <IndicatorItem id="413d30b0-6d4c-4c93-91dc-4cdb9c594d7c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">3320916ed703343c70ba0166595936eb588a12b8</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="6e80aebe-30ed-47a1-a10c-02da994f19ce">
        <IndicatorItem id="afe3094f-62af-4605-ac5b-8e7dfc694c26" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">win32_remote64.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="728e2b0a-7403-41ed-979f-c81d3af91446" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">1fc10a99ce2652ba0ec7bed0f8f05c2c</Content>
        </IndicatorItem>
        <IndicatorItem id="b8e090bf-e2b5-46a2-92bd-5bfadbe7447d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">f08e6bc6c3a6771f697d4f724bb238f837f61d988c29a2d77dd73cd36a4a38b7</Content>
        </IndicatorItem>
        <IndicatorItem id="a0569333-60d2-4bf1-9ca8-6bb843c238d9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">333a5d4082808206eeedd309e02d88e720587e4f</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="88bb62f3-1408-4dd3-ae22-0815bcbfd65e">
        <IndicatorItem id="008c020d-8314-40ca-a040-ed886a5c5c93" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-hotfix-9.4.0_2.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="816698de-2417-437c-ad31-72054f401a05" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">0bb14e2cbce99ac845c62bea9c5d62ba</Content>
        </IndicatorItem>
        <IndicatorItem id="b5dd55c3-94cb-4f49-8418-42030244fdbb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">4f9f7f9b2a3ee884f4aa08c066a458a52f175a78b7748ef4a751543213b92d29</Content>
        </IndicatorItem>
        <IndicatorItem id="8d3f7b89-36f1-4a27-a558-f87f50cd4e40" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">33aa87925aaafa5c97df0c4334b3e70b5ce43552</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a2cb429a-165a-4702-b0ef-11fc706276be">
        <IndicatorItem id="d60e7b64-b7a5-40b7-9c1f-2c1ebea07f3c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">WinHex.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="d184df40-41bc-473c-aee7-16380cda44bf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">a431bf8ab5cfd54fcbfc82ae12bcf3b2</Content>
        </IndicatorItem>
        <IndicatorItem id="7cac7090-8a53-4f3f-a21a-78343b4dd685" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">4795d51d9cf26d9a3decb90695e4d903fd482548b356547c023e2899cd120d56</Content>
        </IndicatorItem>
        <IndicatorItem id="6edd5e42-57a6-493b-97bf-a65574eea300" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">33c23e9ac2c9ccb3d6c3591345c45e506c093c57</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f5fc001d-18e3-43f9-9cd9-6d5d9aeea9ac">
        <IndicatorItem id="3bbb64a4-a903-46fb-ab8b-61b7b0363a62" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">AsmJit.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="05514fa0-282d-4a4d-ab40-20dc8245acef" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">5a053eb4538a0553889651ea7b54f590</Content>
        </IndicatorItem>
        <IndicatorItem id="71f1291f-9b9d-4100-a462-48312c4f6714" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">595e4dc95b391a0566bc8c9d32d352c205d0f8ae19d3842f6d914f0b696f98e2</Content>
        </IndicatorItem>
        <IndicatorItem id="08a62acf-83bc-4a91-acea-f2e61b1f095b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">33da4a93916af6034463aadbda97ad18671d45e1</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a45e6323-0805-457c-8602-42bc3acec15f">
        <IndicatorItem id="19846c42-07fd-4005-93b5-77dbd0da4cc4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">antivm.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="06694158-616b-4753-8c10-e8b5a4b06fd0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d553160f4db53c3ef30bf57aac67811a</Content>
        </IndicatorItem>
        <IndicatorItem id="43a3cf14-1b58-4b57-845c-6ea446422548" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">2c2a1044acd7d47ade2e74b06fe366fdc1c363297b5292c8a362f34018ae100b</Content>
        </IndicatorItem>
        <IndicatorItem id="e89039a1-44d7-4217-af2f-ba4e4a4358a8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">3412967b6ff4d2ceece701b899571987b8c5d70c</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="361bd3ca-36a7-4f12-9dcd-a5d50a8211a5">
        <IndicatorItem id="776a2e2a-309f-45be-acc5-8f1e846e1c67" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">putty.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="a3680c72-93b4-4a82-a8b8-6e41a4750eff" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d7697f8af52b42e2fb59a350886f02a1</Content>
        </IndicatorItem>
        <IndicatorItem id="54b32175-56d9-45db-a1d9-4b1aa8eb5f57" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">0418ecb096bdb3360694780a76838cd333900ebb26a168e3a95225e6579ea20e</Content>
        </IndicatorItem>
        <IndicatorItem id="d9763484-8fd0-4a01-ae99-99b82bd0e1f7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">34da42515658486c097b4a16c8e7ab6d3fd14020</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="82454b2f-59c3-4d4a-868d-9dd4ab30fc93">
        <IndicatorItem id="e0a6c002-a404-448f-8705-fe2b093a51b1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">pywin32-217.win32-py2.7.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="29f506fc-5ab8-4954-b64b-9792cd4d578c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">42202e223b9d21079f397b9116093ac6</Content>
        </IndicatorItem>
        <IndicatorItem id="a74f0c37-0942-427a-968c-b3d3220608ee" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">79c4bcc19a33e6b1ef4308b8d8ca93a6f97a08280d80d3ed856805d560e4489d</Content>
        </IndicatorItem>
        <IndicatorItem id="b4088da1-a979-4bb2-ab8b-c9c1201e1263" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">36016bbccebddd9060073f1c9f0c80a2c2dd9cc1</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="49968217-9397-48d3-b7df-24797f8a54a5">
        <IndicatorItem id="c3950a5e-1221-4389-a72a-c4f1c28fee99" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">TK.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="c90e45f1-6c1b-499a-88cb-1daed37755fe" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d8905758dc805f34902edb4a625a8dd7</Content>
        </IndicatorItem>
        <IndicatorItem id="5e81127a-b0d9-4c93-83de-350c5dfb2dbf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ba6038236dfe8db7ccfe782a7ea55ce182c97767ca2fe195e0f67204e14983e1</Content>
        </IndicatorItem>
        <IndicatorItem id="be133753-306a-4afa-96b9-fd00e2663af4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">3784602da864abb4bc3cf97cf0816f26b4f46d18</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f535320f-42d8-4d32-a545-3cbf10ea262e">
        <IndicatorItem id="a873910b-5315-4e94-a795-175cddfe60e1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Office_Word.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="a4f728c0-8758-4d35-b448-cb8251e22434" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">97ff374ab1a7358eb362406baa0554c8</Content>
        </IndicatorItem>
        <IndicatorItem id="66d0e41b-fc71-4697-afb6-8998d29acb6e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">010ce301d6ff509e111e9102ec7b883fd888f1510fe3bfba6d71986704dbcd28</Content>
        </IndicatorItem>
        <IndicatorItem id="a28feefc-09f9-465e-abe6-3ea21113fc0e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">389c1d337548d2e3721466a3ca3fd54881cd5aee</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b9e5043f-bbfa-4088-a28a-2846d26d7df8">
        <IndicatorItem id="c9013d45-b5cc-41a7-81df-930209f1b528" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">dropper.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="8dde50ac-6bf6-48b6-9c8a-2eead744d1a1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">360303fbb9f31d82afae87a4e71c8e93</Content>
        </IndicatorItem>
        <IndicatorItem id="e32f20d5-dfd4-4d5f-8bce-1912e20e81fa" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">d31c5d91556d0dc52ddc77d70678441f6f7a647eaaf8e1438fdc5cf3160fb935</Content>
        </IndicatorItem>
        <IndicatorItem id="d091d822-a51d-48da-9378-d6699dab8454" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">3cbedf6f7e7c842f1aa3cc6440449fd2defa7df7</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="45b9b8aa-f9e5-4269-9503-9cb44fce77ac">
        <IndicatorItem id="3ff8a327-821c-4af7-8780-a87db6282a96" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ApiHooking.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="dfccaff1-6211-4b6f-9b5e-e7f008c7da7e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f4add3db73a7d1f1cdc836603a95d109</Content>
        </IndicatorItem>
        <IndicatorItem id="ec59a01b-3b7f-4c16-af59-ef8c6392d10d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">511e3eb95e12a2b12b3ade129ed79f0f2399f56c29247b1d535acccabec3203f</Content>
        </IndicatorItem>
        <IndicatorItem id="d7de9bbb-100e-4c10-8156-b79b35db26d5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">3d36944e86fc13f4c6393a9804b84ae8cb039f37</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="6cffbedc-2f63-4a7e-9eac-d0fbdf73db45">
        <IndicatorItem id="60774aec-6a71-43c2-8db9-e471b8119c38" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">SNAP.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="2a670a94-0968-41ca-8945-51e575ff12ce" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d3de67c7200164dc3e6b67e90b5cef3a</Content>
        </IndicatorItem>
        <IndicatorItem id="5a372e25-29d2-452e-8377-cdbeeebf64c0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">fd0d4f1a711a8de644667f0013e27dabb826d01b4a7563266c9cc701e9d5d838</Content>
        </IndicatorItem>
        <IndicatorItem id="334d17d4-b638-41c1-ac57-0f18eacbe46e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">3e89aa84e3e1296f5c031234de28231e4db014d1</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="826cd0d9-b55f-4bc9-973b-dadee575dfa8">
        <IndicatorItem id="d9533f05-68fa-43c1-bfff-bb7d78f94bab" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Agenda.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="b9e7e4be-ae82-4109-8f3e-a6baf2574517" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">b0b3bd03a394caa4ef5360ff3d4d3d43</Content>
        </IndicatorItem>
        <IndicatorItem id="57203ac3-8818-4434-ba74-ff165984cec4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">401e449c1648117af46395c5223a836f534c7333d5922826db803ff6e45c9f77</Content>
        </IndicatorItem>
        <IndicatorItem id="fc07292c-b425-47c1-9dad-803ba1421874" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">3ee787fdb3f8adee102e036c0edd7ffb408c08d5</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2fa0c24b-d001-4e3d-b861-542886bdbd2b">
        <IndicatorItem id="c58d9986-f1c9-4063-a109-be80f05a08c7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">CALC.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="0aae5b21-a39b-47d5-84f4-c700cbc51914" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f22b45729fc40cd6de3e7eef599ada6b</Content>
        </IndicatorItem>
        <IndicatorItem id="d7fefacc-ebbd-4205-acf2-7805e5c7fbb7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">4c7d7c0f4340d7296c9c4f5a80b80793b85c33aabce31badc9dccfa37ef38949</Content>
        </IndicatorItem>
        <IndicatorItem id="92cbd2d0-a41c-40b2-aa4b-03a52c08ff27" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">408d0868274fdf7327c4814170dfa001483ec103</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="9d263519-c2e8-4718-a0c6-528fc20ccb6c">
        <IndicatorItem id="78f10ed4-0949-4c87-8fa6-bdc49069aa7e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ApiHookDll.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="29410dca-8b5d-49e2-9286-5abceb352a1c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">7a4dbc7cd77b981f5c742b93926cd030</Content>
        </IndicatorItem>
        <IndicatorItem id="f7f37fee-921c-4138-bc99-085909d826d1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">c585f02a22f2fe7dd7a1720bfc119613ea32b589ea72dbeb4d6c91d8e7bf399a</Content>
        </IndicatorItem>
        <IndicatorItem id="fbfda5cc-45ee-4ac6-8ff3-b607e54bf750" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">40cc3e2939bc3f8a4aebdaa3aab49de8cc384642</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="79878ad0-11d2-4f5d-83f5-c031d54fd120">
        <IndicatorItem id="7db75788-ae9a-472e-ba15-73c759866ea7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-ocr-9.4.0.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="df1ce195-998e-452a-8674-dfc1d55b71c8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">768ee422a113dc1ae0310f6bc4d7c66d</Content>
        </IndicatorItem>
        <IndicatorItem id="ef1006d6-89a4-4aaa-ad9c-632ed0a92293" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">cba8e646e951dbfde33daddc1ad6429814dad1ae1786c886948ce9ed7029f487</Content>
        </IndicatorItem>
        <IndicatorItem id="68fec412-7987-4181-b6b8-bbd0b59d04c2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">41b844cd42208eab05e203b5e22712eaf568d133</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b5cc45a6-103f-42e5-82a1-b9ed6357e039">
        <IndicatorItem id="78503d7b-d0c6-4217-92b5-ceb91d472b6b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">vmprotect.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="6426291b-1d20-4ea0-9560-a121ead45397" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e176c61ea82b43bbeb543b6c68d7a358</Content>
        </IndicatorItem>
        <IndicatorItem id="479adc7d-bfc1-43a9-b083-7bb706e07da1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">2e099df103d467e3d9a44af15c047e3deb2540ce4d54e01294c511e17e6479e4</Content>
        </IndicatorItem>
        <IndicatorItem id="daa89b1a-80ac-4175-9260-d3a12460d983" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">426d008139ede8b04ef465f0bc669b0ab709be07</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="3ad80cee-4be7-4e28-b879-e5b9d0675d9a">
        <IndicatorItem id="6b6fee34-6445-4a13-827f-55676fe600da" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">CONTA.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="808c6d8c-3d5f-44b1-97c1-cc148fb80dc1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">0f6361b0931307b26022e6ebb4fb87da</Content>
        </IndicatorItem>
        <IndicatorItem id="d9bcd36e-3cc7-4d93-b41d-bdf9547b01d1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">e56a2ebeaa01def702f6653bad90651854d1af461899cabac6db12d81566ba1d</Content>
        </IndicatorItem>
        <IndicatorItem id="bc2e3d32-3e0f-4db5-a239-ef2ce868e08d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">429b82ff48aeb78d2dc1f7e4d9e6e63f79cc2689</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b7ef786d-eeea-4758-9182-0062574cae16">
        <IndicatorItem id="7bc80609-58dd-4e92-9c8a-438600ba20bb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ShellcodeInjector.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="832e88c1-9b93-4293-bcab-033ffbac4162" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">a835bd1a588d516e8d9b12c7b85d54de</Content>
        </IndicatorItem>
        <IndicatorItem id="18756658-84c4-4f6d-addf-df80e9fe4599" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">31e9433eccf1c150462b705af11eff50587d25526225d0c4ba07312af0c81969</Content>
        </IndicatorItem>
        <IndicatorItem id="b5155ef8-2aee-4457-895c-521246629d13" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">4357e25f04f902a67604b8b9a6a122a9d3ca0357</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="56da544d-0c25-4100-ac8d-136f677c2145">
        <IndicatorItem id="5c76dca5-9bba-4053-9c0b-627563963296" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Loader.exe-validate-ca</Content>
        </IndicatorItem>
        <IndicatorItem id="f8c3c59a-fcf0-4d4c-860e-05a966feb198" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">7cefad54a4656d68d5662836d794b5bb</Content>
        </IndicatorItem>
        <IndicatorItem id="a8b3d8a4-02bd-4d66-82b2-55ff5d0c4522" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">7fcd2160127471fbd92e3dfd656d73eef31195f1fe5a1c77027bd2a961467883</Content>
        </IndicatorItem>
        <IndicatorItem id="c7d24d2c-9724-430f-bc8e-18f68a1e0b0e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">441a3f4e360996f53a0ca5bf7280c03771badb90</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="6c97db20-b41d-4fd3-b3bd-700e56f5be93">
        <IndicatorItem id="621105af-03ef-473c-8f3a-2b80bf0d8107" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">dll64.win32</Content>
        </IndicatorItem>
        <IndicatorItem id="9af643a3-875c-4b4b-a106-c76c6951dd07" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">33f2a0070170ab861e92435114db52d8</Content>
        </IndicatorItem>
        <IndicatorItem id="5f249f9e-d9c8-44a9-94b9-2d8ca79b69b1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">bfb2ac272617e4af5ddf176bb4bffcc090e47b1208f4285a7108d6a59ec51837</Content>
        </IndicatorItem>
        <IndicatorItem id="6eb20c8a-9921-432f-a992-3d74d6b82894" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">4437315b462fce721d16edbe77362b0e634aa559</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="dbc9782f-cfb5-430c-a494-caecd0e7e61e">
        <IndicatorItem id="db375929-e82b-4348-ae7c-e05ecc98140f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">codesign_allocate.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="f6abc5f3-525f-425e-802b-2d9fa7562d5f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">9e12941d5c990122fdee6b24fc3a859a</Content>
        </IndicatorItem>
        <IndicatorItem id="0c74cf54-fa9b-484e-873f-6a0f22911477" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">6f788920ac2df748947f767a1e9b5ee3a5c9f4d073fd07792c9ebfc4eaf45ca9</Content>
        </IndicatorItem>
        <IndicatorItem id="315275ae-55e1-4d54-ae11-a5fc78fc39cf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">45179e1b07cb96a8c31443ffa1a7b3f0a6c4de01</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="0b3a3dc2-0250-4293-b08e-c8c14e382a34">
        <IndicatorItem id="82939f4c-2797-4557-9bbc-ceafc5d84af9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">WapSender.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="b9cf5951-9f3a-4c98-824e-6834eeb70123" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">91b034905c4a8cb10b9adedfc7349fdf</Content>
        </IndicatorItem>
        <IndicatorItem id="52b11c18-9c7a-4c8e-a4a5-2009224d4ccb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ed4f21dd3c01e7636cbc30cf549d347cb385099c18bf282880b7df7a18140f6e</Content>
        </IndicatorItem>
        <IndicatorItem id="fff319dd-26dd-4af7-9c22-856bcf6c0880" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">46a5a764bb79b7db937f1f1749438e41bc69872e</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="db5ea72b-ef10-4181-b63f-8b1d025eac95">
        <IndicatorItem id="a733c52d-5b58-44e7-8987-e7cad5940202" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">BCMRes.resources.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="8546c8bf-7097-41bd-8c9f-f4dcc3a14905" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">9b71c1e2b8951da4690ef05eecd67770</Content>
        </IndicatorItem>
        <IndicatorItem id="dc1178f1-059e-4ef6-8b40-1b1b388aef43" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">80ea72c70d8de5e111d4be5fa7515c0b35bbdecc2a4997c2930e918bc263c4c1</Content>
        </IndicatorItem>
        <IndicatorItem id="04a16285-51c8-4fac-938b-97776d95a0b9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">4780d4daac7f4a74ded784571e7bf3e245bff7e9</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2d317b30-5769-4eb1-a7c4-4ee175c956bd">
        <IndicatorItem id="cb8772d5-7c88-4359-b3ec-1bca0306e0b9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">elevator.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="befbaa9c-81c5-49d9-88c9-0edfeddc9bd2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">47aeacba39f33b6ce2fd1f654f760a6c</Content>
        </IndicatorItem>
        <IndicatorItem id="0eccab00-aed5-4737-90d4-38482bc0f436" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">40a10420b9d49f87527bc0396b19ec29e55e9109e80b52456891243791671c1c</Content>
        </IndicatorItem>
        <IndicatorItem id="ddcc3fa9-c5f7-48b0-81db-44dca9cffb0c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">48220b4aeb4a96e983d6b1478144592e26fc982b</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="4abe26d1-4e38-412e-b417-7c6a5f145a6a">
        <IndicatorItem id="87cb17a1-e65c-42d2-9062-b547d81de5cf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs</Content>
        </IndicatorItem>
        <IndicatorItem id="4056771d-d171-41ee-affb-6ab6c2044819" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">b043ec1567ecceb84c20a853d9245132</Content>
        </IndicatorItem>
        <IndicatorItem id="43908460-652c-4353-951d-4e49c42361b3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">f6c3d4c2db6e10d5fe9dcddf771d6261a525e7789189f0cfdb4a87faf34d6dd6</Content>
        </IndicatorItem>
        <IndicatorItem id="41161a7a-3a02-4bcd-b4a8-2103fb6f7cf7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">48c3fa74a00f1115c0e089f23997f112c85741b4</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="c484b8a2-270c-4b0b-8206-df7daf1323fe">
        <IndicatorItem id="75eb810a-f2d2-4ee1-835f-d23beb0e2651" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">SmsFilter.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="b5a5fc33-745b-4b0a-995e-71939d69e743" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">44a6cdacf598a7905401b4f32d13eb41</Content>
        </IndicatorItem>
        <IndicatorItem id="93ecb172-17e0-411f-8848-e468fb44b6d6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">f3caf8fac708bf3a4ea0511e06849a169e020bdf19c0f8f526abce0b3951fa42</Content>
        </IndicatorItem>
        <IndicatorItem id="4470e673-41b9-4f66-a136-c03d24b125fb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">4be90804476b2833fe6afcaba35b07ecaa522a2c</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b68b3e2a-8d13-45d5-b358-03448e627968">
        <IndicatorItem id="1c097af2-a1bf-4107-a051-e6105cab34e9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">QPD001.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="a753f2fa-b613-48b8-9c87-56f4d69f4a84" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">9ed0d182100447ad46b38f8ceef612f2</Content>
        </IndicatorItem>
        <IndicatorItem id="7ce770d7-ac5f-4b48-a307-f7e0537db33d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">656c897b39d7867bd4d38696100a09e379b06ab5e5f6842c1329f6bb83e70161</Content>
        </IndicatorItem>
        <IndicatorItem id="3002d01f-a3d3-4ab3-a23e-d376360cdc33" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">4dbdb482e6f4882ed8d31e1362e84fc104b397d2</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="7067c17a-29e0-47db-9dcb-c5a4f30fec26">
        <IndicatorItem id="1313920b-c61a-49da-bc23-8c1897b8a01e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_signtool.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="e5864d03-e088-4a50-ad80-f1dc21245622" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">ae0d2278aa783b8dc1675f41cff9d07d</Content>
        </IndicatorItem>
        <IndicatorItem id="ea13e166-9b5d-4659-b75b-22a435da002b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">d5b3cc429c8a6fba074d9b1e2963273ac13cead47f63dbbb97e640b74e407134</Content>
        </IndicatorItem>
        <IndicatorItem id="381790a2-e850-4b11-8030-c880fbc345b2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">4eb87cff1cf2f1411248cd06b497cac564ed63fd</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="31ca7518-4adf-4d2a-80aa-a15f9b98530d">
        <IndicatorItem id="b5fef6a6-df4b-4d1b-a031-f9a573ad74ce" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-exploits-2015032101.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="8022ae8a-3f6d-493a-9ba2-cda687a9342a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">27f45f64f69d31839a6ec82185b5e030</Content>
        </IndicatorItem>
        <IndicatorItem id="cf902829-c079-4059-b5d7-9b7eece611ab" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">5ec8cd3180a2576b92d53085ff5e3dcf4e3dccaf2154b59879969ef8011fd1c2</Content>
        </IndicatorItem>
        <IndicatorItem id="43e1ba1d-3f91-40ff-ae53-b5642b0d6920" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">4edb69adbc1ebc884aa65cd42e1187f9223de3d3</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="60d1111a-37b3-42c8-8771-b6641879aeb7">
        <IndicatorItem id="73f6870c-8783-438f-9964-0dd80a0e17a2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-exploits-2014120801.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="9dd191c7-0697-4751-a338-e2e4ba548604" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f855633c69c3095b20a99bd12d023271</Content>
        </IndicatorItem>
        <IndicatorItem id="61f52b63-e56f-4e1f-b249-e335698f8fd0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">7927f3a35d87250253d8abc021d44cc496d2185f376f0d33b0365a68ba81e636</Content>
        </IndicatorItem>
        <IndicatorItem id="98e3f0e6-0f6c-437a-8f68-bfc61e4e0ace" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5004f0d0410666e923212e941f646777b91958b0</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b365aa0f-9101-41ae-9629-1e20a86192c5">
        <IndicatorItem id="f4e83b77-5f9b-45f3-b6e2-f50ee8185279" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">VMProtect_Con.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="e4925ea0-c63e-471c-b284-8a535ec12285" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">5cd44e29316435cda62790801ec4f473</Content>
        </IndicatorItem>
        <IndicatorItem id="294d0659-808b-459a-b02a-308b51b02c1d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">2b5560f11b24de4fac1b0998cfe80138c2a4f87bb15f6eba6f7f58a5cf1f8622</Content>
        </IndicatorItem>
        <IndicatorItem id="10d5cd1b-cf4a-4a73-b06c-967048285d10" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">50651dbc0af0ff5f1623c468fd4ed4eeb3f2460d</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ce871217-3a57-47d2-bf93-4c8b052703e5">
        <IndicatorItem id="74525064-e5fe-4320-b88e-8e64ebe4b8aa" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_jpg.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="bb2196ee-daff-46ae-bb09-956e5fa59762" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">ed6d8b6078e103b2d12a7fd339838a9c</Content>
        </IndicatorItem>
        <IndicatorItem id="17161544-c836-4947-bb44-f91274233307" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">bf2f9d19521cae12bf25a4108418f6c234af6cad2d7a6482323a12a2da13ebd6</Content>
        </IndicatorItem>
        <IndicatorItem id="fdce92a8-b59a-4146-8511-5d5adf043d8b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">52fa70529cee1101067e7f6cc2532ee64506ba11</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="661907ca-69eb-44a2-98ce-1c2f81e80076">
        <IndicatorItem id="d0f5832e-a334-4fb8-aab6-14aa88673865" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">cygz.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="d0a92e3b-d830-42b8-b906-4b6972aae96d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2b6782453501a0f89aa9c697f25aaee8</Content>
        </IndicatorItem>
        <IndicatorItem id="6bb72bfa-a0e3-4641-9bb4-550af687da7d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ced4344df5150b592709e8758e822c06644cfe8cad26c28d50667fff35f3fd08</Content>
        </IndicatorItem>
        <IndicatorItem id="24d70143-153e-44d5-9674-14c3fa6bf2fc" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">533df8b545fb8e68dd8e14def5d6948d1a2c26cb</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b461f994-1c4e-4e13-88f3-9a4e4d2e02b8">
        <IndicatorItem id="f8ef462f-6c66-493a-8ac7-cb850c80e884" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_nostage2.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="0945e537-2293-45c8-adcf-0a1966e8e08d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f063ea5b63c9eb0e8aff3420caf4b64d</Content>
        </IndicatorItem>
        <IndicatorItem id="ef2194f7-89c8-4522-8cbc-b2dd102b0f71" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ce5d792faaca61d7bb63367f8772f492ee963f054bc03e61b4fae774c3a3c343</Content>
        </IndicatorItem>
        <IndicatorItem id="57b3bcf4-44a3-4055-9abf-915754807dbf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">537506539114118726725947814c6368cc507ed4</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="27fd2477-6afc-49ee-9404-69ff8ca526fa">
        <IndicatorItem id="878b9f32-b5dc-4b75-8a1e-7c762d803fbb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_$[35].exe</Content>
        </IndicatorItem>
        <IndicatorItem id="daa39540-9f35-4012-8ce0-9a726b53854e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">4170d7f066178181b7f86b5a1125a761</Content>
        </IndicatorItem>
        <IndicatorItem id="6bef8b7e-f4a0-4290-a826-50b9a65b4770" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">b7df931aa020195726002b235740bc844fc4b105920d4a139ca6b5a069e43575</Content>
        </IndicatorItem>
        <IndicatorItem id="d749d5e5-71ff-4a28-b8df-c02c2c0a1b25" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">548e8ab0169f36b548a5aa5678ef1b033acbcda4</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="03b65e4b-c678-441f-b51f-1d4dabae8e6e">
        <IndicatorItem id="836a3bd4-48f1-490e-b4b0-490851e979ea" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ras.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="3b07af3b-7a79-4315-9e96-5171098feccd" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e8bdefc4ad172e6f0e26bd071b36ca06</Content>
        </IndicatorItem>
        <IndicatorItem id="c309bdba-8b76-428b-8765-00858a089743" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">568b1b2fd194688667619f071c470537b8d3f82ea8824e4b60cea3c4f7199328</Content>
        </IndicatorItem>
        <IndicatorItem id="178f04c4-9794-40e7-b7d5-7543a48b49a4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5583278cec59b29b1418e078ce57dc57cca8831a</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="c2ada7f2-6a47-4421-8e87-5e5c55fb380d">
        <IndicatorItem id="141f6931-dc18-462b-a916-8c33c9b3f93c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Arg1.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="b3bfff24-47e8-4c20-a9f2-0e44b57d2c7b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">7d7dc77c22b63183bfeaadcffc6dc789</Content>
        </IndicatorItem>
        <IndicatorItem id="0aec1f73-8465-4cf6-a1a2-f4bcad63acd6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">b254fe2bb3967a5f5093567a1204bca802e73a3f3a289c320b18f0f73bc7c5ec</Content>
        </IndicatorItem>
        <IndicatorItem id="ea73a81e-45a8-4d25-9d35-972d13856e65" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">55c8477480442b6a9478cb75c5defffc1050b934</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b34dc6ff-799a-43ee-8c6d-59aedd335a6b">
        <IndicatorItem id="ec583bd5-18ac-4fe5-8a71-e74b08da11e9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">VMProtect_Ext.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="09e9201d-97ee-4375-a6f3-8d9c917c9756" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">7c43361c94bddf46c991eb83d9955596</Content>
        </IndicatorItem>
        <IndicatorItem id="e075b7de-3f4e-4737-b36d-225b3fdd441c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">e4c4086b2cd79453fd7a25db4c079f4ff1d183947499fdd4961f5df8d60a1c6d</Content>
        </IndicatorItem>
        <IndicatorItem id="03074b3d-1026-462f-ad3a-b6ee003ed6a9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">56d62fae86162da2fd798dbc8eeecb088c7c20eb</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="3bfebcab-102d-45c5-8226-57d9fac391ea">
        <IndicatorItem id="ddb13f7c-d4b2-4f3b-bbfa-a9604a1e40ea" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">STCAUSAL.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="0ea2693b-d8b1-4e2b-988f-f75704c73bb9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">bb1b6f26d6f94d8fc704b4b7892aeeba</Content>
        </IndicatorItem>
        <IndicatorItem id="a6627fec-c163-41c5-8198-4ceb702a94b3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">e69a5ff4fc4e3a1958d1d25f31ab85bcd477c2bc95365a01c513c22715f2db0d</Content>
        </IndicatorItem>
        <IndicatorItem id="6b86dc56-2946-4417-a49a-6f7d1c6eb395" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">57970567442a5d3e66e10c4852172bfc536d77be</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2a79be7a-847a-4e7b-ae9a-9f4df86b42ba">
        <IndicatorItem id="8d8b5326-a150-4c85-a86b-2e59388548ba" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ppsx.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="3f08a720-4e42-40eb-8ffa-538acfd1aaeb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">7f1c1146f08a03ec811f443ac6decc15</Content>
        </IndicatorItem>
        <IndicatorItem id="52e380aa-4dea-4164-bfe1-12679885fc41" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3e9a6f168c4f9f6ce6c6db3fee35218408ee0f79189f53e174f19a439e4036fb</Content>
        </IndicatorItem>
        <IndicatorItem id="9bdbd1ce-d1cf-49c5-a10b-4f481862e36c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">57a0d519db2354fb7f83f5243d4a9fbecf37f677</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ad92597b-5c41-4e2d-a9a4-1b15336b76a4">
        <IndicatorItem id="21e8a56a-7f81-4991-9028-fda8ddf12e6b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">VMProtectDumper.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="114b3933-61e2-4e83-b2c5-4658e4155e11" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">39aad650128cc31ff28290f3ad290f6d</Content>
        </IndicatorItem>
        <IndicatorItem id="051195a3-7d04-4e67-9687-7b91aae21345" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">1a67b08eb7be0ec141d407b6273bf9358874f8431eb79394f7222387d2e3b198</Content>
        </IndicatorItem>
        <IndicatorItem id="0c73172b-3cf5-4cd4-9653-a37a258a0101" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">57d7c162702b871614c43f1673a91a4f4e182512</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="187ccec8-d926-4839-93e0-27bf6755f88b">
        <IndicatorItem id="27f90e2d-99a5-4c01-8a96-124ac09abd80" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ITAS.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="105b37c7-d982-4ae8-a0df-569138fd67a4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">dfc34a63fe9bb7437fb85bdaa9598a01</Content>
        </IndicatorItem>
        <IndicatorItem id="50fe3ebe-bc9d-4e72-89d5-bddb994f9f02" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">f10aea369bc86b9350584355cc31bb8c909a744e747f8a9840bd0bc85fce176e</Content>
        </IndicatorItem>
        <IndicatorItem id="4b998636-174d-4d2d-8e67-8973137d57c4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5851c3fb0957243b75f93ee7718d8a311035eb0b</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2cc10728-15b0-44c6-a1df-6cf7d478203e">
        <IndicatorItem id="def4af2e-f5c4-4e14-8e15-589ff41edf1c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RamCleaner.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="038e9d50-05da-4771-b35b-908f2d3629e7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">40e118e4ed768f32da3bd4737a5fc60b</Content>
        </IndicatorItem>
        <IndicatorItem id="49939faa-1241-457e-a9d4-d790eaf6e7ad" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">7a136aff189f79dee342378d9d011ef35b639840148989670cd9ed3aaa404cdd</Content>
        </IndicatorItem>
        <IndicatorItem id="afaf8d94-434e-4603-b0f8-b4dd059e84cf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">58611fe7ab6aa2e2550c40a059c9f11e88b04252</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="14cf8358-9da9-4165-8f0e-8876db8b8c6b">
        <IndicatorItem id="e436425e-4007-4fab-bba5-ad440ce1a731" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">MSTORE.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="0da7c1d5-4b7f-4bed-8dc5-f0871a6b853f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">5bcdf425169900ec224039b72c6ec5dc</Content>
        </IndicatorItem>
        <IndicatorItem id="843b7898-ab84-4bd7-8be5-a14abfab5b3d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">c65d9d6defebeacbf761ae61baee0386dd7aeb2bd8577611edfadfb765e6ca52</Content>
        </IndicatorItem>
        <IndicatorItem id="907b39da-f605-4ae9-ac27-a9bddbf0a44e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">589c73842529a15fa9b77b6d4c09b4f519b16fc5</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="d0d34728-504a-4721-b4d7-32b9e20004f2">
        <IndicatorItem id="33a6b773-d9eb-4848-a12f-76b063d05928" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">idau.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="73176008-beb0-4a49-aed8-407a228091b0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e0a0e370e0c26624162f046429f3b0e5</Content>
        </IndicatorItem>
        <IndicatorItem id="add5db39-d7dc-40a4-a403-a2e6affe8ad3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">90690ebe2fece6a3432d3e169d26190162bfc3329ba5e4f0d157bf4ca853ea03</Content>
        </IndicatorItem>
