2520 lines
No EOL
101 KiB
JSON
2520 lines
No EOL
101 KiB
JSON
{
|
|
"type": "bundle",
|
|
"id": "bundle--5b06a4b4-6e74-40b8-ae95-9fc10acd0835",
|
|
"objects": [
|
|
{
|
|
"type": "identity",
|
|
"spec_version": "2.1",
|
|
"id": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-08-23T14:53:05.000Z",
|
|
"modified": "2018-08-23T14:53:05.000Z",
|
|
"name": "Synovus Financial",
|
|
"identity_class": "organization"
|
|
},
|
|
{
|
|
"type": "report",
|
|
"spec_version": "2.1",
|
|
"id": "report--5b06a4b4-6e74-40b8-ae95-9fc10acd0835",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-08-23T14:53:05.000Z",
|
|
"modified": "2018-08-23T14:53:05.000Z",
|
|
"name": "Emotet - 5/21/2018",
|
|
"published": "2018-08-23T14:54:39Z",
|
|
"object_refs": [
|
|
"indicator--7b135136-7931-4be5-99fd-0535af09574f",
|
|
"indicator--fe42e04f-7e58-4f1e-b8cc-cb665e314902",
|
|
"indicator--eea035ef-6290-4240-b74f-aef13d193cb9",
|
|
"indicator--3101104f-45df-4f00-9dbf-fabc6b9deb0c",
|
|
"observed-data--ad53a93e-facb-4ad5-9f85-a22214326190",
|
|
"url--ad53a93e-facb-4ad5-9f85-a22214326190",
|
|
"indicator--92a8762d-a38e-4c99-b691-7b1cd9e32f9a",
|
|
"indicator--0da51511-bce8-4977-9c05-96df30e9566b",
|
|
"indicator--3c1cc519-541a-4a9a-b0b2-00ba1f32fe74",
|
|
"indicator--bd7df7e6-5180-48fe-8cf3-23fb61b0f21b",
|
|
"indicator--993cf2a4-6c32-4bff-91ac-539d4e158628",
|
|
"indicator--40cf6878-f6e8-43c5-b4c5-8c3b4fcfedc3",
|
|
"indicator--906812fa-772c-493d-9929-583ed3eff156",
|
|
"indicator--d43f4d7d-dabe-4b5e-b659-0bbc1de8a35d",
|
|
"indicator--8c1ee6ee-772a-4945-9eab-3103cb146ddd",
|
|
"indicator--3d905dd6-d1a5-4baf-bce2-6828b8fff767",
|
|
"indicator--2fecc582-61d4-4e3d-9760-2046fcf6130f",
|
|
"indicator--ca0331df-e7e8-4743-a550-9df5f93639e9",
|
|
"indicator--3c787c77-4fcf-417a-940b-4d5b65cdfd58",
|
|
"indicator--90de570a-3d6b-438e-8836-5e5d20315b18",
|
|
"indicator--d3387d17-7548-44fc-b158-2e1748fec0eb",
|
|
"indicator--4366fdaa-3e1d-435a-ab53-78b1dced298f",
|
|
"indicator--9dafd2b0-0e8c-49d7-809c-4c0c112b7f77",
|
|
"indicator--790a1845-0e79-480f-b327-56808124942c",
|
|
"indicator--11747515-d7cf-4f5e-bc2a-99f7b918ff30",
|
|
"indicator--be97cb83-10b8-4ec3-b9c9-6dabbb77c8d4",
|
|
"indicator--0d6fd649-0fac-45a3-a39d-a60b903bb4d4",
|
|
"indicator--6ecfe54f-cfe8-4d1e-9ba0-8e1e62665a8d",
|
|
"indicator--ab5bfdb3-575f-4934-964e-d779297e49e5",
|
|
"indicator--cc28f33c-ccdb-4d47-bda9-563ef8ba4709",
|
|
"indicator--e7967451-e224-498e-a14d-ad06a75ff309",
|
|
"indicator--b752609e-c9c0-4d0a-b413-c12b96bcdc32",
|
|
"indicator--e60e390c-443e-4f82-905e-d2e26731e1e3",
|
|
"indicator--fb08b5fc-ba38-4453-90b9-58c56fc478b1",
|
|
"indicator--b60ade76-7574-4389-b3ed-c42a475b475a",
|
|
"indicator--8b95983d-9a6a-4934-9490-036eea3c223d",
|
|
"indicator--c8235eba-5062-4bb4-beb3-38601926a83c",
|
|
"indicator--d6771a70-2191-4198-852b-3be9071daa00",
|
|
"indicator--eafa06a4-c2d4-48bc-b91f-b93ef03a14aa",
|
|
"indicator--f5ac55d0-66e7-4e27-8db5-3b45a82eebeb",
|
|
"indicator--f6387846-5e79-47b0-83fb-80ecbd64bfcd",
|
|
"indicator--b48d8997-b832-4ee6-a803-cfe2c1dd0709",
|
|
"indicator--b677b3e6-4841-498e-814b-655650e0ba53",
|
|
"indicator--790d3d60-0642-40c5-8556-3b4e49778a5f",
|
|
"indicator--d33085f4-4a53-4fbe-959e-fa3961958b43",
|
|
"indicator--7dc82997-0eae-401c-bb6f-4e069c0e47a9",
|
|
"indicator--433df490-8552-4a9e-8544-d7680fa5a501",
|
|
"indicator--bff9ccc9-44a4-4fae-a32b-88cc406d0778",
|
|
"indicator--38de46aa-5c29-48b0-b203-c285f45d8714",
|
|
"indicator--e00fbf0e-f840-4c0e-8003-ab3ad1f34074",
|
|
"indicator--45a0ef00-04ad-45a5-a244-545a76f93693",
|
|
"indicator--41e28f2e-a661-442c-a53e-acc235d250db",
|
|
"indicator--4f6a8260-731e-4e5a-8430-8308a93c7530",
|
|
"indicator--454a387c-f39d-4a6e-a225-e0ab846f30e5",
|
|
"indicator--644f4699-a1df-4db5-b69b-1621c122a406",
|
|
"indicator--b49bed1d-4cd6-450c-9ea2-ea1ab71614c1",
|
|
"indicator--eaa9dd10-68c6-48b3-8806-0616398970e5",
|
|
"indicator--c72f02cc-7da2-4c7c-bd0c-7c4e6bdfbd5e",
|
|
"indicator--7ac3b791-8acc-4f61-be79-ef3cab1ad3be",
|
|
"indicator--af7c7b13-716a-4850-9d79-043d27ebd747",
|
|
"indicator--313b9f36-c656-46fe-8847-5eb6b2b69793",
|
|
"indicator--5f45baf4-0152-465e-a879-a15ef9979c71",
|
|
"indicator--5518616e-3305-45db-9c3b-d27567c99810",
|
|
"indicator--653a06ef-a2c9-4313-9258-6bf392a6858e",
|
|
"indicator--71f630be-cd2f-48c1-a2bc-f65fc4a2a6e0",
|
|
"indicator--4371d231-e8ff-4ac4-97d2-26f7b7e6795b",
|
|
"indicator--95c3ecee-0d29-4bee-9963-27adee8927b2",
|
|
"indicator--01633a75-3ed2-4cd5-a7a8-15e340774316",
|
|
"indicator--549143ed-734c-4efc-bd48-fdfcf7101fe7",
|
|
"indicator--98b3177c-57d8-4e5b-827c-f2787c91a5f7",
|
|
"indicator--6967fb57-57dd-4ee0-bfd7-0571dbd93e61",
|
|
"indicator--d5c1cb2d-cfc8-4c6d-9ee9-0b4ee49ae283",
|
|
"indicator--b7d91d7e-a054-4083-8ef7-9feb4560e85d",
|
|
"indicator--1886ad83-17ca-4f6f-a548-e1fe2ec94225",
|
|
"indicator--0c6c42f0-08b2-4ee1-aedf-27db7b605367",
|
|
"indicator--d8a017de-d31c-4a07-a33b-067ec99d1cff",
|
|
"indicator--8de74505-0cb9-4ea2-87b2-f6fe15ab3648",
|
|
"indicator--ef2d4f82-27fe-4cae-a725-4fbacb2add63",
|
|
"indicator--c41f0a0b-5db7-49db-bf95-f423dbffad00",
|
|
"indicator--73ea8a7e-f9f4-49f0-9f88-4c551517b5a7",
|
|
"indicator--d1728be1-7f44-41ad-9c9a-7f5a5117253a",
|
|
"indicator--3d521c99-2938-466e-90d2-ab7570f2ea22",
|
|
"indicator--00562399-5457-41c3-895a-323d3135ff0f",
|
|
