{ "type": "bundle", "id": "bundle--57bd7251-390c-4ee2-accd-4f69950d210f", "objects": [ { "type": "identity", "spec_version": "2.1", "id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:22:05.000Z", "modified": "2016-08-24T12:22:05.000Z", "name": "CIRCL", "identity_class": "organization" }, { "type": "report", "spec_version": "2.1", "id": "report--57bd7251-390c-4ee2-accd-4f69950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:22:05.000Z", "modified": "2016-08-24T12:22:05.000Z", "name": "Malspam 2016-08-24 (.js in .zip) - campaign: \"Statement\"", "published": "2016-08-24T14:43:39Z", "object_refs": [ "indicator--57bd727d-9290-486a-98df-496a950d210f", "indicator--57bd727d-7e00-42a3-8452-47de950d210f", "indicator--57bd727d-9e68-49ad-b6dd-4926950d210f", "indicator--57bd727e-7328-4bab-8830-4e5d950d210f", "indicator--57bd727e-dbc0-4025-9d3f-412d950d210f", "indicator--57bd727e-fb44-4219-b578-42c0950d210f", "indicator--57bd727e-783c-4af2-83af-4dd0950d210f", "indicator--57bd727e-fcc0-483b-801d-4b79950d210f", "indicator--57bd727f-4144-45c9-b5ca-4d87950d210f", "indicator--57bd727f-8e60-49e3-8399-40fe950d210f", "indicator--57bd727f-1d90-449d-9cf9-47f6950d210f", "indicator--57bd727f-739c-44b7-990f-43ee950d210f", "indicator--57bd727f-2758-4293-a59b-4e47950d210f", "indicator--57bd7280-dbe0-46d3-90dd-45b6950d210f", "indicator--57bd7280-1de8-47d6-a49b-42d7950d210f", "indicator--57bd7280-0cfc-4c32-851e-4602950d210f", "indicator--57bd7280-c824-4bd3-a312-402f950d210f", "indicator--57bd7280-4060-4d28-a590-4521950d210f", "indicator--57bd7281-5604-470b-b423-4a1b950d210f", "indicator--57bd7281-6e78-4b55-9d64-4dc2950d210f", "indicator--57bd7281-1d30-4b39-b7dd-4bb4950d210f", "indicator--57bd7281-71f8-4f85-b4f0-4076950d210f", "indicator--57bd7282-b2a4-4cd3-bb4f-44bc950d210f", "indicator--57bd7282-1e78-4ff9-842f-401e950d210f", "indicator--57bd7282-75e0-412b-b7ff-4c42950d210f", "indicator--57bd7282-7e9c-418b-9c37-4cf5950d210f", "indicator--57bd7282-2358-4e56-a0f3-4ff7950d210f", "indicator--57bd7283-1128-4103-b981-4d8a950d210f", "indicator--57bd7283-d294-49bf-b241-4826950d210f", "indicator--57bd7283-43e0-4527-b834-474b950d210f", "indicator--57bd7283-1744-4b0a-9c7b-4e4e950d210f", "indicator--57bd7283-1d04-40cf-9bdf-4c2e950d210f", "indicator--57bd7283-90c8-4525-a980-48e3950d210f", "indicator--57bd7284-c9cc-44e1-bd5b-4876950d210f", "indicator--57bd7284-1f2c-45d4-aefb-4526950d210f", "indicator--57bd7284-c758-4644-a4c9-4170950d210f", "indicator--57bd7284-9a14-4703-89e4-4627950d210f", "indicator--57bd7284-776c-435f-89dd-43fb950d210f", "indicator--57bd7285-c64c-4dff-8098-490c950d210f", "indicator--57bd7285-eb5c-4d32-a064-4072950d210f", "indicator--57bd7285-e47c-4ef1-86ce-43b5950d210f", "indicator--57bd7285-3114-4d3d-9998-4188950d210f", "indicator--57bd7285-e1b0-43b0-9aac-43c0950d210f", "indicator--57bd7286-4328-4d49-8b2d-4b1e950d210f", "indicator--57bd7286-bab0-4a0c-9ae7-4216950d210f", "indicator--57bd7286-83f0-40de-b36d-42ee950d210f", "indicator--57bd7286-2f7c-4e70-bf20-49ea950d210f", "indicator--57bd7286-b7fc-4e32-9915-47dc950d210f", "indicator--57bd7286-a060-4d89-a770-4f65950d210f", "indicator--57bd7287-6c6c-4a39-8d30-406c950d210f", "indicator--57bd7287-5b50-4369-8182-4391950d210f", "indicator--57bd7287-ac3c-4cc2-9116-457d950d210f", "indicator--57bd7287-6850-4a08-a694-4b72950d210f", "indicator--57bd7287-b264-4716-9959-4f93950d210f", "indicator--57bd7288-1c48-4f42-9cbe-43bc950d210f", "indicator--57bd7288-ded4-46e9-ab7e-4e32950d210f", "indicator--57bd7288-0e58-4059-91da-480b950d210f", "indicator--57bd7288-3bb0-4e39-b201-4b91950d210f", "indicator--57bd7288-6c8c-455b-94a1-4bee950d210f", "indicator--57bd7289-356c-41c4-bf5d-496d950d210f", "indicator--57bd7289-7820-44a3-ae09-4e98950d210f", "indicator--57bd7289-39a0-4599-94ee-4b8b950d210f", "indicator--57bd7289-d654-4bc7-ab0b-4dd9950d210f", "indicator--57bd7289-f5f4-41ac-afb7-46dd950d210f", "indicator--57bd728a-7594-4fba-8694-458b950d210f", "indicator--57bd728a-bc6c-48c8-ac33-426d950d210f", "indicator--57bd728a-3724-4c7c-8d84-43b5950d210f", "indicator--57bd728a-79ac-4063-a76d-4111950d210f", "indicator--57bd728a-6394-462c-92a8-4024950d210f", "indicator--57bd728b-a248-4b8b-bec5-4c4b950d210f", "indicator--57bd728b-d520-4fbb-8408-4dd0950d210f", "indicator--57bd728b-a76c-40a8-ae23-433b950d210f", "indicator--57bd728b-6550-44fa-a23d-4b49950d210f", "indicator--57bd728c-b8e4-4689-9bf5-41e4950d210f", "indicator--57bd728c-6974-490f-8fae-4ab8950d210f", "indicator--57bd728c-94f0-475f-89ed-4bca950d210f", "indicator--57bd728c-e61c-4d8c-94c9-42b0950d210f", "indicator--57bd728c-1150-41f4-9f9e-4538950d210f", "indicator--57bd728d-2ff8-4b06-bf9f-4d12950d210f", "indicator--57bd728d-3d08-4478-9939-45b3950d210f", "indicator--57bd728d-6ccc-41b2-9144-4d0c950d210f", "indicator--57bd728d-fe10-4dc9-863a-47a0950d210f", "indicator--57bd728d-6e98-4824-b83a-4d46950d210f", "indicator--57bd728e-8bb8-41e2-8971-4daa950d210f", "indicator--57bd728e-5480-484d-8c42-43a0950d210f", "indicator--57bd728e-d92c-4d72-80f9-45fe950d210f", "indicator--57bd728e-4e9c-44e9-b3af-4ff2950d210f", "indicator--57bd728e-64a8-47ea-9fbb-458f950d210f", "indicator--57bd728e-1800-492f-8e6f-47c1950d210f", "indicator--57bd728f-5af0-48f2-9cda-4554950d210f", "indicator--57bd728f-3920-4f72-9d88-4fb7950d210f", "indicator--57bd728f-a7b8-4f89-9f35-49e6950d210f", "indicator--57bd728f-10d0-4ccd-95c0-4565950d210f", "indicator--57bd728f-9bc0-45ca-8b3a-4bd7950d210f", "indicator--57bd7290-5d64-40ff-81bc-41e4950d210f", "indicator--57bd7290-8ce8-421d-8550-4dfb950d210f", "indicator--57bd7290-7df4-45c2-a790-48e1950d210f", "indicator--57bd7290-b5d8-46ee-a071-4c62950d210f", "indicator--57bd7290-4810-46d1-9dac-4bf6950d210f", "indicator--57bd7290-36d4-47a1-8bcc-4b9f950d210f", "indicator--57bd7291-93d4-4fa3-9f7e-4aae950d210f", "indicator--57bd7291-d964-48e2-b584-41eb950d210f", "indicator--57bd7291-ea1c-48e9-ac25-439c950d210f", "indicator--57bd7291-8bac-492b-9b97-4770950d210f", "indicator--57bd7291-cf1c-4ece-bb7e-4275950d210f", "indicator--57bd7292-3394-4ca2-aae1-4bc6950d210f", "indicator--57bd7292-8898-4d94-a606-4e9e950d210f", "indicator--57bd7292-f338-43bb-9fae-4841950d210f", "indicator--57bd7292-ba80-4b32-90cd-4ab1950d210f", "indicator--57bd7292-3890-4d28-8915-4a92950d210f", "indicator--57bd7292-4598-4c23-a4d9-4d2d950d210f", "indicator--57bd7293-a790-40a9-861b-4930950d210f", "indicator--57bd7293-e874-4746-ab7b-4a4f950d210f", "indicator--57bd7293-1b68-46c1-ab68-4386950d210f", "indicator--57bd7293-be0c-48f0-abf0-4551950d210f", "indicator--57bd7293-1ed0-457c-bfe4-4d8b950d210f", "indicator--57bd7294-fd74-49e4-96eb-45fb950d210f", "indicator--57bd7294-a744-4009-b7f3-48a2950d210f", "indicator--57bd7294-e4f0-4814-ba14-4840950d210f", "observed-data--57bd7361-1858-4a78-80c1-4252950d210f", "email-message--57bd7361-1858-4a78-80c1-4252950d210f", "x-misp-attribute--57bd73ef-7ad8-45f2-9242-4666950d210f", "indicator--57bd8f84-a288-4061-b4b6-4e2b950d210f", "indicator--57bd8f85-eefc-4ae7-b5aa-4724950d210f", "indicator--57bd8f85-ccd0-4d10-a028-4a90950d210f", "indicator--57bd8f85-f4a4-4ab7-93cb-4f8a950d210f", "indicator--57bd8f85-098c-4d3a-9997-43bc950d210f", "indicator--57bd8f85-5f70-4e9b-9e24-46b8950d210f", "indicator--57bd8f86-69f0-4e4f-90e0-42ac950d210f", "indicator--57bd8f86-44dc-4abb-b07a-49fa950d210f", "indicator--57bd8f86-ac14-4c7c-ba8f-4db3950d210f", "indicator--57bd8f86-1200-4000-a389-4480950d210f", "indicator--57bd8f86-a8e4-4e23-88d1-4334950d210f", "indicator--57bd8f87-9370-4ea5-aa9b-4a88950d210f", "indicator--57bd8f87-d0b8-4c58-abe3-4055950d210f", "indicator--57bd8f87-b844-461c-a30d-40a1950d210f", "indicator--57bd8f87-73e8-490e-a50d-4373950d210f", "indicator--57bd8f87-7e20-4ef9-9b9d-4435950d210f", "indicator--57bd8f87-615c-46a8-9954-41af950d210f", "indicator--57bd8f88-6c10-4498-99c8-4cba950d210f", "indicator--57bd8f88-ff50-4855-8be9-4a42950d210f", "indicator--57bd8f88-a628-410c-983d-42e9950d210f", "x-misp-attribute--57bd90dd-9af8-4819-8580-4be3950d210f", "x-misp-attribute--57bd915f-de6c-4545-bb49-4c6f950d210f", "x-misp-attribute--57bd916d-cee4-478f-bd27-4a80950d210f" ], "labels": [ "Threat-Report", "misp:tool=\"MISP-STIX-Converter\"", "circl:incident-classification=\"malware\"" ], "object_marking_refs": [ "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd727d-9290-486a-98df-496a950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:05.000Z", "modified": "2016-08-24T10:10:05.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '162.210.101.97']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:05Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd727d-7e00-42a3-8452-47de950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:05.000Z", "modified": "2016-08-24T10:10:05.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '162.210.101.98']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:05Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd727d-9e68-49ad-b6dd-4926950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:05.000Z", "modified": "2016-08-24T10:10:05.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '162.210.101.99']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:05Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd727e-7328-4bab-8830-4e5d950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:06.000Z", "modified": "2016-08-24T10:10:06.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '190.160.0.137']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:06Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd727e-dbc0-4025-9d3f-412d950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:06.000Z", "modified": "2016-08-24T10:10:06.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '192.254.232.12']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:06Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd727e-fb44-4219-b578-42c0950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:06.000Z", "modified": "2016-08-24T10:10:06.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '193.109.184.81']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:06Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd727e-783c-4af2-83af-4dd0950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:06.000Z", "modified": "2016-08-24T10:10:06.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '195.130.132.84']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:06Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd727e-fcc0-483b-801d-4b79950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:06.000Z", "modified": "2016-08-24T10:10:06.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '195.67.82.205']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:06Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd727f-4144-45c9-b5ca-4d87950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:07.000Z", "modified": "2016-08-24T10:10:07.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '208.71.106.43']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:07Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd727f-8e60-49e3-8399-40fe950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:07.000Z", "modified": "2016-08-24T10:10:07.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '208.71.106.45']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:07Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd727f-1d90-449d-9cf9-47f6950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:07.000Z", "modified": "2016-08-24T10:10:07.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '208.71.106.48']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:07Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd727f-739c-44b7-990f-43ee950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:07.000Z", "modified": "2016-08-24T10:10:07.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '208.71.106.49']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:07Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd727f-2758-4293-a59b-4e47950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:07.000Z", "modified": "2016-08-24T10:10:07.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '208.71.106.61']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:07Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7280-dbe0-46d3-90dd-45b6950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:08.000Z", "modified": "2016-08-24T10:10:08.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '209.235.144.9']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:08Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7280-1de8-47d6-a49b-42d7950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:08.000Z", "modified": "2016-08-24T10:10:08.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '212.40.179.104']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:08Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7280-0cfc-4c32-851e-4602950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:08.000Z", "modified": "2016-08-24T10:10:08.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '213.205.40.169']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:08Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7280-c824-4bd3-a312-402f950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:08.000Z", "modified": "2016-08-24T10:10:08.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '213.217.149.4']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:08Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7280-4060-4d28-a590-4521950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:08.000Z", "modified": "2016-08-24T10:10:08.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '213.229.74.92']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:08Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7281-5604-470b-b423-4a1b950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:09.000Z", "modified": "2016-08-24T10:10:09.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '217.97.216.17']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:09Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7281-6e78-4b55-9d64-4dc2950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:09.000Z", "modified": "2016-08-24T10:10:09.000Z", "description": "download location", "pattern": "[domain-name:value = '2cfdew.web.fc2.