5136 lines
No EOL
203 KiB
JSON
5136 lines
No EOL
203 KiB
JSON
{
|
|
"type": "bundle",
|
|
"id": "bundle--546bbf42-8e2c-412c-8f8d-4b22950d210b",
|
|
"objects": [
|
|
{
|
|
"type": "identity",
|
|
"spec_version": "2.1",
|
|
"id": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:12:22.000Z",
|
|
"modified": "2014-11-18T22:12:22.000Z",
|
|
"name": "CthulhuSPRL.be",
|
|
"identity_class": "organization"
|
|
},
|
|
{
|
|
"type": "report",
|
|
"spec_version": "2.1",
|
|
"id": "report--546bbf42-8e2c-412c-8f8d-4b22950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:12:22.000Z",
|
|
"modified": "2014-11-18T22:12:22.000Z",
|
|
"name": "OSINT Additional indicators relating to Sofacy (APT28) phishing blog post by PWC",
|
|
"published": "2014-11-19T08:36:13Z",
|
|
"object_refs": [
|
|
"observed-data--546bbf5a-478c-4a48-9122-f2f5950d210b",
|
|
"url--546bbf5a-478c-4a48-9122-f2f5950d210b",
|
|
"observed-data--546bbf5a-65e0-45ad-8753-f2f5950d210b",
|
|
"url--546bbf5a-65e0-45ad-8753-f2f5950d210b",
|
|
"x-misp-attribute--546bbf68-0250-4ca4-bbda-45da950d210b",
|
|
"x-misp-attribute--546bbf68-cea4-4e1f-8713-4ccc950d210b",
|
|
"x-misp-attribute--546bbf78-6f78-4490-943f-f2ea950d210b",
|
|
"indicator--546bc0de-45cc-4b3f-8dd6-4e0f950d210b",
|
|
"indicator--546bc0de-f26c-4f0d-8c2f-4be7950d210b",
|
|
"indicator--546bc11e-a57c-4122-9b9a-4823950d210b",
|
|
"indicator--546bc269-34ac-403f-bf73-42c0950d210b",
|
|
"indicator--546bc269-5eb8-4712-8787-4799950d210b",
|
|
"indicator--546bc269-887c-4448-9378-4604950d210b",
|
|
"indicator--546bc269-afa0-48de-8385-426a950d210b",
|
|
"indicator--546bc269-5994-464c-a396-4d6e950d210b",
|
|
"indicator--546bc269-6140-497b-a62e-48d1950d210b",
|
|
"indicator--546bc269-963c-45be-98f3-451a950d210b",
|
|
"indicator--546bc269-3490-4280-b454-4fca950d210b",
|
|
"indicator--546bc269-f1f0-4cc1-9c36-4c14950d210b",
|
|
"indicator--546bc269-bac8-41d8-8953-4b41950d210b",
|
|
"indicator--546bc269-47fc-4e6f-b102-40fe950d210b",
|
|
"indicator--546bc269-365c-4398-ab6a-4c9d950d210b",
|
|
"indicator--546bc269-eb18-4376-a46c-4ada950d210b",
|
|
"indicator--546bc269-4978-440a-bf0f-4f2c950d210b",
|
|
"indicator--546bc269-ea98-45c3-a152-49d3950d210b",
|
|
"indicator--546bc269-dcf4-42f8-a0b0-4b53950d210b",
|
|
"indicator--546bc26a-d0c4-46c3-87cd-4655950d210b",
|
|
"indicator--546bc26a-341c-4b36-9e1c-4d73950d210b",
|
|
"indicator--546bc26a-e29c-4952-9acf-4faf950d210b",
|
|
"indicator--546bc26a-c974-4c39-90fc-4c83950d210b",
|
|
"indicator--546bc26a-0604-432b-b4da-472e950d210b",
|
|
"indicator--546bc26a-c1c4-473e-b0e1-4e34950d210b",
|
|
"indicator--546bc26a-eda8-4aae-8243-4aac950d210b",
|
|
"indicator--546bc26a-c398-4e04-8bf4-48a2950d210b",
|
|
"indicator--546bc26a-aab0-469a-a9de-4526950d210b",
|
|
"indicator--546bc26a-55a0-47a8-8e7e-4c7c950d210b",
|
|
"indicator--546bc26a-e2bc-4cf4-83d0-4f25950d210b",
|
|
"indicator--546bc26a-5b24-43d7-bf92-4017950d210b",
|
|
"indicator--546bc26a-83b0-43fd-9f1b-4299950d210b",
|
|
"indicator--546bc26a-bc80-45fb-8076-4ba1950d210b",
|
|
"indicator--546bc26a-2f78-4958-bf76-4b4a950d210b",
|
|
"indicator--546bc26a-b874-4ff5-aa56-464b950d210b",
|
|
"indicator--546bc26a-51ec-482c-b813-401c950d210b",
|
|
"indicator--546bc26b-3244-4e26-88ff-4c48950d210b",
|
|
"indicator--546bc26b-d594-469a-b791-4429950d210b",
|
|
"indicator--546bc26b-fbec-4bd9-b62e-4127950d210b",
|
|
"indicator--546bc26b-1cc0-4433-98cd-4c24950d210b",
|
|
"indicator--546bc26b-1aec-4e94-8794-4525950d210b",
|
|
"indicator--546bc26b-62b0-4241-a86d-44fd950d210b",
|
|
"indicator--546bc26b-f5a8-48e5-a749-4456950d210b",
|
|
"indicator--546bc26b-e0a0-4841-874d-4b01950d210b",
|
|
"indicator--546bc26b-ae1c-4cb1-9900-48b0950d210b",
|
|
"indicator--546bc26b-a454-405f-a7fb-4d81950d210b",
|
|
"indicator--546bc26b-7b28-4436-ba2c-43e4950d210b",
|
|
"indicator--546bc26b-abc0-4f92-86df-45d5950d210b",
|
|
"indicator--546bc26b-90d4-4639-8f2b-42f8950d210b",
|
|
"indicator--546bc26b-5ba8-4668-b247-4532950d210b",
|
|
"indicator--546bc26b-3af8-4c35-885a-467c950d210b",
|
|
"indicator--546bc26b-d134-44f4-87ec-4a77950d210b",
|
|
"indicator--546bc26c-7b30-41b6-bc01-495b950d210b",
|
|
"indicator--546bc26c-cfb0-4200-bbad-4f48950d210b",
|
|
"indicator--546bc26c-1f28-4f6a-8054-402e950d210b",
|
|
"indicator--546bc26c-eb94-42d5-ab2a-48dd950d210b",
|
|
"indicator--546bc26c-7d28-4670-9061-4d35950d210b",
|
|
"indicator--546bc26c-f944-4251-87d8-497c950d210b",
|
|
"indicator--546bc26c-7320-4d19-833e-403d950d210b",
|
|
"indicator--546bc26c-38a0-4619-a737-4424950d210b",
|
|
"indicator--546bc26c-6bb0-4ba0-86c9-4d01950d210b",
|
|
"indicator--546bc26c-da40-4a2b-9314-4b57950d210b",
|
|
"indicator--546bc26c-ee28-4aa4-aab9-46ed950d210b",
|
|
"indicator--546bc26c-6470-4f45-a5ac-4c92950d210b",
|
|
"indicator--546bc26c-db00-4ee3-aec2-4347950d210b",
|
|
"indicator--546bc26c-e464-4e92-af76-49e0950d210b",
|
|
"indicator--546bc26c-56ac-4f42-a561-494c950d210b",
|
|
"indicator--546bc26c-a8d8-4690-9731-4b67950d210b",
|
|
"indicator--546bc26d-fea8-4496-a8c1-4881950d210b",
|
|
"indicator--546bc26d-b8f0-4da2-a4e5-472d950d210b",
|
|
"indicator--546bc26d-666c-4726-b45f-4568950d210b",
|
|
"indicator--546bc26d-d17c-4679-b5b0-452b950d210b",
|
|
"indicator--546bc26d-ac5c-4868-850d-4767950d210b",
|
|
"indicator--546bc26d-2dc8-4bcf-b74c-4096950d210b",
|
|
"indicator--546bc26d-0600-4f06-b0d3-4515950d210b",
|
|
"indicator--546bc26d-bd14-4023-8841-40ce950d210b",
|
|
"indicator--546bc26d-a1f8-40e5-b64b-4273950d210b",
|
|
"indicator--546bc26d-6268-4ed7-a76c-402b950d210b",
|
|
"indicator--546bc26d-97a4-4162-b08d-4d04950d210b",
|
|
"indicator--546bc26d-8178-42ee-b469-4ff6950d210b",
|
|
"indicator--546bc26d-9194-4a15-a9f8-46b7950d210b",
|
|
"indicator--546bc26d-d680-46b7-8922-42c2950d210b",
|
|
"indicator--546bc26d-1f34-4ae0-8a2b-4abd950d210b",
|
|
"indicator--546bc26d-d718-477e-8844-4f9b950d210b",
|
|
"indicator--546bc26e-42d4-4748-bae4-44e1950d210b",
|
|
"indicator--546bc26e-a0c8-4f0d-9719-4788950d210b",
|
|
"indicator--546bc26e-7d1c-4e27-9a8d-4de5950d210b",
|
|
"indicator--546bc26e-5ebc-4a60-8921-49a4950d210b",
|
|
"indicator--546bc26e-3a00-4630-87ff-4d6b950d210b",
|
|
"indicator--546bc26e-76a4-4a89-90d0-426c950d210b",
|
|
"indicator--546bc26e-8c38-470d-b410-4ffa950d210b",
|
|
"indicator--546bc26e-9b28-4b8f-a1cc-43ef950d210b",
|
|
"indicator--546bc26e-2974-48bb-b8d1-46e0950d210b",
|
|
"indicator--546bc26e-9aa0-45db-8e79-49e0950d210b",
