{ "type": "bundle", "id": "bundle--57ceb5e1-bd08-4fbb-9967-4b68950d210f", "objects": [ { "type": "identity", "spec_version": "2.1", "id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:03.000Z", "modified": "2016-09-06T12:27:03.000Z", "name": "CIRCL", "identity_class": "organization" }, { "type": "report", "spec_version": "2.1", "id": "report--57ceb5e1-bd08-4fbb-9967-4b68950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:03.000Z", "modified": "2016-09-06T12:27:03.000Z", "name": "Malspam 2016-09-06 (.wsf in .zip) - campaign: \"Invoice INV[x]\"", "published": "2016-09-06T12:27:39Z", "object_refs": [ "indicator--57ceb610-ec44-40f5-8c67-4f63950d210f", "indicator--57ceb610-f20c-4a23-baf7-4825950d210f", "indicator--57ceb611-b710-446f-b4fd-4c77950d210f", "indicator--57ceb611-91c0-4229-8a0b-41bb950d210f", "indicator--57ceb611-78c0-411e-a024-4d59950d210f", "indicator--57ceb611-3274-44c0-8312-48f3950d210f", "indicator--57ceb611-6384-4017-9ce2-43b9950d210f", "indicator--57ceb612-bce4-47e1-a20b-4cca950d210f", "indicator--57ceb612-16a8-4b48-870e-4547950d210f", "indicator--57ceb612-8ebc-4ee3-9a5f-4648950d210f", "indicator--57ceb612-dad0-4848-8744-4289950d210f", "indicator--57ceb612-03f4-40cb-b002-4bc8950d210f", "indicator--57ceb613-b7b8-4435-8acd-40af950d210f", "indicator--57ceb613-0ffc-4189-bf42-4080950d210f", "indicator--57ceb613-9704-406e-ac22-4672950d210f", "indicator--57ceb613-7818-4e29-93ff-4146950d210f", "indicator--57ceb613-6f50-4e67-a568-4b24950d210f", "indicator--57ceb614-7010-4e98-9212-47f3950d210f", "indicator--57ceb614-b024-45b6-85a7-40ca950d210f", "indicator--57ceb614-0070-4ca5-b5a1-43a8950d210f", "indicator--57ceb614-b140-45ce-b6a8-4f57950d210f", "indicator--57ceb614-9fec-4d66-bc7a-4c23950d210f", "indicator--57ceb614-8a54-4e7c-84c7-4ddf950d210f", "indicator--57ceb615-d070-46f8-9427-43f4950d210f", "indicator--57ceb615-edf8-4752-aa7a-4198950d210f", "indicator--57ceb615-4af4-47de-9253-437c950d210f", "indicator--57ceb615-6c8c-4657-b5ac-409d950d210f", "indicator--57ceb615-f238-4400-ab64-4461950d210f", "indicator--57ceb616-19ec-4cb4-a889-4e0c950d210f", "indicator--57ceb616-cad8-4768-8590-420a950d210f", "indicator--57ceb616-4cdc-477e-9412-44d2950d210f", "indicator--57ceb616-c78c-44de-a815-442d950d210f", "indicator--57ceb616-a1d0-4811-83ea-458c950d210f", "indicator--57ceb617-ebac-4bca-b107-4f94950d210f", "indicator--57ceb617-d470-4f66-a6b1-4bfc950d210f", "indicator--57ceb617-2c08-4f2b-91f1-4dda950d210f" ], "labels": [ "Threat-Report", "misp:tool=\"MISP-STIX-Converter\"", "circl:incident-classification=\"malware\"", "ms-caro-malware:malware-platform=\"Win32\"", "ms-caro-malware:malware-platform=\"Win64\"" ], "object_marking_refs": [ "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb610-ec44-40f5-8c67-4f63950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:56.000Z", "modified": "2016-09-06T12:26:56.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '186.202.126.199']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:56Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb610-f20c-4a23-baf7-4825950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:56.000Z", "modified": "2016-09-06T12:26:56.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '188.120.235.214']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:56Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb611-b710-446f-b4fd-4c77950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:57.000Z", "modified": "2016-09-06T12:26:57.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '200.83.4.62']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:57Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb611-91c0-4229-8a0b-41bb950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:57.000Z", "modified": "2016-09-06T12:26:57.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '208.71.106.48']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:57Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb611-78c0-411e-a024-4d59950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:57.000Z", "modified": "2016-09-06T12:26:57.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '213.205.40.169']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:57Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb611-3274-44c0-8312-48f3950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:57.000Z", "modified": "2016-09-06T12:26:57.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '23.95.106.213']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:57Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb611-6384-4017-9ce2-43b9950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:57.000Z", "modified": "2016-09-06T12:26:57.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '81.196.20.134']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:57Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb612-bce4-47e1-a20b-4cca950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:58.000Z", "modified": "2016-09-06T12:26:58.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '81.24.34.9']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:58Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb612-16a8-4b48-870e-4547950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:58.000Z", "modified": "2016-09-06T12:26:58.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '85.12.197.61']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:58Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb612-8ebc-4ee3-9a5f-4648950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:58.000Z", "modified": "2016-09-06T12:26:58.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '88.156.222.94']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:58Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb612-dad0-4848-8744-4289950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:58.000Z", "modified": "2016-09-06T12:26:58.000Z", "description": "download location", "pattern": "[domain-name:value = 'alians-ekb.ru']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:58Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb612-03f4-40cb-b002-4bc8950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:58.000Z", "modified": "2016-09-06T12:26:58.000Z", "description": "download location", "pattern": "[domain-name:value = 'bostoncittyregenerww.