"indicator--4b81dfbc-379b-4b25-91a6-96e164ed03be",
|
|
"indicator--e468770f-a550-4d81-9391-d99d5b703e95",
|
|
"indicator--6c737cdc-7baa-466f-8f23-8d17458b282a",
|
|
"indicator--91d464bc-94b6-4cab-9e7a-35b5b8d1618f",
|
|
"indicator--d0324ad1-f9ea-4469-8be5-96edf53b383b",
|
|
"indicator--c71e2259-1dd5-4352-bbd8-c249c16fce1f",
|
|
"indicator--64301f39-148a-4686-bc42-65f3346fb12a",
|
|
"indicator--a3f3d972-e413-413a-b0bc-d9cc4d6586d8",
|
|
"indicator--03874d17-b879-45e7-9b1e-9b0850877fed",
|
|
"indicator--104f8d93-8647-48b8-8d4a-2b07902692c9",
|
|
"indicator--ac1fcec6-873b-4ec9-8910-189302b31619",
|
|
"indicator--21b312e7-9117-4186-a0dc-55af77e5ac23",
|
|
"indicator--e70ec94e-21fc-42cd-bbe5-6578370de835",
|
|
"indicator--31913ef8-8981-4464-abdc-e82d0e4bd2e0",
|
|
"indicator--8ca846c4-42c9-401a-bddf-d56c38634b65",
|
|
"indicator--a5beb3ed-267e-47a4-b099-c68a435abc0d",
|
|
"indicator--f360f8f5-4134-46d4-a459-721b92f8abe0",
|
|
"indicator--0cbe40e0-f08e-4486-84bf-27e5aa38c217",
|
|
"indicator--cffb6f51-ec66-4cfc-ae6d-2e05bb2338a9",
|
|
"indicator--2ffd9ebc-3f1f-4252-8021-8d6c7bf39a7f",
|
|
"indicator--03c2db94-a978-49d7-a27b-f9f71684b8a9"
|
|
],
|
|
"labels": [
|
|
"Threat-Report",
|
|
"misp:tool=\"MISP-STIX-Converter\"",
|
|
"misp-galaxy:tool=\"Emotet\""
|
|
],
|
|
"object_marking_refs": [
|
|
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--7b135136-7931-4be5-99fd-0535af09574f",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:40:39.000Z",
|
|
"modified": "2018-05-24T11:40:39.000Z",
|
|
"pattern": "[file:hashes.MD5 = '33da043e770f5d78ca3b3d97863ca527']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:40:39Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"md5\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--fe42e04f-7e58-4f1e-b8cc-cb665e314902",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:40:42.000Z",
|
|
"modified": "2018-05-24T11:40:42.000Z",
|
|
"pattern": "[file:hashes.MD5 = '204873e8e3deeb549ae920b27d5258cf']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:40:42Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"md5\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--eea035ef-6290-4240-b74f-aef13d193cb9",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:40:46.000Z",
|
|
"modified": "2018-05-24T11:40:46.000Z",
|
|
"pattern": "[file:hashes.MD5 = '9f70fa70b468f332bb7ade24dfe0c3c7']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:40:46Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"md5\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--3101104f-45df-4f00-9dbf-fabc6b9deb0c",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:40:49.000Z",
|
|
"modified": "2018-05-24T11:40:49.000Z",
|
|
"pattern": "[file:hashes.MD5 = '22b2e23fbe67d3ccefbcf99b076ed3aa']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:40:49Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"md5\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "observed-data",
|
|
"spec_version": "2.1",
|
|
"id": "observed-data--ad53a93e-facb-4ad5-9f85-a22214326190",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-08-23T14:53:04.000Z",
|
|
"modified": "2018-08-23T14:53:04.000Z",
|
|
"first_observed": "2018-08-23T14:53:04Z",
|
|
"last_observed": "2018-08-23T14:53:04Z",
|
|
"number_observed": 1,
|
|
"object_refs": [
|
|
"url--ad53a93e-facb-4ad5-9f85-a22214326190"
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\""
|
|
]
|
|
},
|
|
{
|
|
"type": "url",
|
|
"spec_version": "2.1",
|
|
"id": "url--ad53a93e-facb-4ad5-9f85-a22214326190",
|
|
"value": "https://protonmail.com"
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--92a8762d-a38e-4c99-b691-7b1cd9e32f9a",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:41:13.000Z",
|
|
"modified": "2018-05-24T11:41:13.000Z",
|
|
"pattern": "[url:value = 'http://deist-online.de/ups.com/WebTracking/KKV-71871574417210/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:41:13Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--0da51511-bce8-4977-9c05-96df30e9566b",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:41:19.000Z",
|
|
"modified": "2018-05-24T11:41:19.000Z",
|
|
"pattern": "[url:value = 'http://edv-salz.de/STATUS/Please-pull-invoice-547885/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:41:19Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--3c1cc519-541a-4a9a-b0b2-00ba1f32fe74",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:41:25.000Z",
|
|
"modified": "2018-05-24T11:41:25.000Z",
|
|
"pattern": "[url:value = 'http://kflife.com/aspnet_client/system_web/4_0_30319/Client/Pay-Invoice/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:41:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--bd7df7e6-5180-48fe-8cf3-23fb61b0f21b",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:41:31.000Z",
|
|
"modified": "2018-05-24T11:41:31.000Z",
|
|
"pattern": "[url:value = 'http://ivanrivera.com/Client/Invoice-152185/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:41:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--993cf2a4-6c32-4bff-91ac-539d4e158628",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:41:37.000Z",
|
|
"modified": "2018-05-24T11:41:37.000Z",
|
|
"pattern": "[url:value = 'http://houselight.com.br/STATUS/Invoice-67059306-Invoice-date-052118-Order-no-95855818767/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:41:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--40cf6878-f6e8-43c5-b4c5-8c3b4fcfedc3",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:41:43.000Z",