|
|
"indicator--546bc26e-9674-43ba-bdb4-46f3950d210b",
|
|
"indicator--546bc26e-591c-4f6a-88f0-4bb0950d210b",
|
|
"indicator--546bc26e-88f0-42b1-bdd7-4dc3950d210b",
|
|
"indicator--546bc26e-1120-4ae9-9234-48a0950d210b",
|
|
"indicator--546bc26e-dd90-4dd1-bebd-4549950d210b",
|
|
"indicator--546bc26e-d364-4791-9f34-4aab950d210b",
|
|
"indicator--546bc26f-232c-4f5b-ac91-4a0c950d210b",
|
|
"indicator--546bc26f-cbd4-4cbe-8e77-49b2950d210b",
|
|
"indicator--546bc26f-a08c-449e-94f7-45d3950d210b",
|
|
"indicator--546bc26f-6698-471c-ae84-4385950d210b",
|
|
"indicator--546bc26f-6ef8-4ebd-a08a-4472950d210b",
|
|
"indicator--546bc26f-301c-45cd-9ece-450e950d210b",
|
|
"indicator--546bc26f-79c0-4638-93a5-44ea950d210b",
|
|
"indicator--546bc26f-96b8-4d1e-91e1-495e950d210b",
|
|
"indicator--546bc26f-b024-442e-a066-4402950d210b",
|
|
"indicator--546bc26f-a8b4-4b75-839d-4cdd950d210b",
|
|
"indicator--546bc26f-6900-4a38-ae22-4277950d210b",
|
|
"indicator--546bc26f-d120-4297-84dd-4d67950d210b",
|
|
"indicator--546bc26f-f618-46c2-9c58-48cc950d210b",
|
|
"indicator--546bc26f-024c-4650-8761-4b35950d210b",
|
|
"indicator--546bc26f-46f8-4b5a-8e4a-4fb2950d210b",
|
|
"indicator--546bc26f-ebc4-4e22-ac13-48a3950d210b",
|
|
"indicator--546bc270-e158-4584-bc8b-4096950d210b",
|
|
"indicator--546bc270-54e4-4c80-9f29-4e21950d210b",
|
|
"indicator--546bc270-6b90-4cf0-a050-4e83950d210b",
|
|
"indicator--546bc270-23c8-4721-86c7-4971950d210b",
|
|
"indicator--546bc270-aa88-4ba4-af44-4060950d210b",
|
|
"indicator--546bc270-9bcc-49c0-8ebd-44d3950d210b",
|
|
"indicator--546bc270-5850-44cd-9bbf-4d68950d210b",
|
|
"indicator--546bc270-cd8c-412d-a329-4249950d210b",
|
|
"indicator--546bc270-7390-48e1-8b9e-4b68950d210b",
|
|
"indicator--546bc270-c860-4c9b-9445-4dc3950d210b",
|
|
"indicator--546bc270-38f0-4f12-bb54-4efd950d210b",
|
|
"indicator--546bc270-7568-4b0b-a228-4bd1950d210b",
|
|
"indicator--546bc270-e8a4-4bcb-9a0f-45b4950d210b",
|
|
"indicator--546bc270-7d80-4543-85bc-4c93950d210b",
|
|
"indicator--546bc270-679c-4428-955c-4291950d210b",
|
|
"indicator--546bc270-25e0-4398-8090-4aed950d210b",
|
|
"indicator--546bc271-39a8-4f34-9a9d-4002950d210b",
|
|
"indicator--546bc271-8430-4960-8c02-4e00950d210b",
|
|
"indicator--546bc271-2234-4c13-bd57-4145950d210b",
|
|
"indicator--546bc271-55c0-46eb-a428-4775950d210b",
|
|
"indicator--546bc271-99b4-486e-9d0f-4980950d210b",
|
|
"indicator--546bc271-71a4-4f51-8d49-4eb2950d210b",
|
|
"indicator--546bc271-7220-4f66-a51e-4913950d210b",
|
|
"indicator--546bc271-cd84-473e-a86b-456f950d210b",
|
|
"indicator--546bc271-cfb4-4c68-8782-4611950d210b",
|
|
"indicator--546bc271-14e0-4f27-90cd-4582950d210b",
|
|
"indicator--546bc271-c52c-4cf3-ba25-45fb950d210b",
|
|
"indicator--546bc271-0d6c-46e9-81dc-4ab9950d210b",
|
|
"indicator--546bc271-1470-4e1d-9416-4901950d210b",
|
|
"indicator--546bc271-f284-4515-9943-4a35950d210b",
|
|
"indicator--546bc271-afe0-4850-b309-4729950d210b",
|
|
"indicator--546bc271-79f4-49ba-8e5a-4489950d210b",
|
|
"indicator--546bc272-24e4-4299-bd80-4ffd950d210b",
|
|
"indicator--546bc272-9db0-4341-bb03-472e950d210b",
|
|
"indicator--546bc272-a180-4357-a3d3-4e47950d210b",
|
|
"indicator--546bc272-88b8-4544-bddf-435e950d210b",
|
|
"indicator--546bc272-6454-4eba-93ce-4ba8950d210b",
|
|
"indicator--546bc272-87b4-4356-a702-44e0950d210b",
|
|
"indicator--546bc272-08a4-4762-b105-4419950d210b",
|
|
"indicator--546bc272-3718-4358-98e5-43a6950d210b",
|
|
"indicator--546bc272-49e0-4da8-a548-4f51950d210b",
|
|
"indicator--546bc272-7f24-4ec5-b19a-4e6c950d210b",
|
|
"indicator--546bc272-fcec-4d6d-aa8f-4a7f950d210b",
|
|
"indicator--546bc272-3dc0-4f7c-92a5-4c95950d210b",
|
|
"indicator--546bc272-09c8-4eea-8ccd-40af950d210b",
|
|
"indicator--546bc272-21f4-4a6e-822b-4868950d210b",
|
|
"indicator--546bc272-bdc4-40f9-a07a-4cea950d210b",
|
|
"indicator--546bc272-e5b0-4c80-ab7e-4cbc950d210b",
|
|
"indicator--546bc273-78d8-4904-bfd8-41f9950d210b",
|
|
"indicator--546bc273-2ac0-4822-9986-4ea0950d210b",
|
|
"indicator--546bc273-9b28-4654-aa3b-4368950d210b",
|
|
"indicator--546bc273-f42c-4d3a-bca7-48a5950d210b",
|
|
"indicator--546bc273-d7dc-4b99-9991-42fb950d210b",
|
|
"indicator--546bc273-a1a0-49ff-86e4-4a87950d210b",
|
|
"indicator--546bc273-5548-4a44-821b-4016950d210b",
|
|
"indicator--546bc273-725c-4465-bdba-4d01950d210b",
|
|
"indicator--546bc273-6bc8-40a9-946b-4193950d210b",
|
|
"indicator--546bc273-764c-44e1-a500-4101950d210b",
|
|
"indicator--546bc273-1364-4576-88b4-419c950d210b",
|
|
"indicator--546bc273-49ac-4bf3-b8dc-4564950d210b",
|
|
"indicator--546bc273-b788-4263-97ce-46e6950d210b",
|
|
"indicator--546bc273-6a88-4965-b624-4f28950d210b",
|
|
"indicator--546bc273-9d18-4e1c-bd2a-4431950d210b",
|
|
"indicator--546bc273-55fc-49be-9d26-4536950d210b",
|
|
"indicator--546bc274-2300-467e-bd22-4584950d210b",
|
|
"indicator--546bc274-2678-483b-a13b-4f20950d210b",
|
|
"indicator--546bc274-0ffc-4547-a3c2-4827950d210b",
|
|
"indicator--546bc274-f778-4071-81dd-4ac7950d210b",
|
|
"indicator--546bc274-cd04-4e1a-9fd1-4b62950d210b",
|
|
"indicator--546bc274-4ed4-4529-b809-4db2950d210b",
|
|
"indicator--546bc274-dc48-4d78-868b-47df950d210b",
|
|
"indicator--546bc274-1178-496c-a358-4a35950d210b",
|
|
"indicator--546bc274-c430-41d3-bae8-44a4950d210b",
|
|
"indicator--546bc274-d174-4311-a726-44d8950d210b",
|
|
"indicator--546bc274-834c-4cb2-add0-41e7950d210b",
|
|
"indicator--546bc274-72a4-4bb7-aea9-4880950d210b",
|
|
"indicator--546bc274-6da0-415c-a101-4ba0950d210b",
|
|
"indicator--546bc274-86bc-4305-9825-4d9d950d210b",
|
|
"indicator--546bc274-ef84-4b35-b1f0-4c3b950d210b",
|
|
"indicator--546bc274-4644-4e27-839b-4056950d210b",
|
|
"indicator--546bc275-3884-46bd-805c-41e2950d210b",
|
|
"indicator--546bc275-c3b0-4133-ad55-408d950d210b",
|
|
"indicator--546bc275-92d8-426c-a0c0-48d7950d210b",
|
|
"indicator--546bc275-12c8-4a66-98c2-47bd950d210b",
|
|
"indicator--546bc275-edc0-4d60-b0cb-4bff950d210b",
|
|
"indicator--546bc275-b8a8-4ca2-94eb-46ae950d210b",
|
|
"indicator--546bc275-e580-4aa5-a3d3-4863950d210b",
|
|
"indicator--546bc275-3cb4-4efc-a97a-4f20950d210b",
|
|
"indicator--546bc275-7518-46ea-a40c-48f5950d210b",
|
|
"indicator--546bc275-d7d0-49a5-88e7-49be950d210b",
|
|
"indicator--546bc275-b458-4cce-9709-4b0d950d210b",
|
|
"indicator--546bc275-19b0-4dc8-984e-4c03950d210b"
|
|
],
|
|
"labels": [
|
|
"Threat-Report",
|
|
