{ "type": "bundle", "id": "bundle--57b472bd-2dc0-4304-90a6-4ad4950d210f", "objects": [ { "type": "identity", "spec_version": "2.1", "id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:22:22.000Z", "modified": "2016-08-17T14:22:22.000Z", "name": "CIRCL", "identity_class": "organization" }, { "type": "report", "spec_version": "2.1", "id": "report--57b472bd-2dc0-4304-90a6-4ad4950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:22:22.000Z", "modified": "2016-08-17T14:22:22.000Z", "name": "Malspam 2016-08-17 (.docm) - campaign: \"Order Confirmation-\"", "published": "2016-08-17T14:59:49Z", "object_refs": [ "indicator--57b472df-f6f8-4468-835e-4b9c950d210f", "indicator--57b472df-c1ac-47bf-a402-4778950d210f", "indicator--57b472df-dd8c-4141-bbf7-4337950d210f", "indicator--57b472df-2764-4a6a-bdbe-419c950d210f", "indicator--57b472e0-71a8-40b4-be33-40a2950d210f", "indicator--57b472e0-5490-4fbf-a3bd-45ec950d210f", "indicator--57b472e0-1154-4ef8-aedf-40b8950d210f", "indicator--57b472e0-baa0-442a-9e17-4ae8950d210f", "indicator--57b472e0-ab70-49a9-a53d-4777950d210f", "indicator--57b472e1-ad20-45b9-8540-49ad950d210f", "indicator--57b472e1-1e10-4330-87e7-4d92950d210f", "indicator--57b472e1-db14-4af3-8319-464d950d210f", "indicator--57b472e1-07fc-4d5e-9278-4b05950d210f", "indicator--57b472e2-0ec8-494f-ad57-4f9d950d210f", "indicator--57b472e2-96d0-4185-b388-4af8950d210f", "indicator--57b472e2-61c8-42fc-a7a0-4053950d210f", "indicator--57b472e2-0778-4f13-bd00-4caa950d210f", "indicator--57b472e2-7efc-4b56-b2f3-4d22950d210f", "indicator--57b472e3-ec04-47fe-80fb-42dd950d210f", "indicator--57b472e3-e53c-4299-960e-423f950d210f", "indicator--57b472e3-c648-4dc2-a4b7-45df950d210f" ], "labels": [ "Threat-Report", "misp:tool=\"MISP-STIX-Converter\"", "circl:incident-classification=\"malware\"" ], "object_marking_refs": [ "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472df-f6f8-4468-835e-4b9c950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:19.000Z", "modified": "2016-08-17T14:21:19.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '208.71.106.39']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:19Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472df-c1ac-47bf-a402-4778950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:19.000Z", "modified": "2016-08-17T14:21:19.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '213.205.40.169']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:19Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472df-dd8c-4141-bbf7-4337950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:19.000Z", "modified": "2016-08-17T14:21:19.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '217.119.54.212']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:19Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472df-2764-4a6a-bdbe-419c950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:19.000Z", "modified": "2016-08-17T14:21:19.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '217.119.54.214']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:19Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e0-71a8-40b4-be33-40a2950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:20.000Z", "modified": "2016-08-17T14:21:20.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '64.29.151.221']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:20Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e0-5490-4fbf-a3bd-45ec950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:20.000Z", "modified": "2016-08-17T14:21:20.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '81.196.20.134']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:20Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e0-1154-4ef8-aedf-40b8950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:20.000Z", "modified": "2016-08-17T14:21:20.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '83.96.159.39']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:20Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e0-baa0-442a-9e17-4ae8950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:20.000Z", "modified": "2016-08-17T14:21:20.000Z", "description": "download location", "pattern": "[domain-name:value = 'allgaeu-papparatzi.de']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:20Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e0-ab70-49a9-a53d-4777950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:20.000Z", "modified": "2016-08-17T14:21:20.000Z", "description": "download location", "pattern": "[domain-name:value = 'alynawebx.go.ro']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:20Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e1-ad20-45b9-8540-49ad950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:21.000Z", "modified": "2016-08-17T14:21:21.000Z", "description": "download location", "pattern": "[domain-name:value = 'cronininc.us']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:21Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e1-1e10-4330-87e7-4d92950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:21.000Z", "modified": "2016-08-17T14:21:21.000Z", "description": "download location", "pattern": "[url:value = 'http://allgaeu-papparatzi.de/KJNbhgh57']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:21Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e1-db14-4af3-8319-464d950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:21.000Z", "modified": "2016-08-17T14:21:21.000Z", "description": "download location", "pattern": "[url:value = 'http://alynawebx.go.ro/KJNbhgh57']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:21Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e1-07fc-4d5e-9278-4b05950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:21.000Z", "modified": "2016-08-17T14:21:21.000Z", "description": "download location", "pattern": "[url:value = 'http://cronininc.us/KJNbhgh57']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:21Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e2-0ec8-494f-ad57-4f9d950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:22.000Z", "modified": "2016-08-17T14:21:22.000Z", "description": "download location", "pattern": "[url:value = 'http://joopvandenheuvel.nl/KJNbhgh57']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e2-96d0-4185-b388-4af8950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:22.000Z", "modified": "2016-08-17T14:21:22.000Z", "description": "download location", "pattern": "[url:value = 'http://rund-ums-haus-rosner.de/KJNbhgh57']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e2-61c8-42fc-a7a0-4053950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:22.000Z", "modified": "2016-08-17T14:21:22.000Z", "description": "download location", "pattern": "[url:value = 'http://sora1221.web.fc2.com/KJNbhgh57']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e2-0778-4f13-bd00-4caa950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:22.000Z", "modified": "2016-08-17T14:21:22.000Z", "description": "download location", "pattern": "[url:value = 'http://www.dog-portrait.com/KJNbhgh57']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e2-7efc-4b56-b2f3-4d22950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:22.000Z", "modified": "2016-08-17T14:21:22.000Z", "description": "download location", "pattern": "[domain-name:value = 'joopvandenheuvel.nl']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e3-ec04-47fe-80fb-42dd950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:23.000Z", "modified": "2016-08-17T14:21:23.000Z", "description": "download location", "pattern": "[domain-name:value = 'rund-ums-haus-rosner.de']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:23Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e3-e53c-4299-960e-423f950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:23.000Z", "modified": "2016-08-17T14:21:23.000Z", "description": "download location", "pattern": "[domain-name:value = 'sora1221.web.fc2.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:23Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57b472e3-c648-4dc2-a4b7-45df950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-17T14:21:23.000Z", "modified": "2016-08-17T14:21:23.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.dog-portrait.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-17T14:21:23Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "marking-definition", "spec_version": "2.1", "id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9", "created": "2017-01-20T00:00:00.000Z", "definition_type": "tlp", "name": "TLP:WHITE", "definition": { "tlp": "white" } } ] }