Files

1682 lines
148 KiB
XML
Raw Permalink Normal View History

<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:="https://rufus.citlab.utoronto.ca"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-7cef25ee-341b-4d14-a63b-2af874baade1" version="1.1.1" timestamp="2016-11-16T20:25:14.935544+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-5820aa49-6a40-4e51-86f9-497a8e96ca05" version="1.1.1" timestamp="2016-11-16T15:02:43+00:00">
<stix:STIX_Header>
<stix:Title>Its Parliamentary: KeyBoy and the targeting of the Tibetan Community (MISP Event #17)</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:TTPs>
<stix:TTP id=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload delivery: CVE-2012-0158 (MISP Attribute #811)</ttp:Title>
<ttp:Description>8307e444cad98b1b59568ad2eba5f201</ttp:Description>
<ttp:Exploit_Targets>
<ttp:Exploit_Target>
<stixCommon:Exploit_Target id=":et-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='et:ExploitTargetType'>
<et:Title>8307e444cad98b1b59568ad2eba5f201</et:Title>
<et:Vulnerability>
<et:CVE_ID>CVE-2012-0158</et:CVE_ID>
</et:Vulnerability>
</stixCommon:Exploit_Target>
</ttp:Exploit_Target>
</ttp:Exploit_Targets>
</stix:TTP>
<stix:TTP id=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload delivery: CVE-2014-4114 (MISP Attribute #832)</ttp:Title>
<ttp:Exploit_Targets>
<ttp:Exploit_Target>
<stixCommon:Exploit_Target id=":et-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='et:ExploitTargetType'>
<et:Title>Vulnerability CVE-2014-4114</et:Title>
<et:Vulnerability>
<et:CVE_ID>CVE-2014-4114</et:CVE_ID>
</et:Vulnerability>
</stixCommon:Exploit_Target>
</ttp:Exploit_Target>
</ttp:Exploit_Targets>
</stix:TTP>
<stix:TTP id=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload delivery: CVE-2015-1641 (MISP Attribute #1374)</ttp:Title>
<ttp:Exploit_Targets>
<ttp:Exploit_Target>
<stixCommon:Exploit_Target id=":et-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='et:ExploitTargetType'>
<et:Title>Vulnerability CVE-2015-1641</et:Title>
<et:Vulnerability>
<et:CVE_ID>CVE-2015-1641</et:CVE_ID>
</et:Vulnerability>
</stixCommon:Exploit_Target>
</ttp:Exploit_Target>
</ttp:Exploit_Targets>
</stix:TTP>
<stix:TTP id=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload type: KeyBoy (MISP Attribute #809)</ttp:Title>
<ttp:Behavior>
<ttp:Malware>
<ttp:Malware_Instance>
<ttp:Name>KeyBoy</ttp:Name>
</ttp:Malware_Instance>
</ttp:Malware>
</ttp:Behavior>
</stix:TTP>
</stix:TTPs>
<stix:Incidents>
<stix:Incident id=":incident-5820aa49-6a40-4e51-86f9-497a8e96ca05" timestamp="2016-11-16T15:02:57+00:00" xsi:type='incident:IncidentType'>
<incident:Title>Its Parliamentary: KeyBoy and the targeting of the Tibetan Community</incident:Title>
<incident:External_ID source="MISP Event">17</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2016-11-07T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2016-11-16T15:02:57+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">Open</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ab69-8e78-4925-8f07-497a8e96ca05" timestamp="2016-11-07T11:27:21+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 8f08609e4e0b3d26814b3073a42df415 (MISP Attribute #813)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 8f08609e4e0b3d26814b3073a42df415 (MISP Attribute #813)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ab69-8e78-4925-8f07-497a8e96ca05">
<cybox:Object id=":File-5820ab69-8e78-4925-8f07-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">8f08609e4e0b3d26814b3073a42df415</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:27:21+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ab7b-5a8c-4164-8113-49798e96ca05" timestamp="2016-11-07T11:37:43+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 495adb1b9777002ecfe22aaf52fcee93 (MISP Attribute #814)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 495adb1b9777002ecfe22aaf52fcee93 (MISP Attribute #814)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ab7b-5a8c-4164-8113-49798e96ca05">
<cybox:Object id=":File-5820ab7b-5a8c-4164-8113-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">495adb1b9777002ecfe22aaf52fcee93</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:37:43+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac1b-05c0-4d60-8fc5-497a8e96ca05" timestamp="2016-11-07T11:33:10+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 0c7e55509e0b6d4277b3facf864af018 (MISP Attribute #822)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 0c7e55509e0b6d4277b3facf864af018 (MISP Attribute #822)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac1b-05c0-4d60-8fc5-497a8e96ca05">
<cybox:Object id=":File-5820ac1b-05c0-4d60-8fc5-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">0c7e55509e0b6d4277b3facf864af018</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:33:10+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac71-ff98-486d-b2e6-49798e96ca05" timestamp="2016-11-07T11:32:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 98977426d544bd145979f65f0322ae30 (MISP Attribute #827)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 98977426d544bd145979f65f0322ae30 (MISP Attribute #827)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac71-ff98-486d-b2e6-49798e96ca05">