"misp:tool=\"MISP-STIX-Converter\"",
|
|
"type:OSINT"
|
|
],
|
|
"object_marking_refs": [
|
|
"marking-definition--34098fce-860f-48ae-8e50-ebd3cc5e41da"
|
|
]
|
|
},
|
|
{
|
|
"type": "observed-data",
|
|
"spec_version": "2.1",
|
|
"id": "observed-data--546bbf5a-478c-4a48-9122-f2f5950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T21:51:22.000Z",
|
|
"modified": "2014-11-18T21:51:22.000Z",
|
|
"first_observed": "2014-11-18T21:51:22Z",
|
|
"last_observed": "2014-11-18T21:51:22Z",
|
|
"number_observed": 1,
|
|
"object_refs": [
|
|
"url--546bbf5a-478c-4a48-9122-f2f5950d210b"
|
|
],
|
|
"labels": [
|
|
"misp:type=\"link\"",
|
|
"misp:category=\"External analysis\""
|
|
]
|
|
},
|
|
{
|
|
"type": "url",
|
|
"spec_version": "2.1",
|
|
"id": "url--546bbf5a-478c-4a48-9122-f2f5950d210b",
|
|
"value": "http://pwc.blogs.com/cyber_security_updates/2014/10/additional-indicators-relating-to-sofacy-apt28-phishing.html"
|
|
},
|
|
{
|
|
"type": "observed-data",
|
|
"spec_version": "2.1",
|
|
"id": "observed-data--546bbf5a-65e0-45ad-8753-f2f5950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T21:51:22.000Z",
|
|
"modified": "2014-11-18T21:51:22.000Z",
|
|
"first_observed": "2014-11-18T21:51:22Z",
|
|
"last_observed": "2014-11-18T21:51:22Z",
|
|
"number_observed": 1,
|
|
"object_refs": [
|
|
"url--546bbf5a-65e0-45ad-8753-f2f5950d210b"
|
|
],
|
|
"labels": [
|
|
"misp:type=\"link\"",
|
|
"misp:category=\"External analysis\""
|
|
]
|
|
},
|
|
{
|
|
"type": "url",
|
|
"spec_version": "2.1",
|
|
"id": "url--546bbf5a-65e0-45ad-8753-f2f5950d210b",
|
|
"value": "http://pwc.blogs.com/files/tactical-intelligence-bulletin---sofacy-phishing.pdf"
|
|
},
|
|
{
|
|
"type": "x-misp-attribute",
|
|
"spec_version": "2.1",
|
|
"id": "x-misp-attribute--546bbf68-0250-4ca4-bbda-45da950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T21:51:36.000Z",
|
|
"modified": "2014-11-18T21:51:36.000Z",
|
|
"labels": [
|
|
"misp:type=\"text\"",
|
|
"misp:category=\"External analysis\""
|
|
],
|
|
"x_misp_category": "External analysis",
|
|
"x_misp_type": "text",
|
|
"x_misp_value": "Sofacy"
|
|
},
|
|
{
|
|
"type": "x-misp-attribute",
|
|
"spec_version": "2.1",
|
|
"id": "x-misp-attribute--546bbf68-cea4-4e1f-8713-4ccc950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T21:51:36.000Z",
|
|
"modified": "2014-11-18T21:51:36.000Z",
|
|
"labels": [
|
|
"misp:type=\"text\"",
|
|
"misp:category=\"External analysis\""
|
|
],
|
|
"x_misp_category": "External analysis",
|
|
"x_misp_type": "text",
|
|
"x_misp_value": "APT28"
|
|
},
|
|
{
|
|
"type": "x-misp-attribute",
|
|
"spec_version": "2.1",
|
|
"id": "x-misp-attribute--546bbf78-6f78-4490-943f-f2ea950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T21:51:52.000Z",
|
|
"modified": "2014-11-18T21:51:52.000Z",
|
|
"labels": [
|
|
"misp:type=\"comment\"",
|
|
"misp:category=\"External analysis\""
|
|
],
|
|
"x_misp_category": "External analysis",
|
|
"x_misp_type": "comment",
|
|
"x_misp_value": "Data entered by David Andr\u00c3\u00a9"
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc0de-45cc-4b3f-8dd6-4e0f950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T21:57:50.000Z",
|
|
"modified": "2014-11-18T21:57:50.000Z",
|
|
"pattern": "[alert tcp $EXTERNAL_NET $HTTP_PORTS-> $HOME_NET any (msg:\"Potential Sofacy Phishing Redirect\";flow:established,to_client; content:\"\\\"\\\\x6C\\\\x6F\\\\x63\\\\x61\\\\x74\\\\x69\\\\x6F\\\\x6E\\\"\";classtype:trojan-activity;reference:url,http://pwc.blogs.com/cyber_security_updates/2014/10/phresh-phishing-against-government-defence-and-energy.html; rev:1;)]",
|
|
"pattern_type": "snort",
|
|
"valid_from": "2014-11-18T21:57:50Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"snort\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc0de-f26c-4f0d-8c2f-4be7950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T21:57:50.000Z",
|
|
"modified": "2014-11-18T21:57:50.000Z",
|
|
"pattern": "[alert tcp $EXTERNAL_NET $HTTP_PORTS-> $HOME_NET any (msg:\"Potential Sofacy Phishing Redirect\";flow:established,to_client; content:\"\\\"x6Cx6Fx63x61x74x69x6Fx6E\\\"\"; classtype:trojan-activity;reference:url,http://pwc.blogs.com/cyber_security_updates/2014/10/phresh-phishing-against-government-defence-and-energy.html; rev:1;)]",
|
|
"pattern_type": "snort",
|
|
"valid_from": "2014-11-18T21:57:50Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"snort\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc11e-a57c-4122-9b9a-4823950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T21:58:54.000Z",
|
|
"modified": "2014-11-18T21:58:54.000Z",
|
|
"description": "The following comment occurs in many of the pages we\u00e2\u20ac\u2122ve observed relating to this campaign , but can also appear in some legitimate sites",
|
|
"pattern": "[alert tcp $EXTERNAL_NET $HTTP_PORTS-> $HOME_NET any (msg:\"Potential Sofacy Phishing Redirect\";flow:established,to_client; content:\"// stop for sometime if needed\"; classtype:trojan-activity;reference:url,http://pwc.blogs.com/cyber_security_updates/2014/10/phresh-phishing-against-government-defence-and-energy.html; rev:1;)]",
|
|
"pattern_type": "snort",
|
|
"valid_from": "2014-11-18T21:58:54Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"snort\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-34ac-403f-bf73-42c0950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:24.000Z",
|
|
"modified": "2014-11-18T22:04:24.000Z",
|
|