|
|
"modified": "2018-05-24T11:41:43.000Z",
|
|
"pattern": "[url:value = 'http://onfarmsystems.com/ups.com/WebTracking/TRF-09391329/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:41:43Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--906812fa-772c-493d-9929-583ed3eff156",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:41:49.000Z",
|
|
"modified": "2018-05-24T11:41:49.000Z",
|
|
"pattern": "[url:value = 'http://hellogrid.com/STATUS/Invoice-09969006-Invoice-date-052118-Order-no-41574537247/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:41:49Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--d43f4d7d-dabe-4b5e-b659-0bbc1de8a35d",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:41:55.000Z",
|
|
"modified": "2018-05-24T11:41:55.000Z",
|
|
"pattern": "[url:value = 'http://kjg-schiefbahn.de/STATUS/Direct-Deposit-Notice/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:41:55Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--8c1ee6ee-772a-4945-9eab-3103cb146ddd",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:42:01.000Z",
|
|
"modified": "2018-05-24T11:42:01.000Z",
|
|
"pattern": "[url:value = 'http://cnajs.com/FILE/Invoice-047243/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:42:01Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--3d905dd6-d1a5-4baf-bce2-6828b8fff767",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:42:07.000Z",
|
|
"modified": "2018-05-24T11:42:07.000Z",
|
|
"pattern": "[url:value = 'http://ginca.jp/Client/INV4534915560523538361/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:42:07Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--2fecc582-61d4-4e3d-9760-2046fcf6130f",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:42:13.000Z",
|
|
"modified": "2018-05-24T11:42:13.000Z",
|
|
"pattern": "[url:value = 'http://eurokarton.pl/js/ups.com/WebTracking/IZ-4156347217578/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:42:13Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--ca0331df-e7e8-4743-a550-9df5f93639e9",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:42:19.000Z",
|
|
"modified": "2018-05-24T11:42:19.000Z",
|
|
"pattern": "[url:value = 'https://birgitdresel.de/ups.com/WebTracking/TJ-16728641/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:42:19Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--3c787c77-4fcf-417a-940b-4d5b65cdfd58",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:42:25.000Z",
|
|
"modified": "2018-05-24T11:42:25.000Z",
|
|
"pattern": "[url:value = 'http://europlastic.de/STATUS/New-Invoice-WG92763-IW-78087/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:42:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--90de570a-3d6b-438e-8836-5e5d20315b18",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:42:31.000Z",
|
|
"modified": "2018-05-24T11:42:31.000Z",
|
|
"pattern": "[url:value = 'https://kadow.de/STATUS/New-Invoice-CY56039-ZW-4575/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:42:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--d3387d17-7548-44fc-b158-2e1748fec0eb",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:42:37.000Z",
|
|
"modified": "2018-05-24T11:42:37.000Z",
|
|
"pattern": "[url:value = 'http://leasefor.com/ups.com/WebTracking/BL-7933643910213/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:42:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--4366fdaa-3e1d-435a-ab53-78b1dced298f",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:42:43.000Z",
|
|
"modified": "2018-05-24T11:42:43.000Z",
|
|
"pattern": "[url:value = 'http://liebner.de/ups.com/WebTracking/ZZR-29523172658673/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:42:43Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--9dafd2b0-0e8c-49d7-809c-4c0c112b7f77",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:42:49.000Z",
|
|
"modified": "2018-05-24T11:42:49.000Z",
|
|
"pattern": "[url:value = 'http://fatafati.net/ups.com/WebTracking/DUV-6004272960517/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:42:49Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--790a1845-0e79-480f-b327-56808124942c",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:42:55.000Z",
|
|
"modified": "2018-05-24T11:42:55.000Z",
|
|
"pattern": "[url:value = 'http://axiscook.com/FILE/Invoices/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:42:55Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--11747515-d7cf-4f5e-bc2a-99f7b918ff30",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:43:01.000Z",
|
|
"modified": "2018-05-24T11:43:01.000Z",
|
|
"pattern": "[url:value = 'http://catbones.com/ups.com/WebTracking/UCC-7144476318/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:43:01Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--be97cb83-10b8-4ec3-b9c9-6dabbb77c8d4",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:43:07.000Z",
|
|
"modified": "2018-05-24T11:43:07.000Z",
|
|
"pattern": "[url:value = 'http://h-itshop.de/ACCOUNT/Account-22050/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:43:07Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--0d6fd649-0fac-45a3-a39d-a60b903bb4d4",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:43:13.000Z",