        <IndicatorItem id="589e0cad-b624-4e67-8949-a35b7e25ba82" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5a440cc223e49f99bf921e211d32b4a4f3d18304</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="1bec61eb-c464-41d4-b903-e3eef56c9f80">
        <IndicatorItem id="c953187a-7491-40b9-94d8-bf312aea735c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">scout-p.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="39375b87-0053-4fac-afcf-82c7966e811a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2911e7d0f7a9ee343532865de81b1cc5</Content>
        </IndicatorItem>
        <IndicatorItem id="3a63a8c2-2449-480c-a9fc-8905ccffca55" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">9db48e1cb712104830461c062d0a93f8e3b4043c0ab8b2dc0e1f5599827f4e21</Content>
        </IndicatorItem>
        <IndicatorItem id="3682dd99-48c1-49b5-b85b-f769a65dce93" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5ab36b7bb8b782cdc3a4670adf3afa2dabc978b8</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a596b148-bc58-4b71-9e6a-b96075854bda">
        <IndicatorItem id="9e5753fa-4220-44e2-aeb1-cd8ab3af455d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">inst_helper.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="52175b8c-8d16-43b5-87f2-981ab00af352" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">14b03ada92dd81d6ce57f43889810087</Content>
        </IndicatorItem>
        <IndicatorItem id="9238e1d6-1b75-451b-b85e-cd3ce0b401b8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3190e725cc9eb7c116242da2d3f5dba46853b20f46e681df262e201cc22117e7</Content>
        </IndicatorItem>
        <IndicatorItem id="4a53577f-c4fe-4752-b207-e4fe1eeb9325" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5acb3aa1f44924b0b1d3e9cac3098ad709aa397b</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="8fa790e4-e117-4435-9380-d6e40e7c91f7">
        <IndicatorItem id="72cc5dba-bb45-41f0-8cdb-295e03413bc4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">SALVTIMB.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="6ec7bda0-a664-484a-a7e9-fdcd188fda20" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">1ecb837c25000482f9eba7b016f97d53</Content>
        </IndicatorItem>
        <IndicatorItem id="fb147055-b81b-4440-a603-ac059e59dcba" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">64abe3dea01a2064a62916e531a189ed93d730aed9876dc439c4eb78e3076345</Content>
        </IndicatorItem>
        <IndicatorItem id="0b8d629e-2e62-4187-83ce-a08099fd3d8d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5af183d124743d3a8eb6487d87c2d642c4129445</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="8674b0b2-3a1b-4143-b365-f3f1cd85b9a1">
        <IndicatorItem id="b87e0058-2332-4d4c-b253-a3c9f1950090" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Y2KUPD.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="a495a74d-1147-4351-a9f2-589152cb9de0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f6d8cd5c258af28d37437710d8d1c92b</Content>
        </IndicatorItem>
        <IndicatorItem id="317b7613-8e22-48f0-a7b8-f350048e001a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">0e3857bdba2e678a98da13317fd128341247964349c2483971e650b8d19ef914</Content>
        </IndicatorItem>
        <IndicatorItem id="1ba53b2b-48f8-4d4f-bf3b-57cbcc8ac7cd" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5ca3d40a3b4b9309f04f6eb0829dee38ac55dbb5</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="db130a2c-8b9d-4b14-86d9-99f0aa02bd3f">
        <IndicatorItem id="74963529-3b9f-45b3-8de2-e5e9fc16e450" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">cygxml2-2.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="f89998c4-913b-4ca1-b2dd-7a297487e7ca" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">ba6fd88683895e4e4a4aa32014ee93f6</Content>
        </IndicatorItem>
        <IndicatorItem id="1bb14e38-c586-4e56-a6e7-049d46db0afa" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3e1ed9e5fc7ecaa8a01b6fd160cab39d251390a21fb7f6bb98e070efe1506617</Content>
        </IndicatorItem>
        <IndicatorItem id="6e58a32d-8923-4ac1-aac3-ac9039ea5e96" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5cb07296bda8758a6ad52abf8cbea611ffbfd390</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="39e3614f-9888-496f-85a1-2598fbade232">
        <IndicatorItem id="e36b7456-6f39-4504-b56b-2c54219829a1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">WinEvent.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="fcb35364-035d-4cea-858d-2d5babf52b24" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">5ba76e2041fec128933cc09418df59f3</Content>
        </IndicatorItem>
        <IndicatorItem id="3830a98d-462f-4d88-a6a8-9b26a28ca46d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">635cdff6a80983828b251fef7147f2b92a6446cd55ed7127c8140cdc8100d60b</Content>
        </IndicatorItem>
        <IndicatorItem id="ac937833-e0d4-41c0-a06b-93c672e37adc" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5cf34cc014610ee9904e5839512144345f854a07</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="30210a2c-6d2f-4c89-86c1-7b6600981892">
        <IndicatorItem id="62b1d3aa-c5b1-4fac-abec-91864b4b4468" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">iosusb.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="4b04c4fa-7d8e-41e7-ad64-ab37e228ed63" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">82b07d1f6a53b4073ac2e66638051ff7</Content>
        </IndicatorItem>
        <IndicatorItem id="467627be-774c-4944-acb3-90d4096ce4ba" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">f009f01467722aa8ba3d7543b9dae37fb8f2de2e0d6ff46755d9684b47775e41</Content>
        </IndicatorItem>
        <IndicatorItem id="b291625a-61a8-4e45-9977-3acde6d39833" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5db463fdb694978f876a9f94c9578e8182799ce1</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="c74f6983-5fd5-4726-9a51-8391b38b0b97">
        <IndicatorItem id="9a8d3d2e-8264-4355-b72f-05a093ca35d7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">petran.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="c11a9172-875d-4394-b99d-c20dd38306ce" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e1086a6c67599a6edf00a209891d29d6</Content>
        </IndicatorItem>
        <IndicatorItem id="eb1d70c2-c242-4014-bdb6-da36f88e1524" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">d4414fffcc561578f53bdffc0a61ca081f45f8a7f203ec012ba80a3d2a45b7b0</Content>
        </IndicatorItem>
        <IndicatorItem id="bc96b570-df2e-493e-b280-476dbd66788a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5ebb4bce1fcf09933c2d61c54b58721a20dca562</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="8f142f07-7e8a-46c8-bfdc-fe7758ec53f2">
        <IndicatorItem id="dee13bd8-94fc-45c6-8b83-bd146e863ccc" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Quezzolino.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="0699db1b-699f-4454-8fd1-9db94c217f9e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">7f2aad2ad7bced650d9eb19dc80502c9</Content>
        </IndicatorItem>
        <IndicatorItem id="b8b4b798-984d-4ca5-9b22-350b7c947f22" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">e378812f4347b6ec7a517d9c06dc1cd608322033743ec075afe26857bb65c6b0</Content>
        </IndicatorItem>
        <IndicatorItem id="92003697-3eb5-4b77-ba1a-9ce860a0eb4d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5ef6c7729e2f6d445fd3fd72f93ec637a5c32789</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="fe8f9103-51f8-49cb-a4ba-77959c15ff31">
        <IndicatorItem id="cc3c9571-fdfd-473e-b3e2-2fc3d08e2759" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">cygplist-1.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="c979c98f-4512-44ce-b777-4bcfa9ee85ae" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">ec9e2fcff1499551a0081ea2a8970684</Content>
        </IndicatorItem>
        <IndicatorItem id="a5f64dfb-9417-41ef-b143-30e32b7a8ee3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">eefc30488c1c086f1e1edbf8b492875c2b19a56cebb623d163d1545c9c504f9c</Content>
        </IndicatorItem>
        <IndicatorItem id="f43d3314-537e-4b95-a2f9-4f82f41174c7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5f2c564a015bbcbb062d76cf4ca019112d3b1a50</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="cbc9f224-2370-4f69-a272-c59ebf8152d7">
        <IndicatorItem id="5fb457ec-162b-4017-a044-3fddbb6e31d5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">FTS4BT-5.6.9.0.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="b26e3ec2-269c-4ad6-9a70-fdc1b7a4f41c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">b314db793a2ad64d5ec41b41f310f178</Content>
        </IndicatorItem>
        <IndicatorItem id="afdbf886-6a0b-4294-a235-2ba45753fbb8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">60947bddb5e549732ae3d2b4749f5dbf8d054bb955c768afc49224d297c0ea72</Content>
        </IndicatorItem>
        <IndicatorItem id="79d69559-6280-4eb3-99bf-c01e112b0d11" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5fc4e70f6070ee05bd53fc787820ffac5d509b9f</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="d6029926-332f-480e-a406-c503c8c5b1f5">
        <IndicatorItem id="8c9485e1-c889-40f1-ad35-705c16f749f7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">CONFDAT.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="430885be-d8f3-4346-bd9e-145936e8a169" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">eb4ee35bbeafd2a715dba5826c2468c8</Content>
        </IndicatorItem>
        <IndicatorItem id="d2158e39-eb16-41e7-afb9-97b2b1b3eb48" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">f40712947be07627efbf9d4aa03f158c22afc37e3236beb935a495d3084db50b</Content>
        </IndicatorItem>
        <IndicatorItem id="beb9706b-d443-4fd9-b067-96a872963761" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5fe29720e565e0b15c63c1cd5d94abb781c8c635</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f30c01a6-5ed4-4a5e-8585-285a10b09745">
        <IndicatorItem id="7fdc1b2c-57cb-4839-adc1-f199a9558948" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">VMProtect.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="09dffa38-8b91-426f-b05a-f835c504e199" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">3b726e15b2e161a5acadb1a1bce87cb9</Content>
        </IndicatorItem>
        <IndicatorItem id="9302c477-d32a-4803-a583-0d0742c0e35a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">60562a923d1fb595d6e144a0957bc5f9fda0d3f105c316ab5e7d7cd27ff0c27f</Content>
        </IndicatorItem>
        <IndicatorItem id="f5838ba6-8775-459a-89cf-4a7364f826d8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">5fe9dad18883d1dc64dacb7aa8dd7988ca7b52bb</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2483692c-663b-4148-89a8-4e10a70636c4">
        <IndicatorItem id="6fc1dd14-c648-4018-8013-1ae8ffa3ebb4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">dropper.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="d4bb09ab-c243-410c-ba16-4d5d7a7dabd1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2a6ad4fb3a29795ec7b2f02304464b36</Content>
        </IndicatorItem>
        <IndicatorItem id="a07f1abe-afd3-4dba-87ad-9cb5b261c948" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">01b3cd088328aa2d87f6b3c435fef56b8a6033f78767a680d416f88c3e3ddae7</Content>
        </IndicatorItem>
        <IndicatorItem id="a007ea9d-353e-49aa-9935-bf28db2f81c7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">6081a7794e1fb5349ac25fbba1bb80e4df857c35</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="53263200-cdf3-494f-8c51-01cd36d40282">
        <IndicatorItem id="95b2173a-dbd0-4964-965f-a7e8c1767470" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">NoCache.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="29fa2eee-c6d8-4f54-883f-adb56d045612" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">29dd91494b86e42c45f1556359c5405f</Content>
        </IndicatorItem>
        <IndicatorItem id="d06dcd5c-1352-4a4d-9ad7-f9bc66f913bf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">32fb339ad17e516c1ffe6e84f792cccc200ba059cbefb3854b2aff7c82e365ba</Content>
        </IndicatorItem>
        <IndicatorItem id="05718efe-dd0e-4821-9e73-a88a5694f42f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">61b2fd880f41362add368265e91b018103127205</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a73c342d-2846-4d4d-8e8b-bc95b4532c30">
        <IndicatorItem id="9223ab99-e343-4ffa-971a-0eded723f7a8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_zlib.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="a3af2db3-68f2-4322-a588-4f084a8a97e5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">148b8f6c9e47e59f171e2cc938382ecc</Content>
        </IndicatorItem>
        <IndicatorItem id="b1ad280a-fc96-4b7c-b469-b5eec0efceb1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">60f4e50985afa8c0b2437c78467fc11784416791cd8cacdb37542a3e14d79871</Content>
        </IndicatorItem>
        <IndicatorItem id="42581974-c647-49f7-b75c-92388c754cc4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">6204297b04970e0f7c843a28636b2e5e28213e93</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="fa40c260-826e-459d-8005-b36b7de0bbcb">
        <IndicatorItem id="d29ae58d-9cc1-43c9-98ef-3fe49e2efec5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">mkidp.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="8b014769-77ea-42b0-96b0-bc7235638fde" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">aec0f36dd1296689a740e43e3b51d734</Content>
        </IndicatorItem>
        <IndicatorItem id="75efa383-feb5-4aba-b14f-2996d68a50e7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">c14327a7d2c7ab2d3edb5c0db2f87688c30f4f781c10b6017183f74403494c07</Content>
        </IndicatorItem>
        <IndicatorItem id="e1be6c5b-be00-42a8-b38f-d83bf76c2ecb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">621e2fbcddee9d4915c2bd4689234ed40475dfb3</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f74bf77d-8dab-4eaa-b1d3-009b01c3e274">
        <IndicatorItem id="7ed3a095-a887-4dde-8860-f70dc3afaebb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ABSINST.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="d5572983-bc38-4b74-bb0d-4d2acf616c9c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">49c8806b416bed507f9df77ad01909bc</Content>
        </IndicatorItem>
        <IndicatorItem id="949ec373-717f-4610-9766-e59a3b5acb27" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">babc5fdcf3a382aa3e30e7fb27bcd6c460e9b326aa229e7f0a6dadda03c64dfc</Content>
        </IndicatorItem>
        <IndicatorItem id="af8d05bc-ea36-4346-816b-f9ef53c02e22" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">6246490720a5ffc179f2e9d71821e44f9aeac18d</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="5344abed-272a-4b13-b300-5a8994b0579f">
        <IndicatorItem id="5fd1d56e-8a8b-4b61-b66c-0bcbe7338986" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">keygen_windows.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="141e508c-4ffc-4add-bea1-57a6b29cb3c5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">ef61dcb3711fd43d1a7e40b6dbd7d361</Content>
        </IndicatorItem>
        <IndicatorItem id="dc9bc9a1-54ce-4c05-8ff2-4349f8d4f9bb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">feee319cff39fe40dd0e0651bdbb24e9701d7f5adc9eefbfbd4e7e465ebee7f1</Content>
        </IndicatorItem>
        <IndicatorItem id="57267d39-422e-47e9-8833-33446995df87" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">62de7920de0dd9904b9af388ef5bb4c277a61051</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="d2640408-74e3-4a1f-87dd-a0818599f50c">
        <IndicatorItem id="bfcea82c-fe4b-4d6e-aa02-52790c1d798c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">LIMITI.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="5134aaf4-634d-4799-9445-fa515f28ede4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">1de8a17c47789523d32136e911761f88</Content>
        </IndicatorItem>
        <IndicatorItem id="88317ae6-c923-4ff6-a02b-658907b97bf6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">5887451392b8d97f6e28b8e4256b135279d3cb532e6751e2edbf90525fc2abd7</Content>
        </IndicatorItem>
        <IndicatorItem id="bb3cdf5a-341a-4d51-8174-d5e3e8ebff26" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">6440da9adf359f7b8d3132897f9e8106aa5acd0a</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a7f1c81c-917c-483a-b9ca-4b28cb5ee5a0">
        <IndicatorItem id="fe08d74d-a3c4-41aa-9e97-4dc4931b0eb1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">WiseRegCleaner.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="30cf5df5-6c6f-43ea-aeed-b2541608f58d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">4c1175dce7f7e505cb679813c1a5d681</Content>
        </IndicatorItem>
        <IndicatorItem id="2b609768-b297-4cbb-a6b6-1f7c8dc69b76" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">99e4d4e0117a5b391b2c2030b62915d066900690b14145bf444fbe5f98f90df1</Content>
        </IndicatorItem>
        <IndicatorItem id="13f16554-47fd-4dd3-a8bc-9b4895e6b4d8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">64c403fde6e9d3c902775a0f41b9182e599a7afc</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="4fbc3461-93ee-4b84-9591-711f02da7420">
        <IndicatorItem id="4f5e95a8-c087-4c81-9367-afa23dafe07d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakeport.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="df172438-8bff-4dac-9340-a2b73875bbc4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">095b95749149f237fe92e9c6c8f0f4a9</Content>
        </IndicatorItem>
        <IndicatorItem id="0981fef3-5260-4dca-a240-8130be205dc6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">bb3efa4fabc01da14ab5da04cde23902a866f0a308d58a0664e68555e71ecf69</Content>
        </IndicatorItem>
        <IndicatorItem id="5515e7b3-ed65-47d4-bbb3-d9c9f5073409" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">65739974e1b2f833c81619ea3df5dfb79c172070</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="beb705c6-32b3-45fd-b352-6489cff82820">
        <IndicatorItem id="ef64f570-de30-42dd-9c61-fc6fe26ffee9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">dropper.exe_good</Content>
        </IndicatorItem>
        <IndicatorItem id="0a7a3a75-5fa0-4501-8daa-7a959a9c1b59" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">af06c4e1e064a6490d488506960e8bf8</Content>
        </IndicatorItem>
        <IndicatorItem id="3e7d2c9a-2a59-4338-8d5b-548ebbf94c1c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">5048af2f388cfa1bd9ee077953f5ef1499a81ee57a8876a051ea96bd08ceb69c</Content>
        </IndicatorItem>
        <IndicatorItem id="01bcb61b-c658-40a3-bd97-b51628c038e5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">664c8dfb65f86a691df9641d9d1ab67c5b39cda4</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="935d7087-2a8a-4012-88b8-db3ca62a2438">
        <IndicatorItem id="e7f29765-394f-4494-8b69-90b290ce3fe5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">SQLEXPR.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="5b8eeca3-9522-4416-b0a0-ac2c93268cd1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">1c6737a462b2216520b2edb92a69c214</Content>
        </IndicatorItem>
        <IndicatorItem id="45decc9a-15f3-45fb-847c-4de4d1b83263" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">e1c2e858abf286ac76b072928c9581841618720d182394b8bcbbb7147bec0cf7</Content>
        </IndicatorItem>
        <IndicatorItem id="ab839d83-a8dc-403d-a5b1-92c03762102a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">67301d1e59e1584351f2725b27ec4c8933a7f57d</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="5b171f82-c55c-48cc-84c6-77446c534774">
        <IndicatorItem id="57c68f7f-b9a6-497a-8705-5a9648ee9003" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">_d9jaoFG.fXR</Content>
        </IndicatorItem>
        <IndicatorItem id="a6c003a0-5bea-411f-930e-5ff621d8a43e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">8aaaadb7d6a179226e462a9c8004e80e</Content>
        </IndicatorItem>
        <IndicatorItem id="066515c5-d76b-4ccc-8136-dc7ad2e98312" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">1a855cef1bb454e7313dba60885e16fa8cb3dced1e38b8ad59ad5429c4e12493</Content>
        </IndicatorItem>
        <IndicatorItem id="11a1dbc2-52e2-4826-a229-33cf6bfd1274" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">685c4287e74a9704d422ee577b7acb0748119f56</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a0a06cdd-d909-4f96-a131-bb49eb9a192e">
        <IndicatorItem id="1df7a594-88d2-4ef1-bfef-b7762eb08912" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">wapsender.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="32e0fe91-0eb6-4660-adde-b471a7e13cd5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">29d51c29dd3f0811d403c329053a2f35</Content>
        </IndicatorItem>
        <IndicatorItem id="dbc4cdc6-2822-4cc7-a326-b2a239a7a71f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">f1ab31f87585c824381ecd5411441bb1c755d81dd0f42bc08fbb061b9066fba0</Content>
        </IndicatorItem>
        <IndicatorItem id="04b8c029-5dda-4803-90f8-7687758fb1e8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">6a951c1da9080886fb931d01711b225c1368e6e6</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="20968a45-a75b-4442-8585-7c18f4ff328e">
        <IndicatorItem id="3ac5e637-c465-4187-b3cd-cef0338ef5cd" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">EDIT.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="3c1ffc93-fa9c-4f95-ae59-cd626be4e571" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d71b87917a6f4fe8e78928647fae8863</Content>
        </IndicatorItem>
        <IndicatorItem id="d5dba191-6ed7-4abe-be38-c87a11651362" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">442ee6ef5fc592627a3214336467559a86a57b9ecc899904e2f63320578a9fc8</Content>
        </IndicatorItem>
        <IndicatorItem id="390af3fc-1376-4336-b782-f6a97f915019" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">6cbc7f512855bc83414023fcc7b27d928885b56e</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="186b94e0-cbaa-44f2-abea-b95e81fccd45">
        <IndicatorItem id="6569527a-d3e9-4ded-926f-326c6f937e1d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">cyggcc_s-1.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="8a16e294-a7a9-4449-9bca-a53cdd22facb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">6acf6107069bae8a0b808fc1061737e9</Content>
        </IndicatorItem>
        <IndicatorItem id="9e4b272d-de06-440a-95d2-d6fc80e91df2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3a7373204ccd08adbd8349c8356cae9691f8817267c66de0b9959b979a77bdc0</Content>
        </IndicatorItem>
        <IndicatorItem id="f5407d59-774d-43ea-8eb2-c6f157fc6a35" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">6d351044dbdad9b5a922e174abc6454ff3de3ed3</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="361e1f97-432d-4766-9a79-2d40d218f186">
        <IndicatorItem id="7cd92b40-94d1-4605-a977-b6d470608c0d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSWinMoPolymer.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="d9b917ae-2479-4177-b254-f502c6d62fb5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">7f480a7b88f8127d31ad4ec3c825cf4f</Content>
        </IndicatorItem>
        <IndicatorItem id="3878a29f-db50-4571-a400-d0ef82fbd510" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">43b98d7043144d35b6657174669dcc1e695cb8e34c0df454c652bdede72ffb93</Content>
        </IndicatorItem>
        <IndicatorItem id="1a06bcdd-c831-402a-b950-1bb7400a5d0b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">6d9a2661920c2e0d26d0cd64994360fc5016c03f</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="48c272d3-a37f-4ab8-ab8a-a602e5cffe5d">
        <IndicatorItem id="6c828ee0-2559-421d-b5c3-eeabfb25ac73" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Microsoft Office Access 2007.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="a2a36958-7906-4642-b819-cb6fce5867b2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">0ee9ea3b831677df1ccde2eaafacd165</Content>
        </IndicatorItem>
        <IndicatorItem id="14ad91d7-1974-473b-b9b1-acdf475cf0c2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">13397ce53d5bcc5339a9e5b83144eed11e051666abcf26ad393505cfd82ee9ea</Content>
        </IndicatorItem>
        <IndicatorItem id="5be0fd15-cb7d-4c9f-abdd-1c520f076a85" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">6efd210c94ef5d49de0f705931b9e93b37e688fb</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2a118825-1b61-4151-8423-15025f6c9c0f">
        <IndicatorItem id="fc9a13aa-0cee-4641-8dcf-cb425673f1db" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">vb_decompiler_lite.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="c3e3ff97-71a0-4474-816d-63722048ae8e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d0f69bcd67ff750209aa907644500653</Content>
        </IndicatorItem>
        <IndicatorItem id="c628565b-c863-4f87-9bd4-febdc792ed6e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">285d311762bd9beaf15447dcbc33bb5c08f3c89a269de0046b5f5bf16519cac6</Content>
        </IndicatorItem>
        <IndicatorItem id="64cea231-c180-4efe-92ac-9715808dfd56" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">6f42840a26ccfcc114f316575b82c7b30adfc6bb</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="9419a17b-7004-4558-be9e-a79a3fc017ec">
        <IndicatorItem id="39760fb1-7a45-4a0e-b227-65fff9091ac5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_logon.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="d93edb0c-5dcb-4fa8-9ae9-d77b785f4b9a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">57acb822c5a03afabf9082ef3fd3306d</Content>
        </IndicatorItem>
        <IndicatorItem id="347281de-785a-4061-8dd8-1961152c2dab" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">0dd0325e09c0ba103aedc9e899192204ab29f4a0d35a7e53e5c800d9284a37e8</Content>
        </IndicatorItem>
        <IndicatorItem id="145a0f80-7157-4a09-b469-3d08cf927808" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">6f733dea7027321529d43421cb2cc5444b4e0785</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="89ea54f2-5e79-4f46-9e36-538a11169948">
        <IndicatorItem id="51642f0c-79e6-4185-8a7a-b85407a0591c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Client.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="66492915-6b0a-4694-acc7-7b5361bf5f0f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d2fc4263588dd09831222c60ebcb12ea</Content>
        </IndicatorItem>
        <IndicatorItem id="fcf73a95-eb02-4e10-8d01-3c1602765230" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">f6773236f089605d7604b90f5b6e3e223871f0bbfdad405fd89fde56cfc2ff27</Content>
        </IndicatorItem>
        <IndicatorItem id="3dcd6e3b-5d3c-4143-9472-e3980f1eab06" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">7188e984b7fa4b4d585c044963f93e46738aad3a</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="1499109e-ae5c-45a0-b12d-113cd89ae2a9">
        <IndicatorItem id="7567a373-f2c9-49de-9f82-1cd624df5eb4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">mkisofs.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="941b1c4d-cb9b-4a77-b9c5-92e4cf531db7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">6db0821c12c8fc6e42924ac589aa46c9</Content>
        </IndicatorItem>
        <IndicatorItem id="159ea992-b75c-4141-95d7-b3162b51faf5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">081d62be8d947b1ecbeb8f77c776bb79f06e86e39df4a182c3a3f25744313196</Content>
        </IndicatorItem>
        <IndicatorItem id="1a9463c7-1fec-42ac-9c40-360e693d16b0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">724c7684648b0bdcbcbe090c3eb8f3fa8b8d2da0</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="8487eb82-3cff-4e5b-9ab6-b98089963ace">
        <IndicatorItem id="580068b0-6946-425a-8065-cd40433f4e40" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSIphonePolymer.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="7bba1e00-5467-4324-b184-dedef1357931" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">37c3f6ae3f1ccee442cfefdb93a0abe2</Content>
        </IndicatorItem>
        <IndicatorItem id="35d1f26a-7382-4be0-b70e-fec8e0a26b56" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">9a68ae8f678636414d04cef6aaeea76b31f06870a039474e24ce0d299cfe7ff9</Content>
        </IndicatorItem>
        <IndicatorItem id="d513230e-746b-44a4-a215-dd67a8ee0df6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">7320dfe9ba71a56866ada74eb22ba20afa15a552</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="5915082d-6770-4ec7-815d-058e3f082b98">
        <IndicatorItem id="068e6772-082f-40f0-9376-6dff36599fd2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">cygimobiledevice-3.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="74c11812-9f7a-4a04-a378-9f613211e7b0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">798d889d9d01179187187b93dff893fe</Content>
        </IndicatorItem>
        <IndicatorItem id="7ef558cf-5765-4a58-8a2e-45be1cf3e30d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">77d97dd461b4357a9d9c1e96af007e7a3f090925e55aebe11bbbd97856611a12</Content>
        </IndicatorItem>
        <IndicatorItem id="178c0e2f-9c03-461f-b3f0-2f9993eac7fd" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">74939abd0764c8c36ca4856940fc42508f320f1d</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a04c9f0c-1952-4d81-85d0-626bf8df9912">
        <IndicatorItem id="2a6b1686-9005-4789-8ff4-8e61a9f79536" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_full.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="a2822c36-b41f-4c2f-ad65-51c04fbc38e6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d341cd4cde7d8b10b3362b3d1b640d14</Content>
        </IndicatorItem>
        <IndicatorItem id="8f57243c-fa17-405b-b3ba-223a6a64bb36" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">639152dcce89b669fa00213d853425bee35f8b79970a663492d24ce29421fb75</Content>
        </IndicatorItem>
        <IndicatorItem id="199a8189-2fa0-4955-8b4a-41965ad3f66c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">753bb0e7250d930957dabfdc0809352eed153b31</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ef4b5ae6-ef01-4b30-ba01-fa386783a166">
        <IndicatorItem id="511e93df-4e42-4988-8dd2-71425d134179" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">STAMPE.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="1362c654-5588-44a1-b579-71f2a1bc4399" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">aaf431b35c9decfd899ef935936997e1</Content>
        </IndicatorItem>
        <IndicatorItem id="fd7048b2-de7c-4939-970a-f8a83cfb7a42" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">03dddfa669c3aeabbdaf320ef725d4f9741096a13fe541946655b2acdab66003</Content>
        </IndicatorItem>
        <IndicatorItem id="1dbf37a6-15b7-4cb1-92d7-c8a9c55c5123" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">75cfa620be2f605ea4299b0fca5f66e0592934d8</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="290bd31f-26dc-4aff-8da6-41314140325c">
        <IndicatorItem id="ecf73f23-bde6-439f-ab7a-d54abdf8adaa" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">lj305x_339x-PCL6-pnp-win2kxp2003-it.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="f20109c3-85c6-47be-aefd-1503b6a31cb9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">612b11748ca5a7043ee5078eb10a2ddc</Content>
        </IndicatorItem>
        <IndicatorItem id="27e16b29-ab50-4a31-a080-0efd40d8e9e8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">28bde3aa00980e9ca5893004c59301f32de55a1c37951e0fb437d0b0f86c38d8</Content>
        </IndicatorItem>
        <IndicatorItem id="57c36103-710a-49b3-9f5c-8cc6eb8f68d4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">7635d83e0b4521663ade4bbfbbf331e00767371d</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ad5347ef-98bd-47ec-887c-6bf8d8b70c57">
        <IndicatorItem id="60cd7c9a-7dad-4204-a9c6-6279d41b972b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">MASKMAN.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="d855dcf9-cb60-4059-be51-af9697f15b74" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2ec4f4bef306fca8d9bd441f258324f2</Content>
        </IndicatorItem>
        <IndicatorItem id="3dcd17f4-cc28-408d-aa89-3eb249bcbfab" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">c1b7a8c1cd20032048681f5ace27be3d5b8d2e026e0f7698c69442ec9b518b4d</Content>
        </IndicatorItem>
        <IndicatorItem id="c20a90e5-bfcd-4027-a15d-f3662b5e55c7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">77836d5be70ea57070ff6f289ca6a61a3646b001</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="afaa0aa1-72a4-4b2c-a4fa-8c09711569f3">
        <IndicatorItem id="543e1ebe-e88b-4821-96f0-ea35d1a78d86" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">packer64.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="5900f76a-5d2a-4efc-951b-c7eb0653a560" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">cc0bb7d434d786bf35447cf90e3b88df</Content>
        </IndicatorItem>
        <IndicatorItem id="74a25add-72e1-45fe-9100-dd6af2dca286" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">5691fefbba82244c63e2166e246b1ef16d66b46ff1434e13815c8796177dc522</Content>
        </IndicatorItem>
        <IndicatorItem id="80d033ac-cd1e-4452-8d45-fb51304cc7b7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">779946589786d2dfea06bd102be88df02426b491</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="7b7a2721-f7b4-4aa7-a533-4b12322a530c">
        <IndicatorItem id="6b5f5e33-28fa-4133-8a5f-b1c6323c70f1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">clr.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="4aa674d5-0176-4d66-9d2d-77201f040e6b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f4f3692c0bb00a94130d3b205e1e9baa</Content>
        </IndicatorItem>
        <IndicatorItem id="fd7c2671-0bdd-43f2-b920-8cb35162bcd0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3ea8909c7e92d10a39ba08b002b489e718d77f12754e1bac8e69d62891ac8417</Content>
        </IndicatorItem>
        <IndicatorItem id="d7c71f00-70f5-41d7-9060-e8b34559bf8d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">7818cbabec362de92407234c123f5a6dd910122c</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f489e82d-5c13-4464-aeb9-a5a8f5e8a7e1">
        <IndicatorItem id="3faa4e37-e12a-4af6-a820-b0e2c165b315" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Shared.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="004ca594-9940-42d4-ace5-2ee937f793c8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">81d32d0789ba7705f5ed8183d09d6785</Content>
        </IndicatorItem>
        <IndicatorItem id="5611b65f-d54a-4d9a-a140-f38a358cd380" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">352999525fed75cc48b4d0af95448c67ee75b13b4645d4a3d6c632e4e3044073</Content>
        </IndicatorItem>
        <IndicatorItem id="68cd66b9-0c2e-404d-a669-a145ca67a964" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">78372f41d5e92207f278f059176bd8bdbf7b774c</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="fb5a11a3-4f05-4afb-9f62-e6af04b4a9b3">
        <IndicatorItem id="00c4e549-c567-4b95-b54d-ad59c363fd0e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">AppToDeploy-old.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="d60bd6e1-30d1-4023-abe6-60c093ae37b2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">69e25b6b67a9a1476408bfd09ef85898</Content>
        </IndicatorItem>
        <IndicatorItem id="05b96e9f-6b90-4849-8688-fd52ec37d5e7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">24a74d298d88b25bbaacf103a649896540a1870d89b76a17ad056252c065b393</Content>
        </IndicatorItem>
        <IndicatorItem id="d6ecc246-8c54-4330-a5af-cae2ea93dd45" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">785331937cb79657bd34efd995274e417cee3972</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2c22d7a6-470d-4189-8ae0-919bb7f7c9af">
        <IndicatorItem id="3864e10a-05aa-4076-a990-ab1b8d995113" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">polymer.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="48e8112e-7337-4c72-a0ab-71853a9de86f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">640b52a15b798fa6cee52f2f309f43f4</Content>
        </IndicatorItem>
        <IndicatorItem id="fd9a341e-7432-4eb3-aa62-240d42a7d149" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">4d96580225828b1b735a02835b5d753992be7ccdfcfb80c50d7acaae3e8c63c6</Content>
        </IndicatorItem>
        <IndicatorItem id="55963fc6-113a-4665-bd97-3b3118718805" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">79fc0befe9e5530e2496a9fa6beadaa636119aa8</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a1f4c8f2-81cc-4e36-8395-15cd24e36358">
        <IndicatorItem id="607888a9-3298-4cd4-8cf4-a2074002bfe0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Setup.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="8e6521bc-12a3-44ed-9e8b-07b952e7c343" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">5bad3163f9caf8686c7b9e43934a696f</Content>
        </IndicatorItem>
        <IndicatorItem id="d93d90ca-db80-4687-bf0a-7defcffb2b83" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">988246ec5ee40470dd1c6661f7509d43dfa3debadd66ae4722a091935ecb56d9</Content>
        </IndicatorItem>
        <IndicatorItem id="c14495dd-d67c-4996-9f1c-bbede55c5171" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">7b2507e7e06044fe193b811b7c6ee3768652fc67</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="bab57a6b-84c9-4ab8-ac0d-698d45b623b1">