"pattern": "[domain-name:value = 'northropgrumman.org.uk']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:24Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-5eb8-4712-8787-4799950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'counterterorexpo.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-887c-4448-9378-4604950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'nato.nshq.in']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-afa0-48de-8385-426a950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'bostondynamlcs.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-5994-464c-a396-4d6e950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'natoexhibitionff14.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-6140-497b-a62e-48d1950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'vice-news.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-963c-45be-98f3-451a950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'world-oil-company.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-3490-4280-b454-4fca950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'hushmali.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-f1f0-4cc1-9c36-4c14950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'mfanews.info']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-bac8-41d8-8953-4b41950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'azureon-line.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-47fc-4e6f-b102-40fe950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'us-mg6mail-service.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-365c-4398-ab6a-4c9d950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'mail.telecharger-01.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-eb18-4376-a46c-4ada950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'ns1.mfanews.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-4978-440a-bf0f-4f2c950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'updatepc.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-ea98-45c3-a152-49d3950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'ya-support.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc269-dcf4-42f8-a0b0-4b53950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:25.000Z",
|
|
"modified": "2014-11-18T22:04:25.000Z",
|
|
"pattern": "[domain-name:value = 'changepassword-hotmail.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-d0c4-46c3-87cd-4655950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'mail.sofexjordanx.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-341c-4b36-9e1c-4d73950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'kavkazcentr.info']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-e29c-4952-9acf-4faf950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'webmail.windows-updater.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-c974-4c39-90fc-4c83950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'abbott-export.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-0604-432b-b4da-472e950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'mfapress.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-c1c4-473e-b0e1-4e34950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'www.eurosatory-2014.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-eda8-4aae-8243-4aac950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'yavuz16.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-c398-4e04-8bf4-48a2950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'mfauz.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-aab0-469a-a9de-4526950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'mrthelp.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-55a0-47a8-8e7e-4c7c950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'egreetingsfrom.us']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-e2bc-4cf4-83d0-4f25950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'kitegacc.net']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-5b24-43d7-bf92-4017950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'kitegacc.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-83b0-43fd-9f1b-4299950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'mail.rnil.am']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-bc80-45fb-8076-4ba1950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'hothookup.net']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-2f78-4958-bf76-4b4a950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'netschecker.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-b874-4ff5-aa56-464b950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'webmail-saic.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26a-51ec-482c-b813-401c950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:26.000Z",
|
|
"modified": "2014-11-18T22:04:26.000Z",
|
|
"pattern": "[domain-name:value = 'intuitstatistics.info']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-3244-4e26-88ff-4c48950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'flickr-service.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-d594-469a-b791-4429950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'n0vinite.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-fbec-4bd9-b62e-4127950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'assaas.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-1cc0-4433-98cd-4c24950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'rnil.cl']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-1aec-4e94-8794-4525950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'helpfromhome.co']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-62b0-4241-a86d-44fd950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'gdforum.net']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-f5a8-48e5-a749-4456950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'set121.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-e0a0-4841-874d-4b01950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'academl.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-ae1c-4cb1-9900-48b0950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'changepassword-yahoo.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-a454-405f-a7fb-4d81950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'greetingcardproject.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-7b28-4436-ba2c-43e4950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'adawareblock.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-abc0-4f92-86df-45d5950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'securitypractic.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-90d4-4639-8f2b-42f8950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'rnil.am']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-5ba8-4668-b247-4532950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'ya-login.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-3af8-4c35-885a-467c950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'mx1.g0b.mx']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26b-d134-44f4-87ec-4a77950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:27.000Z",
|
|
"modified": "2014-11-18T22:04:27.000Z",
|
|