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:09Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7281-1d30-4b39-b7dd-4bb4950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:09.000Z", "modified": "2016-08-24T10:10:09.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '61.47.40.35']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:09Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7281-71f8-4f85-b4f0-4076950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:09.000Z", "modified": "2016-08-24T10:10:09.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '62.14.3.195']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:09Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7282-b2a4-4cd3-bb4f-44bc950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:10.000Z", "modified": "2016-08-24T10:10:10.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '62.149.142.134']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:10Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7282-1e78-4ff9-842f-401e950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:10.000Z", "modified": "2016-08-24T10:10:10.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '64.29.151.221']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:10Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7282-75e0-412b-b7ff-4c42950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:10.000Z", "modified": "2016-08-24T10:10:10.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '72.52.99.36']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:10Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7282-7e9c-418b-9c37-4cf5950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:10.000Z", "modified": "2016-08-24T10:10:10.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '80.150.6.138']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:10Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7282-2358-4e56-a0f3-4ff7950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:10.000Z", "modified": "2016-08-24T10:10:10.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '82.197.131.109']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:10Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7283-1128-4103-b981-4d8a950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:11.000Z", "modified": "2016-08-24T10:10:11.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '84.2.38.70']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:11Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7283-d294-49bf-b241-4826950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:11.000Z", "modified": "2016-08-24T10:10:11.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '85.248.42.103']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:11Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7283-43e0-4527-b834-474b950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:11.000Z", "modified": "2016-08-24T10:10:11.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '89.110.146.99']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:11Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7283-1744-4b0a-9c7b-4e4e950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:11.000Z", "modified": "2016-08-24T10:10:11.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '90.156.201.38']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:11Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7283-1d04-40cf-9bdf-4c2e950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:11.000Z", "modified": "2016-08-24T10:10:11.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '90.156.201.41']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:11Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7283-90c8-4525-a980-48e3950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:11.000Z", "modified": "2016-08-24T10:10:11.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '90.156.201.56']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:11Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7284-c9cc-44e1-bd5b-4876950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:12.000Z", "modified": "2016-08-24T10:10:12.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '91.223.89.200']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:12Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7284-1f2c-45d4-aefb-4526950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:12.000Z", "modified": "2016-08-24T10:10:12.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '95.211.144.65']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:12Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7284-c758-4644-a4c9-4170950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:12.000Z", "modified": "2016-08-24T10:10:12.000Z", "description": "download location", "pattern": "[domain-name:value = 'batsumito.web.fc2.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:12Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7284-9a14-4703-89e4-4627950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:12.000Z", "modified": "2016-08-24T10:10:12.000Z", "description": "download location", "pattern": "[domain-name:value = 'bluechaos.dommel.be']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:12Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7284-776c-435f-89dd-43fb950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:12.000Z", "modified": "2016-08-24T10:10:12.000Z", "description": "download location", "pattern": "[domain-name:value = 'bormanns-wetter.de']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:12Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7285-c64c-4dff-8098-490c950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:13.000Z", "modified": "2016-08-24T10:10:13.000Z", "description": "download location", "pattern": "[domain-name:value = 'brothermalw.ws']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:13Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7285-eb5c-4d32-a064-4072950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:13.000Z", "modified": "2016-08-24T10:10:13.000Z", "description": "download location", "pattern": "[domain-name:value = 'chrisbell.50webs.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:13Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7285-e47c-4ef1-86ce-43b5950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:13.000Z", "modified": "2016-08-24T10:10:13.000Z", "description": "download location", "pattern": "[domain-name:value = 'deananddennys.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:13Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7285-3114-4d3d-9998-4188950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:13.000Z", "modified": "2016-08-24T10:10:13.000Z", "description": "download location", "pattern": "[domain-name:value = 'deia500.50webs.