|
|
"modified": "2018-05-24T11:43:13.000Z",
|
|
"pattern": "[url:value = 'http://429days.com/Bq7lgGA/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:43:13Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--6ecfe54f-cfe8-4d1e-9ba0-8e1e62665a8d",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:43:19.000Z",
|
|
"modified": "2018-05-24T11:43:19.000Z",
|
|
"pattern": "[url:value = 'http://hajdamowicz.com/I4UZR/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:43:19Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--ab5bfdb3-575f-4934-964e-d779297e49e5",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:43:25.000Z",
|
|
"modified": "2018-05-24T11:43:25.000Z",
|
|
"pattern": "[url:value = 'http://ahrensgrabenhorst.de/32bzspb/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:43:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--cc28f33c-ccdb-4d47-bda9-563ef8ba4709",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:43:31.000Z",
|
|
"modified": "2018-05-24T11:43:31.000Z",
|
|
"pattern": "[url:value = 'http://andrescal.com.ar/Xn9z/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:43:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--e7967451-e224-498e-a14d-ad06a75ff309",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:43:37.000Z",
|
|
"modified": "2018-05-24T11:43:37.000Z",
|
|
"pattern": "[url:value = 'http://imagesbr.com/nW3HM/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:43:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--b752609e-c9c0-4d0a-b413-c12b96bcdc32",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:43:49.000Z",
|
|
"modified": "2018-05-24T11:43:49.000Z",
|
|
"pattern": "[url:value = 'http://hisociety.at/Factura-7824771/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:43:49Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--e60e390c-443e-4f82-905e-d2e26731e1e3",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:43:55.000Z",
|
|
"modified": "2018-05-24T11:43:55.000Z",
|
|
"pattern": "[url:value = 'http://jana-spreen.de/Correcciones/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:43:55Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--fb08b5fc-ba38-4453-90b9-58c56fc478b1",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:44:01.000Z",
|
|
"modified": "2018-05-24T11:44:01.000Z",
|
|
"pattern": "[url:value = 'http://gerbrecha.com/Facturas-disponibles/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:44:01Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--b60ade76-7574-4389-b3ed-c42a475b475a",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:44:07.000Z",
|
|
"modified": "2018-05-24T11:44:07.000Z",
|
|
"pattern": "[url:value = 'https://fotofolly.com/Factura-Correcciones-para-896674/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:44:07Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--8b95983d-9a6a-4934-9490-036eea3c223d",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:44:13.000Z",
|
|
"modified": "2018-05-24T11:44:13.000Z",
|
|
"pattern": "[url:value = 'http://fantastrick.nl/Paid-Invoice/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:44:13Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--c8235eba-5062-4bb4-beb3-38601926a83c",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:44:19.000Z",
|
|
"modified": "2018-05-24T11:44:19.000Z",
|
|
"pattern": "[url:value = 'http://www.toniruy.ru/Factura-por-descargas/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:44:19Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--d6771a70-2191-4198-852b-3be9071daa00",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:44:25.000Z",
|
|
"modified": "2018-05-24T11:44:25.000Z",
|
|
"pattern": "[url:value = 'http://keithdaley.co.uk/wpp-app/Abierto-Pasado-Vencimiento-Pedidos/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:44:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--eafa06a4-c2d4-48bc-b91f-b93ef03a14aa",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:44:31.000Z",
|
|
"modified": "2018-05-24T11:44:31.000Z",
|
|
"pattern": "[url:value = 'http://groupevl.ca/1-Pasado-Debida-Facturas/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:44:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--f5ac55d0-66e7-4e27-8db5-3b45a82eebeb",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:44:37.000Z",
|
|
"modified": "2018-05-24T11:44:37.000Z",
|
|
"pattern": "[url:value = 'http://bunt.com/classifieds/session/Invoice-form/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:44:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--f6387846-5e79-47b0-83fb-80ecbd64bfcd",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:44:43.000Z",
|
|
"modified": "2018-05-24T11:44:43.000Z",
|
|
"pattern": "[url:value = 'http://heathmarshallhorsemanship.com/Nueva-Factura/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:44:43Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--b48d8997-b832-4ee6-a803-cfe2c1dd0709",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:44:49.000Z",
|
|
"modified": "2018-05-24T11:44:49.000Z",
|
|
"pattern": "[url:value = 'http://generalbikes.com/factura-recibo/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:44:49Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--b677b3e6-4841-498e-814b-655650e0ba53",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:44:55.000Z",