<cybox:Object id=":File-5820ac71-ff98-486d-b2e6-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">98977426d544bd145979f65f0322ae30</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:32:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ad9c-c3c4-455e-a5f2-497a8e96ca05" timestamp="2016-11-07T11:36:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: c5b5f01ba24d6c02636388809f44472e (MISP Attribute #833)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: c5b5f01ba24d6c02636388809f44472e (MISP Attribute #833)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ad9c-c3c4-455e-a5f2-497a8e96ca05">
<cybox:Object id=":File-5820ad9c-c3c4-455e-a5f2-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">c5b5f01ba24d6c02636388809f44472e</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:36:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820adb2-5520-499c-95d3-49798e96ca05" timestamp="2016-11-07T11:37:06+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 371bc132499f455f06fa80696db0df27 (MISP Attribute #834)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 371bc132499f455f06fa80696db0df27 (MISP Attribute #834)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820adb2-5520-499c-95d3-49798e96ca05">
<cybox:Object id=":File-5820adb2-5520-499c-95d3-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">371bc132499f455f06fa80696db0df27</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:37:06+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58239987-0038-44ba-997f-49798e96ca05" timestamp="2016-11-09T16:47:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 087bffa8a570079948310dc9731c5709 (MISP Attribute #1372)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 087bffa8a570079948310dc9731c5709 (MISP Attribute #1372)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58239987-0038-44ba-997f-49798e96ca05">
<cybox:Object id=":File-58239987-0038-44ba-997f-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">087bffa8a570079948310dc9731c5709</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T16:47:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58235402-9d54-437c-b845-69fe8e96ca05" timestamp="2016-11-16T11:56:27+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ver (MISP Attribute #1365)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Host Characteristics</indicator:Type>
<indicator:Description>Artifacts dropped: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ver (MISP Attribute #1365)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58235402-9d54-437c-b845-69fe8e96ca05">
<cybox:Object id=":WinRegistryKey-58235402-9d54-437c-b845-69fe8e96ca05">
<cybox:Properties xsi:type="WinRegistryKeyObj:WindowsRegistryKeyObjectType">
<WinRegistryKeyObj:Key condition="Equals">Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ver</WinRegistryKeyObj:Key>
<WinRegistryKeyObj:Hive condition="Equals">HKEY_CURRENT_USER</WinRegistryKeyObj:Hive>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-16T11:56:27+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582398b8-c1b4-418a-8fe7-49798e96ca05" timestamp="2016-11-09T16:44:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 58105e9772f6befbc319c147a97faded4fbacf839947b34fe3695ae72771da5d (MISP Attribute #1368)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 58105e9772f6befbc319c147a97faded4fbacf839947b34fe3695ae72771da5d (MISP Attribute #1368)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582398b8-c1b4-418a-8fe7-49798e96ca05">
<cybox:Object id=":File-582398b8-c1b4-418a-8fe7-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">58105e9772f6befbc319c147a97faded4fbacf839947b34fe3695ae72771da5d</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T16:44:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582398da-78c0-47ed-8bb9-49798e96ca05" timestamp="2016-11-09T16:44:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 9a55577d357922711ab0821bf5379289293c8517ae1d94d48c389f306af57a04 (MISP Attribute #1369)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 9a55577d357922711ab0821bf5379289293c8517ae1d94d48c389f306af57a04 (MISP Attribute #1369)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582398da-78c0-47ed-8bb9-49798e96ca05">
<cybox:Object id=":File-582398da-78c0-47ed-8bb9-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">9a55577d357922711ab0821bf5379289293c8517ae1d94d48c389f306af57a04</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T16:44:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582399a3-04f8-4542-b205-49798e96ca05" timestamp="2016-11-09T16:48:19+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 5da2f14c382d7cac8dfa6c86e528a646a81f0b40cfee9611c8cfb4b5d589aa88 (MISP Attribute #1373)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 5da2f14c382d7cac8dfa6c86e528a646a81f0b40cfee9611c8cfb4b5d589aa88 (MISP Attribute #1373)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582399a3-04f8-4542-b205-49798e96ca05">