"pattern": "[domain-name:value = 'product-update.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:27Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-7b30-41b6-bc01-495b950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'memoinfo.ru']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-cfb0-4200-bbad-4f48950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'privacy-live.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-1f28-4f6a-8054-402e950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'tolonevvs.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-eb94-42d5-ab2a-48dd950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'us-westmail-undeliversystem.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-7d28-4670-9061-4d35950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'test.chmail.in']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-f944-4251-87d8-497c950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'kakashka.chmail.in']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-7320-4d19-833e-403d950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'gov.hu.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-38a0-4619-a737-4424950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'us-mg6-transfermail-service.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-6bb0-4ba0-86c9-4d01950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'us-mg6-mailreport.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-da40-4a2b-9314-4b57950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'aadexpo2014.co.za']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-ee28-4aa4-aab9-46ed950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'www.gdforum.info']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-6470-4f45-a5ac-4c92950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'militaryinf.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-db00-4ee3-aec2-4347950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'valuetable.hk']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-e464-4e92-af76-49e0950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'googlesetting.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-56ac-4f42-a561-494c950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'hotmail-monitor.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26c-a8d8-4690-9731-4b67950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:28.000Z",
|
|
"modified": "2014-11-18T22:04:28.000Z",
|
|
"pattern": "[domain-name:value = 'junlper.net']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-fea8-4496-a8c1-4881950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'www.ya-support.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-b8f0-4da2-a4e5-472d950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'g-analytics.net']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-666c-4726-b45f-4568950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'www.sofexjordanx.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-d17c-4679-b5b0-452b950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'privacy-yahoo.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-ac5c-4868-850d-4767950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'yahoo.chmail.in']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-2dc8-4bcf-b74c-4096950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'windous.kz']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-0600-4f06-b0d3-4515950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'youtubeclip.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-bd14-4023-8841-40ce950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'aa.69.mu']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-a1f8-40e5-b64b-4273950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'qov.hu.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-6268-4ed7-a76c-402b950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'vvorthyhands.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-97a4-4162-b08d-4d04950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'dkvnz.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-8178-42ee-b469-4ff6950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'mail.account-flickr.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-9194-4a15-a9f8-46b7950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'bulletin-center.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-d680-46b7-8922-42c2950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'yovtube.co']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-1f34-4ae0-8a2b-4abd950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'skidkaturag.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26d-d718-477e-8844-4f9b950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:29.000Z",
|
|
"modified": "2014-11-18T22:04:29.000Z",
|
|
"pattern": "[domain-name:value = 'defenceiq.us']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-42d4-4748-bae4-44e1950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'mail-google.info']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-a0c8-4f0d-9719-4788950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'soft-storage.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-7d1c-4e27-9a8d-4de5950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'clickchekkker.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-5ebc-4a60-8921-49a4950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'intuitanalys.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-3a00-4630-87ff-4d6b950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'sofexjordanx.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-76a4-4a89-90d0-426c950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'intuitstatistic.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-8c38-470d-b410-4ffa950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'militaryexponews.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-9b28-4b8f-a1cc-43ef950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'caciltd.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-2974-48bb-b8d1-46e0950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'windows-updater.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-9aa0-45db-8e79-49e0950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'mail.securitypractic.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-9674-43ba-bdb4-46f3950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'www.surll.me']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-591c-4f6a-88f0-4bb0950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'heidelberqcement.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-88f0-42b1-bdd7-4dc3950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'armypress.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-1120-4ae9-9234-48a0950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'sweetcherry.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-dd90-4dd1-bebd-4549950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'account-flickr.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26e-d364-4791-9f34-4aab950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:30.000Z",