|
|
"modified": "2018-05-24T11:44:55.000Z",
|
|
"pattern": "[url:value = 'http://larrysmith.com/Scan-40567/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:44:55Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--790d3d60-0642-40c5-8556-3b4e49778a5f",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:45:01.000Z",
|
|
"modified": "2018-05-24T11:45:01.000Z",
|
|
"pattern": "[url:value = 'http://labmat.pl/Resumen-de-estados-de-cuenta/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:45:01Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--d33085f4-4a53-4fbe-959e-fa3961958b43",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:45:07.000Z",
|
|
"modified": "2018-05-24T11:45:07.000Z",
|
|
"pattern": "[url:value = 'http://kunkel5.com/aspnet_client/Factura-por-descargas/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:45:07Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--7dc82997-0eae-401c-bb6f-4e069c0e47a9",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:45:13.000Z",
|
|
"modified": "2018-05-24T11:45:13.000Z",
|
|
"pattern": "[url:value = 'http://flewer.pl/klasy/recordatorio/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:45:13Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--433df490-8552-4a9e-8544-d7680fa5a501",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:45:19.000Z",
|
|
"modified": "2018-05-24T11:45:19.000Z",
|
|
"pattern": "[url:value = 'http://halcak.sk/Scan-35311/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:45:19Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--bff9ccc9-44a4-4fae-a32b-88cc406d0778",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:45:25.000Z",
|
|
"modified": "2018-05-24T11:45:25.000Z",
|
|
"pattern": "[url:value = 'http://hygienic.co.th/components/Factura-Correcciones-para-552587/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:45:25Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--38de46aa-5c29-48b0-b203-c285f45d8714",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:45:31.000Z",
|
|
"modified": "2018-05-24T11:45:31.000Z",
|
|
"pattern": "[url:value = 'http://data-gel.com/Service-Inv/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:45:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--e00fbf0e-f840-4c0e-8003-ab3ad1f34074",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:45:38.000Z",
|
|
"modified": "2018-05-24T11:45:38.000Z",
|
|
"pattern": "[url:value = 'http://aqualuna.jp/Invoice-attached/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:45:38Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--45a0ef00-04ad-45a5-a244-545a76f93693",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:45:44.000Z",
|
|
"modified": "2018-05-24T11:45:44.000Z",
|
|
"pattern": "[url:value = 'http://dievoigts.com/Invoice-attached/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:45:44Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--41e28f2e-a661-442c-a53e-acc235d250db",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:45:50.000Z",
|
|
"modified": "2018-05-24T11:45:50.000Z",
|
|
"pattern": "[url:value = 'https://chergo.es/Outstanding-Invoices/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:45:50Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--4f6a8260-731e-4e5a-8430-8308a93c7530",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:45:56.000Z",
|
|
"modified": "2018-05-24T11:45:56.000Z",
|
|
"pattern": "[url:value = 'http://chergo.es/Outstanding-Invoices/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:45:56Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--454a387c-f39d-4a6e-a225-e0ab846f30e5",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:46:02.000Z",
|
|
"modified": "2018-05-24T11:46:02.000Z",
|
|
"pattern": "[url:value = 'http://contactclub.com/Facturas-pendientes/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:46:02Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--644f4699-a1df-4db5-b69b-1621c122a406",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:46:08.000Z",
|
|
"modified": "2018-05-24T11:46:08.000Z",
|
|
"pattern": "[url:value = 'http://fotofolly.com/Factura-Correcciones-para-896674/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:46:08Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--b49bed1d-4cd6-450c-9ea2-ea1ab71614c1",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:46:14.000Z",
|
|
"modified": "2018-05-24T11:46:14.000Z",
|
|
"pattern": "[url:value = 'http://casamatamatera.it/0Vqt4/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:46:14Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--eaa9dd10-68c6-48b3-8806-0616398970e5",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:46:20.000Z",
|
|
"modified": "2018-05-24T11:46:20.000Z",
|
|
"pattern": "[url:value = 'http://intenseit.com.au/grQ97kNdN/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:46:20Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--c72f02cc-7da2-4c7c-bd0c-7c4e6bdfbd5e",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:46:26.000Z",
|
|
"modified": "2018-05-24T11:46:26.000Z",
|
|
"pattern": "[url:value = 'http://gsimaging.net/nIzqr7q7e/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:46:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--7ac3b791-8acc-4f61-be79-ef3cab1ad3be",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:46:32.000Z",