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:13Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7285-e1b0-43b0-9aac-43c0950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:13.000Z", "modified": "2016-08-24T10:10:13.000Z", "description": "download location", "pattern": "[domain-name:value = 'direttaauto.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:13Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7286-4328-4d49-8b2d-4b1e950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:14.000Z", "modified": "2016-08-24T10:10:14.000Z", "description": "download location", "pattern": "[domain-name:value = 'djprestige.net']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:14Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7286-bab0-4a0c-9ae7-4216950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:14.000Z", "modified": "2016-08-24T10:10:14.000Z", "description": "download location", "pattern": "[domain-name:value = 'goforbroke.web.fc2.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:14Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7286-83f0-40de-b36d-42ee950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:14.000Z", "modified": "2016-08-24T10:10:14.000Z", "description": "download location", "pattern": "[domain-name:value = 'hirokuns06.web.fc2.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:14Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7286-2f7c-4e70-bf20-49ea950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:14.000Z", "modified": "2016-08-24T10:10:14.000Z", "description": "download location", "pattern": "[url:value = 'http://2cfdew.web.fc2.com/cibbtsx']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:14Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7286-b7fc-4e32-9915-47dc950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:14.000Z", "modified": "2016-08-24T10:10:14.000Z", "description": "download location", "pattern": "[url:value = 'http://batsumito.web.fc2.com/w3nbwrg']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:14Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7286-a060-4d89-a770-4f65950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:14.000Z", "modified": "2016-08-24T10:10:14.000Z", "description": "download location", "pattern": "[url:value = 'http://bluechaos.dommel.be/c37v3q']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:14Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7287-6c6c-4a39-8d30-406c950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:15.000Z", "modified": "2016-08-24T10:10:15.000Z", "description": "download location", "pattern": "[url:value = 'http://bormanns-wetter.de/gkkks']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:15Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7287-5b50-4369-8182-4391950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:15.000Z", "modified": "2016-08-24T10:10:15.000Z", "description": "download location", "pattern": "[url:value = 'http://brothermalw.ws/0b24a']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:15Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7287-ac3c-4cc2-9116-457d950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:15.000Z", "modified": "2016-08-24T10:10:15.000Z", "description": "download location", "pattern": "[url:value = 'http://chrisbell.50webs.com/9c7cw']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:15Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7287-6850-4a08-a694-4b72950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:15.000Z", "modified": "2016-08-24T10:10:15.000Z", "description": "download location", "pattern": "[url:value = 'http://deananddennys.com/hsbgg7']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:15Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7287-b264-4716-9959-4f93950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:15.000Z", "modified": "2016-08-24T10:10:15.000Z", "description": "download location", "pattern": "[url:value = 'http://deia500.50webs.com/epgvfl']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:15Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7288-1c48-4f42-9cbe-43bc950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:16.000Z", "modified": "2016-08-24T10:10:16.000Z", "description": "download location", "pattern": "[url:value = 'http://direttaauto.com/70ft8']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:16Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7288-ded4-46e9-ab7e-4e32950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:16.000Z", "modified": "2016-08-24T10:10:16.000Z", "description": "download location", "pattern": "[url:value = 'http://djprestige.net/86o7nou4']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:16Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7288-0e58-4059-91da-480b950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:16.000Z", "modified": "2016-08-24T10:10:16.000Z", "description": "download location", "pattern": "[url:value = 'http://goforbroke.web.fc2.com/taeucx']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:16Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7288-3bb0-4e39-b201-4b91950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:16.000Z", "modified": "2016-08-24T10:10:16.000Z", "description": "download location", "pattern": "[url:value = 'http://goforbroke.web.fc2.com/vzv03']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:16Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7288-6c8c-455b-94a1-4bee950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:16.000Z", "modified": "2016-08-24T10:10:16.000Z", "description": "download location", "pattern": "[url:value = 'http://hirokuns06.web.fc2.com/xmo6cxi9']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:16Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7289-356c-41c4-bf5d-496d950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:17.000Z", "modified": "2016-08-24T10:10:17.000Z", "description": "download location", "pattern": "[url:value = 'http://javierbaile.atspace.com/h3113']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:17Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7289-7820-44a3-ae09-4e98950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:17.000Z", "modified": "2016-08-24T10:10:17.000Z", "description": "download location", "pattern": "[url:value = 'http://karinschacht.addr.com/117uuf5h']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:17Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7289-39a0-4599-94ee-4b8b950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:17.000Z", "modified": "2016-08-24T10:10:17.000Z", "description": "download location", "pattern": "[url:value = 'http://leasing.ocipov.ru/volrzzm']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:17Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7289-d654-4bc7-ab0b-4dd9950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:17.000Z", "modified": "2016-08-24T10:10:17.000Z", "description": "download location", "pattern": "[url:value = 