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:58Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb613-b7b8-4435-8acd-40af950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:59.000Z", "modified": "2016-09-06T12:26:59.000Z", "description": "download location", "pattern": "[url:value = 'http://alians-ekb.ru/j8fn3rg3']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:59Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb613-0ffc-4189-bf42-4080950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:59.000Z", "modified": "2016-09-06T12:26:59.000Z", "description": "download location", "pattern": "[url:value = 'http://bostoncittyregenerww.com/js/j8fn3rg3']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:59Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb613-9704-406e-ac22-4672950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:59.000Z", "modified": "2016-09-06T12:26:59.000Z", "description": "download location", "pattern": "[url:value = 'http://mixup0813.web.fc2.com/j8fn3rg3']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:59Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb613-7818-4e29-93ff-4146950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:59.000Z", "modified": "2016-09-06T12:26:59.000Z", "description": "download location", "pattern": "[url:value = 'http://portadeenrolar.ind.br/j8fn3rg3']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:59Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb613-6f50-4e67-a568-4b24950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:26:59.000Z", "modified": "2016-09-06T12:26:59.000Z", "description": "download location", "pattern": "[url:value = 'http://sitio655.vtrbandaancha.net/j8fn3rg3']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:26:59Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb614-7010-4e98-9212-47f3950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:00.000Z", "modified": "2016-09-06T12:27:00.000Z", "description": "download location", "pattern": "[url:value = 'http://sp-moto.ru/j8fn3rg3']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:00Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb614-b024-45b6-85a7-40ca950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:00.000Z", "modified": "2016-09-06T12:27:00.000Z", "description": "download location", "pattern": "[url:value = 'http://tst-technik.de/j8fn3rg3']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:00Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb614-0070-4ca5-b5a1-43a8950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:00.000Z", "modified": "2016-09-06T12:27:00.000Z", "description": "download location", "pattern": "[url:value = 'http://www.cmg-ingegneria.it/j8fn3rg3']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:00Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb614-b140-45ce-b6a8-4f57950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:00.000Z", "modified": "2016-09-06T12:27:00.000Z", "description": "download location", "pattern": "[url:value = 'http://www.lnowak.tkdami.net/j8fn3rg3']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:00Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb614-9fec-4d66-bc7a-4c23950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:00.000Z", "modified": "2016-09-06T12:27:00.000Z", "description": "download location", "pattern": "[url:value = 'http://www.montegelato.it/j8fn3rg3']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:00Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb614-8a54-4e7c-84c7-4ddf950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:00.000Z", "modified": "2016-09-06T12:27:00.000Z", "description": "download location", "pattern": "[url:value = 'http://www.oltransservice.org/j8fn3rg3']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:00Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb615-d070-46f8-9427-43f4950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:01.000Z", "modified": "2016-09-06T12:27:01.000Z", "description": "download location", "pattern": "[url:value = 'http://www.vanetti.it/j8fn3rg3']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:01Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb615-edf8-4752-aa7a-4198950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:01.000Z", "modified": "2016-09-06T12:27:01.000Z", "description": "download location", "pattern": "[url:value = 'http://www.vilastefania.go.ro/j8fn3rg3']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:01Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb615-4af4-47de-9253-437c950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:01.000Z", "modified": "2016-09-06T12:27:01.000Z", "description": "download location", "pattern": "[domain-name:value = 'mixup0813.web.fc2.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:01Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb615-6c8c-4657-b5ac-409d950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:01.000Z", "modified": "2016-09-06T12:27:01.000Z", "description": "download location", "pattern": "[domain-name:value = 'portadeenrolar.ind.br']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:01Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb615-f238-4400-ab64-4461950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:01.000Z", "modified": "2016-09-06T12:27:01.000Z", "description": "download location", "pattern": "[domain-name:value = 'sitio655.vtrbandaancha.net']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:01Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb616-19ec-4cb4-a889-4e0c950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:02.000Z", "modified": "2016-09-06T12:27:02.000Z", "description": "download location", "pattern": "[domain-name:value = 'sp-moto.ru']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:02Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb616-cad8-4768-8590-420a950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:02.000Z", "modified": "2016-09-06T12:27:02.000Z", "description": "download location", "pattern": "[domain-name:value = 'tst-technik.de']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:02Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb616-4cdc-477e-9412-44d2950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:02.000Z", "modified": "2016-09-06T12:27:02.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.cmg-ingegneria.it']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:02Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb616-c78c-44de-a815-442d950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:02.000Z", "modified": "2016-09-06T12:27:02.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.lnowak.tkdami.net']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:02Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb616-a1d0-4811-83ea-458c950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:02.000Z", "modified": "2016-09-06T12:27:02.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.montegelato.it']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:02Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb617-ebac-4bca-b107-4f94950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:03.000Z", "modified": "2016-09-06T12:27:03.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.oltransservice.org']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:03Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb617-d470-4f66-a6b1-4bfc950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:03.000Z", "modified": "2016-09-06T12:27:03.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.vanetti.it']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:03Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57ceb617-2c08-4f2b-91f1-4dda950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-09-06T12:27:03.000Z", "modified": "2016-09-06T12:27:03.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.vilastefania.go.ro']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-09-06T12:27:03Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "marking-definition", "spec_version": "2.1", "id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9", "created": "2017-01-20T00:00:00.000Z", "definition_type": "tlp", "name": "TLP:WHITE", "definition": { "tlp": "white" } } ] }