|
|
"modified": "2018-05-24T11:46:32.000Z",
|
|
"pattern": "[url:value = 'http://jvmusic.ca/VDTkN/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:46:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--af7c7b13-716a-4850-9d79-043d27ebd747",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:46:39.000Z",
|
|
"modified": "2018-05-24T11:46:39.000Z",
|
|
"pattern": "[url:value = 'http://websteroids.ro/W0Xul1jAj/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:46:39Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--313b9f36-c656-46fe-8847-5eb6b2b69793",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:46:51.000Z",
|
|
"modified": "2018-05-24T11:46:51.000Z",
|
|
"pattern": "[url:value = 'http://solid-unit.com/DOC/Invoice-60094596-Invoice-date-052118-Order-no-3911666675/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:46:51Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--5f45baf4-0152-465e-a879-a15ef9979c71",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:46:57.000Z",
|
|
"modified": "2018-05-24T11:46:57.000Z",
|
|
"pattern": "[url:value = 'http://charihome.com/Client/Invoice/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:46:57Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--5518616e-3305-45db-9c3b-d27567c99810",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:47:14.000Z",
|
|
"modified": "2018-05-24T11:47:14.000Z",
|
|
"pattern": "[url:value = 'http://gips-walkenried.de/STATUS/Invoice-93224/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:47:14Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--653a06ef-a2c9-4313-9258-6bf392a6858e",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:47:56.000Z",
|
|
"modified": "2018-05-24T11:47:56.000Z",
|
|
"pattern": "[url:value = 'http://fischer-itsolutions.de/Client/ACCOUNT080862/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:47:56Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--71f630be-cd2f-48c1-a2bc-f65fc4a2a6e0",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:48:03.000Z",
|
|
"modified": "2018-05-24T11:48:03.000Z",
|
|
"pattern": "[url:value = 'http://itmdf.de/ups.com/WebTracking/FS-17532695/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:48:03Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--4371d231-e8ff-4ac4-97d2-26f7b7e6795b",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:48:09.000Z",
|
|
"modified": "2018-05-24T11:48:09.000Z",
|
|
"pattern": "[url:value = 'http://cyzic.com/STATUS/Auditor-of-State-Notification-of-EFT-Deposit/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:48:09Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--95c3ecee-0d29-4bee-9963-27adee8927b2",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:48:15.000Z",
|
|
"modified": "2018-05-24T11:48:15.000Z",
|
|
"pattern": "[url:value = 'https://juergen-dietel.de/Client/Auditor-of-State-Notification-of-EFT-Deposit/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:48:15Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--01633a75-3ed2-4cd5-a7a8-15e340774316",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:48:22.000Z",
|
|
"modified": "2018-05-24T11:48:22.000Z",
|
|
"pattern": "[url:value = 'http://crazy-systems.com/ups.com/WebTracking/SEC-001569551712321/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:48:22Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--549143ed-734c-4efc-bd48-fdfcf7101fe7",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:48:28.000Z",
|
|
"modified": "2018-05-24T11:48:28.000Z",
|
|
"pattern": "[url:value = 'http://hellmuth-worbs.de/ups.com/WebTracking/XWM-026895014/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:48:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--98b3177c-57d8-4e5b-827c-f2787c91a5f7",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:48:34.000Z",
|
|
"modified": "2018-05-24T11:48:34.000Z",
|
|
"pattern": "[url:value = 'http://janpolet.nl/Client/Auditor-of-State-Notification-of-EFT-Deposit/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:48:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--6967fb57-57dd-4ee0-bfd7-0571dbd93e61",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:48:40.000Z",
|
|
"modified": "2018-05-24T11:48:40.000Z",
|
|
"pattern": "[url:value = 'http://bechner.com/ups.com/WebTracking/IFI-8709813039/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:48:40Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--d5c1cb2d-cfc8-4c6d-9ee9-0b4ee49ae283",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:48:46.000Z",
|
|
"modified": "2018-05-24T11:48:46.000Z",
|
|
"pattern": "[url:value = 'http://innervation.com/ups.com/WebTracking/GCV-192478446701844/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:48:46Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--b7d91d7e-a054-4083-8ef7-9feb4560e85d",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:48:52.000Z",
|
|
"modified": "2018-05-24T11:48:52.000Z",
|
|
"pattern": "[url:value = 'http://jamesddunn.com/ups.com/WebTracking/VUE-130658434680/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:48:52Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--1886ad83-17ca-4f6f-a548-e1fe2ec94225",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:48:59.000Z",
|
|
"modified": "2018-05-24T11:48:59.000Z",
|
|