        <IndicatorItem id="97d8f428-7af9-46cc-bdc0-c259c861e0f1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">tor-browser-2.2.35-7.1_en-US.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="fc1652d7-8509-4dd0-bba3-430800167c6e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">fa6d890c0780e5bb42550ac52e46e94d</Content>
        </IndicatorItem>
        <IndicatorItem id="7767ba45-2546-4f3a-a6f6-27b87356b58f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3b471511630e5ae364c28de07dae041a5b44a040f49e15735afa509e44801863</Content>
        </IndicatorItem>
        <IndicatorItem id="7b829de3-ab71-4430-b431-63a827a258a7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">7c1db3fff72b3c8180fe0eedd092328e29b61588</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="df769e6a-4b22-49b1-9bbf-d38fda5690e7">
        <IndicatorItem id="bae5e541-dc56-4f91-8357-974f605467c3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">concrt140.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="7d582cfd-682e-403c-a111-1ed172b2e80e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">c1c1a788693f849f94caab764af7a7bb</Content>
        </IndicatorItem>
        <IndicatorItem id="f34e2389-c480-4d22-a180-d387ccb09ef8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">00a2d004496dacd67d50e81e6d64ae801f6b2acf68f2404a8241d7e4fdea3109</Content>
        </IndicatorItem>
        <IndicatorItem id="a37dee2e-5beb-4e0c-a5f1-7663e2895615" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">7c99ead09840b0eb55011c948777b57af943bd53</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="dc7c3667-7343-464e-8699-37d454285c18">
        <IndicatorItem id="dc96ab34-8399-4c20-9240-4d55e1b860fc" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">POWERPNT.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="457106ad-3ad4-4851-8018-b60df7021815" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">dae2dab64bdffe40c3730f7797c4c372</Content>
        </IndicatorItem>
        <IndicatorItem id="4665b209-5ff2-4d34-8c8d-f7a903f2ada6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">1c5f12e0c15adf930b31402e6586f3a05a0173237ea13adce2f01edde9748992</Content>
        </IndicatorItem>
        <IndicatorItem id="446dc30a-94cb-4dc6-b550-be7d64bf77cf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">80bf90a45be02815e6765e931063948bc563a8af</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ed8f786a-d7b9-4713-aea4-b2637cf996eb">
        <IndicatorItem id="a6d2ea64-bb70-409f-939c-3d4e5213a9de" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">meltapp_uto.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="9b80dc51-8bed-4058-a316-a14e279252f8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">21749bb7bdeac89843a60b0d032cf874</Content>
        </IndicatorItem>
        <IndicatorItem id="5c702f44-8875-47df-b9f7-70cf3c3918a9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3bee8a4ee4efc157949587342ca73316eb9c95442cdb25dc349008c43dc64ba6</Content>
        </IndicatorItem>
        <IndicatorItem id="148e65c9-ed52-4e5a-ab37-31bd51d5fbe7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">827ad016a75e822dccd4d3c0c0cc178e7702a99b</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="55d06f7d-7f80-4545-ad18-0db5854f7cc9">
        <IndicatorItem id="cdbdb10b-a117-4e7f-98e8-dbff967abe70" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-setup-2015032101.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="f34cf87e-673f-4864-8b61-b2307b122079" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">80d9f6c1d803a2321ac5b21615adcad8</Content>
        </IndicatorItem>
        <IndicatorItem id="c9a852a3-5369-459a-9bd7-9182597dc310" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">78d54fd3dfdf0be1baaec7fd9320cd549582dcfb3e14257fa2169c0fa60af994</Content>
        </IndicatorItem>
        <IndicatorItem id="a3bd76de-f943-468e-afce-3833bbfd02f3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">832984edb287df44e38ac750086ccb5572ebc0e6</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2192908c-9661-4591-8ecb-d7c951f85382">
        <IndicatorItem id="f14d42e4-21e2-49c6-abbb-bdd8d0e33d01" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">H4DLL_NonStruct_Kaspersky.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="c9e7ab9a-9b04-4fa3-b3bd-24d09ff51473" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">32d9d4da5e7b99e2d70200d14003e830</Content>
        </IndicatorItem>
        <IndicatorItem id="43fbfe41-5604-46d7-9530-7cd1483300c3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">a61c9ae6ac4149619f058a09b83e7ba16bf6bf2492201fa299c25495ef01ba30</Content>
        </IndicatorItem>
        <IndicatorItem id="a7363bfa-987c-4a8c-ac5d-a50bcbf08f07" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">83852d86836e9d2193067919815418972e5cc03a</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="94b953d0-3b7f-4e58-be79-ae7944f31385">
        <IndicatorItem id="e3477e32-600d-48d4-8375-34d6bb205f87" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">E2KSP1_adc.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="ba9282fa-02cc-49b7-a701-447c067a921e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">6cccb83e8aeb7cb9fd87fef40b336820</Content>
        </IndicatorItem>
        <IndicatorItem id="8194db58-56e6-49c0-8c9d-c3f773b3af37" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">7b1d4378bae812656e4765e79bc388239381404d8a6080a16ff6776312442989</Content>
        </IndicatorItem>
        <IndicatorItem id="96a66146-e8f4-46a5-9f86-5684c2de8fd5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">84e70af98faee8d064d4734f79a5a0099b7a8878</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="6f0b4e32-8823-48bc-84de-34e0bb94f02d">
        <IndicatorItem id="740c5bb7-4ad7-4780-a071-49ae83a3ccf7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">AutoScoutTests.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="ae3bb7f1-4c53-4cc8-a0a4-87ae46f439a4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">a7bb3bcbd0b76c71cead0c9c41d060f3</Content>
        </IndicatorItem>
        <IndicatorItem id="00503c55-005a-44c3-816d-0452900f0b4e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">6e6f6e40a2716d11425a88b560e80fefd1a16d81ddee9663ff42ab82ea3a35bd</Content>
        </IndicatorItem>
        <IndicatorItem id="d27202ec-f33e-4110-a8c3-0673061379b5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">84fe4e29cceafae55caf85952c0a83b92c75fba1</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="3245b6f8-8782-46c0-948f-52150c54d9b1">
        <IndicatorItem id="02568358-085b-4062-8623-afa98abe7bca" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">calc_elevator.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="2adda547-116b-4201-bbd0-a5078db1b237" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">637969fbc85e184e93a96f146abd7bad</Content>
        </IndicatorItem>
        <IndicatorItem id="340badb5-6995-4881-b6bc-30da90249f92" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">9261693b67b6e379ad0e57598602712b8508998c0cb012ca23139212ae0009a1</Content>
        </IndicatorItem>
        <IndicatorItem id="b99c30d5-17b2-48f4-9215-b3cbc10fc14f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">8561291a00ec2c7cef2bd1d5daf48b350baeae8b</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f2008413-ffe9-45a2-b283-4a1ca79494cf">
        <IndicatorItem id="79eab6be-d9ba-4065-a92d-31c51b490a81" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">EMUDAT.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="f4341c1d-aaac-4fdc-b23a-83f781d7dd5f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">1707be88eb06ce450eaf19fa6a43e236</Content>
        </IndicatorItem>
        <IndicatorItem id="2aa3da18-8fb1-4d1a-bd30-a4f44d6c8897" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">6cf4dd214241effa8ccee50d66dfc4df2c67762c0decd0da1fac9787d8231104</Content>
        </IndicatorItem>
        <IndicatorItem id="ff127b58-5a61-46c2-b9ca-a56d8399945a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">86734f4dbf18b079de0b3f22251969a9f8e95004</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="678f332b-5cc0-4749-9327-310445dd78fd">
        <IndicatorItem id="1175a11f-28a7-4b6a-a8d6-9eb19d950999" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">addnum.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="73e9cd2f-beec-4379-9ad6-d3eb3acbbd1d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">41ff8be81c58eb94b5f59e5f91ba0eec</Content>
        </IndicatorItem>
        <IndicatorItem id="0df20557-88b4-4b52-a965-638c5c8adaf9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">8d9695d0af6c38b8552ab3182f41f7ae96dc6cd90e107ee7ce9c132ac9394b61</Content>
        </IndicatorItem>
        <IndicatorItem id="ca8da58d-22dd-4f4d-84cf-16bb24d8ab9a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">8697fca8fb4c27f64f42c393e527165e9604ae4e</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="58f612c4-a4a0-4941-8974-dfc73ffb5e70">
        <IndicatorItem id="91eaff65-fcb1-4adc-b1fa-ff65a3f865af" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Sleep.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="8637502d-bd23-47ca-9284-607b0a8187c5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f413e8519a67390e4618fb3653250572</Content>
        </IndicatorItem>
        <IndicatorItem id="286b56f4-f9d1-495b-8f42-3071e62b10fb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">adca333d2cee959c9323327ec8b3abd1193f34c520b80e4f699b49f70e14971c</Content>
        </IndicatorItem>
        <IndicatorItem id="ce4f5e56-b01e-48f3-aa05-1e064dd3b80e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">87c6760c13c17e35d90a203a2acacfdf2ada0ed2</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="c73a2acb-a39d-4208-ba9b-f02eaca044d0">
        <IndicatorItem id="377a63ad-0df0-4fd3-91f0-247c2ebd9116" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_bzip2.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="be5b4566-92d4-4e87-b71a-a8d6b251b662" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">a64c6ebab211184ab23ae72aebdab976</Content>
        </IndicatorItem>
        <IndicatorItem id="8b65040d-9e0f-40c8-ba80-d872fefb5578" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">8cf6258d002326a03cf4cd70d97837b02a1ba5f3451e88fa354947180fb93eaa</Content>
        </IndicatorItem>
        <IndicatorItem id="de744c0a-db2f-4721-9e70-a6943a57ab4c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">88c9e88086c8aa987eeebe70c5876b7660cd12d0</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2d8f1709-1394-4ca4-a023-058a4ad0768d">
        <IndicatorItem id="2a590bf9-31cc-452c-b497-e6101ef0cf4c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">seg_encrypt.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="090b8f6d-2fa9-4ddc-b5cc-b7d117c67549" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">3ae733df029c56fa2e3fc9c07458d8c2</Content>
        </IndicatorItem>
        <IndicatorItem id="807f5f54-2f5a-4821-b4bd-8d506a5e6eb4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">72269cb148f90e8dd2eefc947eb59af88e8f7bb9fbca2dc0d0d572f7a727a6e1</Content>
        </IndicatorItem>
        <IndicatorItem id="b40e856f-a617-4c92-a93c-ce814bbfba16" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">896fe06a9b746dbd9f581267fbf8209a9d071c77</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f71075b0-d46b-4c3f-ae41-84d8fcc0904d">
        <IndicatorItem id="2e6e6267-a39a-4196-b4d4-980ffbc17f73" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">NortonSS_1YEAR_US.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="5ac4f539-db04-4b5d-931a-6a355d65001c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">56ac87bbab2e471bad63918f3b953745</Content>
        </IndicatorItem>
        <IndicatorItem id="3db1bf45-e6de-4ad3-a4ef-0cd0cebae403" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">edc3fba72f9a485c43c1aa3cbe0c5752d8af2ec7bfecb48a46f467e549daac05</Content>
        </IndicatorItem>
        <IndicatorItem id="54e70e45-1080-4859-af52-d5bac14e95b5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">89b07f90ec9db28d0c53423e6f64745da7e607cb</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="1ee44c01-cfc9-469e-81a1-2710dfa958d1">
        <IndicatorItem id="2773a577-d88a-4c80-81f9-ac6d2a53fb48" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">secondstage-20080805.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="a1b04b4b-e06e-4322-9e28-689eddd393ed" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2c367d915ca37e237df16d8548151a8b</Content>
        </IndicatorItem>
        <IndicatorItem id="7ebd3a2b-4d7d-4b8e-84ba-30992ff0f274" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">b40d0ed8d1b7bbd0d52990ccbb7e927777d9854640c6c4b0adc683d55a965758</Content>
        </IndicatorItem>
        <IndicatorItem id="23f11b10-3ccb-4b61-a08a-b6de44c85cf7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">8a0fa4074403caeef809113ba7c84eba4404ed9c</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="1c373027-d4db-4c53-ad45-9285569ad7ee">
        <IndicatorItem id="f5e9fe3b-431b-4ec8-b57b-3b8b83e61657" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">PBAINST.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="91d3a6f3-f0e0-4b63-a01d-645faf744cf4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">a0d25a924335826c394901425e4d7da1</Content>
        </IndicatorItem>
        <IndicatorItem id="26dec335-9708-4332-a2e2-197dc856b607" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">a99a397d998961c176da6b16a3b68b8d6b209d0dbc90b9ab461657d9b50d5a7d</Content>
        </IndicatorItem>
        <IndicatorItem id="f752dfb2-4e81-45dc-b58c-8b5f743ef5c9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">8ad651b56ab534e47e25b19a4403394c1e9c19e6</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="239f8f2e-d30b-4854-99dc-4c89f15deaeb">
        <IndicatorItem id="e286eae5-1e79-4fba-852e-5f6012bfa9ef" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">QowsV3u_.I5B</Content>
        </IndicatorItem>
        <IndicatorItem id="1042f5e3-0fc2-44ae-8a50-57f542bc2a39" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">708dd9be439c744b43ce18303b8426d9</Content>
        </IndicatorItem>
        <IndicatorItem id="9057aa0a-7833-4f74-aa0d-7f12dfd5e86b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">d8d668e9d0c8e228b5d329b03cafd5e4b144cd955bacd7052d9c4a3b6ca67753</Content>
        </IndicatorItem>
        <IndicatorItem id="678d206c-f060-4ba7-a6b7-06a2717c5f82" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">8b4dbcc306c0df0b96505747e13e9c15747aac38</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="37acb1d1-c707-4a9f-ac47-c597ea7d9a3a">
        <IndicatorItem id="b4411e14-7992-4783-9999-068bd2bf1413" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_lzma.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="99b02b13-9296-405f-8639-6148a32c18ba" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">56f3437184e1ee96b1161135f3c5a1ab</Content>
        </IndicatorItem>
        <IndicatorItem id="6cdceee8-cf7a-4467-8e0e-f4151b939eb3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">8bba59ce301d510bc3b24c941841ee4a8b0858d37e31c9d59193b78e7da81d9a</Content>
        </IndicatorItem>
        <IndicatorItem id="7adc51fd-b6c5-4ed0-bba0-73b471e97d18" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">8cddf9c84e4a7eee3da4939ee0147d1e39ee3e1f</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="dba02cb0-cfb9-4ed5-a26f-b616e98ca027">
        <IndicatorItem id="53340715-42d8-4889-b8ec-5905f95077bb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">foo_flash.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="af0ffb3a-bc77-44c3-9e06-8dd9950e0fb5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">bc7e2c790deaecf69a69c042932e428b</Content>
        </IndicatorItem>
        <IndicatorItem id="780ce0fe-4bf1-4c1e-9eef-fab34afa1e35" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">d5d23fbad723009a6a6364ef28153ffc95190e269cf3749c3cf28128d4c89be1</Content>
        </IndicatorItem>
        <IndicatorItem id="1398c601-f085-4dec-84e0-75bd922f6564" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">8cec37385290b004e0b6514a44cb0bf7b7e64aac</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="0feac639-c7d7-4929-a494-9172c38a48f0">
        <IndicatorItem id="989157f5-9c82-4ac5-8469-aa2038b8b852" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">AutoVer.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="1a157dda-6948-489a-8830-921ee2d5c102" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">30e112dbb3b426d4ff3a99af52317c7b</Content>
        </IndicatorItem>
        <IndicatorItem id="2b1c0226-f123-4869-bb4b-f79aa1960751" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3e75d9a4feeb21434ea3294a36d64dda5165d66b82b1d567e7ba14dc13d437c6</Content>
        </IndicatorItem>
        <IndicatorItem id="10ace2aa-4868-4185-8d12-13880e16a110" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">8d62f6aa21a80a8a7084484716e688a1b7b0d2e7</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="d74babb0-e98a-41cf-8920-d1de9a70708b">
        <IndicatorItem id="c8d7a25f-5e30-41a5-bff9-1ada7a90950d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ldid-2.1.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="b2ed584f-b51c-4957-a7dc-8c40973bedb6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2b71bc9e931f39bebf8b27ad8a6c1341</Content>
        </IndicatorItem>
        <IndicatorItem id="950afe81-8264-490e-b6a9-5762f2ca65f6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">21451a9ffe2d82092e0b9f64601867ef9710e0de6cc2ec40de80571c6e6f8ba6</Content>
        </IndicatorItem>
        <IndicatorItem id="dc83cc03-82e6-446f-be20-9530b8cebd8d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">8e401062e69b1b0907dc6e30a1ef6e6b9fc03dd0</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="53d6aa0d-5bc1-4d65-b1cb-7b038972bd1e">
        <IndicatorItem id="42a8e4f7-91bf-4f8d-8e9a-ccaae5ee5667" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Fusione.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="d91412a6-59d6-459f-97a1-f0ab34600784" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">4cc8407e67e6cb18e79652e4999f9544</Content>
        </IndicatorItem>
        <IndicatorItem id="68f9daeb-3ab3-4ce3-a0e4-2c2419b4a1ba" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">a3c5c15d9bbdd342ed22dc84bbfb66261648acf6bd3f8b56dea0c36a0e55a0f2</Content>
        </IndicatorItem>
        <IndicatorItem id="91895ea8-7c91-4c85-bd5d-6dcd90a2423d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">8fffe10fbd56801e0e15f4796e2354a6c22c8c38</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="1037df1c-ce2a-48fd-ad82-4d10ed82c8b5">
        <IndicatorItem id="7e163cae-bf87-4c92-b923-921a15f379b5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-setup-2014121601.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="57f1b7b8-af0e-4162-a98e-7b15ab9ef3d0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">0c2329c8434221fb54ce3549e2748820</Content>
        </IndicatorItem>
        <IndicatorItem id="083b1201-bfa3-4388-88a0-d8acb04de77c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">9a6837504d6c41409008c3b50bbe006d5cc167e92f6f63a62320a78417307fa5</Content>
        </IndicatorItem>
        <IndicatorItem id="8aa38345-d949-4066-b2c8-eda75da822fe" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">90200a689e426745a286b46e69b447006900f671</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ffe2fd1c-1800-4294-9031-3a9b31ef0a04">
        <IndicatorItem id="e89022a8-68cd-4a0d-8e6b-f3834d3d0d95" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSDB-update-unofficial.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="10e1a6db-c8e1-4c32-9e75-0f0c9f386f9c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">19e932c289b936f407cd93dc4162eec4</Content>
        </IndicatorItem>
        <IndicatorItem id="095a30f0-ab5a-47bd-8a02-eec1f0197c7c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">fff8c7da09ace612e203a7d91b24e56a9e1715d5bfe6a7a4466adff284009a1e</Content>
        </IndicatorItem>
        <IndicatorItem id="8874abcf-2706-4752-9145-16d140e5f26f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">90342657a424fcffa836dfa5136eb362f49fdfb6</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="6a9d061e-eefc-4c6b-9a5b-fbbc87b5981a">
        <IndicatorItem id="cefac0f2-30e9-486c-a55c-44935223bd90" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-ocr-2014120801.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="17a15fb1-3955-4f4e-9040-5a5105295308" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">0d3d40766dd51072fb15b5e99dc9103c</Content>
        </IndicatorItem>
        <IndicatorItem id="c1183fb4-7c4e-491f-b4a3-55c015215eb8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">4846f3d91b3ebb54b5a8739f6ac5baae2ae28d8e363b87ed6fd37e1a012f32ec</Content>
        </IndicatorItem>
        <IndicatorItem id="fb511854-aa83-4420-8ab9-df6ebdf36109" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">90c004bd8d49231a04c5f2087afd9afca73a0b00</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="151c5882-5ec2-4b27-958c-3795bb1020ba">
        <IndicatorItem id="09f6a281-ad85-4365-bb6c-dff5fe1ea5ea" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_noagent.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="1404ea86-1df2-42a5-b407-6fb745b9dd7c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">bdfc8d71ed9d065f7fba87f84adeea3f</Content>
        </IndicatorItem>
        <IndicatorItem id="a39607d6-c84a-4319-8311-095dca477a48" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">91b0995ee522a6a01fe112dd6cdc21f2cd57b26ac84d8e3065f124ccb93c5eb4</Content>
        </IndicatorItem>
        <IndicatorItem id="e3e2277a-292d-4e58-80ba-076253c3fe97" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">9432d96afa2618213a7e2ccd6c9735291c694b9a</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="5d61ab62-decc-4eb4-814a-f96a230d3734">
        <IndicatorItem id="26a84797-715d-41f0-b503-8a6e374e16ea" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">mxml1.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="6042cca4-e2aa-45d0-86cc-2e0ea9ef5639" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">5a0ae7088982e61cad12d0bfcc14d070</Content>
        </IndicatorItem>
        <IndicatorItem id="9b4e1f23-9a5e-42d0-8fcf-c43367f4ab64" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">374f1774b3689e8f1cbbee2cdcef9a94bb30048b0f4f243b8c1c8d1d70ec8442</Content>
        </IndicatorItem>
        <IndicatorItem id="22efbcdc-bcbd-43ee-83a4-8bda98535fe8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">944e99725740271a01012d13ccbc9b9b4094fdbf</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="172f8dc7-527b-43e8-bec2-803b1abd9f83">
        <IndicatorItem id="c8dc0059-52c1-433c-9ec9-c08bbd44a72a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">cuckoomon.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="a7a0c473-2a59-442b-a745-59c3e30ddb73" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">c2979839d2dfee2d26b32510d4c35bc2</Content>
        </IndicatorItem>
        <IndicatorItem id="cfb9589b-ac4b-4f14-bca0-b5e32424500f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ea2244395a2f750564fc26d64b4cd50c2afd779b4404497564e0fe13a255b707</Content>
        </IndicatorItem>
        <IndicatorItem id="ce2bfb11-ecb3-496e-971f-8f684759e09a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">956397670afa8921a29110f9926ba118b0a9b5fe</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="6c2d7149-2800-4aac-abbe-76e90979d0c7">
        <IndicatorItem id="bf30bca2-54f4-4a11-b5dc-98b04312b148" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">soldier</Content>
        </IndicatorItem>
        <IndicatorItem id="a53b7df6-0de8-48c4-976e-517b4579e399" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e020e15263f94716347b3755415e3db2</Content>
        </IndicatorItem>
        <IndicatorItem id="4128e160-3965-4cd8-831e-34876e01ad95" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">1b8fc7508f0e1ccfb2fabb513054dfe517e29f42383d865e68f1b70fc96cc239</Content>
        </IndicatorItem>
        <IndicatorItem id="062e1d39-b974-4143-be07-e041f5df07a2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">96d230111d22f00762507dfde87cef89818741a5</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="75b9351b-a96d-4208-934d-e0fd0746608b">
        <IndicatorItem id="432aac68-2710-45ee-b704-8858977b0d24" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSWin32Dropper.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="dd3e242c-8591-4a8c-9f3f-7fd0ba27b7d8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">32fcb852290c66212c9f5377313b3c54</Content>
        </IndicatorItem>
        <IndicatorItem id="8ca27ff0-4615-489c-850d-5c6f3b4698d0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">0ca7fafd58f8ddca6dd182790b1a634205f45bac5c4a3ff4cecc3473d0c47726</Content>
        </IndicatorItem>
        <IndicatorItem id="1f534667-5422-4f89-8c2d-6f2970395bdd" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">97400f2cd6873187109fb9a4be4cc199067e8e4b</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="8fcd1463-2804-49f5-b8b4-bdbe28b75cb3">
        <IndicatorItem id="263e1481-b571-4457-a981-1e8825e655c8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">NTop_XTRA_3_15_0.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="9405d292-49fc-4309-8e01-37f08548a20e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">dd2461596f23a42bfaa417ae59778dd6</Content>
        </IndicatorItem>
        <IndicatorItem id="efd45d62-3cbf-4855-aa0c-2772e5651233" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">7f974955714319a86b478fbe7f10fe0cd8f2cd15bb87f6b006f7a9deae010d6d</Content>
        </IndicatorItem>
        <IndicatorItem id="e08a3f0a-d5ab-4f6e-94c3-ff9343053d88" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">97e7de9f59ea3b73d494cf06bfcc2f697854b087</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="670d1d95-7c38-449e-b59a-31646e3b380a">
        <IndicatorItem id="ce01eed5-f113-4df7-b39a-03b9b46f329e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">PUTTEOR.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="bc1981f0-27e6-4d5b-a597-bb6515ea10fb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e830bc1a73bd2fa0343098af12dfb5bb</Content>
        </IndicatorItem>
        <IndicatorItem id="33452070-a628-4cca-aeee-72a51e812e97" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">c859aa2de123b3526dd7e5645d8b631d1a7ce54d62534288940f215243fda561</Content>
        </IndicatorItem>
        <IndicatorItem id="978e235a-d84c-4671-b66c-77d5a41b0b95" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">99b08a3242fef9692878719c049962c1f653f0b1</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="eefae230-69dc-404b-9fb8-51c3208a8af8">
        <IndicatorItem id="1446343e-83c3-4ea9-8038-c54e7ec9b92e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">OfflineInstall.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="3ef675ba-123f-4e3e-b180-9572c11a2273" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">c1230aa332b3642ae0c6f64abf7823a9</Content>
        </IndicatorItem>
        <IndicatorItem id="99b4ec91-7f02-4632-892f-d86e11b844e1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3c031a468d230b44c1fe6bbc59d5445f78ce329885bc9f66687852fa7e61f7ed</Content>
        </IndicatorItem>
        <IndicatorItem id="011eab24-433f-44fc-938a-d3b98a53d595" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">99e4e7ed8dd2d54f6b68b7c0f03bb361ede438ac</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="655c168e-9525-4b11-ba57-17bd3d28ae14">
        <IndicatorItem id="1351c917-49d7-457f-b511-4d56e1e80620" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">LPInstaller.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="e259b2b8-79d5-4554-baf1-eca6bc1f3639" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">58a5485bebda446634c538f20362f0e4</Content>
        </IndicatorItem>
        <IndicatorItem id="bf847e87-c78b-42d0-b01e-8830a4117f47" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">976a843ee5a35e5015b5b2394e520e82403e6f81f877a4206bfe705bcb5e13e4</Content>
        </IndicatorItem>
        <IndicatorItem id="183aead1-706c-4f42-80b8-ad5bfed9eae6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">9b1ed2cd261bc4b6f1ccf8441dbf3d5c936b63c4</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="d7656284-fd17-4a52-8fe9-95339ffb2d1a">
        <IndicatorItem id="d201fbad-9d12-4d72-8a1f-95e0d63359d0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSMobile_2011032101-debug.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="577a42b6-b6e7-4b95-bbc6-55dc8398f3b2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">63de9e55e07f81e6d38eb859483b103d</Content>
        </IndicatorItem>
        <IndicatorItem id="fbffe4c1-ae26-4921-af5c-c749a97fd3e3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">6d22dbb5285391be5dcce7a2aed9f14b7ef57de90fd5b02d4bd7ba07d4a5d455</Content>
        </IndicatorItem>
        <IndicatorItem id="dd0e647e-646f-4ce9-81fe-076bae2ca3ea" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">9cfa6d066024a458e133fb9cfbafbdfa0b1c64f9</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="c60edefe-7a47-45b8-b6fa-9c9a38d8e404">
        <IndicatorItem id="3e853845-01aa-4c84-8e24-d750d23804c7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">bes_10.2.0-2.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="0de45c0d-6e6e-4c36-a421-7322a3877c6e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">85b8336ae0f1599eac6a4825aafd6f23</Content>
        </IndicatorItem>
        <IndicatorItem id="1bc5eca1-f703-4072-ab40-27c9840023fa" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">9415a9ae4a58ccc6a0e859aaf27e8a9b5e9aba1cb4fb2a711b9d209e388df6d8</Content>
        </IndicatorItem>
        <IndicatorItem id="dcf91cec-16d7-4753-8052-c38e4472761c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">9d5c5fee6f4da66e9a692886a458b5aab2c1de62</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="3b2b8119-a97e-4848-bc10-f26d69f031ca">
        <IndicatorItem id="8b493eae-b577-4794-919d-8893216dde29" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">install_flash_player.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="e40c19b4-a87d-4eb2-8753-6521b6353ae6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">1ee3aa67213868df9b08d00f3bfca6b1</Content>
        </IndicatorItem>
        <IndicatorItem id="5db457c3-ecec-4ed7-a3fe-6bc44dcbd65f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">5e5157e77089c4cfcfb2dfc82a574e465a943323e330dfe15316553d41f3d7eb</Content>
        </IndicatorItem>
        <IndicatorItem id="6882285e-4f07-4791-b70d-e55a231111a3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">9f6a16d59f1159110caf32df1ad2bb6183d8bc49</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f288038e-d322-46b5-9703-9e1f584dba97">
        <IndicatorItem id="f42799fa-33e1-43ae-b4e7-04f4ec40d8c4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">MPK.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="cffb9b61-69d7-4861-ba5b-7c0d044d19bf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">b4ffce10c64d1107901318b43b012e9a</Content>
        </IndicatorItem>
        <IndicatorItem id="227e7bf9-c50e-4e4c-8ed9-a6647a6957e4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">c8b3fa82fdd97f731851fa19611499b2c7a493cd689ac4d1796b3687d7fb6c82</Content>
        </IndicatorItem>
        <IndicatorItem id="1fc998cc-7c64-4cb6-a705-ce9fc3fb5dac" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">a047c5270762a05632b908c65beb14908bc4972f</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="80245dab-254e-4593-929b-b52d919bc01e">
        <IndicatorItem id="6e3d556c-110b-4b5e-a98d-1d5eabf3f8f0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-setup-9.4.0.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="b1731e18-cc19-4bbd-b1ee-2c757b4e90e1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">abd35fcbcfe6b55340cc4c7f993b7212</Content>
        </IndicatorItem>
        <IndicatorItem id="edfcd631-060b-474b-bc48-1be115a4610c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">c6aa5c8c72cb8dff50cefa4f3ec60fda50f64c54148658e3a1912728d83f5024</Content>
        </IndicatorItem>
        <IndicatorItem id="cd9c6f1b-6706-42e7-b00c-a3eecb7ed987" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">a0afad754583c3e48b56feabec8cca83627dccea</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="7a3c6bfe-1ea9-4883-bee4-183b3363a678">
        <IndicatorItem id="f5b07b29-b6bf-4e12-aad8-d7fc773a9d80" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Project1.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="b800d903-6ddf-47de-bb4b-86da25356b95" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">a05c9161177ee61f3e5aba75fc0a4970</Content>
        </IndicatorItem>
        <IndicatorItem id="310d7de3-53f1-4a73-aa10-ead1e743d434" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">559266876f060621f9b910ec75404946121460375b6f7812da717896e96dec26</Content>
        </IndicatorItem>
        <IndicatorItem id="4193763e-c593-4ccf-abf7-27501cf41e50" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">a14d7340ac6baf0b38eee37d7e3097d92a7e75e7</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="485737a0-e46a-416a-b0ff-647b8f593902">
        <IndicatorItem id="3ba91667-b97e-4a93-a951-b7c53b3ba68d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">PatchSleep.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="7f926482-8f14-4bf3-8aeb-1389c936fdfb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d00dceedb67e866c76b0968f8a4aa8e8</Content>
        </IndicatorItem>
        <IndicatorItem id="1026943b-fbc0-43df-9c81-4cd735c2db2f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">65c3784519e5ea050b8b669d2f074183c663abf5ef5335f7c2dcc6c283d5c991</Content>
        </IndicatorItem>
        <IndicatorItem id="01780705-1a33-4612-8035-e0278d74459e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">a29145b3eda915c5eb0909f5205a765950b81c12</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b2310581-0f63-4e69-b0c6-1fd30c726f00">
        <IndicatorItem id="318fc40c-48b8-43fc-9697-5e1e9bbef531" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Sierra Wireless Software Suite Full Installer v2-33.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="80da60f9-efff-48c0-a316-6c4a079b8761" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">b834ac77ed662c67942163bfa776f64e</Content>
        </IndicatorItem>
        <IndicatorItem id="9ba98217-2eef-44b6-943b-ced1cdad1734" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">1bff9f531ad4cbf5a829436b6e459867ec0a956cc1a40c0bd8eb3c0d4846293b</Content>
        </IndicatorItem>
        <IndicatorItem id="dcf49c49-57d3-4705-add9-e35a72959758" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">a32191c086d1b3d2e83b493490560cc225faf69c</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="de4a7dc6-2511-4b3c-a684-2a3f8eb1ae5b">
        <IndicatorItem id="771d17e3-6dc3-4c79-ac52-7961538265cd" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">DISEGNO.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="bb4e74e0-33f0-4341-9095-78a08a5ff51c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e5d5b83f1b1261f14e503636bda97414</Content>
        </IndicatorItem>
        <IndicatorItem id="a2b7ebee-7239-4d4d-b8db-2944de44ddd8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">a9d52b28ca8e049386417ffed62dd8da5b21d99aeb13dea25e6cc081e7c12393</Content>
        </IndicatorItem>
        <IndicatorItem id="2eddf619-cf45-4673-8e15-fe1a02bc8c5a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">a38d49651d80b052e3066c1b01292e4bc6f0abd9</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="0e99aa6d-b06c-4d85-8dbd-f8d0263ca3fd">
        <IndicatorItem id="4deb5896-b6ba-4ff1-b920-43e0d1769291" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">core.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="9d015070-54e1-4543-80ad-8b38ff96650b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">9bce542aa3fdd21c63e18d453ae8039d</Content>
        </IndicatorItem>
        <IndicatorItem id="fba5ddf6-9f01-483f-9916-cceff3a2d68a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">957fcc2d137e9164635831dd0ab8bca8079ec8b1a4c2eb6e8ac254c5732b025b</Content>
        </IndicatorItem>
        <IndicatorItem id="aaa173d5-a873-4a07-a386-4a0dd4b39935" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">a3a7545333638ec13ad33af6c4ec32a2d4f56c5d</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="81c462b8-8d45-4a87-9ce5-fcd9f1905f76">
        <IndicatorItem id="e3832005-be20-4943-870c-c4cb5e14ede1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ldid.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="26c77692-8f68-48cc-971e-fd39b061fb18" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">07238bdf46b7830ab24d2116023d5a44</Content>
        </IndicatorItem>
        <IndicatorItem id="5a78904a-d4d8-47d0-b26c-81de77f536ef" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">55d1a2e48799a40611d43447de148f830fa867b21bdbaa065806ac84cadc43e4</Content>
        </IndicatorItem>