'http://masakipingpong.web.fc2.com/gaqqpehk']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:17Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7289-f5f4-41ac-afb7-46dd950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:17.000Z", "modified": "2016-08-24T10:10:17.000Z", "description": "download location", "pattern": "[url:value = 'http://minots.atspace.com/mrfzkf']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:17Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728a-7594-4fba-8694-458b950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:18.000Z", "modified": "2016-08-24T10:10:18.000Z", "description": "download location", "pattern": "[url:value = 'http://naderu.web.fc2.com/l1y81i6']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:18Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728a-bc6c-48c8-ac33-426d950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:18.000Z", "modified": "2016-08-24T10:10:18.000Z", "description": "download location", "pattern": "[url:value = 'http://over.50webs.com/y1r0z1t']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:18Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728a-3724-4c7c-8d84-43b5950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:18.000Z", "modified": "2016-08-24T10:10:18.000Z", "description": "download location", "pattern": "[url:value = 'http://rejoincomp2.in/117uuf5h']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:18Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728a-79ac-4063-a76d-4111950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:18.000Z", "modified": "2016-08-24T10:10:18.000Z", "description": "download location", "pattern": "[url:value = 'http://rsit.cba.pl/x7aipb']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:18Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728a-6394-462c-92a8-4024950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:18.000Z", "modified": "2016-08-24T10:10:18.000Z", "description": "download location", "pattern": "[url:value = 'http://selectron.ch/~se_allgemein/p7fnf']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:18Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728b-a248-4b8b-bec5-4c4b950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:19.000Z", "modified": "2016-08-24T10:10:19.000Z", "description": "download location", "pattern": "[url:value = 'http://smilehomeutsumi504.web.fc2.com/by11k6r']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:19Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728b-d520-4fbb-8408-4dd0950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:19.000Z", "modified": "2016-08-24T10:10:19.000Z", "description": "download location", "pattern": "[url:value = 'http://sopranolady7.wang/14czb']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:19Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728b-a76c-40a8-ae23-433b950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:19.000Z", "modified": "2016-08-24T10:10:19.000Z", "description": "download location", "pattern": "[url:value = 'http://stigmata.org.uk/p4010h']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:19Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728b-6550-44fa-a23d-4b49950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:19.000Z", "modified": "2016-08-24T10:10:19.000Z", "description": "download location", "pattern": "[url:value = 'http://tetteco.web.fc2.com/izjgf']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:19Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728c-b8e4-4689-9bf5-41e4950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:20.000Z", "modified": "2016-08-24T10:10:20.000Z", "description": "download location", "pattern": "[url:value = 'http://ttd.co.th/~ttd.co.th/s78zc63']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:20Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728c-6974-490f-8fae-4ab8950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:20.000Z", "modified": "2016-08-24T10:10:20.000Z", "description": "download location", "pattern": "[url:value = 'http://vgweb.ru/mdjuzc']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:20Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728c-94f0-475f-89ed-4bca950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:20.000Z", "modified": "2016-08-24T10:10:20.000Z", "description": "download location", "pattern": "[url:value = 'http://wangmewang.name/1njm2']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:20Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728c-e61c-4d8c-94c9-42b0950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:20.000Z", "modified": "2016-08-24T10:10:20.000Z", "description": "download location", "pattern": "[url:value = 'http://webmail.vtr.net/~pablo.saldias/cfgzs2']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:20Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728c-1150-41f4-9f9e-4538950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:20.000Z", "modified": "2016-08-24T10:10:20.000Z", "description": "download location", "pattern": "[url:value = 'http://wishmaster.dommel.be/cfm2g']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:20Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728d-2ff8-4b06-bf9f-4d12950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:21.000Z", "modified": "2016-08-24T10:10:21.000Z", "description": "download location", "pattern": "[url:value = 'http://wm08g63hd.homepage.t-online.de/8kkap']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:21Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728d-3d08-4478-9939-45b3950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:21.000Z", "modified": "2016-08-24T10:10:21.000Z", "description": "download location", "pattern": "[url:value = 'http://www.archeoetnos.com/t7nv1']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:21Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728d-6ccc-41b2-9144-4d0c950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:21.000Z", "modified": "2016-08-24T10:10:21.000Z", "description": "download location", "pattern": "[url:value = 'http://www.bbfreeholidays.com/v3ixzfx']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:21Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728d-fe10-4dc9-863a-47a0950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:21.000Z", "modified": "2016-08-24T10:10:21.000Z", "description": "download location", "pattern": "[url:value = 'http://www.beck-kituzo.hu/14czb']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:21Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728d-6e98-4824-b83a-4d46950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:21.000Z", "modified": "2016-08-24T10:10:21.000Z", "description": "download location", "pattern": "[url:value = 'http://www.energetica.it/hznqd2sv']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:21Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728e-8bb8-41e2-8971-4daa950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:22.000Z", "modified": "2016-08-24T10:10:22.000Z", "description": "download location", "pattern": "[url:value = 