"pattern": "[url:value = 'http://cedecarmona.com/ups.com/WebTracking/MOC-98465082/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:48:59Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--0c6c42f0-08b2-4ee1-aedf-27db7b605367",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:49:11.000Z",
|
|
"modified": "2018-05-24T11:49:11.000Z",
|
|
"pattern": "[url:value = 'https://ibkrentel.de/STATUS/Invoices/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:49:11Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--d8a017de-d31c-4a07-a33b-067ec99d1cff",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:49:17.000Z",
|
|
"modified": "2018-05-24T11:49:17.000Z",
|
|
"pattern": "[url:value = 'http://iyioglu.com/jKmV/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:49:17Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--8de74505-0cb9-4ea2-87b2-f6fe15ab3648",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:49:23.000Z",
|
|
"modified": "2018-05-24T11:49:23.000Z",
|
|
"pattern": "[url:value = 'http://dmsta.com/DG9zb/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:49:23Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--ef2d4f82-27fe-4cae-a725-4fbacb2add63",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:49:29.000Z",
|
|
"modified": "2018-05-24T11:49:29.000Z",
|
|
"pattern": "[url:value = 'https://averin.pro/j7oL/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:49:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--c41f0a0b-5db7-49db-bf95-f423dbffad00",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:49:35.000Z",
|
|
"modified": "2018-05-24T11:49:35.000Z",
|
|
"pattern": "[url:value = 'http://davehale.co.uk/gpRiJY/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:49:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--73ea8a7e-f9f4-49f0-9f88-4c551517b5a7",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:49:41.000Z",
|
|
"modified": "2018-05-24T11:49:41.000Z",
|
|
"pattern": "[url:value = 'http://FlorissantFire.com/aspnet_client/H068W54/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:49:41Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--d1728be1-7f44-41ad-9c9a-7f5a5117253a",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:49:47.000Z",
|
|
"modified": "2018-05-24T11:49:47.000Z",
|
|
"pattern": "[url:value = 'http://fredmeseck.com/ups.com/WebTracking/WZ-582819876301/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:49:47Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--3d521c99-2938-466e-90d2-ab7570f2ea22",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:49:53.000Z",
|
|
"modified": "2018-05-24T11:49:53.000Z",
|
|
"pattern": "[url:value = 'http://edcentric.org/ups.com/WebTracking/JG-97917329625936/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:49:53Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--00562399-5457-41c3-895a-323d3135ff0f",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:50:15.000Z",
|
|
"modified": "2018-05-24T11:50:15.000Z",
|
|
"pattern": "[url:value = 'http://anzo.jp/Client/Invoice-05-21-18/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:50:15Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--4b81dfbc-379b-4b25-91a6-96e164ed03be",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:50:21.000Z",
|
|
"modified": "2018-05-24T11:50:21.000Z",
|
|
"pattern": "[url:value = 'http://ezinet.co.za/ACCOUNT/invoice/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:50:21Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--e468770f-a550-4d81-9391-d99d5b703e95",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:50:28.000Z",
|
|
"modified": "2018-05-24T11:50:28.000Z",
|
|
"pattern": "[url:value = 'http://detss.com/Client/INV55295737106080394160/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:50:28Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--6c737cdc-7baa-466f-8f23-8d17458b282a",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:50:34.000Z",
|
|
"modified": "2018-05-24T11:50:34.000Z",
|
|
"pattern": "[url:value = 'http://jeny.nl/ups.com/WebTracking/IHC-095131093/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:50:34Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--91d464bc-94b6-4cab-9e7a-35b5b8d1618f",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:50:46.000Z",
|
|
"modified": "2018-05-24T11:50:46.000Z",
|
|
"pattern": "[url:value = 'http://jeffarchibald.ca/FILE/Invoice-14477606-Invoice-date-052118-Order-no-3568026653/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:50:46Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--d0324ad1-f9ea-4469-8be5-96edf53b383b",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:50:53.000Z",
|
|
"modified": "2018-05-24T11:50:53.000Z",
|
|
"pattern": "[url:value = 'https://frankfurter-blumenbote.de/fbb2015/ups.com/WebTracking/VVP-8825990635/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:50:53Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--c71e2259-1dd5-4352-bbd8-c249c16fce1f",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:50:59.000Z",
|
|
"modified": "2018-05-24T11:50:59.000Z",
|
|
"pattern": "[url:value = 'http://homexxl.de/images/supplier/ups.com/WebTracking/ZQW-768705390/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:50:59Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--64301f39-148a-4686-bc42-65f3346fb12a",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:51:11.000Z",