        <IndicatorItem id="63ec1822-22bc-40a7-98e9-11ac4148b884" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">a3df4270a10a6a83faef107515581d8507d6fe05</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="c217c337-6157-4cba-8004-08ae791570d4">
        <IndicatorItem id="2c3bdfc7-8522-4879-8c89-34806322eb8c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">setup.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="d23b171b-f349-4eab-8dce-3f997b40d779" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">c219ac463ef4bb377b0b5e7ec19ce976</Content>
        </IndicatorItem>
        <IndicatorItem id="78f4fca1-3d88-4d1b-91fc-1193d9f47dcd" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">a5948e46db292b61d4c4032a7c7af15453477dd6ce4453daa4a6753c7763d873</Content>
        </IndicatorItem>
        <IndicatorItem id="e48b732c-ab6a-4448-bb3f-9f5f0f4acbc3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">a56a1b3f473346f0395c0de433938dbf4fa25a11</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ee29358c-7efd-490c-b18b-920ac1a82f40">
        <IndicatorItem id="e869abc7-2bc4-4c03-8e52-b3c97c821936" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">MAIN.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="81a965b1-3f06-4286-80d9-7d8632ce1f1a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">439e6d1b3fb051fa311bcfe1670f8a47</Content>
        </IndicatorItem>
        <IndicatorItem id="2f1ec20a-b6f5-4e1e-a569-d56a8044c854" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">2a83621703aae61467158e0c85869e0f2277ee0427472c4c5ac268859fee7798</Content>
        </IndicatorItem>
        <IndicatorItem id="7c4425a8-6dbf-48b7-b57b-ba288a6925bb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">a5763a96c727c51d851c0174fb340fbe84de37da</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2814b83f-92a8-429e-b6ef-f9b1ec3389ae">
        <IndicatorItem id="9933f6f2-f879-4197-a33e-6fdc2a175cd1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">OYMAN.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="9be574e4-9f40-411f-870e-7bfb0bb25cd1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">5e000fd125d326782a4b3dbd8eb65cf2</Content>
        </IndicatorItem>
        <IndicatorItem id="155697bc-a930-4d2a-8d93-86556beac134" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">602bb8e06f9ec55f1b4c78a77e4ec229548763076a69e6606a898c4dd9731ff4</Content>
        </IndicatorItem>
        <IndicatorItem id="489a27dd-4be0-4ef3-9de1-d73e971b6f86" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">a6e5539410661a8407ea022f4f55aa13ca674fa1</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="5c83c5bc-3f04-4356-8f91-ac0778c92c67">
        <IndicatorItem id="a9e00367-c6b1-4021-ab13-0bb2d1df6d55" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">CALCOLO.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="575c76d0-57e2-4bae-bd70-f8a39acf1399" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">6b6838c075c818dee0f52c4b2a692eed</Content>
        </IndicatorItem>
        <IndicatorItem id="2f5860c3-4a8a-47c2-9ba0-7f7385393826" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">eb4a395d7a0bb8b755b79f76ffe4bbed04dd630e07132a4ff12d684e178c7a03</Content>
        </IndicatorItem>
        <IndicatorItem id="c23be082-ae51-44fd-b762-30a03670653b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">a89c422df9659483d0b7b4d1d2b755960cae2d25</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f76ab8ac-acab-4d15-a7be-3203a89ebc9a">
        <IndicatorItem id="d344ad21-f437-4ec2-a947-835042041c1b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">EMUDCOLO.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="b924b683-6fdc-4be8-9f81-29c15bbc32cf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">658f5bae19ed9c8cea38f0d0b975bc22</Content>
        </IndicatorItem>
        <IndicatorItem id="c0d2c4d9-7d7e-48e2-afe8-6fc157adeb98" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">5da4b794cda68bc7f0141d8b84a6b17ca22011fc27a7730ff9b5a4e3b33320ef</Content>
        </IndicatorItem>
        <IndicatorItem id="9d1c4090-8535-4395-8cd0-986e046f2329" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">a94eaf297d1b70ab525b49b5aa3425ea1e96bc05</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="3472c074-cba1-4614-a69f-375239690911">
        <IndicatorItem id="c7ed696c-e249-4a09-949f-a5241bdeeacc" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">msutton-comraider_setup.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="9d6beea6-4028-41cc-9366-8afd4ba74abf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">89eab97e6862ab4c47d9f66f850e58ee</Content>
        </IndicatorItem>
        <IndicatorItem id="41530a03-d992-4440-a2b1-887f96a91d07" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">84058a01bb257a5c0f9a27f893ded585d349c9d87036d1a386fb8368cea2f545</Content>
        </IndicatorItem>
        <IndicatorItem id="0b36e851-e3f2-4684-9bcb-a6bcf405946b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ab30ae8b0bf1f3986d9635ea6caddf3878b26fa1</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="1a0b014d-a556-425a-94a4-2a98a3a8fb9e">
        <IndicatorItem id="10b16130-ba64-4cd6-b269-1edc3eadb6e4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-money-2014120801.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="5a062a3b-6065-407d-b7ae-25ca3e6f42e4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">c89f6c16e581e975a12ec19191a766d1</Content>
        </IndicatorItem>
        <IndicatorItem id="788ffa61-2ad1-44fe-843a-ce41330d99fd" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">654e7dd64ab4ef04ea22f63fb0497346fb8d484a488be428d78d32a17654604d</Content>
        </IndicatorItem>
        <IndicatorItem id="25e140cb-615a-4384-b2ca-72594f40527c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ab57daff9d93e71bcdf7f4b356089d3ae681602b</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f85845df-3ae3-43a0-b1e7-ed50f400374c">
        <IndicatorItem id="7d057253-389f-4e2c-ab57-08f0324d7b7d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Soldier.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="f10d0151-f33e-464f-afd7-e68396e19c8a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">5169e6cf3d06429b94bafd835b5e2791</Content>
        </IndicatorItem>
        <IndicatorItem id="0f5217db-2bca-46d1-874f-eee897fe1283" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ec0e0c640f83d91fc50d657870f4b1d07bff0300ad6ba841bc7a211160ca79bf</Content>
        </IndicatorItem>
        <IndicatorItem id="36b8838c-8bc6-4d5e-818c-accb1abf5884" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ac63f0f2ccfd7ef77b1369130e2d4316c306b4d8</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="d7955fd7-4640-4ecd-b3b2-3dc59a5e4313">
        <IndicatorItem id="2ce5c5a9-85da-4e02-b327-bffa485bfb7b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_dat.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="200df435-4dbc-4a6f-973a-39db75d22854" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f91a6d14a7e0257d2da9b1b6fbc6010c</Content>
        </IndicatorItem>
        <IndicatorItem id="9b836f10-8045-4685-bd0c-e0eb04ea8129" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">72ec760b698dc19693eaa846b2cc21ebceec4ee122feb30cb0802a9920af9898</Content>
        </IndicatorItem>
        <IndicatorItem id="55a45fa0-2504-4e70-8a69-392ba97a6cb8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ac8945be4493b660b4ab4283e644b9b0ab3f74a7</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="8e6423c1-a35b-424e-b4cc-f18ae153e561">
        <IndicatorItem id="ab17af39-71ae-4a2d-9692-c2eb7dec5190" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ie4setup.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="d645d739-0f05-4e04-806f-68df03d85fda" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">492de4d3eb48182e1bc0c39508b11355</Content>
        </IndicatorItem>
        <IndicatorItem id="c352db51-793f-43b8-ada0-cf6ffcb5d08d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">25ac093f3ceaaef2061ba86e8887ab494b4113b6fcc611bc69fddaca912715ac</Content>
        </IndicatorItem>
        <IndicatorItem id="69140d97-6750-4cf5-bad0-8468dfc8967a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ac9f559efde64457e2681a0baa88c1441f87a01d</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="9dad8344-730b-425c-ba06-6ebb3d89c782">
        <IndicatorItem id="82f6c7a4-d01a-42ff-b0d1-449565b5dae8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">CICCIO.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="5743f08d-1ce7-4b39-a849-4260a8a71364" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">525d30a04edc838cb927f92771a8dbdb</Content>
        </IndicatorItem>
        <IndicatorItem id="9fa84163-3cf3-4464-bfba-09dcb18b027f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">48097208ba892a8bb63e87b8d0dde52ac4d28591b9cf5aea1b93e1df0c24d500</Content>
        </IndicatorItem>
        <IndicatorItem id="e2402338-6f50-4dd4-98b9-593ae527c394" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ad82e8a839f84f856ef0d32425871987ac8ecb50</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="cf7c4ccd-e4a9-443d-9521-1acf8592ebb2">
        <IndicatorItem id="dcfd3076-94c7-4d5f-b233-e185c2ec46e1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSASP-7.3.0.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="d2848271-e430-4394-8df3-f941e1d0da77" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">8aa3c6e9cdb8724088c67c414691b66e</Content>
        </IndicatorItem>
        <IndicatorItem id="2dc83f5b-6c31-4eff-84e5-cf1cb89afb20" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">a801ca60fe94c8182274cbea1f5d3666d0b9aada7feffe3d9a613eb1c3a6f949</Content>
        </IndicatorItem>
        <IndicatorItem id="692f8c21-ebf7-4708-a23d-353eeedca5e8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ae4ca2e5a431c67a427a36823aeeebd89f3ed0cb</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="47524435-b1ba-4fce-93f7-b491c8dd0e1b">
        <IndicatorItem id="9fe84dfb-3614-4d06-abaf-e4a109a21ad8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Sierra_Wireless_Software_Suite_Light_Installer_v1-1-2.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="7e721cdc-fb33-48be-9e09-74896af7f10c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2c588e6cedd33f8d4f3122ec3b90b5dc</Content>
        </IndicatorItem>
        <IndicatorItem id="ceb645dd-5961-4ff8-a3ee-1ec5b98def51" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">e69f9773be05b1d0757ca826206aef1585e67282d2fbf544869034cff3a49194</Content>
        </IndicatorItem>
        <IndicatorItem id="503a041f-992a-441e-8594-7629dfc89ad6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">af2f9a22a1fa3b57ffeb41c45049e73fe4a6a284</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f860b09b-a131-42f9-a4ba-029e3b61b141">
        <IndicatorItem id="1cfb8d58-d26f-4813-ba9d-f3d687e63988" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">kis15.0.1.415it-it.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="0ebb67dc-e838-4813-a7c7-f8b6af643013" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">1024b2fb3058a691d20c0845a35a38d0</Content>
        </IndicatorItem>
        <IndicatorItem id="fe9b60ec-705a-408c-af31-3257f61f4454" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">683f59b3f4ea8b5b50446e08861a208eb154db039f5c769db52fb2df2ff39517</Content>
        </IndicatorItem>
        <IndicatorItem id="4e6ea7e1-ae06-45b0-bc51-91aaca9d00ef" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">afa5d700967a657dee8befc026241caaa41c5fba</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="08f790dd-fd35-4236-9e7a-8180e8d43e08">
        <IndicatorItem id="ebf18ba5-2a0c-4cbb-9071-cafb5989d2c5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">winappdbg-1.4.win32.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="4af1ed0e-78cb-4eb0-8111-a92e98cec21b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f2e0816f239a4066dcf4f035d3c91021</Content>
        </IndicatorItem>
        <IndicatorItem id="2dae75d5-5521-4e46-92cb-3f76dfdaebd1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">f4c27c563e9fd56990f1082cc185c8a6f0b04fee97b57042db10300e1eb37f97</Content>
        </IndicatorItem>
        <IndicatorItem id="9b88513c-eb6a-4457-ae4c-20929c5e0f0b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">b01b815d200a6cc90a0a15f9cde89fa93b7f9dc6</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2312770d-2b80-4268-b387-ef023e3de384">
        <IndicatorItem id="e291b3ea-ef23-4f9d-bc08-0aa07c954088" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-money-9.4.0.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="3c21d4b2-e00d-41e0-b02a-a81af2afb416" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">b0d0828a54cd184137de8d0deb698119</Content>
        </IndicatorItem>
        <IndicatorItem id="39292285-e29b-4923-a560-df96c3c0eaa9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">6e678dc4d933b186557f671913fb2fada37f342d5007dac0b745ca718d2e7405</Content>
        </IndicatorItem>
        <IndicatorItem id="e6a5f3db-0b66-4fb2-904a-2d072f505f62" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">b0e59fc1d41f66919fc25e454d26d9fd004e03bb</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a8b354c7-1faa-4673-bd49-5717f9a1f0d4">
        <IndicatorItem id="ad57c7f3-8d2a-415f-870a-ab5929c7d984" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCS_0000000001.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="a809343d-96b6-4fa3-978e-f847087c20bb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">6f653987ef4837ab20bd0b2d2f609ab0</Content>
        </IndicatorItem>
        <IndicatorItem id="4291e467-7fe1-44b5-b797-cdf58456869b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">a9e25fbb95253412de09bc1e4323602afbf5077aca71f861cbc7ad74581511a2</Content>
        </IndicatorItem>
        <IndicatorItem id="ef4cbd0a-8bc3-42ea-ab3b-cb93ed3e8e22" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">b149a8009f1c4e845778370d25f2df980adea362</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="3fddf6a1-83e7-447d-93cd-5fd3e5d40746">
        <IndicatorItem id="afc69acc-3745-4f19-86a6-b18fedaeb791" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">libusbmuxd.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="e1f1aac0-8546-4a89-b0bd-096f465dca8d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">650a784652a9717a921ca41b0e2ad337</Content>
        </IndicatorItem>
        <IndicatorItem id="5deb4207-8ef9-4d58-b89e-2699b65678b9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">de0fb47273fbffd2de3457a730c7e2ae6038b3452805f5bd95257a17ed004ac5</Content>
        </IndicatorItem>
        <IndicatorItem id="7a604a4c-942d-464f-8d56-c324786d8b3c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">b2065e7db241b202f8766dd4f295f0ec5b3c7df3</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="d44efbe1-c956-4d65-b616-16ecc45621a4">
        <IndicatorItem id="008589b2-b0e7-4d60-baa1-e52dcd46683e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">calc.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="b8290e3e-4448-4448-a2e2-67393ec7bce3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">0a011ad2222a93014e7420db94f6aa2d</Content>
        </IndicatorItem>
        <IndicatorItem id="c9749142-0601-41ce-a26d-7569303079ca" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">7279dfe295bfb075bff6a856097491fbd4c932970bb654c969a995322f0d03db</Content>
        </IndicatorItem>
        <IndicatorItem id="d83407f3-1168-49c4-b002-cae321f0d572" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">b36ceec3b2bf64802b56c610d3f0be29adc7d4b5</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="3246c036-2a2e-4935-bc62-296ad8c8e455">
        <IndicatorItem id="02443b1e-4e35-46b7-99bc-d8202c7237e6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">dualshield-hotfix-DUAL-347.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="1c93c5b4-dc53-4d71-979f-c21808de7df5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">15f8310eca75b9b00f1b691128d92de0</Content>
        </IndicatorItem>
        <IndicatorItem id="576c0ee9-0cfd-4550-8355-760ba31d3f8e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">fdc4a5593fe32d96fa2afbc110d90d6ce202b6adbd71fbd424642cd409b212c4</Content>
        </IndicatorItem>
        <IndicatorItem id="08f25cbd-d6ce-44b0-84bb-232439bd8a67" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">b58800c440d0da498f0fc6d2f53326035f5c3d16</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2d8fe1d1-6227-493a-ac2d-8527f4e2e454">
        <IndicatorItem id="8005b2e2-59f7-4db2-b816-c1775bdaf33e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ApiHookDll64.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="a5082882-6bfc-4a64-a8b9-61bf95be6a2d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">4c5f33ef824dbe36543a2b7e533dd179</Content>
        </IndicatorItem>
        <IndicatorItem id="38e65c89-87eb-45f8-a0d9-d334522ff5e0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">8d13453b459acd28dbc706677983b1397912124acf802dfa2b2f5c64f45c230b</Content>
        </IndicatorItem>
        <IndicatorItem id="0f572712-e9f0-4ac4-b3fd-c0481b444d4e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">b630c8bbbd1b957e21dbbdd5b4419a676f53e303</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b7c00e6e-c386-4136-a7ae-64a1b771e3ce">
        <IndicatorItem id="bbb1a409-9f35-42ad-bd5e-0bb21fc3f7d4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">plb.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="c77775fd-3be5-41c1-a12b-f89f74697f75" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">4b8bb84127b0967d316e3d507a0f3b59</Content>
        </IndicatorItem>
        <IndicatorItem id="a5472452-8adf-4888-aff9-b129abc19916" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">f8addfa091021a34f8b16fac0687b685b72ff1cac87ba1392d6195ab42954d42</Content>
        </IndicatorItem>
        <IndicatorItem id="5f68b8f5-f031-4eba-a0cf-460111b42010" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">b6435e8a9356ef2dc0d31b491b78f8c870a4bbec</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="9ac7e94a-3d3c-4005-879e-4d6f96dedc6d">
        <IndicatorItem id="c11c051e-8fb8-46d1-b49c-ade844dd5000" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">pelf.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="9662810c-8786-4f41-bc25-31009de005d8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">875a81e316b0759f246bde12bf5be852</Content>
        </IndicatorItem>
        <IndicatorItem id="fa955471-2295-4e60-b317-ba116c919026" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">eda9ba61ad01810aa53eece81626e913c4058a3b3cbf65fded907528117db0ec</Content>
        </IndicatorItem>
        <IndicatorItem id="9c400fa8-50bf-48f6-8d00-5c27628f0b29" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">b683759f398e76e471879efb52df1738bf1fc307</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="6206ab63-d537-49d2-8383-e391987e0917">
        <IndicatorItem id="ee8a5cce-44eb-47e3-866b-64be27b7b0e7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-translate-2014120801.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="c683afd2-7ff3-4c1d-a3fd-98f222c64ba2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">a4d16a3874aaf01d69c27032cb8988c3</Content>
        </IndicatorItem>
        <IndicatorItem id="b05f2769-2b66-4067-b9c2-ed6fc450f100" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">b15b2acbe02d7b0649b41d1fe7e0cd008761cba28d20c5d9fa9c17e3a430d0eb</Content>
        </IndicatorItem>
        <IndicatorItem id="ebe3faf6-0f60-40b4-9699-044bacedabe3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">b70d21894318a95717db2c5113be455ccd4c72e0</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="51782233-a763-4c20-b2a7-e2ea02d7efc5">
        <IndicatorItem id="066a458f-69fc-4076-9442-5208b608456c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">elevator.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="1c9fe8e8-4ef5-4c0a-bf82-6ba2e41276f9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">56eac983a8caa8c0037c6ba25e9a2d9f</Content>
        </IndicatorItem>
        <IndicatorItem id="4f5e296e-0d7e-4a1d-bc4a-42307caf546d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">fc609adef44b5c64de029b2b2cff22a6f36b6bdf9463c1bd320a522ed39de5d9</Content>
        </IndicatorItem>
        <IndicatorItem id="585d5bfd-30d9-4f4c-8f9c-2ecfe1aacfd8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">b7ec5d36ca702cc9690ac7279fd4fea28d8bd060</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="04ba5549-b516-4d9e-8ec3-56cafd237559">
        <IndicatorItem id="7929f9e0-d897-412c-90d5-ebf951792854" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ros.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="ea720865-4caf-44fa-9892-87a973569489" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">251de11b2d47bab208b578db6f4aa38f</Content>
        </IndicatorItem>
        <IndicatorItem id="afb844b9-fff9-4556-887e-6a29801e75ef" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">a9af1d410b796a7d89050bb8189048260564a1ff0b94db25d0f465ea18b1c02b</Content>
        </IndicatorItem>
        <IndicatorItem id="98655055-9aa9-47d4-b58d-2bdc94347625" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">b904f58d5bfd82d0778bdc9911f3b2193398e7cc</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="cc7beb11-929f-4e13-9f72-1d2fe90b10b3">
        <IndicatorItem id="c69155c6-7761-4e0c-89ae-a21a09dd494f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RSA_Demo_Authentication_Manager_7.1.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="7b59b2a6-22f5-499a-83c8-863b3424bf9d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">8390d4d97eb1075960fc69160ffec184</Content>
        </IndicatorItem>
        <IndicatorItem id="181a54fc-8f01-46cb-a3fa-3a2546ae77b4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">37fe299ed3fd2584c9f6ff5473b2de4a7bd27e2561e0aa41df5afc5bf6ec3c41</Content>
        </IndicatorItem>
        <IndicatorItem id="441a40de-49e3-4a65-b729-b6797b0bc923" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">b924089075e7c5a3f5517190743718db551488e6</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="068579f0-40ba-465c-914e-ae04a3b67e43">
        <IndicatorItem id="e12ed70a-1357-46a9-b63e-5b666c268706" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Microsoft Office Publisher 2007.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="304d5a74-53ff-4556-a522-39552e317540" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">64e273360b3f45a60cf99ad564954a19</Content>
        </IndicatorItem>
        <IndicatorItem id="83d29e15-9780-42b5-b63d-f449eae5b86b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">73ab06fce6b9746c1010a3c588c62069213d94134823b7527559a0f41c88d20d</Content>
        </IndicatorItem>
        <IndicatorItem id="f8a3c334-ea54-480e-9de0-4910968eb68e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ba553804706964473d3782468b1575548da0e211</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ada7b50a-868a-4182-89b6-6cb0c6bf7dde">
        <IndicatorItem id="745dc355-78d3-497d-8e2e-3e0d27b12e93" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">scout-pulito.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="904eb451-da18-4ea2-ab2e-8827bb3f3329" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">b8bb19a432127cae3680ab46140c4789</Content>
        </IndicatorItem>
        <IndicatorItem id="c9e48516-d482-45ac-a59a-eda06762710d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">5a45524e9ad739585c3851b32f660d777624c811d0b293b3474fa2568e8022d4</Content>
        </IndicatorItem>
        <IndicatorItem id="86f720d3-76f4-43c8-88f0-c2ad4d120c3b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">bab514067c72f51786054136d2e6ab927c62b275</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="d5e7ea4f-c4f7-41c8-8542-5218b4883dd4">
        <IndicatorItem id="55e33730-e389-4199-abc2-bd10f38a9c0b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">AutoScoutTests_vmp.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="d7e37783-ed7d-4516-9043-cd02bbbba764" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">cef9886a936a35af81ed23b702305ab6</Content>
        </IndicatorItem>
        <IndicatorItem id="5585cd01-417a-4a6d-b405-c65a48afefca" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">61fe96a5118b531e7f1659085bcd61084354961fb557588bae3619665a8dc681</Content>
        </IndicatorItem>
        <IndicatorItem id="2a802197-81bf-44af-a82f-73bda39a5d57" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">bbfbf78a4bfa692b9d152ecc679dcfe1db63ccd6</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="8913498f-7334-46a1-b9e4-ac3ff0f389f4">
        <IndicatorItem id="ef77ce60-a625-447d-b0f2-4db17774c56b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSDB-7.3.0.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="70bf736e-c6c9-441b-a1d3-4ab654d62d7a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">98ef32a6462b3ba8cabb372f5aa95cff</Content>
        </IndicatorItem>
        <IndicatorItem id="dfeb00b4-7bf4-4669-8d7e-0b2c7b894bc2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3ffcd563ca6222ff5e88928a363e38d482302de57b04c36dd710a4bd1c5d430e</Content>
        </IndicatorItem>
        <IndicatorItem id="157db75c-22bf-4ceb-8b28-fbd95d44d8fb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">bcb604b382a4e82827aec23246609c1314e993eb</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="905b815d-5bb5-4612-ac66-aa75c79c7bb8">
        <IndicatorItem id="82fdc44a-8a64-48cb-98aa-f5a03f60fcec" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">CPP-ProductKeyFinder.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="6b4296b0-80a4-417c-938a-01a31bfa24d1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f62c6e428738f074cf90f21e289dd34f</Content>
        </IndicatorItem>
        <IndicatorItem id="d13ea3f3-13e3-4185-a82e-c3f3370b9d21" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">a4afe60c024a34ae16dfbde1224550224ab3195f3d5dfe35c50ebd6a12fd4170</Content>
        </IndicatorItem>
        <IndicatorItem id="850f230e-f089-47f4-aa17-34a3a6a492d8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">be8a1093a62d3c2741227510ec09029a18b23a27</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="8f3f19b7-b6db-4245-8929-e18257d2cb07">
        <IndicatorItem id="b605d0b1-81a3-49d2-abce-718f53a4e27e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">libplist.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="f4463c3a-14a2-4c74-9471-bb1733a98cea" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">7d8ffd2d94d8eefeb6ae5e9bac5b5acf</Content>
        </IndicatorItem>
        <IndicatorItem id="11f10d3c-5092-4c1f-922b-157783716e27" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">2fc9051101b18b9616ce459221b84fef1c482e895c8625d0b366ab76baad6ad6</Content>
        </IndicatorItem>
        <IndicatorItem id="c1b3b004-5615-406d-b2db-cccac1b7f41d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">bfdd623cb959c97bf8cfd98c174eef43a88d879f</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ae425106-43f9-4947-9d65-0269e2a75025">
        <IndicatorItem id="ebbb4c4d-9900-49d6-bd0c-b68f792431fa" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ExeLoader.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="93df2cd3-0589-4f96-98ca-005177655379" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">83aff63d5b3855cff982422bebc779d4</Content>
        </IndicatorItem>
        <IndicatorItem id="a1a16f09-50a5-4904-8ba3-f7f851e9b040" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">32599e86cb3bc9e1f91ff630fa41cd140354a21ac47bdb48082fbb8fba900f53</Content>
        </IndicatorItem>
        <IndicatorItem id="6b22f9cf-8471-462f-872c-c00b38ae04ae" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">bff3f180564f072f45d72bd6a840e9cde68e863e</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2f962491-aee0-481d-9223-5cdf4b62d735">
        <IndicatorItem id="c4b127fc-7e60-4024-bbaa-677ddfed3526" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">DynMenu.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="2c34fcc7-0c6d-435a-b5eb-c7d343083fd1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">145b5fe784160a39877eddc6e7629155</Content>
        </IndicatorItem>
        <IndicatorItem id="0b1ca99c-99b9-4642-bac7-0d4d1715e8bc" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ddf1371ec3cafedd2caacfa351e9be77e9dbf263f143d6f81a6202e4303ac8d8</Content>
        </IndicatorItem>
        <IndicatorItem id="b769f9c7-39ec-43dd-b070-d48ea5cb468c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">c281e6eeab03aa06784f21206c86f2b30fec1dc7</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="af89ba27-a161-4f1a-a939-85f524e3632f">
        <IndicatorItem id="d49881c3-ea50-4a42-93f6-7830634e7b61" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">GETIMBRA.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="2e6ff1f1-b8d9-4560-8c03-757e8dca678d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">878fa0d8f5b48b2d91220c35d9d09695</Content>
        </IndicatorItem>
        <IndicatorItem id="f7a3cf86-26bc-43a5-80a9-d5f35748cfdc" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">2cf44c90107891c22543fb0b71612fcf3e531352425b5bd9d6763a019e3b06a0</Content>
        </IndicatorItem>
        <IndicatorItem id="bb357dc4-26a1-410b-a734-f03d4a98d737" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">c3dc5b959b4204c950beb278271be50efcca74a5</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="35fc8bbf-ac95-4a0e-8474-2dfe6bf6605d">
        <IndicatorItem id="336d039b-c900-47cb-8b44-86a96af6618d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Loader.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="40645c2e-3bf2-4e5e-b195-74b40b940d45" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">780c1904904356bb7e4304f37bd98c7b</Content>
        </IndicatorItem>
        <IndicatorItem id="4ffb05c7-37cc-4d6f-9ea8-e6207844987d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">c52f4d1cf3ff09b22cf2f4bef867456aa7426c00fcd19c38b66ee3adc7eba057</Content>
        </IndicatorItem>
        <IndicatorItem id="6d1d6052-79f2-45bb-8f96-ac811f6b4c65" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">c520096fc851bb0da060fb6cab274387ca8e8f88</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f5ed29cf-c182-4c35-bd38-67c8c35ce706">
        <IndicatorItem id="3710fce1-6ba9-4b0b-b9bb-ce79eb37cf52" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_notepad.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="abd3c931-4192-4323-b3d4-5f674ab5b6f7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">bcd74698b43531a3df7fb2f76f4b0a56</Content>
        </IndicatorItem>
        <IndicatorItem id="d2baf2be-a72c-4089-8f25-14031fe3acbb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">a23b5fc7d309b982f9dafc712b6a95c1cfce6102f86a7dc3f3013819638081a9</Content>
        </IndicatorItem>
        <IndicatorItem id="d816de17-c61f-410c-803f-ba8ff18420b0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">c5959b7d97f2855950bc35c9e0477b1940a43fc2</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="994444c8-d74a-4678-8114-3ac75bda46fa">
        <IndicatorItem id="cf87170d-7ee8-4e68-9de4-152ead564084" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">POSTLIST.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="617975ed-ee0a-483f-a47d-be04f1e0e8af" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e9fee25f286004357efc21038b71c3ea</Content>
        </IndicatorItem>
        <IndicatorItem id="5a6e389c-bb33-4ca4-b5c7-154084585360" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3f44a887f3c06f2fbc77e8c1f4f3af0308abc85cad4268a194eea51395e9cd61</Content>
        </IndicatorItem>
        <IndicatorItem id="8fce7319-2988-4fe7-a67e-3cfebe9b4dc4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">c5989c1360d61b53bfb1dbd45ec223d806b8dc88</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="0c6bbf6d-b5b5-42ce-8df0-e2d3c0d6924c">
        <IndicatorItem id="64c57ac9-8738-4303-be8e-27acab9838b1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcscrypt.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="bdd2ed3b-3519-41d6-b88c-9b4f7b8857b1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">062dba4f938910eb5f84fc70a224466a</Content>
        </IndicatorItem>
        <IndicatorItem id="cafbbb21-3cf3-4177-a660-47b6d48e256c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">2424e1d1c1820a2cbb194f053f84f4a2c11ee2c75f301985c9236678944d3756</Content>
        </IndicatorItem>
        <IndicatorItem id="b6e56f44-6f0d-4859-841e-b82e54ce9a39" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">c6677a7ae8844ccccea5672bb950f40111b6f1ca</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="63651ee0-c842-4a3c-8fca-009679e0b538">
        <IndicatorItem id="e1311aae-64fa-4f7b-9212-48f0a40ce65b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">PROVA.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="59b52912-2298-44bd-843b-ef05a1b1e802" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">5a724230ca622bdcdc0ba41e524821ca</Content>
        </IndicatorItem>
        <IndicatorItem id="5fd98df1-7931-433a-92b5-3bbc6b57587d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">90324a869541e0e67f0a3d4dcbdcdeefcaa4839edcb55ee163b7f26f80725278</Content>
        </IndicatorItem>
        <IndicatorItem id="7afa1b6a-afc2-4b46-918c-d8012d47aac8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">c6993c06bb4721a8637390b282e30d5a1c91a22f</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="153db28a-2b0c-43a2-a8a8-372a2659b59b">
        <IndicatorItem id="5bd65520-71c7-4904-96b5-05c6e91a4d91" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Updater.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="c8b75477-c47f-4695-8f80-03d26317a90b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">bc6545ab89ec3df3c915ef3c55be29a7</Content>
        </IndicatorItem>
        <IndicatorItem id="5efa5501-a762-49bc-9a7f-bf756a069b13" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">a58dd0b17c7989e3dcad1057c4f8473d5c18bc134b29f8aa52b30062c73ae672</Content>
        </IndicatorItem>
        <IndicatorItem id="cdb7951c-799c-4457-ae48-445cf3033ba7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">c6ed9d301a7c52d83896a7437ada2503a9f57d16</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a4247126-3605-4dab-a33e-d912c89ba7bd">
        <IndicatorItem id="7a59ed4b-cdc9-4ab1-91e4-ee4fe7aa830b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">hp_LJ3050-3052-3055-3390-3392_Full_Solution_AMWE.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="5b5c50fe-81d1-4304-b4df-c6e13c00a2ab" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">83fde241ef91a6d4134bdf27f6e89405</Content>
        </IndicatorItem>
        <IndicatorItem id="5ce665a2-1c5f-4334-8bd1-43b659b82d7b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">436e43664724b946197849cc803f364e10b5924567d96eb6e7cb7ce56a323825</Content>
        </IndicatorItem>
        <IndicatorItem id="ba154bea-9787-415b-a8eb-746f6020f161" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">c724345c3139c62b46e13c4c96730a2e370dd991</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="265cc4d2-fdce-4293-bb74-19ad5fe422bc">
        <IndicatorItem id="dfa005f3-c102-4ca8-80d8-f4f96cac8fbd" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">test_fs.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="510a0653-c508-4489-bc9f-0540868ab75b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">b1c1f4f3e9189ca1763e8b2ca3bbfdfa</Content>
        </IndicatorItem>
        <IndicatorItem id="58ac15c6-cc05-4982-bbfe-aa9d51f17e6c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">cedaf3f2bdbd936ca276b636bb119136d67e0e2fa74614442c95bdbae6c50585</Content>
        </IndicatorItem>
        <IndicatorItem id="f319e01b-2d61-4951-95a6-7ad8d695aa58" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">c7d3c7b4ff167ccc0957f5659c5591f2ed43e70a</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="5ba310a2-5862-45fe-a541-aeddc2d2fb6b">
        <IndicatorItem id="3fd21740-d4ca-4ddf-b791-c9f8de2e9034" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">fakedoc_rename.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="c2cad3c3-bc0d-4b18-928e-74a03c586d36" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d9faaf817ef1c3ee664659049dde5f39</Content>
        </IndicatorItem>
        <IndicatorItem id="c7a731e6-7f48-4371-b7a8-2b26d52b6d98" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ab4de0951de38c475d846da1da8336b97e886b6dbd694332f3624ee5595186fe</Content>
        </IndicatorItem>
        <IndicatorItem id="b45571b8-5f90-4da7-bcb2-bf36c07863b7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">c893cd86c0e0d6ed267a5f38c8e51b79436dac62</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="05aa8564-1bf8-4381-b24b-ac5552ee40d6">
        <IndicatorItem id="879116d8-01b3-4e8f-9e09-421ca3868e39" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">AutoScoutTests-size.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="ac79bfda-9d8f-4bea-b692-453b04b8bf7b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f69da77c13a651074c919ab26507c011</Content>
        </IndicatorItem>
        <IndicatorItem id="19ba6075-4471-42c0-ade1-c5e0254ff721" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">07ed3d9bd82a3b490f33f36117af3ad02152d51e9c2470eb0089dab1305368f1</Content>