|
|
"modified": "2014-11-18T22:04:30.000Z",
|
|
"pattern": "[domain-name:value = 'setnewpass-yahoo.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:30Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-232c-4f5b-ac91-4a0c950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'scanmalware.info']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-cbd4-4cbe-8e77-49b2950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'greetingcardsproject.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-a08c-449e-94f7-45d3950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'q0v.pl']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-6698-471c-ae84-4385950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'link-google.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-6ef8-4ebd-a08a-4472950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'www.forsvaret.co']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-301c-45cd-9ece-450e950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'cubic.com.co']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-79c0-4638-93a5-44ea950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'mail.mrthelp.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-96b8-4d1e-91e1-495e950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'www.us-mg7mail-transferservice.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-b024-442e-a066-4402950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'www.vljaihln.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-a8b4-4b75-839d-4cdd950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'ifcdsc.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-6900-4a38-ae22-4277950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'smigroup-online.co.uk']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-d120-4297-84dd-4d67950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = '100plusapps.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-f618-46c2-9c58-48cc950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'pruintco.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-024c-4650-8761-4b35950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'www.yahoo-monitor.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-46f8-4b5a-8e4a-4fb2950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'www.chmail.in']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc26f-ebc4-4e22-ac13-48a3950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:31.000Z",
|
|
"modified": "2014-11-18T22:04:31.000Z",
|
|
"pattern": "[domain-name:value = 'litu.su']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-e158-4584-bc8b-4096950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'www.dkvnz.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-54e4-4c80-9f29-4e21950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'mail.yahoo-monitor.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-6b90-4cf0-a050-4e83950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'us-mg7mail-transferservice.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-23c8-4721-86c7-4971950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'evrosatory.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-aa88-4ba4-af44-4060950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'wind0ws.kz']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-9bcc-49c0-8ebd-44d3950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'farnboroughair2014.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-5850-44cd-9bbf-4d68950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'mfa-gov.info']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-cd8c-412d-a329-4249950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'y-privacy.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-7390-48e1-8b9e-4b68950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'login-osce.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-c860-4c9b-9445-4dc3950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'helpmicrosoft.net']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-38f0-4f12-bb54-4efd950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'sofexjordan2014.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-7568-4b0b-a228-4bd1950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'malwarecheck.info']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-e8a4-4bcb-9a0f-45b4950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'update-hub.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-7d80-4543-85bc-4c93950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'mx3.set121.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-679c-4428-955c-4291950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'srv-yahoo.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc270-25e0-4398-8090-4aed950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:32.000Z",
|
|
"modified": "2014-11-18T22:04:32.000Z",
|
|