|
|
"modified": "2018-05-24T11:51:11.000Z",
|
|
"pattern": "[url:value = 'http://czeppel.de/FILE/New-Invoice-FY2348-TA-5179/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:51:11Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--a3f3d972-e413-413a-b0bc-d9cc4d6586d8",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:51:17.000Z",
|
|
"modified": "2018-05-24T11:51:17.000Z",
|
|
"pattern": "[url:value = 'http://bmsdesign.com/Client/Payment/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:51:17Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--03874d17-b879-45e7-9b1e-9b0850877fed",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:51:23.000Z",
|
|
"modified": "2018-05-24T11:51:23.000Z",
|
|
"pattern": "[url:value = 'https://hillringsberg.com/ups.com/WebTracking/NT-98643761/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:51:23Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--104f8d93-8647-48b8-8d4a-2b07902692c9",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:51:29.000Z",
|
|
"modified": "2018-05-24T11:51:29.000Z",
|
|
"pattern": "[url:value = 'http://josephdutton.com/ACCOUNT/Invoice/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:51:29Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--ac1fcec6-873b-4ec9-8910-189302b31619",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:51:42.000Z",
|
|
"modified": "2018-05-24T11:51:42.000Z",
|
|
"pattern": "[url:value = 'http://klumpp.me/DOC/Emailing-P161122EO-013518/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:51:42Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--21b312e7-9117-4186-a0dc-55af77e5ac23",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:51:54.000Z",
|
|
"modified": "2018-05-24T11:51:54.000Z",
|
|
"pattern": "[url:value = 'http://ergotherapie-gerolstein.de/ups.com/WebTracking/KGE-08714359596985/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:51:54Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--e70ec94e-21fc-42cd-bbe5-6578370de835",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:52:00.000Z",
|
|
"modified": "2018-05-24T11:52:00.000Z",
|
|
"pattern": "[url:value = 'http://kursy-bhp-sieradz.pl/pub/DOC/Invoice-313081/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:52:00Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--31913ef8-8981-4464-abdc-e82d0e4bd2e0",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:52:18.000Z",
|
|
"modified": "2018-05-24T11:52:18.000Z",
|
|
"pattern": "[url:value = 'http://animematsuri.com/ups.com/WebTracking/JX-63349309/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:52:18Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--8ca846c4-42c9-401a-bddf-d56c38634b65",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:52:31.000Z",
|
|
"modified": "2018-05-24T11:52:31.000Z",
|
|
"pattern": "[url:value = 'http://lambertons.com/FILE/New-Invoice-ZK99463-GJ-56124/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:52:31Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--a5beb3ed-267e-47a4-b099-c68a435abc0d",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:52:43.000Z",
|
|
"modified": "2018-05-24T11:52:43.000Z",
|
|
"pattern": "[url:value = 'http://coromandelhistory.co.nz/DOC/Direct-Deposit-Notice/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:52:43Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--f360f8f5-4134-46d4-a459-721b92f8abe0",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:53:07.000Z",
|
|
"modified": "2018-05-24T11:53:07.000Z",
|
|
"pattern": "[url:value = 'http://kevinlombardo.com/3FB22/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:53:07Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--0cbe40e0-f08e-4486-84bf-27e5aa38c217",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:53:13.000Z",
|
|
"modified": "2018-05-24T11:53:13.000Z",
|
|
"pattern": "[url:value = 'http://cabola.com.br/a2VA4q9/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:53:13Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--cffb6f51-ec66-4cfc-ae6d-2e05bb2338a9",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:53:19.000Z",
|
|
"modified": "2018-05-24T11:53:19.000Z",
|
|
"pattern": "[url:value = 'http://k8ir.com/xOpouO/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:53:19Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--2ffd9ebc-3f1f-4252-8021-8d6c7bf39a7f",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:53:26.000Z",
|
|
"modified": "2018-05-24T11:53:26.000Z",
|
|
"pattern": "[url:value = 'http://franssmanmedia.nl/BdRXyt/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:53:26Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--03c2db94-a978-49d7-a27b-f9f71684b8a9",
|
|
"created_by_ref": "identity--5a68c02d-959c-4c8a-a571-0dcac0a8060a",
|
|
"created": "2018-05-24T11:53:32.000Z",
|
|
"modified": "2018-05-24T11:53:32.000Z",
|
|
"pattern": "[url:value = 'http://chris-dark.com/lGGPjL/']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2018-05-24T11:53:32Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "marking-definition",
|
|
"spec_version": "2.1",
|
|
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
|
|
"created": "2017-01-20T00:00:00.000Z",
|
|
"definition_type": "tlp",
|
|
"name": "TLP:WHITE",
|
|
"definition": {
|
|
"tlp": "white"
|
|
}
|
|
}
|
|
]
|
|
} |