        </IndicatorItem>
        <IndicatorItem id="db24e85f-658c-4b77-a172-e6d346dab4e9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">c926351a98a617b0be47608c5d03d08a2a82ee1d</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="3ae8a11a-c2f5-474e-8218-9797ac0eaa64">
        <IndicatorItem id="da761e52-4506-49f9-b8b3-242b3c0885e5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">sseIdrvdll32e.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="3b8feca7-fae8-4d68-b207-58128b10a1db" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">0f5817f32ff94351ed4133be59b319b9</Content>
        </IndicatorItem>
        <IndicatorItem id="1c222664-5bc2-49b3-b710-ca8940b2def3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">8ee48f42bcc3006d84ac7230f8a3aa811bbe1c0d5120573638c5ffe41af15fe8</Content>
        </IndicatorItem>
        <IndicatorItem id="def6a12a-cb08-4cb0-b679-8ac597891e7d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ca5ddf4b72258eb3c3d49a4511858ea4a2c18653</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="37c8121a-2762-43b9-8a38-3de96c5fbfbc">
        <IndicatorItem id="fe46912f-8be3-485e-8b21-a0ebcea39d0f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Patch.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="05ae2a3a-e02f-4515-9ffb-ab076ca096e8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">5cb4e4e218b97c09c885d157e83f7247</Content>
        </IndicatorItem>
        <IndicatorItem id="5a8c061e-e990-4e0c-bffa-28512df50abd" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">150924668c8d7cd9899360eba12f13246538c50fbe7ef1ebf234ed7128c9936e</Content>
        </IndicatorItem>
        <IndicatorItem id="66513d75-91c4-4ae2-a9c2-5b7e934e7468" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ca84583819c9723fe8d9fc69d8cee66687a180c7</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="76d373ef-e71f-432d-9433-42585ec6b1e1">
        <IndicatorItem id="889916ff-620b-4d59-90e8-4ecfab2ab4d4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">NipperME.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="50644251-ffae-47a8-a2b9-9d1eb78c4ed4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">5b048ab9669d8db59dfa4587a1ed0cf0</Content>
        </IndicatorItem>
        <IndicatorItem id="a2261337-5128-4e47-9b80-d69d91a69e48" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">2ae912e59afee8b92687549c81a49e5146985dae27502ad9e06637e481d5d627</Content>
        </IndicatorItem>
        <IndicatorItem id="e12fd367-6be4-412f-b0fa-4c283f757db3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">cb6f5376524f3b9110b9e61954c39f86e7e5dde4</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="3a070883-dc9a-4403-9c71-4c3c04a9bf13">
        <IndicatorItem id="4b452b7c-aaef-4140-809b-25c8de0a966a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ExeLoader64.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="47d9a4d4-e489-4193-888f-6fcab16d4782" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">0c635c5cfb5116c2cefc35ff23d41931</Content>
        </IndicatorItem>
        <IndicatorItem id="cb2d0237-f420-49cc-8ea3-6ec40bd9f32c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">1c3c6ade5e2e1a8f1476ceae58c143aae0d71a535fb3bc81981072ebd634f3ab</Content>
        </IndicatorItem>
        <IndicatorItem id="2fddfbea-788a-4c02-af44-26c2a4f1267c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">cbd5c6e49de23e91b155335bcb7fc494c3155d4a</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="d21eca28-868d-416b-b871-f38c60216cdb">
        <IndicatorItem id="ac342b19-4857-4fe3-8c98-baf1bb462672" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ssePmxdll32e.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="68ea7aa5-5d31-4fbb-858c-4326f31f2910" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d40c814ee7918bf836f4ef7fe065e2f5</Content>
        </IndicatorItem>
        <IndicatorItem id="edeb66d7-a93b-48b1-a662-af71558529b3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">b26d39d79b068a7d13fe3526f29bb26165b518fca3b0baf28ad0daa8ed576e85</Content>
        </IndicatorItem>
        <IndicatorItem id="3de2b0b4-f87a-44d9-a767-27a55a306b50" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">cdf2e2fa4d33f7e9813bd4f900ae321c5605c1d8</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="048f32ba-3f66-4d81-847f-773a37d8c032">
        <IndicatorItem id="119b8599-11b1-4e6c-b39b-fd43414d7540" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">unins000.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="9d4e591f-100b-4baa-9aab-d615232d3b88" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">6d733812e0121f1bbb8dbf2e19c478fe</Content>
        </IndicatorItem>
        <IndicatorItem id="5f1562bd-4aef-4278-b9de-d37fff3db1fa" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">c8a7064daa5c1e209a7085a829b4d393b8d80835deae7c1d1b35a0d437c0e0f8</Content>
        </IndicatorItem>
        <IndicatorItem id="04d66264-b93e-4621-97b1-736c82cf15d8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ceb83a86664f53a41ab91027713a6043997cd14c</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="6760f287-ff45-4e71-a8ed-d269c4982bcb">
        <IndicatorItem id="055a0c84-a7a9-4e15-98f7-2635e85b1579" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">VR.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="85f51ef2-0a4d-432c-a7df-b8cd9aab4aac" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">807c09828455846508b3232388d4eecf</Content>
        </IndicatorItem>
        <IndicatorItem id="d929e857-9934-411b-900c-45295f01da33" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">58378701354e6eaa658d5f0977032522a80ce171e15b841b18dec8a56cb566ea</Content>
        </IndicatorItem>
        <IndicatorItem id="5444d3f6-10e5-4055-81e2-5a8c79275d44" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">d06144b87c2eae9d7dfafb0c29d70a88f28c0ee7</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="1a5786e3-0b51-47d0-878c-f8d71da29f92">
        <IndicatorItem id="1a88dc58-ea37-44fa-97cb-a69467c7b285" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">kpress.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="06112cbf-7478-4cbb-bf06-6b85d4a55b10" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">eedb2f28eec31de121432f3f9c3c5ba7</Content>
        </IndicatorItem>
        <IndicatorItem id="0f8aba72-63b4-4461-a5b7-deb3f8dcc49d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">da400b87fba59ba933e1a77ce4ca27e6b42e27a3fd5551fbe8bf39853ed30bf4</Content>
        </IndicatorItem>
        <IndicatorItem id="99ba29f0-e4fc-4b99-9774-dee625f7256d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">d0bf7118bdea8868e794171e176c7e1b45da7cfd</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ee64b5c0-0b9a-4a60-94c8-9ed250979d3e">
        <IndicatorItem id="08a69605-a674-4b41-897d-d661e6a3a768" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-exploits-2014093001.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="09547c27-0a9b-4da9-8977-e398dadaca2c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">5527d16136944bc3795bc65bcbbe65f3</Content>
        </IndicatorItem>
        <IndicatorItem id="c53c329b-495a-49c6-bf92-0cf900c70cfb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">42dc1f9417fb067c3b96622ccf6e8c80c9d07202cc28f3c4d460d5bdc6ff249f</Content>
        </IndicatorItem>
        <IndicatorItem id="7a0481f4-1870-45ac-b2ea-074476ffa825" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">d228b700a6f4542a63337ab0899bd7e90982c30e</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="824ffa45-75df-45bc-8382-9f205be19df4">
        <IndicatorItem id="32e2e22f-56a5-4dac-bdbc-da0cdeb2cc20" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">PMIEFuck-WinWord.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="89cf23a2-da2c-4350-b84c-0722d3d67aa2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">b58e692d0558ba1b9cfcdda2775c7fac</Content>
        </IndicatorItem>
        <IndicatorItem id="f8b93f84-95f2-4ab3-80c1-14818153827b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ad55c2dcf7e3373ea074061d119c891b34e4364cd7f5f679b475b5ec3371592e</Content>
        </IndicatorItem>
        <IndicatorItem id="1fb85933-f4fd-4124-9f71-89b3ab3e3563" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">d2cc4bf197b9d408bcec69252725bbcdb516308c</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="4930ff9f-bd01-4ad4-bcac-b3ed4f761efa">
        <IndicatorItem id="f7e09809-3509-42b2-8136-a090e0630896" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">PGPDesktop901.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="f1140b95-06bd-4e8c-abd5-534991a57de3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">a819716b5980bc562b8964b9531945a5</Content>
        </IndicatorItem>
        <IndicatorItem id="2bea59c7-201a-4d6a-8652-6f99c75938df" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ad88c494669cf7224ca9511bfd4fcd130984f34d740e8d06661eb4b9967f019c</Content>
        </IndicatorItem>
        <IndicatorItem id="7acec20c-88d3-4d75-839c-c43d0649ab74" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">d3d9b85ae383218afcb57fc8a621278261f39a4c</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="479fcfe8-fe60-4b9e-b441-a401f9bf0e88">
        <IndicatorItem id="c68e91eb-f3c1-4be5-b300-b351dc3799bc" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">idaw64.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="e439767c-bf7a-4948-9f35-74c8d27af437" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">88175f15c1b93ccdc50a899c5db033c4</Content>
        </IndicatorItem>
        <IndicatorItem id="19fc1420-537c-453b-8866-f1ef3d1375a7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">6138fdaec7015624419c1e18157e938e8efebc54232e34b78f6cc41b4ecfea50</Content>
        </IndicatorItem>
        <IndicatorItem id="8efe58e4-b9a5-4121-a4b8-3cbaef3b92e3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">d44ecc0b45a7d2eddd23d23b054135a7b413bd7b</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b8d62954-331c-4d21-a32b-22f00bcfb6e9">
        <IndicatorItem id="7589f2b7-1304-43b4-b31b-e99ae4c56fb9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">_MPK.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="7ad4c811-b773-4e56-acaa-96f23b2e20bf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">9ff1afd5fc8595cd35741696a7a24a4c</Content>
        </IndicatorItem>
        <IndicatorItem id="4fc4e06c-2b7b-4862-895d-eb8d91533ed1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">637cf542512b0b6507b39686c7e87af30e7aa3a02eb9481a49efb4d0951adfe8</Content>
        </IndicatorItem>
        <IndicatorItem id="46a013d5-b4c7-498d-bd5a-384e194153c8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">d73123ae61b9183f82ac9fa64c813f2b7483e772</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="aacf3bcf-06f2-4ed9-89c7-1f8820a9e6dc">
        <IndicatorItem id="18cb8c45-a154-4517-8a0f-58ad6f195479" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">cygusbmuxd-2.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="c589dfc7-6e2c-4f87-a225-77b36d200a59" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">ed3158a7e3072f6da8dcbee7e535c518</Content>
        </IndicatorItem>
        <IndicatorItem id="360e2956-ba23-4923-ac1b-5fd19a184e66" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">22c586057af0f0d615a1753b68936763d36e682bc094ea4c805845f612ba591b</Content>
        </IndicatorItem>
        <IndicatorItem id="30870604-5f1f-4cba-abb8-f8fc530373fc" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">d85570ec70c1c3453eb1d4f5aa330cc050ea92f9</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="3821e2da-9481-429a-acdb-3a6dbc50517d">
        <IndicatorItem id="bfd26295-48e1-4189-af77-9c67bd69ef37" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">DropboxInstaller.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="ed0a3505-937c-488b-87ef-fafce28a5d21" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">96f185bd275e1c831da65d7c999e3db0</Content>
        </IndicatorItem>
        <IndicatorItem id="44bd32a3-9960-47a1-8be1-3e369b2638fc" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">c8d923daf0484747933acacec66edd2a7c1e1636e6551e45d0e4883195ae2458</Content>
        </IndicatorItem>
        <IndicatorItem id="41251ab0-7f9d-4cf7-ba61-82e16cb24b53" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">d85bfdd5a261a7e85b6e1fce018e62b866bf7d53</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="70b2b6ad-6295-4c15-8c45-832cc6cb15c0">
        <IndicatorItem id="95fdef7d-f8fb-4e76-9f17-a61cfa9f3181" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">EXCEL.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="90700485-b00f-4802-9bec-991830c6b7bf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2b7677ebb41abfd97225b2dcf8bbea35</Content>
        </IndicatorItem>
        <IndicatorItem id="441cecd8-23ef-431d-8c89-d9732cc42e2f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">dac6abd5ba0865b7983cff40f7a13d9cde89fed3c5b81c2b785e884f9ccdf28c</Content>
        </IndicatorItem>
        <IndicatorItem id="9b90f8b2-1e1f-4d73-995a-49a58d3233f2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">d86c6c85f3fe7981f7824f21bcaf45f876943e55</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="acb2301f-2de6-41ef-afb9-c1f69d252c88">
        <IndicatorItem id="7ee02249-bb86-4167-8ed9-148988291d5b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">H4DLL-VISTA.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="38baca42-915f-4204-90f0-4a8294d3ad6e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">738cf6db1f93006967ed1aeef87c6ba6</Content>
        </IndicatorItem>
        <IndicatorItem id="d61aeef1-c47c-47df-95ad-f4943e7f7a26" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">5f6bc6573d006609d1f0b5c3d051dc6eb5b30dbc60c4e2e7c7b6826434c6a59b</Content>
        </IndicatorItem>
        <IndicatorItem id="55890d86-ed5d-4e88-b277-f8a9c82367f6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">d89f0d3e65532a41615d0ee21f2b2379eb0b27d5</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="8afc8827-3177-4394-a572-1633d49c7faf">
        <IndicatorItem id="5c8dadde-c59c-4bb6-8e91-0a3c1ba0aabf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-translate-9.4.0.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="d5be99f1-7978-4b2c-83d5-0a3287e97607" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">168b06ee1219ada0afe184f9a70d12a0</Content>
        </IndicatorItem>
        <IndicatorItem id="a8ff5846-02cb-4e50-bb25-ee1a4e030e1c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">cc87e067021f8b419cc73863d26bd54e25b6f4c8149d6d331ba50e54aea917ad</Content>
        </IndicatorItem>
        <IndicatorItem id="fa8f2a55-3530-409b-9e01-2791bb43e95a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">d981a1a553729bc6ad875d57825dda17b226c385</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ad2b640b-99a0-4957-bacd-d146f1917636">
        <IndicatorItem id="a3c37ddf-d250-4d7d-8e34-8874fa513293" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Cellebrite.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="3620a1e2-c882-4066-9bda-d9802000b1ba" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">a6c75fc49b6674d2ca2033430177d3b4</Content>
        </IndicatorItem>
        <IndicatorItem id="10a5eb95-7f14-45e0-8866-f09bc2ecac7b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">4d8951f93381442e7961f4aa69550f610160567ee44386f0637269af596b07b4</Content>
        </IndicatorItem>
        <IndicatorItem id="3052dae3-eec9-430a-a932-ed5d40774863" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">db96fff7861c780789a1a3f5c8fbf1bbf80fd615</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ea08a499-3256-4f7b-ac24-d21fb6eb5b10">
        <IndicatorItem id="3924b29f-3271-4b62-912f-e6f1f7dddcd3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ApiHookDll32.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="eb7a6ff0-60da-4d10-9916-d57ece3f823e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">713c269faa5f650710997004d3be6971</Content>
        </IndicatorItem>
        <IndicatorItem id="e886d1e1-0b54-49c2-be2f-eacadfe25f56" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">6739dd4361c559fd9099dfc967b06eb5bac95ee8693986ac29c7b368dc7cff08</Content>
        </IndicatorItem>
        <IndicatorItem id="78e9d547-1fb0-4cd2-a739-1244c00ee156" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">dd6ac4da70c52dc6aad69590c2335925859c838b</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b8a3e3c4-af2c-4b65-b732-b6a575ca49b0">
        <IndicatorItem id="1905242f-147b-4911-94e6-7f9d519dde96" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Setup_.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="d8d89841-387e-441c-9baa-b3719433266b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e1e36fa0c482c71fd777be049272f7d2</Content>
        </IndicatorItem>
        <IndicatorItem id="84b5c08f-fc08-47e9-a86e-25340f23159b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">e32cfd415d5aee289a62a02b28b7815346cd150d70c0e1f95bb92ecf26a855de</Content>
        </IndicatorItem>
        <IndicatorItem id="0978bb7b-1739-47e2-a0ec-5ee56db369c0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ded04333c0eeb0f7978da4f298c191ecf42f98c2</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="1259ed37-dbf9-4a2f-b9e0-07355c08a397">
        <IndicatorItem id="2bc16ed6-a26d-4f19-bf78-49296079cb33" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ArcDropper.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="b5e095a4-c9d8-478c-9c0c-b3a3de52f23a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">a226d93f726bdaf119088e62b9b70989</Content>
        </IndicatorItem>
        <IndicatorItem id="f46a900d-f734-4341-89be-efc1a6dd9f60" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">b20b198d9e3af27ecac4a83b66234cae4eef6db0c1192b6f9ba9ca946033034b</Content>
        </IndicatorItem>
        <IndicatorItem id="49cef3d6-a36c-4a38-b275-7646cdb1e208" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">df7e96430c086efef38810de0ce981f7c4b5bd3a</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b14ccc3e-af87-4360-b0be-65eb8fb64250">
        <IndicatorItem id="7b21cc0a-90e0-453f-8dd8-da957473d76f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSWin32Polymer.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="ee404bce-4e60-4c08-b80e-a4b17633ea2f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">57a8aca381d5c991dd622bad6221c02d</Content>
        </IndicatorItem>
        <IndicatorItem id="d8875043-bd8d-42dd-87b1-98c1886e55be" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">342c4cac3b39eef3b1b455fc5e8cf493547f65aba415ba699c98bf675a746a49</Content>
        </IndicatorItem>
        <IndicatorItem id="3feb4593-03bb-41dd-92bf-8458f4f7b275" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">dfed8652101fa37eddffac7cbfa8b5792dc7a96b</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="3f881afa-fb35-4bd4-b49f-6b8d3dabf322">
        <IndicatorItem id="99ec2764-3072-422f-94da-00d7b4f0575f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">H4DLL.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="30b5a9b6-797d-4105-a43d-fb694f095ebf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">aaf26a0477841b45969fdce35bd2e1e1</Content>
        </IndicatorItem>
        <IndicatorItem id="7474ffc1-d5a7-4b22-8fa1-15ca1bb69d66" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">d9c55606c757e78940c3a22fc25ae12ed93a68c9f88983e58cd4795047504246</Content>
        </IndicatorItem>
        <IndicatorItem id="554b6b1f-f646-4d7b-b9fd-1c25662f7b4b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">e113e2904aaae7aa5c2438fea757846cad8a7e9b</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="26d1d35d-3dab-496e-ba8f-609b25245a93">
        <IndicatorItem id="41098bbc-058a-4e78-b957-d02022681af1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">LANCODE.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="63653738-ef08-4ac5-8f33-53af3af100b4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">0787751f46469c2d3e5de5d4fbd11692</Content>
        </IndicatorItem>
        <IndicatorItem id="e3e2829a-7bff-446f-afec-478868e2a0c1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">7f27100409815208dcaa4c05dc5d1e5d7541a08371e579778a9b9cae298a498e</Content>
        </IndicatorItem>
        <IndicatorItem id="d1cf71d0-463b-444a-b68a-f7e5ee5bdc56" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">e1767a98afaa3517652c9d0d1aca9245782d2ff2</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a12e8987-328d-47b5-9b52-13af7bdfef42">
        <IndicatorItem id="8a1829b5-1d62-4673-bb8b-c90fc814f6b4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">win32_remote.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="f7edc8dc-7215-4303-8130-ce9b67218ca9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">aee7029335a4df8ac44d3587e41c21dc</Content>
        </IndicatorItem>
        <IndicatorItem id="9178c218-4fb2-4afb-a180-921b22442d0b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">3f85279eee498578935e7f51881f8411be5ac7ba45f2334699230cd0b9d60032</Content>
        </IndicatorItem>
        <IndicatorItem id="e71a451c-2e25-4c34-9075-5e2e3cfabf22" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">e19a240f49e953a8ec9a7efc3b0e47cc8ecb07c2</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="eeb0b765-c9c6-4ca0-a51a-780843ec2b84">
        <IndicatorItem id="c910ece3-ee75-478a-bcee-05f45233da42" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">win64_remotex64.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="065234b9-070b-440c-8be4-f3b791fcc8c6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">227f885ffa41252a18bdb1b43323a9d6</Content>
        </IndicatorItem>
        <IndicatorItem id="15028bb5-e20a-4cd4-b2ea-cfc6eec5e67b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ba4d1658047690d3fc9dd96fb5d56c146dcaa14c1e72f2fd5bbab1920ed0741b</Content>
        </IndicatorItem>
        <IndicatorItem id="829e5491-4065-424f-b3ff-5586b8c55c38" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">e1b8542ee7315ca5ad34dc60cc0c2f0f59b73aa3</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="65542247-3dbe-4144-a662-18171452f2ad">
        <IndicatorItem id="d2260fab-8a24-4689-b20f-e0bc957cbff2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">keygen.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="43cf6089-2aef-4860-bbd2-fbec80d2a31b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d84db581cd7317363a6eacc567fdfbe5</Content>
        </IndicatorItem>
        <IndicatorItem id="a74eb5d0-d4dd-41db-aaa9-786d7437b459" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">514c0c34572895c41d83e674bbda9135da545c48c8e1dd9ff5a7ec5a8d52c72d</Content>
        </IndicatorItem>
        <IndicatorItem id="38d8433a-7717-4eec-83a5-4b94daaa742f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">e33ccf7389525d9d195587e62804a37bd7b5e728</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f461d83f-7054-4d06-be93-5bdcbe374e03">
        <IndicatorItem id="e6c95695-02ef-47f8-8b78-52bfda7d4359" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">setup_Universal_U3_Customizer.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="69b8f7da-9827-43ce-b89d-b3a27da2185b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">448975cbf086c450d1ac6285f1b57e95</Content>
        </IndicatorItem>
        <IndicatorItem id="ee2618c1-6f95-40f3-9980-a4be3ef0e808" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">b606cad7024a165b899e3d2ae9625e6d0f207928eb2838a6c4c8b26ddd583bb8</Content>
        </IndicatorItem>
        <IndicatorItem id="74b9d029-6a2c-41da-8cf4-46dadbf76843" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">e4c874697e71bb3b3b7fa0d5142f5c28df786313</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="0784c3c0-a928-4b65-8dd7-9fcb86a7197a">
        <IndicatorItem id="9e922741-9036-4d8e-b896-ea944c31da95" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">tnp.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="a02d8bce-f5c4-43ca-a7ab-d1cac0b5ebbb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">96ebe410e37debc175a137c82ceee7d9</Content>
        </IndicatorItem>
        <IndicatorItem id="fb6cf7ca-c2bb-4b42-a161-c52e5ebbf5e7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ecb4779c87ea2c0a95ccd1d0231ba063e4b53d86d28b29d0566a8ef0192f485d</Content>
        </IndicatorItem>
        <IndicatorItem id="e559e728-b83f-4bfe-9567-fc5149abb42a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">e63d07c5ea064dee4a714e65f0745f439899be91</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="768fef7b-48a8-43d4-a976-2772c9aa05b3">
        <IndicatorItem id="74552e90-3924-4e7b-a15a-9a642e7cf073" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ARROTO.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="f243e304-a2c5-46ce-b4b5-2c3971aeae1c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d43a982b76e823ae916c5f3aa1dd3254</Content>
        </IndicatorItem>
        <IndicatorItem id="6610886f-802f-4a06-85ff-e714e09f5045" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">045d84ea644b90cf5ddcb5ec26c6683835ad7640c83488523a0ebc0d4063c92a</Content>
        </IndicatorItem>
        <IndicatorItem id="1eca9a4b-eece-4329-b8a3-7659cb32336f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">e7c9235be748cba6ccd570cc39e112293bdf2b91</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="751c8ff3-0cb4-4fc5-a0c0-6b50ed318e0c">
        <IndicatorItem id="8dc0cbb8-e631-4eda-bdf9-2b1d64966424" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">SP4I386.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="9077c7d1-c40a-42e0-a25c-558f5ad95091" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">a18aa31f0d54d99b6520e95b78c6758f</Content>
        </IndicatorItem>
        <IndicatorItem id="dbb6cade-19ce-4401-8b4a-f9646d908a75" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">62cac70e6ee1b46d4fd5402a567e8519a4ae16bc32b906c90f74ea471e97e4f5</Content>
        </IndicatorItem>
        <IndicatorItem id="6dc5b68c-b465-47f2-afd3-65d02a9148e6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">e8d11f404bcb5dc068fd1ed2e347a4f5ac762a11</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="0d0eef99-f188-47f0-a4d9-a07d40ea8981">
        <IndicatorItem id="fe7e6116-09d3-4b80-9963-cda56d2fbcbf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">VR2.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="25c74694-9c3d-4c8e-a2f8-ce083b244aea" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2fe29513b40eb73e122285513d91ff04</Content>
        </IndicatorItem>
        <IndicatorItem id="13ad2722-fe23-44e2-b382-5c4248fcb6a3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">5af63dcc0c0330a2de8e4a3f3756e7951d2ce02655f94eee77682653eb6ae949</Content>
        </IndicatorItem>
        <IndicatorItem id="3a2e8740-47ee-4746-954f-efa8a9379a65" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">e904dca98c2fec54b8c07befefa4b65c65058f75</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="656e2b24-0fc5-4c44-bfea-c76c600601a8">
        <IndicatorItem id="eee86925-97c1-4e5d-a11e-4e79a39f966c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">CALC97.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="d46f6a8c-7d6a-45c8-9f6d-11e4265cf2b3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">01955ddec1a6434324c912f5e6f4fea7</Content>
        </IndicatorItem>
        <IndicatorItem id="4d6bb326-df24-4a02-b48f-2bd80fb5d622" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">c4a28888ba96e92c22d497d0690e9d484bdf093da12d419fde7c7f3674d845cd</Content>
        </IndicatorItem>
        <IndicatorItem id="ef823704-43b1-4e58-9086-92df7493d0f5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">e967c24fc9344abc77dfcba79effebf2154dd6c2</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a5587b96-b295-4cb6-8ee3-b2ce93d7054c">
        <IndicatorItem id="f175b109-64f7-4d00-99ef-b5042d66f752" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">sigmake.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="856f6492-9dc5-44f8-aff8-3db0d11fa97c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">014402d32082497d9fae6b339f358401</Content>
        </IndicatorItem>
        <IndicatorItem id="cbd16919-10a9-4a49-9251-4d5b3a4829aa" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">941ceeb2cbe1969dc41059e0766b5d6df687e8e8d96e31efea71699686ab6b9e</Content>
        </IndicatorItem>
        <IndicatorItem id="d9be9761-e9d9-49bb-a0ce-99ca514047d3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ea072de4b781749a694628da0758c934ce9cb0a4</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="7bb0fdd4-9466-4f20-9c42-068c57916a37">
        <IndicatorItem id="9438aeab-2207-4237-8e5b-f4482ffd34ab" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">OFFDIAG.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="8fafaf85-e93a-4a64-b53b-49b5d4a5e1c0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d54e2e633cea68716023e0e524325ffc</Content>
        </IndicatorItem>
        <IndicatorItem id="43880a37-4e41-41fb-893b-874e1726be76" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">72dc79c35aac14f453674ac3b62c268843a9c614ae99da01879db04c1dd995f9</Content>
        </IndicatorItem>
        <IndicatorItem id="47fb6b7a-0368-43d9-bb2b-8ff4208cdf99" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ec316bb9b9d0a09c2bd566e98d6507edb9932eec</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="87399158-8b7b-4643-a54d-46bb324edf6d">
        <IndicatorItem id="475f4abc-40b2-4174-8fc2-0eb0b0973196" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">MASKGEN.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="ed995f95-bf86-4349-aec3-6670991eaee3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">331660769ba66b683f4ba4c72a773f13</Content>
        </IndicatorItem>
        <IndicatorItem id="0635c9a4-7ee0-4d7b-87c2-a4efff4354da" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">296e9f04e0f291e9d6aff8443b4ab53ebc21fa524b18be0eb100b900cef1b5fa</Content>
        </IndicatorItem>
        <IndicatorItem id="ec749d06-9ae2-4787-ad42-dbd152c4ce80" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">eca51153154c563a3e49f028f79e4463bb71c9c0</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="cb0e1c64-da77-490a-b2d4-0e4662a9779c">
        <IndicatorItem id="9b8502c4-a4e0-4fb0-bb36-55bd125b272b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">veeam_backup_7.0.0.839.patch3_setup.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="fbc317c1-8336-4b18-ae57-fc3e3b95d6ab" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2b3990318513f2df3851dcf3605aa2f5</Content>
        </IndicatorItem>
        <IndicatorItem id="12807d95-9044-45bd-887e-aa9d1534ccf9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">917a3d71a1cddeb983e3ce1823f60eca1942981265ebfbbe4cf243f1545bb575</Content>
        </IndicatorItem>
        <IndicatorItem id="870cabcb-806a-482a-aa11-638c7dbb1802" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ecbd1d800479afe1c034c677ead22d2330cd8990</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ec2c1c90-19f5-476d-8ea8-fb3ed274dd10">
        <IndicatorItem id="682409e6-97ef-4cf1-84cb-f624177db158" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-setup-2014120801.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="8424693b-0df8-4add-8787-42f6cdb1558a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">48946b57b2dc7fea9de4f4e82411a6e7</Content>
        </IndicatorItem>
        <IndicatorItem id="4843a3ce-3312-4974-9150-0aae72972b55" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">b292df8f088af93ab479c47c8afef0144e952a742e9d136b078ea07fa691e328</Content>
        </IndicatorItem>
        <IndicatorItem id="5a4ad986-75bd-4e4b-8858-e88752a7907f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ecd0d9842e482c3f33051a04de2a746c94532cf8</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="7158265a-2cec-440a-be10-35d77b3551af">
        <IndicatorItem id="f44c74c8-0ada-46c8-8ad6-add68595aad1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">cooker.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="3472d5ed-5520-4388-aea3-d538f2b068b0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">a0764ea07a40604b295e8600a3b73231</Content>
        </IndicatorItem>
        <IndicatorItem id="59653321-4a06-4250-bc2f-4798aecb728f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">9a1dc317baac5b31e8f9498c979e623db6e57f34aaea6dac923853cec1a30397</Content>
        </IndicatorItem>
        <IndicatorItem id="3e967a72-1e90-468c-9a66-61931ee7c686" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ed91c8a09126bd27edeb0a6f9e5ef64a9b5bd29c</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="5cf4cd0f-9f27-496a-bdf5-bd1ab11bdc30">
        <IndicatorItem id="e52551ae-2c61-4a54-909c-0c1a21eabf31" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-hotfix-9.4.0.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="81a398d1-2d65-43a9-8235-185a0d21f633" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">c170a9961560e4c96215a06f75985fc8</Content>
        </IndicatorItem>
        <IndicatorItem id="ae7182f5-6894-4847-b348-55848f1c0f26" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">598bab73e4e2e9a09da64a16c807fea62bac20ec206384194478fcaf9eac1b14</Content>
        </IndicatorItem>
        <IndicatorItem id="bf72c83d-f5d8-4fce-b622-ce42cf9a6887" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">edc03b57e86aab5f869533ce2487f6918e26d5fe</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a0d325c0-1b08-4c00-97e4-21464faab3d3">
        <IndicatorItem id="56e106e6-39f0-4d59-812a-b69224e2fdfc" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">firststage-2010031201.signed.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="5c3b28c6-a0d7-41c1-af71-e555eb516e3f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">cca243be233cfa4c3f44c2035b5db135</Content>
        </IndicatorItem>
        <IndicatorItem id="96b76832-1f3c-4a3b-a2db-6f61a34ba074" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">1a178c22b5e9a7e99c0c733ff9d8452b22a3418b3c137687c8407c309e79a714</Content>
        </IndicatorItem>
        <IndicatorItem id="d4f1ea3d-ed53-42e5-96d1-7b8932539e1f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ee0d1a3ca639971d130eff10c22350c77a4a062c</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="1b58e1c8-e3b6-422c-b7d0-d6e9be269832">
        <IndicatorItem id="4cb13171-b22f-460a-a36d-978c47d83fc4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSDB-bare-7.6.0.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="9d735829-4c8f-4e38-b033-8a1737f30c27" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">4bd8de4ce17067db858d63997315aee3</Content>
        </IndicatorItem>
        <IndicatorItem id="c3c08730-7aa7-466b-9373-f6dccdf70886" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">f2f6dfc7fc3ff1170a80d661c1dbc18dbdfa456c1327ac475a7b21a38ec014be</Content>
        </IndicatorItem>
        <IndicatorItem id="abc0b42c-741c-4332-86af-9cdda4bbd27a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ee52c9416e9da9a1f67785bada3c9f4dae89d1e3</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="7d4977e1-4861-41a3-8178-d0ffc48f7ece">
        <IndicatorItem id="80b63eaa-35ef-4c22-9bd5-a67ee16dfb52" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">wps.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="803a7933-0af1-4ddf-a4ee-b1d5916713e3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">ceacc145be4a0c871eb69d323a3890c3</Content>
        </IndicatorItem>
        <IndicatorItem id="f644c625-0ad7-4343-b319-86c7d56da990" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">23972fe89540cf6636288612ecb6090b9f0c23e12bf02d5cb69def679105157c</Content>
        </IndicatorItem>
        <IndicatorItem id="7fb5067b-d6b2-4276-a4d0-13bc8f3d8c38" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">eee02518ea2c34dd4a39f5a8d971d473020d7119</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="c67c4972-b3e2-429e-8b22-2d93c4a81fed">
        <IndicatorItem id="71fc1121-65b8-498a-b45f-2dea92a0cc84" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">GetDiskDrives.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="bc08f47b-00dd-417b-a948-dd99273716eb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">416f42c3d0c4ddf6c11e457c40119227</Content>
        </IndicatorItem>
        <IndicatorItem id="986d167d-1f45-43f5-9d5d-5feb91118940" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">2e456b7065573ad5e62db360f5a451f1e460df08479a8fffc89e5857d70516b9</Content>
        </IndicatorItem>
        <IndicatorItem id="cee0422b-baec-4980-bb34-f039f44a1ae0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f01e3ac3050101633cef8fb53cbf87a91131331c</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f470f1fa-3f93-4b46-9e51-6d64a74f147a">
        <IndicatorItem id="ca2fd706-ac65-40ee-bf5e-1487be767907" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">WINWORD.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="7fc9096c-4ae6-45fd-b924-4bc48bbd8743" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">60b9933665169020a3565781e4058e08</Content>
        </IndicatorItem>
        <IndicatorItem id="3f3af3df-5890-42ea-a365-8ffe078adbbf" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">200c0623f75433c1e2821d930e6f3e072c5e06f2bd1770551595acc3b170febf</Content>