"pattern": "[domain-name:value = 'bostondyn.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-39a8-4f34-9a9d-4002950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'aerospacesystem.us.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-8430-4960-8c02-4e00950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'eurosatary.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-2234-4c13-bd57-4145950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'telecharger-01.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-55c0-46eb-a428-4775950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'chmali.ir']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-99b4-486e-9d0f-4980950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'privacy.google-settings.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-71a4-4f51-8d49-4eb2950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'yandex-site.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-7220-4f66-a51e-4913950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'www.7daysinabudhabi.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-cd84-473e-a86b-456f950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'www.account-flickr.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-cfb4-4c68-8782-4611950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'google-settings.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-14e0-4f27-90cd-4582950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'gcardproject.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-c52c-4cf3-ba25-45fb950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'eurosator.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-0d6c-46e9-81dc-4ab9950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'update-zimbra.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-1470-4e1d-9416-4901950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'asisonlline.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-f284-4515-9943-4a35950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'mfapress.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-afe0-4850-b309-4729950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'stockliquidationgroup.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc271-79f4-49ba-8e5a-4489950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:33.000Z",
|
|
"modified": "2014-11-18T22:04:33.000Z",
|
|
"pattern": "[domain-name:value = 'pasport-yandex.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:33Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-24e4-4299-bd80-4ffd950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'konami-game.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-9db0-4341-bb03-472e950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'www.adawareblock.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-a180-4357-a3d3-4e47950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'persa124.in']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-88b8-4544-bddf-435e950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'eurosatory-2014.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-6454-4eba-93ce-4ba8950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'clickchekker.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-87b4-4356-a702-44e0950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'al-wayi.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-08a4-4762-b105-4419950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'molodirect.net']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-3718-4358-98e5-43a6950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'com-0cd.net']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-49e0-4da8-a548-4f51950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'us-mg6mailyahoo.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-7f24-4ec5-b19a-4e6c950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'finance-reports.everyday.com-w13.net']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-fcec-4d6d-aa8f-4a7f950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'apple-iclouds.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-3dc0-4f7c-92a5-4c95950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'unizg.net']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-09c8-4eea-8ccd-40af950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'mfanews.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-21f4-4a6e-822b-4868950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'mail.ya-support.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-bdc4-40f9-a07a-4cea950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'checkmalware.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc272-e5b0-4c80-ab7e-4cbc950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:34.000Z",
|
|
"modified": "2014-11-18T22:04:34.000Z",
|
|
"pattern": "[domain-name:value = 'geaviations.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-78d8-4904-bfd8-41f9950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'flashsecurity.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-2ac0-4822-9986-4ea0950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'imperialc0nsult.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-9b28-4654-aa3b-4368950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'cublc.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-f42c-4d3a-bca7-48a5950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'evronaval.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-d7dc-4b99-9991-42fb950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'xuetue2013.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-a1a0-49ff-86e4-4a87950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'www.valuetable.hk']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-5548-4a44-821b-4016950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'mail.chmail.in']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-725c-4465-bdba-4d01950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'nshq.in']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-6bc8-40a9-946b-4193950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'forsvaret.co']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-764c-44e1-a500-4101950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'in-eternal-memory-of.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-1364-4576-88b4-419c950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'www.us-westmail-undeliversystem.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-49ac-4bf3-b8dc-4564950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'gdforum.info']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-b788-4263-97ce-46e6950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'sex-toy-shop.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-6a88-4965-b624-4f28950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'novinitie.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-9d18-4e1c-bd2a-4431950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'yahoo-monitor.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc273-55fc-49be-9d26-4536950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:35.000Z",
