{ "type": "bundle", "id": "bundle--5cf51bbd-6180-4dc7-a2dd-4baa950d210f", "objects": [ { "type": "identity", "spec_version": "2.1", "id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2019-08-27T08:27:26.000Z", "modified": "2019-08-27T08:27:26.000Z", "name": "CIRCL", "identity_class": "organization" }, { "type": "report", "spec_version": "2.1", "id": "report--5cf51bbd-6180-4dc7-a2dd-4baa950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2019-08-27T08:27:26.000Z", "modified": "2019-08-27T08:27:26.000Z", "name": "OSINT - FlawedAmmy RAT", "published": "2019-08-27T08:44:13Z", "object_refs": [ "indicator--5cf52bbb-4290-499c-89de-44eb950d210f", "x-misp-object--5cf52a79-5fac-4e72-a9f0-446f950d210f", "indicator--5cf52cad-d400-4d77-b041-4ab4950d210f" ], "labels": [ "Threat-Report", "misp:tool=\"MISP-STIX-Converter\"", "type:OSINT", "osint:lifetime=\"perpetual\"", "osint:certainty=\"50\"", "misp-galaxy:rat=\"FlawedAmmy\"" ], "object_marking_refs": [ "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--5cf52bbb-4290-499c-89de-44eb950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2019-06-03T14:16:27.000Z", "modified": "2019-06-03T14:16:27.000Z", "description": "C2", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '185.117.89.130']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2019-06-03T14:16:27Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "x-misp-object", "spec_version": "2.1", "id": "x-misp-object--5cf52a79-5fac-4e72-a9f0-446f950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2019-06-03T14:11:05.000Z", "modified": "2019-06-03T14:11:05.000Z", "labels": [ "misp:name=\"microblog\"", "misp:meta-category=\"misc\"" ], "x_misp_attributes": [ { "type": "text", "object_relation": "post", "value": "2019-06-02: #FlawedAmmy RAT #Signed \r\n\u00f0\u0178\u0090\u20ac\r\n\r\nDigital Signature -> [JIN CONSULTANCY LIMITED] Thawte\r\nh/t @malwrhunterteam\r\n \r\nC2: 185[.]117.89.130\r\nMD5: fe3e4635f555f86b64be6e8c9cfa6d6f\r\nLeaked AmmyAdmin Source Code Still Relevant as Compiled Into RAT \r\n\u00f0\u0178\u00a4\u201d", "category": "Other", "uuid": "5cf52a79-7e0c-45fd-851b-454a950d210f" }, { "type": "url", "object_relation": "url", "value": "https://mobile.twitter.com/VK_Intel/status/1135497995351449600", "category": "Network activity", "to_ids": true, "uuid": "5cf52a79-8b90-4387-a28b-476b950d210f" }, { "type": "text", "object_relation": "username-quoted", "value": "@malwrhunterteam", "category": "Other", "uuid": "5cf52a79-e2a4-4094-8d07-4802950d210f" }, { "type": "text", "object_relation": "username", "value": "VK_Intel", "category": "Other", "uuid": "5cf52a79-9310-4d16-b3d5-431b950d210f" }, { "type": "datetime", "object_relation": "creation-date", "value": "2019-06-03T12:46:00", "category": "Other", "uuid": "5cf52a79-65ec-4835-80ba-49ac950d210f" } ], "x_misp_meta_category": "misc", "x_misp_name": "microblog" }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--5cf52cad-d400-4d77-b041-4ab4950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2019-06-03T14:20:29.000Z", "modified": "2019-06-03T14:20:29.000Z", "pattern": "[file:hashes.MD5 = 'fe3e4635f555f86b64be6e8c9cfa6d6f']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2019-06-03T14:20:29Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "file" } ], "labels": [ "misp:name=\"file\"", "misp:meta-category=\"file\"", "misp:to_ids=\"True\"" ] }, { "type": "marking-definition", "spec_version": "2.1", "id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9", "created": "2017-01-20T00:00:00.000Z", "definition_type": "tlp", "name": "TLP:WHITE", "definition": { "tlp": "white" } } ] }