        </IndicatorItem>
        <IndicatorItem id="8b15053f-39f3-422e-b81a-f051510654e3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f039f975acec4b8b60b7619cc75e0b87d809315c</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="967d7ac8-320e-402b-9a5e-f1667870f4de">
        <IndicatorItem id="d58f86b3-9122-4d1d-b60d-e1a487da88f6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSMacOsPolymer.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="03294d70-9842-43ff-9506-ea0bec9ced1f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">7ebc36666f11c4285ee68501dc3c1b5a</Content>
        </IndicatorItem>
        <IndicatorItem id="614f0e16-9533-4078-ae95-9e64ccb3bd32" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">71fe815f897877e69e4a37844a6d2feb40fdecaed1dd55b07472234e87e22767</Content>
        </IndicatorItem>
        <IndicatorItem id="f2dcb2bf-7b14-4244-ba6e-d4feaf2a21f8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f19e73120166b637ee7a941540979efaa4a284b5</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2328dd08-af9b-4299-a6ab-06b494aade86">
        <IndicatorItem id="0e93291c-14d6-436d-bfd0-ea5c0b39bd7d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">rcs-setup-2015020201.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="247e8017-8468-4386-ab5e-1697fddac00e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">942dfaa789db5b5e349be1c077114cb1</Content>
        </IndicatorItem>
        <IndicatorItem id="a8567925-b31e-4cc7-9b37-dbe1056399c0" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">bc0ca8f7de902d9b387db9533d0bee3f94e3e915495821bc739adb6ccb70bed2</Content>
        </IndicatorItem>
        <IndicatorItem id="bb6a05dd-c65f-4993-b3f3-e2d5961ff58f" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f24bf41a756388fbf9b90bad8e7a6ab4f979bf0d</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="0cb43db4-c324-472a-8008-7a2f661100c0">
        <IndicatorItem id="21d12fad-a405-4dc1-b824-5948a4115202" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">SANHQInstall.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="9f393624-cb01-4b9b-9291-24cbf8a3be24" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">916e6874c4da8d8fcc4b62a3d0948245</Content>
        </IndicatorItem>
        <IndicatorItem id="5ce24840-dbbb-4813-b0c0-c7552ebed62a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">51965ab9ffcb63f6104d451fd15f78331cbba796e28ac7748e8eefbe0b0f006c</Content>
        </IndicatorItem>
        <IndicatorItem id="acca0cf5-c15b-409b-bd72-67e24c16f351" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f3148c679ac9979de35fd8d5b20b189946d7c4cd</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="ef23083d-4dff-4886-9016-5f889f1bd0a7">
        <IndicatorItem id="0281e2da-46f0-4574-83dd-ff21e72a1bf9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">VMware-converter-en-5.1.0-1087880.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="bcb16762-88b1-489a-a1fc-c3496aa765c1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f4d90eaec30bacf6fc709a5623c7bb4c</Content>
        </IndicatorItem>
        <IndicatorItem id="c6befdb5-d241-4e60-a5b4-1c31d65bea39" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">32abff1cee3791ea98f7205eb504465c60bd7e57c2b6048929eed56822e67efc</Content>
        </IndicatorItem>
        <IndicatorItem id="e87618a2-2061-427d-855b-afc33df8835a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f3a57d486f540d5994c00c60d4d1150de6106d81</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b75a8a12-df23-4bad-86b4-84a90a0aa2bd">
        <IndicatorItem id="8c09212b-2ff7-4713-8972-dba44179e959" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">SETUP.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="7211921f-3b06-4596-b994-625d1e899dea" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2377d5fa8c47ed262d49575e2e612433</Content>
        </IndicatorItem>
        <IndicatorItem id="d78fbeb3-07dc-4174-b7b9-6d3a97b7a75e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">b524abb464b30366afff9b01da259432f76fef62a7b9d128284e289e76b3da16</Content>
        </IndicatorItem>
        <IndicatorItem id="a4ddd375-4822-465f-9205-042ed10c2ee5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f3c3f9e3139efb822e7b574898e95c38498462c0</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="9090f53a-be7a-4144-b9ea-728380444311">
        <IndicatorItem id="ba30d9f5-6b5e-4eab-9d06-2e7fc2b2e2fe" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">FTS4BT-6.10.6.0.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="c77af8d8-309d-494c-a004-013a05c7028d" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">d551c32f8a187013e724c1953fdd1d59</Content>
        </IndicatorItem>
        <IndicatorItem id="6be416a1-3716-4e79-b3c4-7b97a7d00ed2" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ac149d3edd34428b5a9958b0f33cde23d6bfb5c8609062bcb03e9488fed10b47</Content>
        </IndicatorItem>
        <IndicatorItem id="48ae6307-3fce-462e-8817-9d3c24c1b6ea" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f4423de02ed8ee3d3d02dae0d08f559bd1d70792</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="025845a7-6cb6-4a7a-8cca-5fa5711771a4">
        <IndicatorItem id="36c5b268-dd6c-47c8-acd6-aaa6488f3864" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">dropper.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="eb906d79-cabb-41ff-882e-2a32f7322ec5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">375e36fa33888f4d48a8d40809165277</Content>
        </IndicatorItem>
        <IndicatorItem id="038bd6ad-9a8c-43d5-8f5e-b70c57d85657" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">c3baa6e1a9ca0c79c35a53cfb5cc4bb76e45ed623841bd359d7241a8d82c5a54</Content>
        </IndicatorItem>
        <IndicatorItem id="3109f5e5-5f01-491f-afad-0780835198a7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f67d3e3c5892f9f8ecfa4e75fd46942937f43cc9</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2f59fa75-cae6-485b-bb6a-e7f5e1788765">
        <IndicatorItem id="1d840c7e-978b-44b2-bc92-fab84e7690e9" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">EMUDKONF.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="73331c7a-a0e0-44c2-a5af-75bf073c89ca" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">e8ae74c8dd8a29352cf6ac3c68df6ae6</Content>
        </IndicatorItem>
        <IndicatorItem id="4854c216-bdc0-43bd-bef7-41c8ea505a9c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">ebab6eda6d74afc99021ded4d146bc4cc23f9a2a026d0fbfa217578e9acd22a8</Content>
        </IndicatorItem>
        <IndicatorItem id="c0d12639-de15-43b3-b602-9cc9467db372" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f6df7e7b570337d6b2ea8774a0c98a6731beff04</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a032fa26-414d-4dc8-b10f-11d8fc7905be">
        <IndicatorItem id="f69f4c8b-4203-4ea5-93a9-d4723cd6f6f1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ExeLoader32.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="9e3fbda3-536d-43e2-b33f-a28d2bcf17ae" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">be6655c17f0a797f2c01b2ab42b55107</Content>
        </IndicatorItem>
        <IndicatorItem id="100454bc-c61b-4e7c-b869-bd8e61b04d77" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">7561ace6f04ca6d023d7eba0c8cd49b2515baa71a40926f625538e41e21f641f</Content>
        </IndicatorItem>
        <IndicatorItem id="b1b05f4b-75f0-4d3a-a856-0da1b22fbd4e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f7653b3b9d71303d8ac9425985400b321934ddcc</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="a71c0c03-cef8-4c2b-82be-a8a5b323b48c">
        <IndicatorItem id="cc47050c-6424-496a-8fd3-1c368a8fbbe3" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">ptmobj.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="258a0774-069e-481e-94ef-caebe0e8050e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">7421ef518702479d9b1a4b82318a1095</Content>
        </IndicatorItem>
        <IndicatorItem id="90fec9d9-4a84-4f38-a068-471afa92b700" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">b800ba5adfc26f20b4049dba2442be73347e999a224716c7ecb5271e482e0a4d</Content>
        </IndicatorItem>
        <IndicatorItem id="7de30fda-6070-47d4-beab-5a84e2159d12" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f771f3b68376fa211e590a7f5cb65f7cbab20187</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="f77e8b88-1218-4b92-92e2-457470b93447">
        <IndicatorItem id="90df2338-00a3-447a-a538-4cd167a557ed" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">so_1.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="c5bd0a58-4955-45d4-9b7f-ffe5eff0578b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">8a19326b0ecbad83058b0ab803bad254</Content>
        </IndicatorItem>
        <IndicatorItem id="34cabae3-89ee-4838-85cb-bbcd3fecc51e" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">2c72175f96c651eea3d3411efacf73e0fb3e7543451b73f5e2521f47be67f006</Content>
        </IndicatorItem>
        <IndicatorItem id="ae13b8cb-dfcc-47e3-9184-c679c113cfed" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f80dbd487b738df05fe27b8d5238cbd3e429dd97</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="fe876190-40e4-4f30-a032-5918d83cdfeb">
        <IndicatorItem id="7121d683-2f80-4f48-bb08-ef93bc871545" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSWinMoDropper.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="db626ee0-78fa-445d-a458-026304614fce" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">1d384e3660e9087a1f5c8af8514fc4c8</Content>
        </IndicatorItem>
        <IndicatorItem id="9d28d369-bf0c-4862-aa70-d9c306a1b680" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">1381fb1455e99da4221589a7d0e51208e8038871586747209031d934fed5f2e6</Content>
        </IndicatorItem>
        <IndicatorItem id="7fa4d82b-ca3a-49f1-87ce-75837ddccdc7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f9377a0161ded2273265b3ce5d3b9809ce3a8e60</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="685da6a4-2c04-44ec-8538-c3f998e0d3b2">
        <IndicatorItem id="38b53a0d-ccca-4caa-aa20-c1eb4bf171cc" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">setup.dll</Content>
        </IndicatorItem>
        <IndicatorItem id="58167fe0-731f-4a4f-a12e-953d2199d546" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">1c5764dd71b9109dbbcd83201be2ceae</Content>
        </IndicatorItem>
        <IndicatorItem id="39ca623c-948e-4e96-a684-a1ba8c941557" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">abbac3dda22f825197dd65b8c1076c5ab8d7ecaa2ce2821b242f63154eafce3a</Content>
        </IndicatorItem>
        <IndicatorItem id="3defcfd8-d132-40db-9cb4-fc66bf244037" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f9860169568558df2eb06b9a7ab9d0a89f45cd44</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="e11dfb08-d0a6-4010-b11f-0deb02ede9fe">
        <IndicatorItem id="e83166fd-b159-4936-9dd8-f9dc437e8981" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Console.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="3068a75e-f4b2-449d-9a97-8f299cb6c04a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">497960ccefaed2b4c8e5ec3274c9dc3c</Content>
        </IndicatorItem>
        <IndicatorItem id="40fcf65d-31e4-407a-a719-047a48bcb58a" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">5d761821b44d6fc1de9020b17aed6b9dd58f9a00f83860ce9511783c98de5d46</Content>
        </IndicatorItem>
        <IndicatorItem id="333c32d1-af51-465d-bc7f-d1adfe56719c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">f9bb44c6cfeb17ecd12e238630cc83ddfc23b72a</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="db254c57-6b97-4d01-b26e-41c28d14c293">
        <IndicatorItem id="db9c44a9-176c-4d3e-bed7-725044c149d8" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">CREARCH.EXE</Content>
        </IndicatorItem>
        <IndicatorItem id="60cd3c15-1da0-4b6b-80a1-c5b1f5e172b6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">27fdc0db940764a1218b7a3698571bf2</Content>
        </IndicatorItem>
        <IndicatorItem id="8eb3761f-378a-4fa0-9ce2-03219641d9b5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">e2f8c5f8c3ab687b91dd28081fec71e0bb9f70066237768e7020fd992c80f2d5</Content>
        </IndicatorItem>
        <IndicatorItem id="a6ac4759-1275-4ffd-8c78-94a0a0d10418" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">fb106fdbb8ab0ee1272271aa880c254f8da59e42</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="b207ffdb-9e74-47f9-8f55-a8b389d69f6f">
        <IndicatorItem id="8726267b-219f-4852-88b2-749c8b4b1dda" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSMacOsDropper.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="9d892264-da94-4136-87f1-b1108fd1bbc4" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">f12ed5b550d6856ccb501f9ad65f956b</Content>
        </IndicatorItem>
        <IndicatorItem id="0ed44eaf-1986-4ba4-8aea-b77e224e079c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">a72dc5010dc21c3bc9075c74fc7b87f0f89cfbeb1b1c4cdab06db4262d84969d</Content>
        </IndicatorItem>
        <IndicatorItem id="e5465eb5-5bc6-4bb3-b2d7-ab45e19afff7" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">fb9fddb2b74e62d2e949520de23d6a2a2a16e576</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="548493b6-66e1-47a9-ae59-517fa8339a30">
        <IndicatorItem id="dcc01f23-8ee0-4173-b637-a595033bcd7c" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">SharePoint.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="eced449e-5df6-422d-81e4-16126a2df868" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">cb7cd0801dddf01580c986890538a231</Content>
        </IndicatorItem>
        <IndicatorItem id="e3687777-b4dd-41ea-b339-7b050ffd7ffb" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">5e54fc43c0013f38c12ad777dd209a463c7d73db3a0c01ca0903976d856dfae4</Content>
        </IndicatorItem>
        <IndicatorItem id="0af5168a-3e7b-428d-a5b6-c339407dcc76" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">fbf5b3ac63177bc6d0f442a17fed7cc99f2b1469</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="2ae4248f-0c32-4114-beb4-729df460b227">
        <IndicatorItem id="53a5124c-afbd-4368-861d-25da70f95803" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">RCSDB-update-7.3.1.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="234e7a57-fcb2-492f-b126-6607b6364c81" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">983ea03599f2371d3aa4b561fbdb9d35</Content>
        </IndicatorItem>
        <IndicatorItem id="3bda46d7-418c-4fd8-a367-2680cce3f9b5" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">1b72081c4422785d8c6c016b10bdd7545e5fc6f1ff73277b0366e9b40e624616</Content>
        </IndicatorItem>
        <IndicatorItem id="0a0d9008-299c-42c3-8da7-8ad3e68ef1a6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">fd9516d2c5493009009eedc0e98e345956516d1d</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="9c3d65a7-88ee-409b-b501-5e14c8d1f991">
        <IndicatorItem id="9bfd936d-9756-4b1c-b99a-28f2d8d75971" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">jre-8u25-windows-i586.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="89927c2e-a169-4126-ac8f-7686580343d6" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">2cdd85286c5531557f3f20a7cafa7291</Content>
        </IndicatorItem>
        <IndicatorItem id="6c27b45b-f8ee-44cd-b72e-cd077d9af08b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">8f6988e717e0334b33b7f4697c8ebbb5038c218994c8da7dc295986fe43b2b8b</Content>
        </IndicatorItem>
        <IndicatorItem id="4a00fb6d-edaa-4c66-8931-d53e1a415048" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ff3d21c97e9ca71157f12221ccf0788a9775ec92</Content>
        </IndicatorItem>
    </Indicator>     
    <Indicator operator="OR" id="309a38e3-b205-48b2-8503-d645af3b04e7">
        <IndicatorItem id="4906feaa-787f-4f0f-b7f4-9089b83a1952" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/FileName" type="mir"/>
            <Content type="string">Office2010_ProPlus_x86.exe</Content>
        </IndicatorItem>
        <IndicatorItem id="987f99d1-f636-4609-992f-494f47d5160b" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
            <Content type="md5">fcbaba0fa7683a9d10fc455c4bf75eb1</Content>
        </IndicatorItem>
        <IndicatorItem id="62ebb824-c295-4454-8607-0391c2a65317" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
            <Content type="sha256">e326ff4b3581b0c6cabdf973ad62a3feadad31f65bac975572f55cf1462bbab7</Content>
        </IndicatorItem>
        <IndicatorItem id="ce0eee84-8ec2-400d-9ca2-4b8ca0403bd1" condition="contains" preserve-case="false" negate="false">
            <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
            <Content type="sha1">ff5a6ed3712766feb130bf8187f01c42aca590cd</Content>
        </IndicatorItem>
    </Indicator>    
    </Indicator>
  </definition>
</ioc>", "deleted": false, "disable_correlation": false, "timestamp": "1438334554", "to_ids": false, "type": "attachment", "uuid": "55bb3e5a-66f4-4b4b-a87e-4c5e950d210b", "value": "hackingteam_openIOC1-0.ioc.xml" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334604", "to_ids": true, "type": "sha1", "uuid": "55bb3e8c-e68c-44e3-8156-417c950d210b", "value": "0097a9fba6b0bcb09e9473816e51c2c8e48284ff" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334604", "to_ids": true, "type": "md5", "uuid": "55bb3e8c-0bb8-4a5d-805b-4700950d210b", "value": "2a2578d7f22d3b2ee52c5d46bb5fdf05" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334605", "to_ids": true, "type": "sha256", "uuid": "55bb3e8d-830c-4dd5-80a2-49ce950d210b", "value": "4d9ced2ee7d979055d33564cfa5a67773e34f3e51d615f162003311c76f51bdb" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334605", "to_ids": true, "type": "sha1", "uuid": "55bb3e8d-bfc8-4570-8ce6-4f8d950d210b", "value": "0540e5eacd37ea3285f8a239dd72e3e7e4faf33e" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334605", "to_ids": true, "type": "md5", "uuid": "55bb3e8d-145c-41ba-99c2-46da950d210b", "value": "f713c1e740d67292db2d96c7755a63bc" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334605", "to_ids": true, "type": "sha256", "uuid": "55bb3e8d-cdc8-4cfe-8ca9-445a950d210b", "value": "9f3673b51a622dbe8ea5f92ad37ff12ed0a03ff5c30a9ca20575dca08c624fa3" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334605", "to_ids": true, "type": "sha1", "uuid": "55bb3e8d-4a7c-4158-9c7a-49ba950d210b", "value": "076b09d71c5c55e7ae6f044791142470799648bc" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334605", "to_ids": true, "type": "md5", "uuid": "55bb3e8d-b38c-4e40-b38d-427c950d210b", "value": "dfd6d9d5d7074e3d822ee7002a2538b6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334605", "to_ids": true, "type": "sha256", "uuid": "55bb3e8d-6934-4977-92d5-4d19950d210b", "value": "d70699e40511f4dd459420751e66a2564f050ab17b101ca9955423de2c579fa6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334606", "to_ids": true, "type": "sha1", "uuid": "55bb3e8e-efd8-4d2a-b870-4bf0950d210b", "value": "0837b3eed579123555ae09244b3f23aded72b9b4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334606", "to_ids": true, "type": "md5", "uuid": "55bb3e8e-2670-4c78-97ab-4237950d210b", "value": "5c1215ec7da96f58a1e3e66b60c1d4ed" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334606", "to_ids": true, "type": "sha256", "uuid": "55bb3e8e-be4c-4def-aeb1-4d9d950d210b", "value": "2ef643a29808aa6dedeb69165d8682d5a58a95aa68bce856783a2b8dc2d71087" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334606", "to_ids": true, "type": "sha1", "uuid": "55bb3e8e-c280-46f8-bfa6-481a950d210b", "value": "09920b2f0d20df022da507ab7b334392f7380cb4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334606", "to_ids": true, "type": "md5", "uuid": "55bb3e8e-e84c-4572-9f45-4d24950d210b", "value": "4b5d19d8a0bc70b2165144cb9be227e7" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334606", "to_ids": true, "type": "sha256", "uuid": "55bb3e8e-5764-43b3-931a-4522950d210b", "value": "8306c3a000636a21275774fcc17cd0bf75d1959bd9ea6bdb272666fda8494649" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334606", "to_ids": true, "type": "sha1", "uuid": "55bb3e8e-dba8-4660-b2af-4523950d210b", "value": "09a77488453f586ac03782a539225487c44c3a30" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334607", "to_ids": true, "type": "md5", "uuid": "55bb3e8f-a0c4-45cd-b71e-4f6e950d210b", "value": "365bf9ae89eebc67a34e09ad07ebf166" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334607", "to_ids": true, "type": "sha256", "uuid": "55bb3e8f-1e5c-4550-8fc3-46af950d210b", "value": "314211107852b35dbf7d2abc54581aadfce1ddf79e1930bb44e37ea4af338541" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334607", "to_ids": true, "type": "sha1", "uuid": "55bb3e8f-74c8-458d-a3bb-4555950d210b", "value": "09b49ee08641e1d18532a67acc09d98a1b708545" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334607", "to_ids": true, "type": "md5", "uuid": "55bb3e8f-7ad8-4809-8c2b-4589950d210b", "value": "710cdda3bc6ff73c2399d0a718c9fbe8" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334607", "to_ids": true, "type": "sha256", "uuid": "55bb3e8f-c9d8-4b1a-b3a5-44a8950d210b", "value": "8caa3a2f4c39992952cd2bb38bebadbbee5fb68114500e37832221d4e59aea30" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334607", "to_ids": true, "type": "sha1", "uuid": "55bb3e8f-43f4-4103-9826-415b950d210b", "value": "0ac7f04dd08120e93ea449b49eb8e557a5a2ef22" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334607", "to_ids": true, "type": "md5", "uuid": "55bb3e8f-4cd4-4265-8418-4907950d210b", "value": "94bac050560b074bf7f48dcc282ab7ff" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334608", "to_ids": true, "type": "sha256", "uuid": "55bb3e90-8a24-4451-9317-4363950d210b", "value": "b0d3aad477487039fbe9a33a66bd3654fb17f8af731c965d78977ebeb20392a8" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334608", "to_ids": true, "type": "sha1", "uuid": "55bb3e90-1e90-45c7-b0a4-4122950d210b", "value": "0ad4455380b6c2224bf6d0d5112653db2e05ab28" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334608", "to_ids": true, "type": "md5", "uuid": "55bb3e90-6334-40b1-840f-4d3e950d210b", "value": "37b5ee810eee08eb46da2d4d1710262f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334608", "to_ids": true, "type": "sha256", "uuid": "55bb3e90-f49c-4747-a365-4980950d210b", "value": "f3fc6d8ed53b5be3be601281848d26134fa85ba4737ab69b13a50a3a8dd523cb" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334608", "to_ids": true, "type": "sha1", "uuid": "55bb3e90-723c-4a12-99d1-4b03950d210b", "value": "0e6ebd6d90cc59eb572762afaca548dcc63397d8" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334608", "to_ids": true, "type": "md5", "uuid": "55bb3e90-392c-4007-8990-4f68950d210b", "value": "0be0c072cf2a885d77886705e24e08d8" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334608", "to_ids": true, "type": "sha256", "uuid": "55bb3e90-9868-4e17-8609-44bd950d210b", "value": "b924993e72cc8fd0b505e95cea5e8b09d17d2a15c9d9ebc2b0c32843edcd40ee" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334609", "to_ids": true, "type": "sha1", "uuid": "55bb3e91-9e40-4bc1-8d85-41b1950d210b", "value": "11662f991e15213c282357723bcc49059f6c55f2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334609", "to_ids": true, "type": "md5", "uuid": "55bb3e91-1528-4e9b-97f9-4ca7950d210b", "value": "158105fd8f227ab0a2e3440724520275" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334609", "to_ids": true, "type": "sha256", "uuid": "55bb3e91-1f10-4a05-9e2e-4569950d210b", "value": "d64a0092cf3b55f68c671d462be80241d3a45b75667bb29f624f52aea7f1246f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334609", "to_ids": true, "type": "sha1", "uuid": "55bb3e91-9258-4c7f-a861-46a5950d210b", "value": "11c87f734bce1fec82087fd16e568472e960fe17" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334609", "to_ids": true, "type": "md5", "uuid": "55bb3e91-ac48-48cf-85f8-4b69950d210b", "value": "84964d5410d6c7754e36e7592334df5e" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334609", "to_ids": true, "type": "sha256", "uuid": "55bb3e91-b3c0-4a8f-832b-429a950d210b", "value": "da07eca4cd4cccc81d9418fcc796d28bc95756c8d6d4ad9503effd12b6c0aef7" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334609", "to_ids": true, "type": "sha1", "uuid": "55bb3e91-4648-4af0-973b-4a3b950d210b", "value": "1351e784ebdffacf0fd143c07581136e94ca2319" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334610", "to_ids": true, "type": "md5", "uuid": "55bb3e92-d7c0-4807-b6b7-40a8950d210b", "value": "48d638a3194f8740d9f05faf62670ff9" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334610", "to_ids": true, "type": "sha256", "uuid": "55bb3e92-9c08-4786-8e91-42c3950d210b", "value": "fb3b9464e866b35b3d7a3b506f967b32e1c2015e0703780c89993ce6d50a0ea6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334610", "to_ids": true, "type": "sha1", "uuid": "55bb3e92-60b4-4e6c-9072-45c2950d210b", "value": "13b20e7945eb7342540b5fab2eb2f03063518239" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334610", "to_ids": true, "type": "md5", "uuid": "55bb3e92-aa70-4a5b-be6d-43d6950d210b", "value": "0df77ac381a54c34bf3f12d13f516be1" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334610", "to_ids": true, "type": "sha256", "uuid": "55bb3e92-e9e8-4af2-9714-43cc950d210b", "value": "5e75e0babe92f1a7691a43641fadb7be84d4d273b8bcc6cce5dfeb5523a6b709" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334610", "to_ids": true, "type": "sha1", "uuid": "55bb3e92-a7b0-4015-8830-4331950d210b", "value": "158be9f90b5f37590808e0c97323b6476d4c9f9b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334610", "to_ids": true, "type": "md5", "uuid": "55bb3e92-4c0c-4dce-9d03-4477950d210b", "value": "38bd6cd2b91810c30ceb661e54032f5c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334610", "to_ids": true, "type": "sha256", "uuid": "55bb3e92-d5fc-4f4c-8dd1-443b950d210b", "value": "92af7c751d9353ceb1b449bb6ea1a29c7a68a5bd2344759ad1c974ac5c63dee6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334611", "to_ids": true, "type": "sha1", "uuid": "55bb3e93-5db8-4724-af10-4602950d210b", "value": "1b8f53c2ee42fff1f333223e82d3e538792b9778" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334611", "to_ids": true, "type": "md5", "uuid": "55bb3e93-8a28-4ec3-8847-4a90950d210b", "value": "309ad3a96832730545d1ff1f4fdd8de2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334611", "to_ids": true, "type": "sha256", "uuid": "55bb3e93-3a60-48b2-bfdb-43c6950d210b", "value": "0a5c0224092468a4669f04721e291e3e89653d1ecf436c5c4dd7f1f8df4d0ff7" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334611", "to_ids": true, "type": "sha1", "uuid": "55bb3e93-2874-42bf-a0ee-4e11950d210b", "value": "1ba03151aee8276e95666df59e36506a9136634d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334611", "to_ids": true, "type": "md5", "uuid": "55bb3e93-ecd8-45a4-b019-4a2d950d210b", "value": "f7133f6037738c9c0ade22104349e8bc" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334611", "to_ids": true, "type": "sha256", "uuid": "55bb3e93-7ad4-4652-8682-4e76950d210b", "value": "3d8a446c2da93d0c909caf9724ad452c66c944cf71f582a9b5002e9b2cc67793" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334611", "to_ids": true, "type": "sha1", "uuid": "55bb3e93-69f0-49be-9cbd-4299950d210b", "value": "1f78800e17ecf9535eb695b5665f1da4258be70b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334612", "to_ids": true, "type": "md5", "uuid": "55bb3e94-2c84-4595-82bd-400c950d210b", "value": "432f4e8794a2ea8a64e4c75ea80b790e" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334612", "to_ids": true, "type": "sha256", "uuid": "55bb3e94-e16c-481e-ab68-4175950d210b", "value": "d94b971cecd864fe6153ebe94a775157f3cdb69e8ad802eb78cfc0136737c0f2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334612", "to_ids": true, "type": "sha1", "uuid": "55bb3e94-debc-4f58-bf8b-4276950d210b", "value": "21b5f25b33e6db635ecc245291b092748d075719" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334612", "to_ids": true, "type": "md5", "uuid": "55bb3e94-d544-4ee7-9f69-47d2950d210b", "value": "652a5cd27ff8966d26db94bb394ce4d1" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334612", "to_ids": true, "type": "sha256", "uuid": "55bb3e94-dd84-44d9-8c7d-4424950d210b", "value": "b6d736a68360253a94cc89bafbfa3141c382079d3e74346b12251da26149d1c3" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334612", "to_ids": true, "type": "sha1", "uuid": "55bb3e94-8ecc-4e3a-bf6e-4161950d210b", "value": "23442e4cee456a1571f65c75e0e53c388e194d7f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334612", "to_ids": true, "type": "md5", "uuid": "55bb3e94-44a0-4e39-8521-4e80950d210b", "value": "92a05da3047dd74826e09acc2692fe57" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334613", "to_ids": true, "type": "sha256", "uuid": "55bb3e95-7414-4310-9a44-4074950d210b", "value": "cfa438d2d1426c983134203329e30ac92a4c5f6170e1687dc287ecf67ef53404" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334613", "to_ids": true, "type": "sha1", "uuid": "55bb3e95-4478-406d-ba84-4704950d210b", "value": "23ba80af8dfb460b579b46309f4b7f0de53bbdd4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334613", "to_ids": true, "type": "md5", "uuid": "55bb3e95-c56c-47f8-83e6-43e7950d210b", "value": "c36d60abed084c6d61741b08ff6681df" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334613", "to_ids": true, "type": "sha256", "uuid": "55bb3e95-0f4c-4927-904f-489d950d210b", "value": "a1eae49b5f732a7ceef30fa8aa1218c9c97e6436bfab5555ed79e4b29b0fda83" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334613", "to_ids": true, "type": "sha1", "uuid": "55bb3e95-85b4-4393-81e4-44d4950d210b", "value": "26f87e87c78f075ff69aa7de4f6c50f97f499ab7" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334613", "to_ids": true, "type": "md5", "uuid": "55bb3e95-8c64-442e-972b-45c5950d210b", "value": "e3bd52648f653b38d75d325f2c205130" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334613", "to_ids": true, "type": "sha256", "uuid": "55bb3e95-3e50-4b75-af35-4bee950d210b", "value": "79deeb5af79f9a48cbbbb37400b940dc1e709230d0b176669bc1d095c4bedca7" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334613", "to_ids": true, "type": "sha1", "uuid": "55bb3e95-a21c-4875-973c-4435950d210b", "value": "275c5629439be1efa5f586b0bde9f447b85be829" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334614", "to_ids": true, "type": "md5", "uuid": "55bb3e96-7e5c-4209-82b0-47a9950d210b", "value": "2e6707641e23e18134e93e3c4f51c840" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334614", "to_ids": true, "type": "sha256", "uuid": "55bb3e96-007c-4e23-acd6-43a2950d210b", "value": "71864e38545034655c934d46f6b50485cb3d605ad39a7c3889f7d3816440bf1c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334614", "to_ids": true, "type": "sha1", "uuid": "55bb3e96-7dec-402c-aa3b-473f950d210b", "value": "28fb3ef8f16da864f44529f1fa09872af6b7e858" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334614", "to_ids": true, "type": "md5", "uuid": "55bb3e96-3fb8-470e-8cd8-4d3e950d210b", "value": "081b26d9ca74faae821e0b2eb2bb1fc5" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334614", "to_ids": true, "type": "sha256", "uuid": "55bb3e96-b3ec-4031-bf0f-44fe950d210b", "value": "4ae1e35dc83825dc81e886b7597f00781b184be4fa288a8aa7a3c0f62a526387" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334614", "to_ids": true, "type": "sha1", "uuid": "55bb3e96-c5b0-4edc-b928-4611950d210b", "value": "2f4e851d21c45e9b0a77a9cd9a0d5500a7740395" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334614", "to_ids": true, "type": "md5", "uuid": "55bb3e96-0d38-42ba-8d3f-4cff950d210b", "value": "68cd61eefa0e6a7a6b36fb359bdd93ae" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334615", "to_ids": true, "type": "sha256", "uuid": "55bb3e97-2d70-4447-bb6c-4415950d210b", "value": "b785b107632a3b8e9070a5a9a610202b46d916709f6b969b30c5d3375a2f38e7" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334615", "to_ids": true, "type": "sha1", "uuid": "55bb3e97-14e0-4263-a34e-4339950d210b", "value": "2f9a28719745d1f95818c424bef3bd202f4172e9" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334615", "to_ids": true, "type": "md5", "uuid": "55bb3e97-74a0-4d90-9f30-43bf950d210b", "value": "56fd59bf9f93ab512cfb0822e20dc157" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334615", "to_ids": true, "type": "sha256", "uuid": "55bb3e97-f428-4f3f-841a-4a01950d210b", "value": "f82c4673a15ff6c5806f54811c4e782b595a0a445476c3ccdbdc4cd200bfe36e" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334615", "to_ids": true, "type": "sha1", "uuid": "55bb3e97-41f0-4f7c-8fd4-4376950d210b", "value": "333a5d4082808206eeedd309e02d88e720587e4f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334615", "to_ids": true, "type": "md5", "uuid": "55bb3e97-2874-49d5-9142-42ef950d210b", "value": "1fc10a99ce2652ba0ec7bed0f8f05c2c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334615", "to_ids": true, "type": "sha256", "uuid": "55bb3e97-f2b4-4873-b2fb-4fd1950d210b", "value": "f08e6bc6c3a6771f697d4f724bb238f837f61d988c29a2d77dd73cd36a4a38b7" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334616", "to_ids": true, "type": "sha1", "uuid": "55bb3e98-1cb0-4621-9058-49cd950d210b", "value": "33aa87925aaafa5c97df0c4334b3e70b5ce43552" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334616", "to_ids": true, "type": "md5", "uuid": "55bb3e98-bce4-4a6e-8445-4582950d210b", "value": "0bb14e2cbce99ac845c62bea9c5d62ba" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334616", "to_ids": true, "type": "sha256", "uuid": "55bb3e98-1b38-4c5a-9c1a-4c40950d210b", "value": "4f9f7f9b2a3ee884f4aa08c066a458a52f175a78b7748ef4a751543213b92d29" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334616", "to_ids": true, "type": "sha1", "uuid": "55bb3e98-f53c-4414-a35f-4884950d210b", "value": "3412967b6ff4d2ceece701b899571987b8c5d70c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334616", "to_ids": true, "type": "md5", "uuid": "55bb3e98-91ac-4e3d-9f38-45ed950d210b", "value": "d553160f4db53c3ef30bf57aac67811a" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334616", "to_ids": true, "type": "sha256", "uuid": "55bb3e98-ebf4-40b4-98c4-4167950d210b", "value": "2c2a1044acd7d47ade2e74b06fe366fdc1c363297b5292c8a362f34018ae100b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334616", "to_ids": true, "type": "sha1", "uuid": "55bb3e98-e344-4bda-a558-4046950d210b", "value": "34da42515658486c097b4a16c8e7ab6d3fd14020" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334616", "to_ids": true, "type": "md5", "uuid": "55bb3e98-9ffc-4a65-8940-439a950d210b", "value": "d7697f8af52b42e2fb59a350886f02a1" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334617", "to_ids": true, "type": "sha256", "uuid": "55bb3e99-a1fc-4a57-9559-48da950d210b", "value": "0418ecb096bdb3360694780a76838cd333900ebb26a168e3a95225e6579ea20e" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334617", "to_ids": true, "type": "sha1", "uuid": "55bb3e99-9b64-478d-8f96-48db950d210b", "value": "36016bbccebddd9060073f1c9f0c80a2c2dd9cc1" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334617", "to_ids": true, "type": "md5", "uuid": "55bb3e99-6244-4621-901f-4eca950d210b", "value": "42202e223b9d21079f397b9116093ac6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334617", "to_ids": true, "type": "sha256", "uuid": "55bb3e99-1088-48fd-974b-49f4950d210b", "value": "79c4bcc19a33e6b1ef4308b8d8ca93a6f97a08280d80d3ed856805d560e4489d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334617", "to_ids": true, "type": "sha1", "uuid": "55bb3e99-a4a0-463b-842e-44b3950d210b", "value": "389c1d337548d2e3721466a3ca3fd54881cd5aee" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334617", "to_ids": true, "type": "md5", "uuid": "55bb3e99-0f50-4d38-8fac-48fe950d210b", "value": "97ff374ab1a7358eb362406baa0554c8" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334617", "to_ids": true, "type": "sha256", "uuid": "55bb3e99-795c-45ce-b020-4f66950d210b", "value": "010ce301d6ff509e111e9102ec7b883fd888f1510fe3bfba6d71986704dbcd28" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334618", "to_ids": true, "type": "sha1", "uuid": "55bb3e9a-0dbc-4b06-8fce-4b45950d210b", "value": "3cbedf6f7e7c842f1aa3cc6440449fd2defa7df7" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334618", "to_ids": true, "type": "md5", "uuid": "55bb3e9a-bdb4-44e4-b673-42be950d210b", "value": "360303fbb9f31d82afae87a4e71c8e93" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334618", "to_ids": true, "type": "sha256", "uuid": "55bb3e9a-580c-4700-8b62-4ede950d210b", "value": "d31c5d91556d0dc52ddc77d70678441f6f7a647eaaf8e1438fdc5cf3160fb935" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334618", "to_ids": true, "type": "sha1", "uuid": "55bb3e9a-df00-4ebd-a876-46f0950d210b", "value": "41b844cd42208eab05e203b5e22712eaf568d133" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334618", "to_ids": true, "type": "md5", "uuid": "55bb3e9a-6828-44fc-90ad-4929950d210b", "value": "768ee422a113dc1ae0310f6bc4d7c66d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334618", "to_ids": true, "type": "sha256", "uuid": "55bb3e9a-085c-4d00-b5f7-469d950d210b", "value": "cba8e646e951dbfde33daddc1ad6429814dad1ae1786c886948ce9ed7029f487" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334618", "to_ids": true, "type": "sha1", "uuid": "55bb3e9a-6b3c-46e3-8912-487d950d210b", "value": "4357e25f04f902a67604b