'http://www.kardborren.se/8kdz07']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728e-5480-484d-8c42-43a0950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:22.000Z", "modified": "2016-08-24T10:10:22.000Z", "description": "download location", "pattern": "[url:value = 'http://www.lenkinetorty.szm.com/40dw9']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728e-d92c-4d72-80f9-45fe950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:22.000Z", "modified": "2016-08-24T10:10:22.000Z", "description": "download location", "pattern": "[url:value = 'http://www.pobierowo-jest-ok.neostrada.pl/w84mjk']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728e-4e9c-44e9-b3af-4ff2950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:22.000Z", "modified": "2016-08-24T10:10:22.000Z", "description": "download location", "pattern": "[url:value = 'http://www.shivartatoo.com/nuklyuql']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728e-64a8-47ea-9fbb-458f950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:22.000Z", "modified": "2016-08-24T10:10:22.000Z", "description": "download location", "pattern": "[url:value = 'http://www.smees.be/43d0mbs']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728e-1800-492f-8e6f-47c1950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:22.000Z", "modified": "2016-08-24T10:10:22.000Z", "description": "download location", "pattern": "[url:value = 'http://www.yerridixielandband.jazztel.es/qo5u468']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:22Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728f-5af0-48f2-9cda-4554950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:23.000Z", "modified": "2016-08-24T10:10:23.000Z", "description": "download location", "pattern": "[domain-name:value = 'javierbaile.atspace.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:23Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728f-3920-4f72-9d88-4fb7950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:23.000Z", "modified": "2016-08-24T10:10:23.000Z", "description": "download location", "pattern": "[domain-name:value = 'karinschacht.addr.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:23Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728f-a7b8-4f89-9f35-49e6950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:23.000Z", "modified": "2016-08-24T10:10:23.000Z", "description": "download location", "pattern": "[domain-name:value = 'leasing.ocipov.ru']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:23Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728f-10d0-4ccd-95c0-4565950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:23.000Z", "modified": "2016-08-24T10:10:23.000Z", "description": "download location", "pattern": "[domain-name:value = 'masakipingpong.web.fc2.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:23Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd728f-9bc0-45ca-8b3a-4bd7950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:23.000Z", "modified": "2016-08-24T10:10:23.000Z", "description": "download location", "pattern": "[domain-name:value = 'minots.atspace.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:23Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7290-5d64-40ff-81bc-41e4950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:24.000Z", "modified": "2016-08-24T10:10:24.000Z", "description": "download location", "pattern": "[domain-name:value = 'naderu.web.fc2.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:24Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7290-8ce8-421d-8550-4dfb950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:24.000Z", "modified": "2016-08-24T10:10:24.000Z", "description": "download location", "pattern": "[domain-name:value = 'over.50webs.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:24Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7290-7df4-45c2-a790-48e1950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:24.000Z", "modified": "2016-08-24T10:10:24.000Z", "description": "download location", "pattern": "[domain-name:value = 'rejoincomp2.in']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:24Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7290-b5d8-46ee-a071-4c62950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:24.000Z", "modified": "2016-08-24T10:10:24.000Z", "description": "download location", "pattern": "[domain-name:value = 'rsit.cba.pl']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:24Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7290-4810-46d1-9dac-4bf6950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:24.000Z", "modified": "2016-08-24T10:10:24.000Z", "description": "download location", "pattern": "[domain-name:value = 'selectron.ch']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:24Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7290-36d4-47a1-8bcc-4b9f950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:24.000Z", "modified": "2016-08-24T10:10:24.000Z", "description": "download location", "pattern": "[domain-name:value = 'smilehomeutsumi504.web.fc2.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:24Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7291-93d4-4fa3-9f7e-4aae950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:25.000Z", "modified": "2016-08-24T10:10:25.000Z", "description": "download location", "pattern": "[file:name = 'sopranolady7.wang']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:25Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Payload delivery" } ], "labels": [ "misp:type=\"filename\"", "misp:category=\"Payload delivery\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7291-d964-48e2-b584-41eb950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:25.000Z", "modified": "2016-08-24T10:10:25.000Z", "description": "download location", "pattern": "[domain-name:value = 'stigmata.org.uk']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:25Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7291-ea1c-48e9-ac25-439c950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:25.000Z", "modified": "2016-08-24T10:10:25.000Z", "description": "download location", "pattern": "[domain-name:value = 'tetteco.web.fc2.