|
|
"modified": "2014-11-18T22:04:35.000Z",
|
|
"pattern": "[domain-name:value = 'standartnevvs.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-2300-467e-bd22-4584950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'pornforyou.in']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-2678-483b-a13b-4f20950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'mail.q0v.pl']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-0ffc-4547-a3c2-4827950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'mail.windows-updater.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-f778-4071-81dd-4ac7950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'allcashin.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-cd04-4e1a-9fd1-4b62950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'arnf.bg']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-4ed4-4529-b809-4db2950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'gpwpl.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-dc48-4d78-868b-47df950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'updateapi.longmusic.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-1178-496c-a358-4a35950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'chmail.in']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-c430-41d3-bae8-44a4950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'brokersads.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-d174-4311-a726-44d8950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'testservice24.net']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-834c-4cb2-add0-41e7950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'kavkazjlhad.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-72a4-4bb7-aea9-4880950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'livemicrosoft.net']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-6da0-415c-a101-4ba0950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'surll.me']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-86bc-4305-9825-4d9d950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'accesd-de-desjardins.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-ef84-4b35-b1f0-4c3b950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'mail.hushmali.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc274-4644-4e27-839b-4056950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:36.000Z",
|
|
"modified": "2014-11-18T22:04:36.000Z",
|
|
"pattern": "[domain-name:value = 'sunmicrosystem.info']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:36Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc275-3884-46bd-805c-41e2950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:37.000Z",
|
|
"modified": "2014-11-18T22:04:37.000Z",
|
|
"pattern": "[domain-name:value = 'bytly.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc275-c3b0-4133-ad55-408d950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:37.000Z",
|
|
"modified": "2014-11-18T22:04:37.000Z",
|
|
"pattern": "[domain-name:value = 'mx.rnil.cl']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc275-92d8-426c-a0c0-48d7950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:37.000Z",
|
|
"modified": "2014-11-18T22:04:37.000Z",
|
|
"pattern": "[domain-name:value = 'poczta.mon.q0v.pl']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc275-12c8-4a66-98c2-47bd950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:37.000Z",
|
|
"modified": "2014-11-18T22:04:37.000Z",
|
|
"pattern": "[domain-name:value = 'ns.mfanews.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc275-edc0-4d60-b0cb-4bff950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:37.000Z",
|
|
"modified": "2014-11-18T22:04:37.000Z",
|
|
"pattern": "[domain-name:value = '7daysinabudhabi.org']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc275-b8a8-4ca2-94eb-46ae950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:37.000Z",
|
|
"modified": "2014-11-18T22:04:37.000Z",
|
|
"pattern": "[domain-name:value = 'privacy-hotmail.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc275-e580-4aa5-a3d3-4863950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:37.000Z",
|
|
"modified": "2014-11-18T22:04:37.000Z",
|
|
"pattern": "[domain-name:value = 'ns1.al-wayi.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc275-3cb4-4efc-a97a-4f20950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:37.000Z",
|
|
"modified": "2014-11-18T22:04:37.000Z",
|
|
"pattern": "[domain-name:value = 'ecards-yahoo.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc275-7518-46ea-a40c-48f5950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:37.000Z",
|
|
"modified": "2014-11-18T22:04:37.000Z",
|
|
"pattern": "[domain-name:value = 'eurosatory2014.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc275-d7d0-49a5-88e7-49be950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:37.000Z",
|
|
"modified": "2014-11-18T22:04:37.000Z",
|
|
"pattern": "[domain-name:value = 'yahoo-analytics.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc275-b458-4cce-9709-4b0d950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:37.000Z",
|
|
"modified": "2014-11-18T22:04:37.000Z",
|
|
"pattern": "[domain-name:value = 'www.srv-yahoo.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--546bc275-19b0-4dc8-984e-4c03950d210b",
|
|
"created_by_ref": "identity--55f6ea5f-fd34-43b8-ac1d-40cb950d210f",
|
|
"created": "2014-11-18T22:04:37.000Z",
|
|
"modified": "2014-11-18T22:04:37.000Z",
|
|
"pattern": "[domain-name:value = 'set133.com']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2014-11-18T22:04:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"hostname\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "marking-definition",
|
|
"spec_version": "2.1",
|
|
"id": "marking-definition--34098fce-860f-48ae-8e50-ebd3cc5e41da",
|
|
"created": "2017-01-20T00:00:00.000Z",
|
|
"definition_type": "tlp",
|
|
"name": "TLP:GREEN",
|
|
"definition": {
|
|
"tlp": "green"
|
|
}
|
|
}
|
|
]
|
|
} |