8b9a6a122a9d3ca0357" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334619", "to_ids": true, "type": "md5", "uuid": "55bb3e9b-3f88-49cc-b9ca-4535950d210b", "value": "a835bd1a588d516e8d9b12c7b85d54de" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334619", "to_ids": true, "type": "sha256", "uuid": "55bb3e9b-1798-4c87-96ad-4571950d210b", "value": "31e9433eccf1c150462b705af11eff50587d25526225d0c4ba07312af0c81969" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334619", "to_ids": true, "type": "sha1", "uuid": "55bb3e9b-bb50-46b0-b4a3-4509950d210b", "value": "441a3f4e360996f53a0ca5bf7280c03771badb90" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334619", "to_ids": true, "type": "md5", "uuid": "55bb3e9b-b9cc-445f-9f33-4da9950d210b", "value": "7cefad54a4656d68d5662836d794b5bb" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334619", "to_ids": true, "type": "sha256", "uuid": "55bb3e9b-8a70-4345-a609-4e62950d210b", "value": "7fcd2160127471fbd92e3dfd656d73eef31195f1fe5a1c77027bd2a961467883" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334619", "to_ids": true, "type": "sha1", "uuid": "55bb3e9b-66f0-4a3d-bed7-4d03950d210b", "value": "4437315b462fce721d16edbe77362b0e634aa559" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334619", "to_ids": true, "type": "md5", "uuid": "55bb3e9b-ac20-48a9-ad9f-4785950d210b", "value": "33f2a0070170ab861e92435114db52d8" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334619", "to_ids": true, "type": "sha256", "uuid": "55bb3e9b-f150-431e-8275-4f18950d210b", "value": "bfb2ac272617e4af5ddf176bb4bffcc090e47b1208f4285a7108d6a59ec51837" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334620", "to_ids": true, "type": "sha1", "uuid": "55bb3e9c-f520-4732-9c83-4ed2950d210b", "value": "48220b4aeb4a96e983d6b1478144592e26fc982b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334620", "to_ids": true, "type": "md5", "uuid": "55bb3e9c-4c88-47ed-95da-4dd5950d210b", "value": "47aeacba39f33b6ce2fd1f654f760a6c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334620", "to_ids": true, "type": "sha256", "uuid": "55bb3e9c-9bbc-4914-b6e4-4b51950d210b", "value": "40a10420b9d49f87527bc0396b19ec29e55e9109e80b52456891243791671c1c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334620", "to_ids": true, "type": "sha1", "uuid": "55bb3e9c-de94-4a34-bdb2-40df950d210b", "value": "48c3fa74a00f1115c0e089f23997f112c85741b4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334620", "to_ids": true, "type": "md5", "uuid": "55bb3e9c-baf0-4c51-8b7a-4315950d210b", "value": "b043ec1567ecceb84c20a853d9245132" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334620", "to_ids": true, "type": "sha256", "uuid": "55bb3e9c-0214-4a4d-9574-451f950d210b", "value": "f6c3d4c2db6e10d5fe9dcddf771d6261a525e7789189f0cfdb4a87faf34d6dd6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334620", "to_ids": true, "type": "sha1", "uuid": "55bb3e9c-3b8c-4a61-9e5c-46cc950d210b", "value": "4dbdb482e6f4882ed8d31e1362e84fc104b397d2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334621", "to_ids": true, "type": "md5", "uuid": "55bb3e9d-5264-43e9-bffb-4217950d210b", "value": "9ed0d182100447ad46b38f8ceef612f2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334621", "to_ids": true, "type": "sha256", "uuid": "55bb3e9d-3758-48fe-b4b9-40c9950d210b", "value": "656c897b39d7867bd4d38696100a09e379b06ab5e5f6842c1329f6bb83e70161" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334621", "to_ids": true, "type": "sha1", "uuid": "55bb3e9d-b24c-45ac-a475-4b11950d210b", "value": "4eb87cff1cf2f1411248cd06b497cac564ed63fd" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334621", "to_ids": true, "type": "md5", "uuid": "55bb3e9d-0c70-4e58-9b91-4096950d210b", "value": "ae0d2278aa783b8dc1675f41cff9d07d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334621", "to_ids": true, "type": "sha256", "uuid": "55bb3e9d-d60c-486e-b3c9-49aa950d210b", "value": "d5b3cc429c8a6fba074d9b1e2963273ac13cead47f63dbbb97e640b74e407134" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334621", "to_ids": true, "type": "sha1", "uuid": "55bb3e9d-2820-4023-b96b-4779950d210b", "value": "4edb69adbc1ebc884aa65cd42e1187f9223de3d3" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334621", "to_ids": true, "type": "md5", "uuid": "55bb3e9d-be2c-49f5-abe0-402e950d210b", "value": "27f45f64f69d31839a6ec82185b5e030" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334622", "to_ids": true, "type": "sha256", "uuid": "55bb3e9e-9bd8-4a7f-868b-4d42950d210b", "value": "5ec8cd3180a2576b92d53085ff5e3dcf4e3dccaf2154b59879969ef8011fd1c2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334622", "to_ids": true, "type": "sha1", "uuid": "55bb3e9e-8130-4ebd-8895-4a6b950d210b", "value": "5004f0d0410666e923212e941f646777b91958b0" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334622", "to_ids": true, "type": "md5", "uuid": "55bb3e9e-2e6c-48a7-ac9a-4111950d210b", "value": "f855633c69c3095b20a99bd12d023271" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334622", "to_ids": true, "type": "sha256", "uuid": "55bb3e9e-c17c-4894-bd42-432a950d210b", "value": "7927f3a35d87250253d8abc021d44cc496d2185f376f0d33b0365a68ba81e636" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334622", "to_ids": true, "type": "sha1", "uuid": "55bb3e9e-09cc-43a6-800c-4ad1950d210b", "value": "50651dbc0af0ff5f1623c468fd4ed4eeb3f2460d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334622", "to_ids": true, "type": "md5", "uuid": "55bb3e9e-8e68-4e58-a537-43df950d210b", "value": "5cd44e29316435cda62790801ec4f473" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334622", "to_ids": true, "type": "sha256", "uuid": "55bb3e9e-0bd8-49ce-8928-4855950d210b", "value": "2b5560f11b24de4fac1b0998cfe80138c2a4f87bb15f6eba6f7f58a5cf1f8622" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334622", "to_ids": true, "type": "sha1", "uuid": "55bb3e9e-e984-4c6d-8c4c-4f61950d210b", "value": "52fa70529cee1101067e7f6cc2532ee64506ba11" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334623", "to_ids": true, "type": "md5", "uuid": "55bb3e9f-ca90-466b-92bc-4d62950d210b", "value": "ed6d8b6078e103b2d12a7fd339838a9c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334623", "to_ids": true, "type": "sha256", "uuid": "55bb3e9f-d014-4a35-b980-4145950d210b", "value": "bf2f9d19521cae12bf25a4108418f6c234af6cad2d7a6482323a12a2da13ebd6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334623", "to_ids": true, "type": "sha1", "uuid": "55bb3e9f-0158-4008-9f4c-44f2950d210b", "value": "537506539114118726725947814c6368cc507ed4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334623", "to_ids": true, "type": "md5", "uuid": "55bb3e9f-fb64-439c-b36c-46b4950d210b", "value": "f063ea5b63c9eb0e8aff3420caf4b64d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334623", "to_ids": true, "type": "sha256", "uuid": "55bb3e9f-43b4-4fe9-8cb6-4e3e950d210b", "value": "ce5d792faaca61d7bb63367f8772f492ee963f054bc03e61b4fae774c3a3c343" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334623", "to_ids": true, "type": "sha1", "uuid": "55bb3e9f-fd0c-47e7-925a-46d7950d210b", "value": "548e8ab0169f36b548a5aa5678ef1b033acbcda4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334623", "to_ids": true, "type": "md5", "uuid": "55bb3e9f-f13c-4331-9d61-483a950d210b", "value": "4170d7f066178181b7f86b5a1125a761" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334624", "to_ids": true, "type": "sha256", "uuid": "55bb3ea0-0e54-454b-82d7-421f950d210b", "value": "b7df931aa020195726002b235740bc844fc4b105920d4a139ca6b5a069e43575" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334624", "to_ids": true, "type": "sha1", "uuid": "55bb3ea0-ae00-4af8-b19c-4438950d210b", "value": "57a0d519db2354fb7f83f5243d4a9fbecf37f677" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334624", "to_ids": true, "type": "md5", "uuid": "55bb3ea0-c300-4094-bdcf-48c9950d210b", "value": "7f1c1146f08a03ec811f443ac6decc15" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334624", "to_ids": true, "type": "sha256", "uuid": "55bb3ea0-94d0-4fdf-b0cd-4801950d210b", "value": "3e9a6f168c4f9f6ce6c6db3fee35218408ee0f79189f53e174f19a439e4036fb" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334624", "to_ids": true, "type": "sha1", "uuid": "55bb3ea0-8130-4a3d-ac14-4066950d210b", "value": "58611fe7ab6aa2e2550c40a059c9f11e88b04252" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334624", "to_ids": true, "type": "md5", "uuid": "55bb3ea0-5940-47e1-8d6c-49a5950d210b", "value": "40e118e4ed768f32da3bd4737a5fc60b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334624", "to_ids": true, "type": "sha256", "uuid": "55bb3ea0-9254-4d41-8b95-4f78950d210b", "value": "7a136aff189f79dee342378d9d011ef35b639840148989670cd9ed3aaa404cdd" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334625", "to_ids": true, "type": "sha1", "uuid": "55bb3ea1-1628-4da8-88ed-4e64950d210b", "value": "589c73842529a15fa9b77b6d4c09b4f519b16fc5" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334625", "to_ids": true, "type": "md5", "uuid": "55bb3ea1-4ed8-4561-bbfd-42c8950d210b", "value": "5bcdf425169900ec224039b72c6ec5dc" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334625", "to_ids": true, "type": "sha256", "uuid": "55bb3ea1-32a0-4287-af3c-4208950d210b", "value": "c65d9d6defebeacbf761ae61baee0386dd7aeb2bd8577611edfadfb765e6ca52" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334625", "to_ids": true, "type": "sha1", "uuid": "55bb3ea1-df54-4aca-9141-40f6950d210b", "value": "5ab36b7bb8b782cdc3a4670adf3afa2dabc978b8" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334625", "to_ids": true, "type": "md5", "uuid": "55bb3ea1-1c90-4158-af81-4f9c950d210b", "value": "2911e7d0f7a9ee343532865de81b1cc5" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334625", "to_ids": true, "type": "sha256", "uuid": "55bb3ea1-31f4-4163-bd67-4512950d210b", "value": "9db48e1cb712104830461c062d0a93f8e3b4043c0ab8b2dc0e1f5599827f4e21" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334625", "to_ids": true, "type": "sha1", "uuid": "55bb3ea1-84d0-4569-813d-42cc950d210b", "value": "5ef6c7729e2f6d445fd3fd72f93ec637a5c32789" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334625", "to_ids": true, "type": "md5", "uuid": "55bb3ea1-4a84-48a3-bb20-43af950d210b", "value": "7f2aad2ad7bced650d9eb19dc80502c9" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334626", "to_ids": true, "type": "sha256", "uuid": "55bb3ea2-3190-45d0-b1f7-4d74950d210b", "value": "e378812f4347b6ec7a517d9c06dc1cd608322033743ec075afe26857bb65c6b0" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334626", "to_ids": true, "type": "sha1", "uuid": "55bb3ea2-d3dc-4cb8-9060-4c3e950d210b", "value": "5fe9dad18883d1dc64dacb7aa8dd7988ca7b52bb" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334626", "to_ids": true, "type": "md5", "uuid": "55bb3ea2-a8cc-4f09-ae62-4663950d210b", "value": "3b726e15b2e161a5acadb1a1bce87cb9" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334626", "to_ids": true, "type": "sha256", "uuid": "55bb3ea2-f3f4-4f80-a8b0-4e64950d210b", "value": "60562a923d1fb595d6e144a0957bc5f9fda0d3f105c316ab5e7d7cd27ff0c27f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334626", "to_ids": true, "type": "sha1", "uuid": "55bb3ea2-a9e4-4468-a9b9-4a6c950d210b", "value": "6081a7794e1fb5349ac25fbba1bb80e4df857c35" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334626", "to_ids": true, "type": "md5", "uuid": "55bb3ea2-4ea4-4d09-8b36-454e950d210b", "value": "2a6ad4fb3a29795ec7b2f02304464b36" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334626", "to_ids": true, "type": "sha256", "uuid": "55bb3ea2-ed88-41de-ba77-414f950d210b", "value": "01b3cd088328aa2d87f6b3c435fef56b8a6033f78767a680d416f88c3e3ddae7" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334627", "to_ids": true, "type": "sha1", "uuid": "55bb3ea3-43a8-45fa-addd-4993950d210b", "value": "6204297b04970e0f7c843a28636b2e5e28213e93" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334627", "to_ids": true, "type": "md5", "uuid": "55bb3ea3-d288-4c56-8cd7-4914950d210b", "value": "148b8f6c9e47e59f171e2cc938382ecc" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334627", "to_ids": true, "type": "sha256", "uuid": "55bb3ea3-c350-443a-b618-47a0950d210b", "value": "60f4e50985afa8c0b2437c78467fc11784416791cd8cacdb37542a3e14d79871" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334627", "to_ids": true, "type": "sha1", "uuid": "55bb3ea3-2544-4358-b25e-4b53950d210b", "value": "621e2fbcddee9d4915c2bd4689234ed40475dfb3" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334627", "to_ids": true, "type": "md5", "uuid": "55bb3ea3-1ec8-4258-817c-42ba950d210b", "value": "aec0f36dd1296689a740e43e3b51d734" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334627", "to_ids": true, "type": "sha256", "uuid": "55bb3ea3-c324-4e7e-8919-403e950d210b", "value": "c14327a7d2c7ab2d3edb5c0db2f87688c30f4f781c10b6017183f74403494c07" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334627", "to_ids": true, "type": "sha1", "uuid": "55bb3ea3-99c8-4ce6-a49b-4563950d210b", "value": "62de7920de0dd9904b9af388ef5bb4c277a61051" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334628", "to_ids": true, "type": "md5", "uuid": "55bb3ea4-ee34-4b53-8ca8-44b5950d210b", "value": "ef61dcb3711fd43d1a7e40b6dbd7d361" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334628", "to_ids": true, "type": "sha256", "uuid": "55bb3ea4-e60c-444a-b552-4519950d210b", "value": "feee319cff39fe40dd0e0651bdbb24e9701d7f5adc9eefbfbd4e7e465ebee7f1" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334628", "to_ids": true, "type": "sha1", "uuid": "55bb3ea4-78d0-4da1-a489-4303950d210b", "value": "6a951c1da9080886fb931d01711b225c1368e6e6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334628", "to_ids": true, "type": "md5", "uuid": "55bb3ea4-ce44-4ae8-8f0b-4012950d210b", "value": "29d51c29dd3f0811d403c329053a2f35" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334628", "to_ids": true, "type": "sha256", "uuid": "55bb3ea4-3808-47b9-8bb9-4be8950d210b", "value": "f1ab31f87585c824381ecd5411441bb1c755d81dd0f42bc08fbb061b9066fba0" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334628", "to_ids": true, "type": "sha1", "uuid": "55bb3ea4-b9c4-470f-92b0-4542950d210b", "value": "6efd210c94ef5d49de0f705931b9e93b37e688fb" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334628", "to_ids": true, "type": "md5", "uuid": "55bb3ea4-afc4-4b98-8edd-4a9b950d210b", "value": "0ee9ea3b831677df1ccde2eaafacd165" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334629", "to_ids": true, "type": "sha256", "uuid": "55bb3ea5-5e2c-485b-9b96-482c950d210b", "value": "13397ce53d5bcc5339a9e5b83144eed11e051666abcf26ad393505cfd82ee9ea" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334629", "to_ids": true, "type": "sha1", "uuid": "55bb3ea5-4b94-40ff-882d-4620950d210b", "value": "6f733dea7027321529d43421cb2cc5444b4e0785" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334629", "to_ids": true, "type": "md5", "uuid": "55bb3ea5-7034-405c-9af4-42e7950d210b", "value": "57acb822c5a03afabf9082ef3fd3306d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334629", "to_ids": true, "type": "sha256", "uuid": "55bb3ea5-1a08-49a3-9a17-4cca950d210b", "value": "0dd0325e09c0ba103aedc9e899192204ab29f4a0d35a7e53e5c800d9284a37e8" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334629", "to_ids": true, "type": "sha1", "uuid": "55bb3ea5-a758-4c80-90cf-43e2950d210b", "value": "753bb0e7250d930957dabfdc0809352eed153b31" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334629", "to_ids": true, "type": "md5", "uuid": "55bb3ea5-23dc-4c5b-ab1c-4f6e950d210b", "value": "d341cd4cde7d8b10b3362b3d1b640d14" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334629", "to_ids": true, "type": "sha256", "uuid": "55bb3ea5-f6d8-46a6-8e92-4f1f950d210b", "value": "639152dcce89b669fa00213d853425bee35f8b79970a663492d24ce29421fb75" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334629", "to_ids": true, "type": "sha1", "uuid": "55bb3ea5-c2cc-49c7-bf81-4e1e950d210b", "value": "779946589786d2dfea06bd102be88df02426b491" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334630", "to_ids": true, "type": "md5", "uuid": "55bb3ea6-2ac0-4b41-8cb1-4952950d210b", "value": "cc0bb7d434d786bf35447cf90e3b88df" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334630", "to_ids": true, "type": "sha256", "uuid": "55bb3ea6-265c-4f52-9751-4f5b950d210b", "value": "5691fefbba82244c63e2166e246b1ef16d66b46ff1434e13815c8796177dc522" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334630", "to_ids": true, "type": "sha1", "uuid": "55bb3ea6-5524-4814-bb0c-412f950d210b", "value": "7818cbabec362de92407234c123f5a6dd910122c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334630", "to_ids": true, "type": "md5", "uuid": "55bb3ea6-9774-4755-806d-43fa950d210b", "value": "f4f3692c0bb00a94130d3b205e1e9baa" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334630", "to_ids": true, "type": "sha256", "uuid": "55bb3ea6-0a58-4c32-ae3f-409c950d210b", "value": "3ea8909c7e92d10a39ba08b002b489e718d77f12754e1bac8e69d62891ac8417" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334630", "to_ids": true, "type": "sha1", "uuid": "55bb3ea6-1eb4-4add-883a-4369950d210b", "value": "79fc0befe9e5530e2496a9fa6beadaa636119aa8" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334630", "to_ids": true, "type": "md5", "uuid": "55bb3ea6-0494-4058-b22c-4baf950d210b", "value": "640b52a15b798fa6cee52f2f309f43f4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334631", "to_ids": true, "type": "sha256", "uuid": "55bb3ea7-e7b8-4ded-a2b8-408a950d210b", "value": "4d96580225828b1b735a02835b5d753992be7ccdfcfb80c50d7acaae3e8c63c6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334631", "to_ids": true, "type": "sha1", "uuid": "55bb3ea7-e9f8-44fb-822a-4368950d210b", "value": "7b2507e7e06044fe193b811b7c6ee3768652fc67" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334631", "to_ids": true, "type": "md5", "uuid": "55bb3ea7-a4bc-4f55-865e-4020950d210b", "value": "5bad3163f9caf8686c7b9e43934a696f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334631", "to_ids": true, "type": "sha256", "uuid": "55bb3ea7-8090-41b3-99d7-4605950d210b", "value": "988246ec5ee40470dd1c6661f7509d43dfa3debadd66ae4722a091935ecb56d9" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334631", "to_ids": true, "type": "sha1", "uuid": "55bb3ea7-85f0-4a5c-8e2c-42bb950d210b", "value": "7c1db3fff72b3c8180fe0eedd092328e29b61588" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334631", "to_ids": true, "type": "md5", "uuid": "55bb3ea7-ba30-4a86-9b69-4a4f950d210b", "value": "fa6d890c0780e5bb42550ac52e46e94d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334631", "to_ids": true, "type": "sha256", "uuid": "55bb3ea7-e684-46c7-b6ec-4377950d210b", "value": "3b471511630e5ae364c28de07dae041a5b44a040f49e15735afa509e44801863" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334632", "to_ids": true, "type": "sha1", "uuid": "55bb3ea8-3ca4-4ba5-8868-4bd6950d210b", "value": "80bf90a45be02815e6765e931063948bc563a8af" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334632", "to_ids": true, "type": "md5", "uuid": "55bb3ea8-c800-4678-9cb2-47ce950d210b", "value": "dae2dab64bdffe40c3730f7797c4c372" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334632", "to_ids": true, "type": "sha256", "uuid": "55bb3ea8-78dc-4730-94a9-4beb950d210b", "value": "1c5f12e0c15adf930b31402e6586f3a05a0173237ea13adce2f01edde9748992" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334632", "to_ids": true, "type": "sha1", "uuid": "55bb3ea8-6bbc-4c01-a872-4c77950d210b", "value": "827ad016a75e822dccd4d3c0c0cc178e7702a99b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334632", "to_ids": true, "type": "md5", "uuid": "55bb3ea8-ee40-435d-8681-4abc950d210b", "value": "21749bb7bdeac89843a60b0d032cf874" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334632", "to_ids": true, "type": "sha256", "uuid": "55bb3ea8-38c4-42ba-b4a8-4d08950d210b", "value": "3bee8a4ee4efc157949587342ca73316eb9c95442cdb25dc349008c43dc64ba6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334632", "to_ids": true, "type": "sha1", "uuid": "55bb3ea8-3528-48a9-a2ef-4da5950d210b", "value": "83852d86836e9d2193067919815418972e5cc03a" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334632", "to_ids": true, "type": "md5", "uuid": "55bb3ea8-72c8-4907-bcc7-403f950d210b", "value": "32d9d4da5e7b99e2d70200d14003e830" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334633", "to_ids": true, "type": "sha256", "uuid": "55bb3ea9-9d68-4ed6-af88-436f950d210b", "value": "a61c9ae6ac4149619f058a09b83e7ba16bf6bf2492201fa299c25495ef01ba30" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334633", "to_ids": true, "type": "sha1", "uuid": "55bb3ea9-ee90-4ee8-8e10-4232950d210b", "value": "84fe4e29cceafae55caf85952c0a83b92c75fba1" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334633", "to_ids": true, "type": "md5", "uuid": "55bb3ea9-94e0-4bef-a3ad-488b950d210b", "value": "a7bb3bcbd0b76c71cead0c9c41d060f3" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334633", "to_ids": true, "type": "sha256", "uuid": "55bb3ea9-cc40-43db-b907-467e950d210b", "value": "6e6f6e40a2716d11425a88b560e80fefd1a16d81ddee9663ff42ab82ea3a35bd" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334633", "to_ids": true, "type": "sha1", "uuid": "55bb3ea9-73bc-4036-bc6f-4d13950d210b", "value": "8561291a00ec2c7cef2bd1d5daf48b350baeae8b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334633", "to_ids": true, "type": "md5", "uuid": "55bb3ea9-fc1c-46e9-8085-4af2950d210b", "value": "637969fbc85e184e93a96f146abd7bad" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334633", "to_ids": true, "type": "sha256", "uuid": "55bb3ea9-6324-4c4c-a957-4ef5950d210b", "value": "9261693b67b6e379ad0e57598602712b8508998c0cb012ca23139212ae0009a1" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334634", "to_ids": true, "type": "sha1", "uuid": "55bb3eaa-5628-4930-98e7-4bbe950d210b", "value": "8697fca8fb4c27f64f42c393e527165e9604ae4e" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334634", "to_ids": true, "type": "md5", "uuid": "55bb3eaa-8748-4506-b03a-4880950d210b", "value": "41ff8be81c58eb94b5f59e5f91ba0eec" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334634", "to_ids": true, "type": "sha256", "uuid": "55bb3eaa-1fac-47e9-8def-49dc950d210b", "value": "8d9695d0af6c38b8552ab3182f41f7ae96dc6cd90e107ee7ce9c132ac9394b61" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334634", "to_ids": true, "type": "sha1", "uuid": "55bb3eaa-3704-471d-b117-4958950d210b", "value": "87c6760c13c17e35d90a203a2acacfdf2ada0ed2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334634", "to_ids": true, "type": "md5", "uuid": "55bb3eaa-52a8-4043-85cb-4df4950d210b", "value": "f413e8519a67390e4618fb3653250572" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334634", "to_ids": true, "type": "sha256", "uuid": "55bb3eaa-2050-485b-bb8b-431d950d210b", "value": "adca333d2cee959c9323327ec8b3abd1193f34c520b80e4f699b49f70e14971c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334634", "to_ids": true, "type": "sha1", "uuid": "55bb3eaa-3d20-4b0f-aa14-4934950d210b", "value": "88c9e88086c8aa987eeebe70c5876b7660cd12d0" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334635", "to_ids": true, "type": "md5", "uuid": "55bb3eab-d0d4-434a-b7b6-468c950d210b", "value": "a64c6ebab211184ab23ae72aebdab976" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334635", "to_ids": true, "type": "sha256", "uuid": "55bb3eab-e3e0-4aad-a9c0-4bc3950d210b", "value": "8cf6258d002326a03cf4cd70d97837b02a1ba5f3451e88fa354947180fb93eaa" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334635", "to_ids": true, "type": "sha1", "uuid": "55bb3eab-9f48-48b3-80d6-4d8e950d210b", "value": "89b07f90ec9db28d0c53423e6f64745da7e607cb" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334635", "to_ids": true, "type": "md5", "uuid": "55bb3eab-7860-4c79-beac-4f70950d210b", "value": "56ac87bbab2e471bad63918f3b953745" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334635", "to_ids": true, "type": "sha256", "uuid": "55bb3eab-76b8-4640-aa0a-4167950d210b", "value": "edc3fba72f9a485c43c1aa3cbe0c5752d8af2ec7bfecb48a46f467e549daac05" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334635", "to_ids": true, "type": "sha1", "uuid": "55bb3eab-c674-4282-a74c-408d950d210b", "value": "8a0fa4074403caeef809113ba7c84eba4404ed9c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334635", "to_ids": true, "type": "md5", "uuid": "55bb3eab-72a0-4348-9be5-46e8950d210b", "value": "2c367d915ca37e237df16d8548151a8b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334635", "to_ids": true, "type": "sha256", "uuid": "55bb3eac-5348-4c05-a847-4c43950d210b", "value": "b40d0ed8d1b7bbd0d52990ccbb7e927777d9854640c6c4b0adc683d55a965758" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334636", "to_ids": true, "type": "sha1", "uuid": "55bb3eac-ec10-4cf0-88a9-4f56950d210b", "value": "8cddf9c84e4a7eee3da4939ee0147d1e39ee3e1f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334636", "to_ids": true, "type": "md5", "uuid": "55bb3eac-53e0-4c67-9bea-46da950d210b", "value": "56f3437184e1ee96b1161135f3c5a1ab" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334636", "to_ids": true, "type": "sha256", "uuid": "55bb3eac-830c-423d-b045-4a73950d210b", "value": "8bba59ce301d510bc3b24c941841ee4a8b0858d37e31c9d59193b78e7da81d9a" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334636", "to_ids": true, "type": "sha1", "uuid": "55bb3eac-7bec-457f-b075-4abd950d210b", "value": "8cec37385290b004e0b6514a44cb0bf7b7e64aac" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334636", "to_ids": true, "type": "md5", "uuid": "55bb3eac-7080-405d-b878-4f5e950d210b", "value": "bc7e2c790deaecf69a69c042932e428b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334636", "to_ids": true, "type": "sha256", "uuid": "55bb3eac-f5c0-452a-857c-4ce7950d210b", "value": "d5d23fbad723009a6a6364ef28153ffc95190e269cf3749c3cf28128d4c89be1" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334636", "to_ids": true, "type": "sha1", "uuid": "55bb3eac-1b28-4b2b-b35f-450e950d210b", "value": "90342657a424fcffa836dfa5136eb362f49fdfb6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334637", "to_ids": true, "type": "md5", "uuid": "55bb3ead-6e04-4474-8891-46d5950d210b", "value": "19e932c289b936f407cd93dc4162eec4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334637", "to_ids": true, "type": "sha256", "uuid": "55bb3ead-c828-42c5-b736-46c8950d210b", "value": "fff8c7da09ace612e203a7d91b24e56a9e1715d5bfe6a7a4466adff284009a1e" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334637", "to_ids": true, "type": "sha1", "uuid": "55bb3ead-ec88-4107-b328-4e0a950d210b", "value": "9432d96afa2618213a7e2ccd6c9735291c694b9a" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334637", "to_ids": true, "type": "md5", "uuid": "55bb3ead-86bc-4111-b668-4f53950d210b", "value": "bdfc8d71ed9d065f7fba87f84adeea3f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334637", "to_ids": true, "type": "sha256", "uuid": "55bb3ead-a304-4235-9b91-4cb6950d210b", "value": "91b0995ee522a6a01fe112dd6cdc21f2cd57b26ac84d8e3065f124ccb93c5eb4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334637", "to_ids": true, "type": "sha1", "uuid": "55bb3ead-ef18-4d11-b2d3-4147950d210b", "value": "944e99725740271a01012d13ccbc9b9b4094fdbf" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334637", "to_ids": true, "type": "md5", "uuid": "55bb3ead-87bc-480a-a2d3-4a05950d210b", "value": "5a0ae7088982e61cad12d0bfcc14d070" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334638", "to_ids": true, "type": "sha256", "uuid": "55bb3eae-9510-4537-bdf3-44f6950d210b", "value": "374f1774b3689e8f1cbbee2cdcef9a94bb30048b0f4f243b8c1c8d1d70ec8442" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334638", "to_ids": true, "type": "sha1", "uuid": "55bb3eae-1af4-431f-a3cf-43f6950d210b", "value": "956397670afa8921a29110f9926ba118b0a9b5fe" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334638", "to_ids": true, "type": "md5", "uuid": "55bb3eae-13d4-4621-ba78-4909950d210b", "value": "c2979839d2dfee2d26b32510d4c35bc2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334638", "to_ids": true, "type": "sha256", "uuid": "55bb3eae-f288-4fc7-bed6-40d5950d210b", "value": "ea2244395a2f750564fc26d64b4cd50c2afd779b4404497564e0fe13a255b707" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334638", "to_ids": true, "type": "sha1", "uuid": "55bb3eae-e1c8-4f17-b552-47b1950d210b", "value": "97400f2cd6873187109fb9a4be4cc199067e8e4b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334638", "to_ids": true, "type": "md5", "uuid": "55bb3eae-3d18-4e20-833d-40be950d210b", "value": "32fcb852290c66212c9f5377313b3c54" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334638", "to_ids": true, "type": "sha256", "uuid": "55bb3eae-9098-4c04-ba15-4cde950d210b", "value": "0ca7fafd58f8ddca6dd182790b1a634205f45bac5c4a3ff4cecc3473d0c47726" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334639", "to_ids": true, "type": "sha1", "uuid": "55bb3eaf-3f00-4122-9782-48a4950d210b", "value": "9b1ed2cd261bc4b6f1ccf8441dbf3d5c936b63c4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334639", "to_ids": true, "type": "md5", "uuid": "55bb3eaf-a690-49be-82f7-45ae950d210b", "value": "58a5485bebda446634c538f20362f0e4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334639", "to_ids": true, "type": "sha256", "uuid": "55bb3eaf-e7d8-42fd-888d-4b3f950d210b", "value": "976a843ee5a35e5015b5b2394e520e82403e6f81f877a4206bfe705bcb5e13e4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334639", "to_ids": true, "type": "sha1", "uuid": "55bb3eaf-24cc-43fd-a85f-42ac950d210b", "value": "9cfa6d066024a458e133fb9cfbafbdfa0b1c64f9" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334639", "to_ids": true, "type": "md5", "uuid": "55bb3eaf-7b7c-401f-b5b4-4e6f950d210b", "value": "63de9e55e07f81e6d38eb859483b103d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334639", "to_ids": true, "type": "sha256", "uuid": "55bb3eaf-f95c-431e-b07d-408a950d210b", "value": "6d22dbb5285391be5dcce7a2aed9f14b7ef57de90fd5b02d4bd7ba07d4a5d455" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334639", "to_ids": true, "type": "sha1", "uuid": "55bb3eaf-acf4-4f03-b8fd-478f950d210b", "value": "9f6a16d59f1159110caf32df1ad2bb6183d8bc49" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334640", "to_ids": true, "type": "md5", "uuid": "55bb3eb0-9f70-48ac-9967-4fbe950d210b", "value": "1ee3aa67213868df9b08d00f3bfca6b1" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334640", "to_ids": true, "type": "sha256", "uuid": "55bb3eb0-1b00-4e40-a20f-4d45950d210b", "value": "5e5157e77089c4cfcfb2dfc82a574e465a943323e330dfe15316553d41f3d7eb" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334640", "to_ids": true, "type": "sha1", "uuid": "55bb3eb0-9ee0-42c6-9dea-4c46950d210b", "value": "a047c5270762a05632b908c65beb14908bc4972f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334640", "to_ids": true, "type": "md5", "uuid": "55bb3eb0-7300-4987-bbad-43cd950d210b", "value": "b4ffce10c64d1107901318b43b012e9a" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334640", "to_ids": true, "type": "sha256", "uuid": "55bb3eb0-f6e8-4fee-8366-44a7950d210b", "value": "c8b3fa82fdd97f731851fa19611499b2c7a493cd689ac4d1796b3687d7fb6c82" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334640", "to_ids": true, "type": "sha1", "uuid": "55bb3eb0-b180-4b4b-9424-4a28950d210b", "value": "a14d7340ac6baf0b38eee37d7e3097d92a7e75e7" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334640", "to_ids": true, "type": "md5", "uuid": "55bb3eb0-4ff8-42b7-a711-42e5950d210b", "value": "a05c9161177ee61f3e5aba75fc0a4970" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334641", "to_ids": true, "type": "sha256", "uuid": "55bb3eb1-8e7c-4452-997d-47da950d210b", "value": "559266876f060621f9b910ec75404946121460375b6f7812da717896e96dec26" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334641", "to_ids": true, "type": "sha1", "uuid": "55bb3eb1-2e28-4a87-94fc-47f3950d210b", "value": "a3a7545333638ec13ad33af6c4ec32a2d4f56c5d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334641", "to_ids": true, "type": "md5", "uuid": "55bb3eb1-25b8-435a-a323-4f7c950d210b", "value": "9bce542aa3fdd21c63e18d453ae8039d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334641", "to_ids": true, "type": "sha256", "uuid": "55bb3eb1-b494-407b-929b-4d0b950d210b", "value": "957fcc2d137e9164635831dd0ab8bca8079ec8b1a4c2eb6e8ac254c5732b025b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334641", "to_ids": true, "type": "sha1", "uuid": "55bb3eb1-6010-4876-8527-4acf950d210b", "value": "a56a1b3f473346f0395c0de433938dbf4fa25a11" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334641", "to_ids": true, "type": "md5", "uuid": "55bb3eb1-f958-47c4-8315-4ec9950d210b", "value": "c219ac463ef4bb377b0b5e7ec19ce976" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334641", "to_ids": true, "type": "sha256", "uuid": "55bb3eb1-bea4-41ff-8197-4a5e950d210b", "value": "a5948e46db292b61d4c4032a7c7af15453477dd6ce4453daa4a6753c7763d873" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334642", "to_ids": true, "type": "sha1", "uuid": "55bb3eb2-48e8-4606-9062-4e9f950d210b", "value": "a6e5539410661a8407ea022f4f55aa13ca674fa1" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334642", "to_ids": true, "type": "md5", "uuid": "55bb3eb2-9c74-4920-a128-4624950d210b", "value": "5e000fd125d326782a4b3dbd8eb65cf2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334642", "to_ids": true, "type": "sha256", "uuid": "55bb3eb2-3e28-44f2-beaf-4947950d210b", "value": "602bb8e06f9ec55f1b4c78a77e4ec229548763076a69e6606a898c4dd9731ff4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334642", "to_ids": true, "type": "sha1", "uuid": "55bb3eb2-bb5c-4784-b9f7-425c950d210b", "value": "ab30ae8b0bf1f3986d9635ea6caddf3878b26fa1" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334642", "to_ids": true, "type": "md5", "uuid": "55bb3eb2-f240-4a40-801d-4b91950d210b", "value": "89eab97e6862ab4c47d9f66f850e58ee" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334642", "to_ids": true, "type": "sha256", "uuid": "55bb3eb2-1f84-4fb5-8d59-45a4950d210b", "value": "84058a01bb257a5c0f9a27f893ded585d349c9d87036d1a386fb8368cea2f545" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334642", "to_ids": true, "type": "sha1", "uuid": "55bb3eb2-0ce8-4ebc-a72a-4f7a950d210b", "value": "ab57daff9d93e71bcdf7f4b356089d3ae681602b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334643", "to_ids": true, "type": "md5", "uuid": "55bb3eb3-6760-4d9c-96f8-4198950d210b", "value": "c89f6c16e581e975a12ec19191a766d1" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334643", "to_ids": true, "type": "sha256", "uuid": "55bb3eb3-0b08-4db1-83cb-420d950d210b", "value": "654e7dd64ab4ef04ea22f63fb0497346fb8d484a488be428d78d32a17654604d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334643", "to_ids": true, "type": "sha1", "uuid": "55bb3eb3-1588-4fb3-b59b-438b950d210b", "value": "ac63f0f2ccfd7ef77b1369130e2d4316c306b4d8" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334643", "to_ids": true, "type": "md5", "uuid": "55bb3eb3-63b0-4b72-ab1d-4254950d210b", "value": "5169e6cf3d06429b94bafd835b5e2791" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334643", "to_ids": true, "type": "sha256", "uuid": "55bb3eb3-1db8-4d39-851d-4ac7950d210b", "value": "ec0e0c640f83d91fc50d657870f4b1d07bff0300ad6ba841bc7a211160ca79bf" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334643", "to_ids": true, "type": "sha1", "uuid": "55bb3eb3-e6fc-4a17-bc0c-4489950d210b", "value": "ac8945be4493b660b4ab4283e644b9b0ab3f74a7" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334643", "to_ids": true, "type": "md5", "uuid": "55bb3eb3-9eb4-481b-a92b-4f93950d210b", "value": "f91a6d14a7e0257d2da9b1b6fbc6010c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334644", "to_ids": true, "type": "sha256", "uuid": "55bb3eb4-631c-4a47-b6ac-41b2950d210b", "value": "72ec760b698dc19693eaa846b2cc21ebceec4ee122feb30cb0802a9920af9898" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334644", "to_ids": true, "type": "sha1", "uuid": "55bb3eb4-f198-49fa-95cc-433c950d210b", "value": "ae4ca2e5a431c67a427a36823aeeebd89f3ed0cb" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334644", "to_ids": true, "type": "md5", "uuid": "55bb3eb4-5c48-4c34-9ef5-40ad950d210b", "value": "8aa3c6e9cdb8724088c67c414691b66e" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334644", "to_ids": true, "type": "sha256", "uuid": "55bb3eb4-dcd8-4bc1-9cfd-400d950d210b", "value": "a801ca60fe94c8182274cbea1f5d3666d0b9aada7feffe3d9a613eb1c3a6f949" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334644", "to_ids": true, "type": "sha1", "uuid": "55bb3eb4-d554-4341-9961-49e3950d210b", "value": "b01b815d200a6cc90a0a15f9cde89fa93b7f9dc6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334644", "to_ids": true, "type": "md5", "uuid": "55bb3eb4-6f6c-4ddb-b7c7-4063950d210b", "value": "f2e0816f239a4066dcf4f035d3c91021" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334644", "to_ids": true, "type": "sha256", "uuid": "55bb3eb4-f598-4a34-a72b-4283950d210b", "value": "f4c27c563e9fd56990f1082cc185c8a6f0b04fee97b57042db10300e1eb37f97" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334645", "to_ids": true, "type": "sha1", "uuid": "55bb3eb5-4514-4732-b264-4dcf950d210b", "value": "b0e59fc1d41f66919fc25e454d26d9fd004e03bb" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334645", "to_ids": true, "type": "md5", "uuid": "55bb3eb5-29a4-4f77-90d6-4675950d210b", "value": "b0d0828a54cd184137de8d0deb698119" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334645", "to_ids": true, "type": "sha256", "uuid": "55bb3eb5-e724-4888-aa5a-44c1950d210b", "value": "6e678dc4d933b186557f671913fb2fada37f342d5007dac0b745ca718d2e7405" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334645", "to_ids": true, "type": "sha1", "uuid": "55bb3eb5-bbf0-46ed-91fc-42c7950d210b", "value": "b149a8009f1c4e845778370d25f2df980adea362" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334645", "to_ids": true, "type": "md5", "uuid": "55bb3eb5-6bc4-4ef7-bbb6-4328950d210b", "value": "6f653987ef4837ab20bd0b2d2f609ab0" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334645", "to_ids": true, "type": "sha256", "uuid": "55bb3eb5-ed5c-431a-8c73-4289950d210b", "value": "a9e25fbb95253412de09bc1e4323602afbf5077aca71f861cbc7ad74581511a2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334645", "to_ids": true, "type": "sha1", "uuid": "55bb3eb5-6298-409a-b6f9-4cf4950d210b", "value": "b36ceec3b2bf64802b56c610d3f0be29adc7d4b5" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334646", "to_ids": true, "type": "md5", "uuid": "55bb3eb6-91a8-44b6-b199-4d99950d210b", "value": "0a011ad2222a93014e7420db94f6aa2d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334646", "to_ids": true, "type": "sha256", "uuid": "55bb3eb6-f658-4d9f-8fbe-48ca950d210b", "value": "7279dfe295bfb075bff6a856097491fbd4c932970bb654c969a995322f0d03db" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334646", "to_ids": true, "type": "sha1", "uuid": "55bb3eb6-5dc4-4fce-a0d2-4d5b950d210b", "value": "b6435e8a9356ef2dc0d31b491b78f8c870a4bbec" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334646", "to_ids": true, "type": "md5", "uuid": "55bb3eb6-9bec-4fc8-a4f6-40b1950d210b", "value": "4b8bb84127b0967d316e3d507a0f3b59" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334646", "to_ids": true, "type": "sha256", "uuid": "55bb3eb6-89dc-4e0d-af49-48f1950d210b", "value": "f8addfa091021a34f8b16fac0687b685b72ff1cac87ba1392d6195ab42954d42" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334646", "to_ids": true, "type": "sha1", "uuid": "55bb3eb6-6188-4406-a5f1-43c0950d210b", "value": "b683759f398e76e471879efb52df1738bf1fc307" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334646", "to_ids": true, "type": "md5", "uuid": "55bb3eb6-2354-4b8a-85a0-4404950d210b", "value": "875a81e316b0759f246bde12bf5be852" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334646", "to_ids": true, "type": "sha256", "uuid": "55bb3eb6-1954-4824-a281-4633950d210b", "value": "eda9ba61ad01810aa53eece81626e913c4058a3b3cbf65fded907528117db0ec" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334647", "to_ids": true, "type": "sha1", "uuid": "55bb3eb7-55ac-4b3f-8293-42d4950d210b", "value": "b70d21894318a95717db2c5113be455ccd4c72e0" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334647", "to_ids": true, "type": "md5", "uuid": "55bb3eb7-ce08-4f77-9b58-44f9950d210b", "value": "a4d16a3874aaf01d69c27032cb8988c3" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334647", "to_ids": true, "type": "sha256", "uuid": "55bb3eb7-6304-4659-b849-44a8950d210b", "value": "b15b2acbe02d7b0649b41d1fe7e0cd008761cba28d20c5d9fa9c17e3a430d0eb" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334647", "to_ids": true, "type": "sha1", "uuid": "55bb3eb7-7370-4d6d-a2d0-42de950d210b", "value": "b7ec5d36ca702cc9690ac7279fd4fea28d8bd060" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334647", "to_ids": true, "type": "md5", "uuid": "55bb3eb7-1340-43cc-93f0-4527950d210b", "value": "56eac983a8caa8c0037c6ba25e9a2d9f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334647", "to_ids": true, "type": "sha256", "uuid": "55bb3eb7-089c-4e52-95db-450b950d210b", "value": "fc609adef44b5c64de029b2b2cff22a6f36b6bdf9463c1bd320a522ed39de5d9" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334647", "to_ids": true, "type": "sha1", "uuid": "55bb3eb7-a8d0-4ced-afea-4c95950d210b", "value": "b904f58d5bfd82d0778bdc9911f3b2193398e7cc" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334648", "to_ids": true, "type": "md5", "uuid": "55bb3eb8-c200-472f-b86e-4559950d210b", "value": "251de11b2d47bab208b578db6f4aa38f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334648", "to_ids": true, "type": "sha256", "uuid": "55bb3eb8-84d4-4d0e-878f-44dd950d210b", "value": "a9af1d410b796a7d89050bb8189048260564a1ff0b94db25d0f465ea18b1c02b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334648", "to_ids": true, "type": "sha1", "uuid": "55bb3eb8-4a88-419d-841b-4810950d210b", "value": "ba553804706964473d3782468b1575548da0e211" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334648", "to_ids": true, "type": "md5", "uuid": "55bb3eb8-406c-481e-b46e-4895950d210b", "value": "64e273360b3f45a60cf99ad564954a19" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334648", "to_ids": true, "type": "sha256", "uuid": "55bb3eb8-fef4-4092-841e-487e950d210b", "value": "73ab06fce6b9746c1010a3c588c62069213d94134823b7527559a0f41c88d20d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334648", "to_ids": true, "type": "sha1", "uuid": "55bb3eb8-727c-4613-9c06-418b950d210b", "value": "bab514067c72f51786054136d2e6ab927c62b275" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334648", "to_ids": true, "type": "md5", "uuid": "55bb3eb8-9654-4eb2-92b1-476d950d210b", "value": "b8bb19a432127cae3680ab46140c4789" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334649", "to_ids": true, "type": "sha256", "uuid": "55bb3eb9-fac4-4004-b29f-4c8d950d210b", "value": "5a45524e9ad739585c3851b32f660d777624c811d0b293b3474fa2568e8022d4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334649", "to_ids": true, "type": "sha1", "uuid": "55bb3eb9-b524-4e5f-99e9-4b44950d210b", "value": "bbfbf78a4bfa692b9d152ecc679dcfe1db63ccd6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334649", "to_ids": true, "type": "md5", "uuid": "55bb3eb9-b958-45d4-a471-45f8950d210b", "value": "cef9886a936a35af81ed23b702305ab6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334649", "to_ids": true, "type": "sha256", "uuid": "55bb3eb9-1570-45b7-ae9b-40cd950d210b", "value": "61fe96a5118b531e7f1659085bcd61084354961fb557588bae3619665a8dc681" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334649", "to_ids": true, "type": "sha1", "uuid": "55bb3eb9-f52c-4dbf-90a3-4e7c950d210b", "value": "be8a1093a62d3c2741227510ec09029a18b23a27" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334649", "to_ids": true, "type": "md5", "uuid": "55bb3eb9-539c-4c0c-bb11-4841950d210b", "value": "f62c6e428738f074cf90f21e289dd34f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334649", "to_ids": true, "type": "sha256", "uuid": "55bb3eb9-c48c-46e8-9141-4b18950d210b", "value": "a4afe60c024a34ae16dfbde1224550224ab3195f3d5dfe35c50ebd6a12fd4170" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334649", "to_ids": true, "type": "sha1", "uuid": "55bb3eba-7d1c-4dc5-8830-4c2c950d210b", "value": "bff3f180564f072f45d72bd6a840e9cde68e863e" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334650", "to_ids": true, "type": "md5", "uuid": "55bb3eba-2db8-492b-aa16-4fd9950d210b", "value": "83aff63d5b3855cff982422bebc779d4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334650", "to_ids": true, "type": "sha256", "uuid": "55bb3eba-e984-4ffb-ad3f-4e79950d210b", "value": "32599e86cb3bc9e1f91ff630fa41cd140354a21ac47bdb48082fbb8fba900f53" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334650", "to_ids": true, "type": "sha1", "uuid": "55bb3eba-dc64-47b0-a0d5-4e39950d210b", "value": "c520096fc851bb0da060fb6cab274387ca8e8f88" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334650", "to_ids": true, "type": "md5", "uuid": "55bb3eba-efd4-46a6-9d91-4cdf950d210b", "value": "780c1904904356bb7e4304f37bd98c7b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334650", "to_ids": true, "type": "sha256", "uuid": "55bb3eba-906c-42ad-acda-450c950d210b", "value": "c52f4d1cf3ff09b22cf2f4bef867456aa7426c00fcd19c38b66ee3adc7eba057" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334650", "to_ids": true, "type": "sha1", "uuid": "55bb3eba-54f4-4c4e-91a6-44a9950d210b", "value": "c5959b7d97f2855950bc35c9e0477b1940a43fc2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334650", "to_ids": true, "type": "md5", "uuid": "55bb3eba-020c-4d92-8cfe-41c6950d210b", "value": "bcd74698b43531a3df7fb2f76f4b0a56" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334651", "to_ids": true, "type": "sha256", "uuid": "55bb3ebb-54e8-4c21-8fbb-44d3950d210b", "value": "a23b5fc7d309b982f9dafc712b6a95c1cfce6102f86a7dc3f3013819638081a9" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334651", "to_ids": true, "type": "sha1", "uuid": "55bb3ebb-a034-4cae-a636-4df2950d210b", "value": "c6993c06bb4721a8637390b282e30d5a1c91a22f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334651", "to_ids": true, "type": "md5", "uuid": "55bb3ebb-8fb4-4228-8802-4b58950d210b", "value": "5a724230ca622bdcdc0ba41e524821ca" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334651", "to_ids": true, "type": "sha256", "uuid": "55bb3ebb-2150-4d30-a6bd-4d22950d210b", "value": "90324a869541e0e67f0a3d4dcbdcdeefcaa4839edcb55ee163b7f26f80725278" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334651", "to_ids": true, "type": "sha1", "uuid": "55bb3ebb-8bdc-40ed-bc9e-4de3950d210b", "value": "c7d3c7b4ff167ccc0957f5659c5591f2ed43e70a" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334651", "to_ids": true, "type": "md5", "uuid": "55bb3ebb-e304-483a-a0b7-4764950d210b", "value": "b1c1f4f3e9189ca1763e8b2ca3bbfdfa" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334651", "to_ids": true, "type": "sha256", "uuid": "55bb3ebb-3c20-4cdc-8d9b-4668950d210b", "value": "cedaf3f2bdbd936ca276b636bb119136d67e0e2fa74614442c95bdbae6c50585" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334652", "to_ids": true, "type": "sha1", "uuid": "55bb3ebc-ce04-418f-83b0-46b4950d210b", "value": "c893cd86c0e0d6ed267a5f38c8e51b79436dac62" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334652", "to_ids": true, "type": "md5", "uuid": "55bb3ebc-6838-4d5f-949f-4cea950d210b", "value": "d9faaf817ef1c3ee664659049dde5f39" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334652", "to_ids": true, "type": "sha256", "uuid": "55bb3ebc-ca50-4e55-bbbc-4fef950d210b", "value": "ab4de0951de38c475d846da1da8336b97e886b6dbd694332f3624ee5595186fe" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334652", "to_ids": true, "type": "sha1", "uuid": "55bb3ebc-5b00-4876-9a64-46e7950d210b", "value": "c926351a98a617b0be47608c5d03d08a2a82ee1d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334652", "to_ids": true, "type": "md5", "uuid": "55bb3ebc-88b8-4fe7-8d54-4363950d210b", "value": "f69da77c13a651074c919ab26507c011" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334652", "to_ids": true, "type": "sha256", "uuid": "55bb3ebc-db0c-440f-a709-4470950d210b", "value": "07ed3d9bd82a3b490f33f36117af3ad02152d51e9c2470eb0089dab1305368f1" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334652", "to_ids": true, "type": "sha1", "uuid": "55bb3ebc-cacc-4f96-a728-461a950d210b", "value": "ca84583819c9723fe8d9fc69d8cee66687a180c7" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334653", "to_ids": true, "type": "md5", "uuid": "55bb3ebd-44dc-48d1-91ac-4708950d210b", "value": "5cb4e4e218b97c09c885d157e83f7247" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334653", "to_ids": true, "type": "sha256", "uuid": "55bb3ebd-791c-400c-ad02-4da6950d210b", "value": "150924668c8d7cd9899360eba12f13246538c50fbe7ef1ebf234ed7128c9936e" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334653", "to_ids": true, "type": "sha1", "uuid": "55bb3ebd-e428-4d0f-85b4-4693950d210b", "value": "d228b700a6f4542a63337ab0899bd7e90982c30e" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334653", "to_ids": true, "type": "md5", "uuid": "55bb3ebd-a378-4131-9f5a-44dd950d210b", "value": "5527d16136944bc3795bc65bcbbe65f3" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334653", "to_ids": true, "type": "sha256", "uuid": "55bb3ebd-f030-4014-aae6-43e7950d210b", "value": "42dc1f9417fb067c3b96622ccf6e8c80c9d07202cc28f3c4d460d5bdc6ff249f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334653", "to_ids": true, "type": "sha1", "uuid": "55bb3ebd-2a4c-4ba2-b919-4b9c950d210b", "value": "d2cc4bf197b9d408bcec69252725bbcdb516308c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334653", "to_ids": true, "type": "md5", "uuid": "55bb3ebd-cd7c-4203-b34b-4fd0950d210b", "value": "b58e692d0558ba1b9cfcdda2775c7fac" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334653", "to_ids": true, "type": "sha256", "uuid": "55bb3ebd-6044-4377-8864-4e2c950d210b", "value": "ad55c2dcf7e3373ea074061d119c891b34e4364cd7f5f679b475b5ec3371592e" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334654", "to_ids": true, "type": "sha1", "uuid": "55bb3ebe-eeb4-4b80-b503-4b0f950d210b", "value": "d73123ae61b9183f82ac9fa64c813f2b7483e772" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334654", "to_ids": true, "type": "md5", "uuid": "55bb3ebe-04bc-47b4-81fb-420d950d210b", "value": "9ff1afd5fc8595cd35741696a7a24a4c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334654", "to_ids": true, "type": "sha256", "uuid": "55bb3ebe-74c0-46c3-9f06-4ccd950d210b", "value": "637cf542512b0b6507b39686c7e87af30e7aa3a02eb9481a49efb4d0951adfe8" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334654", "to_ids": true, "type": "sha1", "uuid": "55bb3ebe-d204-483c-adeb-454c950d210b", "value": "d86c6c85f3fe7981f7824f21bcaf45f876943e55" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334654", "to_ids": true, "type": "md5", "uuid": "55bb3ebe-8fc4-469b-8f16-45b3950d210b", "value": "2b7677ebb41abfd97225b2dcf8bbea35" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334654", "to_ids": true, "type": "sha256", "uuid": "55bb3ebe-f770-4cea-9eb0-40aa950d210b", "value": "dac6abd5ba0865b7983cff40f7a13d9cde89fed3c5b81c2b785e884f9ccdf28c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334654", "to_ids": true, "type": "sha1", "uuid": "55bb3ebe-25b0-4c29-b78b-49b7950d210b", "value": "d89f0d3e65532a41615d0ee21f2b2379eb0b27d5" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334655", "to_ids": true, "type": "md5", "uuid": "55bb3ebf-13a0-4551-ace7-4df8950d210b", "value": "738cf6db1f93006967ed1aeef87c6ba6" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334655", "to_ids": true, "type": "sha256", "uuid": "55bb3ebf-8e94-4608-ba25-487b950d210b", "value": "5f6bc6573d006609d1f0b5c3d051dc6eb5b30dbc60c4e2e7c7b6826434c6a59b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334655", "to_ids": true, "type": "sha1", "uuid": "55bb3ebf-134c-4891-b8dd-45a8950d210b", "value": "d981a1a553729bc6ad875d57825dda17b226c385" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334655", "to_ids": true, "type": "md5", "uuid": "55bb3ebf-ff88-4d0e-ba2f-4f1e950d210b", "value": "168b06ee1219ada0afe184f9a70d12a0" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334655", "to_ids": true, "type": "sha256", "uuid": "55bb3ebf-7200-4f13-bac6-482a950d210b", "value": "cc87e067021f8b419cc73863d26bd54e25b6f4c8149d6d331ba50e54aea917ad" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334655", "to_ids": true, "type": "sha1", "uuid": "55bb3ebf-fbcc-4565-9dc3-450e950d210b", "value": "dd6ac4da70c52dc6aad69590c2335925859c838b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334655", "to_ids": true, "type": "md5", "uuid": "55bb3ebf-06e4-4af2-8d99-42c0950d210b", "value": "713c269faa5f650710997004d3be6971" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334656", "to_ids": true, "type": "sha256", "uuid": "55bb3ec0-c120-4fd5-965a-43a8950d210b", "value": "6739dd4361c559fd9099dfc967b06eb5bac95ee8693986ac29c7b368dc7cff08" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334656", "to_ids": true, "type": "sha1", "uuid": "55bb3ec0-ce90-446b-9cdd-45bf950d210b", "value": "ded04333c0eeb0f7978da4f298c191ecf42f98c2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334656", "to_ids": true, "type": "md5", "uuid": "55bb3ec0-c644-44fc-b26a-414f950d210b", "value": "e1e36fa0c482c71fd777be049272f7d2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334656", "to_ids": true, "type": "sha256", "uuid": "55bb3ec0-08b8-4f8e-ad20-4a76950d210b", "value": "e32cfd415d5aee289a62a02b28b7815346cd150d70c0e1f95bb92ecf26a855de" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334656", "to_ids": true, "type": "sha1", "uuid": "55bb3ec0-5acc-4b18-b20a-4923950d210b", "value": "df7e96430c086efef38810de0ce981f7c4b5bd3a" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334656", "to_ids": true, "type": "md5", "uuid": "55bb3ec0-0cd4-437a-8699-486c950d210b", "value": "a226d93f726bdaf119088e62b9b70989" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334656", "to_ids": true, "type": "sha256", "uuid": "55bb3ec0-b57c-4a59-9b09-4b1a950d210b", "value": "b20b198d9e3af27ecac4a83b66234cae4eef6db0c1192b6f9ba9ca946033034b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334657", "to_ids": true, "type": "sha1", "uuid": "55bb3ec1-40fc-4309-8e67-4dc1950d210b", "value": "e113e2904aaae7aa5c2438fea757846cad8a7e9b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334657", "to_ids": true, "type": "md5", "uuid": "55bb3ec1-1f4c-4c1d-ae91-4e43950d210b", "value": "aaf26a0477841b45969fdce35bd2e1e1" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334657", "to_ids": true, "type": "sha256", "uuid": "55bb3ec1-cd2c-4b56-8d3b-42c6950d210b", "value": "d9c55606c757e78940c3a22fc25ae12ed93a68c9f88983e58cd4795047504246" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334657", "to_ids": true, "type": "sha1", "uuid": "55bb3ec1-c1c0-4efc-a007-4d67950d210b", "value": "e19a240f49e953a8ec9a7efc3b0e47cc8ecb07c2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334657", "to_ids": true, "type": "md5", "uuid": "55bb3ec1-c290-40bb-99ce-434c950d210b", "value": "aee7029335a4df8ac44d3587e41c21dc" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334657", "to_ids": true, "type": "sha256", "uuid": "55bb3ec1-30a0-4cd4-9be6-4000950d210b", "value": "3f85279eee498578935e7f51881f8411be5ac7ba45f2334699230cd0b9d60032" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334657", "to_ids": true, "type": "sha1", "uuid": "55bb3ec1-2a88-4594-8430-4998950d210b", "value": "e4c874697e71bb3b3b7fa0d5142f5c28df786313" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334657", "to_ids": true, "type": "md5", "uuid": "55bb3ec2-2648-40e9-a064-438b950d210b", "value": "448975cbf086c450d1ac6285f1b57e95" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334658", "to_ids": true, "type": "sha256", "uuid": "55bb3ec2-0ca8-4c3e-b510-48a9950d210b", "value": "b606cad7024a165b899e3d2ae9625e6d0f207928eb2838a6c4c8b26ddd583bb8" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334658", "to_ids": true, "type": "sha1", "uuid": "55bb3ec2-d490-45a1-91b4-4cf9950d210b", "value": "ea072de4b781749a694628da0758c934ce9cb0a4" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334658", "to_ids": true, "type": "md5", "uuid": "55bb3ec2-022c-4aea-9dc8-43d8950d210b", "value": "014402d32082497d9fae6b339f358401" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334658", "to_ids": true, "type": "sha256", "uuid": "55bb3ec2-9f80-4c4c-9bde-49af950d210b", "value": "941ceeb2cbe1969dc41059e0766b5d6df687e8e8d96e31efea71699686ab6b9e" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334658", "to_ids": true, "type": "sha1", "uuid": "55bb3ec2-4314-4d76-b13a-4652950d210b", "value": "ec316bb9b9d0a09c2bd566e98d6507edb9932eec" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334658", "to_ids": true, "type": "md5", "uuid": "55bb3ec2-35b4-40bd-b986-4164950d210b", "value": "d54e2e633cea68716023e0e524325ffc" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334658", "to_ids": true, "type": "sha256", "uuid": "55bb3ec2-5bc0-4e81-8c75-4769950d210b", "value": "72dc79c35aac14f453674ac3b62c268843a9c614ae99da01879db04c1dd995f9" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334659", "to_ids": true, "type": "sha1", "uuid": "55bb3ec3-9640-462b-84a5-4af2950d210b", "value": "ed91c8a09126bd27edeb0a6f9e5ef64a9b5bd29c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334659", "to_ids": true, "type": "md5", "uuid": "55bb3ec3-1b1c-42f5-9577-4093950d210b", "value": "a0764ea07a40604b295e8600a3b73231" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334659", "to_ids": true, "type": "sha256", "uuid": "55bb3ec3-8458-4994-9184-4ac4950d210b", "value": "9a1dc317baac5b31e8f9498c979e623db6e57f34aaea6dac923853cec1a30397" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334659", "to_ids": true, "type": "sha1", "uuid": "55bb3ec3-4600-49b4-b4a9-426b950d210b", "value": "edc03b57e86aab5f869533ce2487f6918e26d5fe" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334659", "to_ids": true, "type": "md5", "uuid": "55bb3ec3-28dc-49d2-b7ee-468f950d210b", "value": "c170a9961560e4c96215a06f75985fc8" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334659", "to_ids": true, "type": "sha256", "uuid": "55bb3ec3-21bc-4ec5-a8f1-4926950d210b", "value": "598bab73e4e2e9a09da64a16c807fea62bac20ec206384194478fcaf9eac1b14" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334659", "to_ids": true, "type": "sha1", "uuid": "55bb3ec3-5fc0-48a1-a142-40e5950d210b", "value": "ee0d1a3ca639971d130eff10c22350c77a4a062c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334660", "to_ids": true, "type": "md5", "uuid": "55bb3ec4-6544-46ea-91ed-4256950d210b", "value": "cca243be233cfa4c3f44c2035b5db135" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334660", "to_ids": true, "type": "sha256", "uuid": "55bb3ec4-449c-43ce-a947-43b1950d210b", "value": "1a178c22b5e9a7e99c0c733ff9d8452b22a3418b3c137687c8407c309e79a714" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334660", "to_ids": true, "type": "sha1", "uuid": "55bb3ec4-3500-431a-8d90-431c950d210b", "value": "ee52c9416e9da9a1f67785bada3c9f4dae89d1e3" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334660", "to_ids": true, "type": "md5", "uuid": "55bb3ec4-20d8-41cb-a8bb-4568950d210b", "value": "4bd8de4ce17067db858d63997315aee3" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334660", "to_ids": true, "type": "sha256", "uuid": "55bb3ec4-6cc8-4ebc-9b21-45ec950d210b", "value": "f2f6dfc7fc3ff1170a80d661c1dbc18dbdfa456c1327ac475a7b21a38ec014be" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334660", "to_ids": true, "type": "sha1", "uuid": "55bb3ec4-1b0c-44ca-8a04-4f90950d210b", "value": "f039f975acec4b8b60b7619cc75e0b87d809315c" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334660", "to_ids": true, "type": "md5", "uuid": "55bb3ec4-72fc-4368-b7cd-451c950d210b", "value": "60b9933665169020a3565781e4058e08" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334661", "to_ids": true, "type": "sha256", "uuid": "55bb3ec5-117c-4be0-b8a2-42fe950d210b", "value": "200c0623f75433c1e2821d930e6f3e072c5e06f2bd1770551595acc3b170febf" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334661", "to_ids": true, "type": "sha1", "uuid": "55bb3ec5-b230-48dc-b36f-40d7950d210b", "value": "f19e73120166b637ee7a941540979efaa4a284b5" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334661", "to_ids": true, "type": "md5", "uuid": "55bb3ec5-4c88-476c-a654-4bf8950d210b", "value": "7ebc36666f11c4285ee68501dc3c1b5a" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334661", "to_ids": true, "type": "sha256", "uuid": "55bb3ec5-302c-4416-9dad-45bb950d210b", "value": "71fe815f897877e69e4a37844a6d2feb40fdecaed1dd55b07472234e87e22767" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334661", "to_ids": true, "type": "sha1", "uuid": "55bb3ec5-a200-4143-8425-418b950d210b", "value": "f3c3f9e3139efb822e7b574898e95c38498462c0" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334661", "to_ids": true, "type": "md5", "uuid": "55bb3ec5-92ec-4a17-81c4-4016950d210b", "value": "2377d5fa8c47ed262d49575e2e612433" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334661", "to_ids": true, "type": "sha256", "uuid": "55bb3ec5-9590-4587-85e7-472b950d210b", "value": "b524abb464b30366afff9b01da259432f76fef62a7b9d128284e289e76b3da16" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334661", "to_ids": true, "type": "sha1", "uuid": "55bb3ec5-7da4-47f4-9a9b-4b43950d210b", "value": "f7653b3b9d71303d8ac9425985400b321934ddcc" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334662", "to_ids": true, "type": "md5", "uuid": "55bb3ec6-51cc-41c2-ada5-4c37950d210b", "value": "be6655c17f0a797f2c01b2ab42b55107" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334662", "to_ids": true, "type": "sha256", "uuid": "55bb3ec6-8458-422a-87ae-471b950d210b", "value": "7561ace6f04ca6d023d7eba0c8cd49b2515baa71a40926f625538e41e21f641f" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334662", "to_ids": true, "type": "sha1", "uuid": "55bb3ec6-1634-43cc-89c8-4bd4950d210b", "value": "f771f3b68376fa211e590a7f5cb65f7cbab20187" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334662", "to_ids": true, "type": "md5", "uuid": "55bb3ec6-34d4-4e04-8625-49be950d210b", "value": "7421ef518702479d9b1a4b82318a1095" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334662", "to_ids": true, "type": "sha256", "uuid": "55bb3ec6-ae14-4373-807b-4cc8950d210b", "value": "b800ba5adfc26f20b4049dba2442be73347e999a224716c7ecb5271e482e0a4d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334662", "to_ids": true, "type": "sha1", "uuid": "55bb3ec6-0f40-4ea7-a82c-4750950d210b", "value": "f80dbd487b738df05fe27b8d5238cbd3e429dd97" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334662", "to_ids": true, "type": "md5", "uuid": "55bb3ec6-4768-4e0c-ab9a-44bb950d210b", "value": "8a19326b0ecbad83058b0ab803bad254" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334663", "to_ids": true, "type": "sha256", "uuid": "55bb3ec7-a0e8-44a5-9090-493c950d210b", "value": "2c72175f96c651eea3d3411efacf73e0fb3e7543451b73f5e2521f47be67f006" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334663", "to_ids": true, "type": "sha1", "uuid": "55bb3ec7-10c8-4f9b-8060-4297950d210b", "value": "f9860169568558df2eb06b9a7ab9d0a89f45cd44" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334663", "to_ids": true, "type": "md5", "uuid": "55bb3ec7-2244-4227-945e-47a5950d210b", "value": "1c5764dd71b9109dbbcd83201be2ceae" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334663", "to_ids": true, "type": "sha256", "uuid": "55bb3ec7-f110-4ac8-ab05-4aa0950d210b", "value": "abbac3dda22f825197dd65b8c1076c5ab8d7ecaa2ce2821b242f63154eafce3a" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334663", "to_ids": true, "type": "sha1", "uuid": "55bb3ec7-2720-4bc3-ad6e-4613950d210b", "value": "fb106fdbb8ab0ee1272271aa880c254f8da59e42" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334663", "to_ids": true, "type": "md5", "uuid": "55bb3ec7-64c0-42a8-a411-4aa4950d210b", "value": "27fdc0db940764a1218b7a3698571bf2" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334663", "to_ids": true, "type": "sha256", "uuid": "55bb3ec7-22c0-4a56-a345-41db950d210b", "value": "e2f8c5f8c3ab687b91dd28081fec71e0bb9f70066237768e7020fd992c80f2d5" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334664", "to_ids": true, "type": "sha1", "uuid": "55bb3ec8-7fa0-4e55-808b-42a6950d210b", "value": "fb9fddb2b74e62d2e949520de23d6a2a2a16e576" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334664", "to_ids": true, "type": "md5", "uuid": "55bb3ec8-0df8-4068-90e3-417f950d210b", "value": "f12ed5b550d6856ccb501f9ad65f956b" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334664", "to_ids": true, "type": "sha256", "uuid": "55bb3ec8-734c-46f6-9004-4542950d210b", "value": "a72dc5010dc21c3bc9075c74fc7b87f0f89cfbeb1b1c4cdab06db4262d84969d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334664", "to_ids": true, "type": "sha1", "uuid": "55bb3ec8-07e4-4890-a3f5-42d7950d210b", "value": "fd9516d2c5493009009eedc0e98e345956516d1d" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334664", "to_ids": true, "type": "md5", "uuid": "55bb3ec8-0128-4a19-8e35-415c950d210b", "value": "983ea03599f2371d3aa4b561fbdb9d35" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334664", "to_ids": true, "type": "sha256", "uuid": "55bb3ec8-2f8c-4249-a194-451f950d210b", "value": "1b72081c4422785d8c6c016b10bdd7545e5fc6f1ff73277b0366e9b40e624616" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334664", "to_ids": true, "type": "sha1", "uuid": "55bb3ec8-cd20-4d25-b584-4034950d210b", "value": "ff3d21c97e9ca71157f12221ccf0788a9775ec92" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334665", "to_ids": true, "type": "md5", "uuid": "55bb3ec9-5b1c-4635-91d3-4f82950d210b", "value": "2cdd85286c5531557f3f20a7cafa7291" }, { "category": "Payload delivery", "comment": "Verified bad with VirusTotal", "deleted": false, "disable_correlation": false, "timestamp": "1438334665", "to_ids": true, "type": "sha256", "uuid": "55bb3ec9-94d4-4d43-97b5-4703950d210b", "value": "8f6988e717e0334b33b7f4697c8ebbb5038c218994c8da7dc295986fe43b2b8b" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438334998", "to_ids": true, "type": "sha1", "uuid": "55bb4016-84d8-4936-ba45-490f950d210b", "value": "22e1893d9da4fe32aa5abe60f14dad6e52c45095" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438334999", "to_ids": true, "type": "md5", "uuid": "55bb4017-9f80-4607-8d21-4d60950d210b", "value": "3c8fa6759db3772f109b6e9860fcdc93" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438334999", "to_ids": true, "type": "sha256", "uuid": "55bb4017-c9b4-4513-b3b7-4d93950d210b", "value": "9581e36c5a55faae049a89fcfa584cde4fa7294b156e31de3e1a33035f4df3a4" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438334999", "to_ids": true, "type": "sha1", "uuid": "55bb4017-dd64-4bd5-b876-44db950d210b", "value": "3320916ed703343c70ba0166595936eb588a12b8" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438334999", "to_ids": true, "type": "md5", "uuid": "55bb4017-9c90-4008-ae9d-4857950d210b", "value": "f27de7b44ae44588445238ef441c9d99" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438334999", "to_ids": true, "type": "sha256", "uuid": "55bb4017-ead8-4614-8982-47ec950d210b", "value": "14844c483d486348f598f31956aa13e50f3fa85320287d91815be3a611c8f1a1" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438334999", "to_ids": true, "type": "sha1", "uuid": "55bb4017-cb9c-4e28-ac52-4dce950d210b", "value": "5acb3aa1f44924b0b1d3e9cac3098ad709aa397b" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438334999", "to_ids": true, "type": "md5", "uuid": "55bb4017-c04c-4dad-9527-4d68950d210b", "value": "14b03ada92dd81d6ce57f43889810087" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438334999", "to_ids": true, "type": "sha256", "uuid": "55bb4018-1b6c-422d-8435-4049950d210b", "value": "3190e725cc9eb7c116242da2d3f5dba46853b20f46e681df262e201cc22117e7" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335000", "to_ids": true, "type": "sha1", "uuid": "55bb4018-de80-49aa-800d-4ea4950d210b", "value": "5cb07296bda8758a6ad52abf8cbea611ffbfd390" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335000", "to_ids": true, "type": "md5", "uuid": "55bb4018-a0f0-44dc-8c4c-4a77950d210b", "value": "ba6fd88683895e4e4a4aa32014ee93f6" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335000", "to_ids": true, "type": "sha256", "uuid": "55bb4018-ed3c-4374-aaa6-4f26950d210b", "value": "3e1ed9e5fc7ecaa8a01b6fd160cab39d251390a21fb7f6bb98e070efe1506617" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335000", "to_ids": true, "type": "sha1", "uuid": "55bb4018-40e4-4385-8bdf-4929950d210b", "value": "5db463fdb694978f876a9f94c9578e8182799ce1" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335000", "to_ids": true, "type": "md5", "uuid": "55bb4018-e748-42d9-96bc-4d6f950d210b", "value": "82b07d1f6a53b4073ac2e66638051ff7" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335000", "to_ids": true, "type": "sha256", "uuid": "55bb4018-ae98-4a9f-9ee7-430d950d210b", "value": "f009f01467722aa8ba3d7543b9dae37fb8f2de2e0d6ff46755d9684b47775e41" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335000", "to_ids": true, "type": "sha1", "uuid": "55bb4018-b918-4567-ae33-491c950d210b", "value": "664c8dfb65f86a691df9641d9d1ab67c5b39cda4" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335001", "to_ids": true, "type": "md5", "uuid": "55bb4019-67dc-4f6a-8c3d-442f950d210b", "value": "af06c4e1e064a6490d488506960e8bf8" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335001", "to_ids": true, "type": "sha256", "uuid": "55bb4019-e630-464b-8abd-47ef950d210b", "value": "5048af2f388cfa1bd9ee077953f5ef1499a81ee57a8876a051ea96bd08ceb69c" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335001", "to_ids": true, "type": "sha1", "uuid": "55bb4019-741c-4236-8b44-42d1950d210b", "value": "685c4287e74a9704d422ee577b7acb0748119f56" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335001", "to_ids": true, "type": "md5", "uuid": "55bb4019-e74c-4469-9c9f-4b8a950d210b", "value": "8aaaadb7d6a179226e462a9c8004e80e" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335001", "to_ids": true, "type": "sha256", "uuid": "55bb4019-885c-486a-b8fe-4923950d210b", "value": "1a855cef1bb454e7313dba60885e16fa8cb3dced1e38b8ad59ad5429c4e12493" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335001", "to_ids": true, "type": "sha1", "uuid": "55bb4019-d204-40ef-9af3-4816950d210b", "value": "896fe06a9b746dbd9f581267fbf8209a9d071c77" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335001", "to_ids": true, "type": "md5", "uuid": "55bb4019-88fc-4781-8f45-4c93950d210b", "value": "3ae733df029c56fa2e3fc9c07458d8c2" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335002", "to_ids": true, "type": "sha256", "uuid": "55bb401a-e16c-473c-82bf-41fb950d210b", "value": "72269cb148f90e8dd2eefc947eb59af88e8f7bb9fbca2dc0d0d572f7a727a6e1" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335002", "to_ids": true, "type": "sha1", "uuid": "55bb401a-1ac0-4139-8217-4d66950d210b", "value": "8b4dbcc306c0df0b96505747e13e9c15747aac38" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335002", "to_ids": true, "type": "md5", "uuid": "55bb401a-8fb4-4ad8-b878-4314950d210b", "value": "708dd9be439c744b43ce18303b8426d9" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335002", "to_ids": true, "type": "sha256", "uuid": "55bb401a-8720-4237-a30c-4741950d210b", "value": "d8d668e9d0c8e228b5d329b03cafd5e4b144cd955bacd7052d9c4a3b6ca67753" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335002", "to_ids": true, "type": "sha1", "uuid": "55bb401a-f6c0-4e45-a3eb-43ca950d210b", "value": "8e401062e69b1b0907dc6e30a1ef6e6b9fc03dd0" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335002", "to_ids": true, "type": "md5", "uuid": "55bb401a-f5fc-4b7f-8a94-4616950d210b", "value": "2b71bc9e931f39bebf8b27ad8a6c1341" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335002", "to_ids": true, "type": "sha256", "uuid": "55bb401a-3a80-4574-afeb-462c950d210b", "value": "21451a9ffe2d82092e0b9f64601867ef9710e0de6cc2ec40de80571c6e6f8ba6" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335003", "to_ids": true, "type": "sha1", "uuid": "55bb401b-397c-4f6c-80f0-4a79950d210b", "value": "96d230111d22f00762507dfde87cef89818741a5" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335003", "to_ids": true, "type": "md5", "uuid": "55bb401b-1e8c-4b11-b155-4eec950d210b", "value": "e020e15263f94716347b3755415e3db2" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335003", "to_ids": true, "type": "sha256", "uuid": "55bb401b-c6c8-4817-a332-4758950d210b", "value": "1b8fc7508f0e1ccfb2fabb513054dfe517e29f42383d865e68f1b70fc96cc239" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335003", "to_ids": true, "type": "sha1", "uuid": "55bb401b-60b4-41f8-b3e6-4cd5950d210b", "value": "99e4e7ed8dd2d54f6b68b7c0f03bb361ede438ac" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335003", "to_ids": true, "type": "md5", "uuid": "55bb401b-4bbc-4909-8413-4e86950d210b", "value": "c1230aa332b3642ae0c6f64abf7823a9" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335003", "to_ids": true, "type": "sha256", "uuid": "55bb401b-033c-48e6-ab30-4a55950d210b", "value": "3c031a468d230b44c1fe6bbc59d5445f78ce329885bc9f66687852fa7e61f7ed" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335003", "to_ids": true, "type": "sha1", "uuid": "55bb401b-0e30-4162-a083-43b1950d210b", "value": "d0bf7118bdea8868e794171e176c7e1b45da7cfd" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335004", "to_ids": true, "type": "md5", "uuid": "55bb401c-1240-4adb-a8db-4c22950d210b", "value": "eedb2f28eec31de121432f3f9c3c5ba7" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335004", "to_ids": true, "type": "sha256", "uuid": "55bb401c-82e8-4e8d-bc5e-4539950d210b", "value": "da400b87fba59ba933e1a77ce4ca27e6b42e27a3fd5551fbe8bf39853ed30bf4" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335004", "to_ids": true, "type": "sha1", "uuid": "55bb401c-e454-44c4-bc73-45b8950d210b", "value": "f67d3e3c5892f9f8ecfa4e75fd46942937f43cc9" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335004", "to_ids": true, "type": "md5", "uuid": "55bb401c-3eb8-48ca-bb83-4aec950d210b", "value": "375e36fa33888f4d48a8d40809165277" }, { "category": "Payload delivery", "comment": "Analysis suggests file is bad", "deleted": false, "disable_correlation": false, "timestamp": "1438335004", "to_ids": true, "type": "sha256", "uuid": "55bb401c-4308-44ff-b9e6-4b44950d210b", "value": "c3baa6e1a9ca0c79c35a53cfb5cc4bb76e45ed623841bd359d7241a8d82c5a54" } ] } }