<cybox:Object id=":File-582399a3-04f8-4542-b205-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">5da2f14c382d7cac8dfa6c86e528a646a81f0b40cfee9611c8cfb4b5d589aa88</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T16:48:19+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820aba7-e398-41cb-939b-49798e96ca05" timestamp="2016-11-07T11:28:23+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: tibetvoices.com (MISP Attribute #817)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: tibetvoices.com (MISP Attribute #817)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820aba7-e398-41cb-939b-49798e96ca05">
<cybox:Object id=":DomainName-5820aba7-e398-41cb-939b-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">tibetvoices.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:28:23+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac33-aa80-4d97-99a2-49798e96ca05" timestamp="2016-11-07T11:35:42+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.about.jkub.com (MISP Attribute #823)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.about.jkub.com (MISP Attribute #823)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac33-aa80-4d97-99a2-49798e96ca05">
<cybox:Object id=":DomainName-5820ac33-aa80-4d97-99a2-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.about.jkub.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:35:42+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac33-586c-4674-b96d-49798e96ca05" timestamp="2016-11-16T12:10:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.eleven.mypop3.org (MISP Attribute #824)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.eleven.mypop3.org (MISP Attribute #824)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac33-586c-4674-b96d-49798e96ca05">
<cybox:Object id=":DomainName-5820ac33-586c-4674-b96d-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.eleven.mypop3.org</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-16T12:10:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac34-dfc4-4772-8fb6-49798e96ca05" timestamp="2016-11-16T12:10:21+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.backus.myftp.name (MISP Attribute #825)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.backus.myftp.name (MISP Attribute #825)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac34-dfc4-4772-8fb6-49798e96ca05">
<cybox:Object id=":DomainName-5820ac34-dfc4-4772-8fb6-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.backus.myftp.name</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-16T12:10:21+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ab93-ca00-4627-a8e9-497a8e96ca05" timestamp="2016-11-10T12:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 45.125.12.147 (MISP Attribute #815)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 45.125.12.147 (MISP Attribute #815)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ab93-ca00-4627-a8e9-497a8e96ca05">
<cybox:Object id=":Address-5820ab93-ca00-4627-a8e9-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">45.125.12.147</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T12:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ab93-8b90-4f61-8591-497a8e96ca05" timestamp="2016-11-16T11:56:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 103.40.102.233 (MISP Attribute #816)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 103.40.102.233 (MISP Attribute #816)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ab93-8b90-4f61-8591-497a8e96ca05">
<cybox:Object id=":Address-5820ab93-8b90-4f61-8591-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">103.40.102.233</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-16T11:56:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820abec-8b88-4398-ba31-497a8e96ca05" timestamp="2016-11-07T11:29:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 116.193.154.69 (MISP Attribute #820)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 116.193.154.69 (MISP Attribute #820)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820abec-8b88-4398-ba31-497a8e96ca05">
<cybox:Object id=":Address-5820abec-8b88-4398-ba31-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">116.193.154.69</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:29:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac98-f508-4869-9701-497a8e96ca05" timestamp="2016-11-16T15:02:43+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 103.242.134.243 (MISP Attribute #828)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 103.242.134.243 (MISP Attribute #828)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac98-f508-4869-9701-497a8e96ca05">
<cybox:Object id=":Address-5820ac98-f508-4869-9701-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">103.242.134.243</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-16T15:02:43+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ad1d-a7c0-4f84-9d29-497a8e96ca05" timestamp="2016-11-07T11:35:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 45.32.47.148 (MISP Attribute #829)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 45.32.47.148 (MISP Attribute #829)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ad1d-a7c0-4f84-9d29-497a8e96ca05">