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:25Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7291-8bac-492b-9b97-4770950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:25.000Z", "modified": "2016-08-24T10:10:25.000Z", "description": "download location", "pattern": "[domain-name:value = 'ttd.co.th']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:25Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7291-cf1c-4ece-bb7e-4275950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:25.000Z", "modified": "2016-08-24T10:10:25.000Z", "description": "download location", "pattern": "[domain-name:value = 'vgweb.ru']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:25Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7292-3394-4ca2-aae1-4bc6950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:26.000Z", "modified": "2016-08-24T10:10:26.000Z", "description": "download location", "pattern": "[domain-name:value = 'wangmewang.name']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:26Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7292-8898-4d94-a606-4e9e950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:26.000Z", "modified": "2016-08-24T10:10:26.000Z", "description": "download location", "pattern": "[domain-name:value = 'webmail.vtr.net']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:26Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7292-f338-43bb-9fae-4841950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:26.000Z", "modified": "2016-08-24T10:10:26.000Z", "description": "download location", "pattern": "[domain-name:value = 'wishmaster.dommel.be']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:26Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7292-ba80-4b32-90cd-4ab1950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:26.000Z", "modified": "2016-08-24T10:10:26.000Z", "description": "download location", "pattern": "[domain-name:value = 'wm08g63hd.homepage.t-online.de']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:26Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7292-3890-4d28-8915-4a92950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:26.000Z", "modified": "2016-08-24T10:10:26.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.archeoetnos.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:26Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7292-4598-4c23-a4d9-4d2d950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:26.000Z", "modified": "2016-08-24T10:10:26.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.bbfreeholidays.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:26Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7293-a790-40a9-861b-4930950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:27.000Z", "modified": "2016-08-24T10:10:27.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.beck-kituzo.hu']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:27Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7293-e874-4746-ab7b-4a4f950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:27.000Z", "modified": "2016-08-24T10:10:27.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.energetica.it']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:27Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7293-1b68-46c1-ab68-4386950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:27.000Z", "modified": "2016-08-24T10:10:27.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.kardborren.se']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:27Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7293-be0c-48f0-abf0-4551950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:27.000Z", "modified": "2016-08-24T10:10:27.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.lenkinetorty.szm.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:27Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7293-1ed0-457c-bfe4-4d8b950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:27.000Z", "modified": "2016-08-24T10:10:27.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.pobierowo-jest-ok.neostrada.pl']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:27Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7294-fd74-49e4-96eb-45fb950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:28.000Z", "modified": "2016-08-24T10:10:28.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.shivartatoo.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:28Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7294-a744-4009-b7f3-48a2950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:28.000Z", "modified": "2016-08-24T10:10:28.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.smees.be']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:28Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd7294-e4f0-4814-ba14-4840950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:10:28.000Z", "modified": "2016-08-24T10:10:28.000Z", "description": "download location", "pattern": "[domain-name:value = 'www.yerridixielandband.jazztel.es']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T10:10:28Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "observed-data", "spec_version": "2.1", "id": "observed-data--57bd7361-1858-4a78-80c1-4252950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:13:53.000Z", "modified": "2016-08-24T10:13:53.000Z", "first_observed": "2016-08-24T10:13:53Z", "last_observed": "2016-08-24T10:13:53Z", "number_observed": 1, "object_refs": [ "email-message--57bd7361-1858-4a78-80c1-4252950d210f" ], "labels": [ "misp:type=\"email-subject\"", "misp:category=\"Payload delivery\"" ] }, { "type": "email-message", "spec_version": "2.1", "id": "email-message--57bd7361-1858-4a78-80c1-4252950d210f", "is_multipart": false, "subject": "Statement" }, { "type": "x-misp-attribute", "spec_version": "2.1", "id": "x-misp-attribute--57bd73ef-7ad8-45f2-9242-4666950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T10:16:15.000Z", "modified": "2016-08-24T10:16:15.000Z", "labels": [ "misp:type=\"text\"", "misp:category=\"Payload delivery\"" ], "x_misp_category": "Payload delivery", "x_misp_comment": "email body", "x_misp_type": "text", "x_misp_value": "Hi,\r\n\r\nThe monthly financial statement is attached within the email.\r\nPlease review it before processing.\r\n\r\n\r\n\r\nKing regards,\r\n{Firstname} {Lastname}\r\n\r\n(Topic-ID: {SOMETHINGRANDOM)" }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f84-a288-4061-b4b6-4e2b950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:56.000Z", "modified": "2016-08-24T12:13:56.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '202.67.211.56']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:56Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f85-eefc-4ae7-b5aa-4724950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:57.000Z", "modified": "2016-08-24T12:13:57.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '213.180.150.17']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:57Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f85-ccd0-4d10-a028-4a90950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:57.000Z", "modified": "2016-08-24T12:13:57.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '90.156.201.19']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:57Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f85-f4a4-4ab7-93cb-4f8a950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:57.000Z", "modified": "2016-08-24T12:13:57.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '91.207.44.3']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:57Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f85-098c-4d3a-9997-43bc950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:57.000Z", "modified": "2016-08-24T12:13:57.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '92.240.253.2']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:57Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f85-5f70-4e9b-9e24-46b8950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:57.000Z", "modified": "2016-08-24T12:13:57.000Z", "description": "download location", "pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '95.211.80.4']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:57Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"ip-dst\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f86-69f0-4e4f-90e0-42ac950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:58.000Z", "modified": "2016-08-24T12:13:58.000Z", "description": "download location", "pattern": "[domain-name:value = 'biopocasie.sk']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:58Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"domain\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f86-44dc-4abb-b07a-49fa950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:58.000Z", "modified": "2016-08-24T12:13:58.000Z", "description": "download location", "pattern": "[domain-name:value = 'cyfrowemotywy.cba.pl']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:58Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f86-ac14-4c7c-ba8f-4db3950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:58.000Z", "modified": "2016-08-24T12:13:58.000Z", "description": "download location", "pattern": "[domain-name:value = 'generator-diesel.com.ua']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:58Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f86-1200-4000-a389-4480950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:58.000Z", "modified": "2016-08-24T12:13:58.000Z", "description": "download location", "pattern": "[url:value = 'http://biopocasie.sk/93d37mak']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:58Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f86-a8e4-4e23-88d1-4334950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:58.000Z", "modified": "2016-08-24T12:13:58.000Z", "description": "download location", "pattern": "[url:value = 'http://cyfrowemotywy.cba.pl/wvllsuc']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:58Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f87-9370-4ea5-aa9b-4a88950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:59.000Z", "modified": "2016-08-24T12:13:59.000Z", "description": "download location", "pattern": "[url:value = 'http://generator-diesel.com.ua/g9rj4']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:59Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f87-d0b8-4c58-abe3-4055950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:59.000Z", "modified": "2016-08-24T12:13:59.000Z", "description": "download location", "pattern": "[url:value = 'http://idesign.com.hk/~webus/mcvepz5']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:59Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f87-b844-461c-a30d-40a1950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:59.000Z", "modified": "2016-08-24T12:13:59.000Z", "description": "download location", "pattern": "[url:value = 'http://karate-kleczew.republika.pl/r8mpvs']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:59Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f87-73e8-490e-a50d-4373950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:59.000Z", "modified": "2016-08-24T12:13:59.000Z", "description": "download location", "pattern": "[url:value = 'http://manuelt.atspace.com/th0dh8zk']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:59Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f87-7e20-4ef9-9b9d-4435950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:59.000Z", "modified": "2016-08-24T12:13:59.000Z", "description": "download location", "pattern": "[url:value = 'http://salebe.web.fc2.com/alr5nk88']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:59Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"url\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f87-615c-46a8-9954-41af950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:13:59.000Z", "modified": "2016-08-24T12:13:59.000Z", "description": "download location", "pattern": "[domain-name:value = 'idesign.com.hk']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:13:59Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f88-6c10-4498-99c8-4cba950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:14:00.000Z", "modified": "2016-08-24T12:14:00.000Z", "description": "download location", "pattern": "[domain-name:value = 'karate-kleczew.republika.pl']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:14:00Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f88-ff50-4855-8be9-4a42950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:14:00.000Z", "modified": "2016-08-24T12:14:00.000Z", "description": "download location", "pattern": "[domain-name:value = 'manuelt.atspace.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:14:00Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "indicator", "spec_version": "2.1", "id": "indicator--57bd8f88-a628-410c-983d-42e9950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:14:00.000Z", "modified": "2016-08-24T12:14:00.000Z", "description": "download location", "pattern": "[domain-name:value = 'salebe.web.fc2.com']", "pattern_type": "stix", "pattern_version": "2.1", "valid_from": "2016-08-24T12:14:00Z", "kill_chain_phases": [ { "kill_chain_name": "misp-category", "phase_name": "Network activity" } ], "labels": [ "misp:type=\"hostname\"", "misp:category=\"Network activity\"", "misp:to_ids=\"True\"" ] }, { "type": "x-misp-attribute", "spec_version": "2.1", "id": "x-misp-attribute--57bd90dd-9af8-4819-8580-4be3950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:19:41.000Z", "modified": "2016-08-24T12:19:41.000Z", "labels": [ "misp:type=\"text\"", "misp:category=\"External analysis\"" ], "x_misp_category": "External analysis", "x_misp_type": "text", "x_misp_value": "Downloaded file is encrypted.\r\nAfter decryption (through the .js), it is executed:\r\n\r\n\"%WINDIR%\\system32\\rundll32.exe\" C:\\DOCUME~1\\ADMINI~1\\LOCALS~1\\Temp\\EQDKM1~1.DLL,qwerty 323" }, { "type": "x-misp-attribute", "spec_version": "2.1", "id": "x-misp-attribute--57bd915f-de6c-4545-bb49-4c6f950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:21:51.000Z", "modified": "2016-08-24T12:21:51.000Z", "labels": [ "misp:type=\"text\"", "misp:category=\"Payload type\"" ], "x_misp_category": "Payload type", "x_misp_type": "text", "x_misp_value": "Zepto" }, { "type": "x-misp-attribute", "spec_version": "2.1", "id": "x-misp-attribute--57bd916d-cee4-478f-bd27-4a80950d210f", "created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f", "created": "2016-08-24T12:22:05.000Z", "modified": "2016-08-24T12:22:05.000Z", "labels": [ "misp:type=\"text\"", "misp:category=\"Payload type\"" ], "x_misp_category": "Payload type", "x_misp_type": "text", "x_misp_value": "Locky" }, { "type": "marking-definition", "spec_version": "2.1", "id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9", "created": "2017-01-20T00:00:00.000Z", "definition_type": "tlp", "name": "TLP:WHITE", "definition": { "tlp": "white" } } ] }