<cybox:Object id=":Address-5820ad1d-a7c0-4f84-9d29-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">45.32.47.148</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:35:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ad1d-5d34-489f-97b8-497a8e96ca05" timestamp="2016-11-07T11:35:48+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 157.7.84.81 (MISP Attribute #830)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 157.7.84.81 (MISP Attribute #830)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ad1d-5d34-489f-97b8-497a8e96ca05">
<cybox:Object id=":Address-5820ad1d-5d34-489f-97b8-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">157.7.84.81</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:35:48+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ad50-de2c-4f26-bd5c-497a8e96ca05" timestamp="2016-11-07T11:35:28+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 192.241.149.43 (MISP Attribute #831)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 192.241.149.43 (MISP Attribute #831)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ad50-de2c-4f26-bd5c-497a8e96ca05">
<cybox:Object id=":Address-5820ad50-de2c-4f26-bd5c-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">192.241.149.43</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:35:28+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582c9016-1a1c-471e-890f-69fe8e96ca05" timestamp="2016-11-16T11:57:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 112.10.117.47 (MISP Attribute #1880)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 112.10.117.47 (MISP Attribute #1880)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582c9016-1a1c-471e-890f-69fe8e96ca05">
<cybox:Object id=":Address-582c9016-1a1c-471e-890f-69fe8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">112.10.117.47</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-16T11:57:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58238a80-e5bc-449f-9440-497a8e96ca05" timestamp="2016-11-09T15:43:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: tibetanparliarnent@yahoo.com (MISP Attribute #1366)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: tibetanparliarnent@yahoo.com (MISP Attribute #1366)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58238a80-e5bc-449f-9440-497a8e96ca05">
<cybox:Object id=":EmailMessage-58238a80-e5bc-449f-9440-497a8e96ca05">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">tibetanparliarnent@yahoo.com</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T15:43:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820aafa-d53c-4131-8582-497a8e96ca05" timestamp="2016-11-07T11:25:30+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 8307e444cad98b1b59568ad2eba5f201 (MISP Attribute #810)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 8307e444cad98b1b59568ad2eba5f201 (MISP Attribute #810)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820aafa-d53c-4131-8582-497a8e96ca05">
<cybox:Object id=":File-5820aafa-d53c-4131-8582-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">8307e444cad98b1b59568ad2eba5f201</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:25:30+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ab43-0ce0-46a9-bc84-49798e96ca05" timestamp="2016-11-07T11:26:43+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 0b4d45db323f68b465ae052d3a872068 (MISP Attribute #812)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 0b4d45db323f68b465ae052d3a872068 (MISP Attribute #812)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ab43-0ce0-46a9-bc84-49798e96ca05">
<cybox:Object id=":File-5820ab43-0ce0-46a9-bc84-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">0b4d45db323f68b465ae052d3a872068</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:26:43+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820abc0-979c-4a84-8800-497a8e96ca05" timestamp="2016-11-07T11:28:48+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: beadf21b923600554b0ce54df42e78f5 (MISP Attribute #818)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: beadf21b923600554b0ce54df42e78f5 (MISP Attribute #818)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820abc0-979c-4a84-8800-497a8e96ca05">
<cybox:Object id=":File-5820abc0-979c-4a84-8800-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">beadf21b923600554b0ce54df42e78f5</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:28:48+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820abd0-acb8-474a-bbf0-49798e96ca05" timestamp="2016-11-07T11:29:04+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 69df3d3df4d99bc6045d073d89c68697 (MISP Attribute #819)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 69df3d3df4d99bc6045d073d89c68697 (MISP Attribute #819)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820abd0-acb8-474a-bbf0-49798e96ca05">
<cybox:Object id=":File-5820abd0-acb8-474a-bbf0-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">69df3d3df4d99bc6045d073d89c68697</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:29:04+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac07-868c-41f0-85c2-49798e96ca05" timestamp="2016-11-07T11:29:59+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 05b5cf94f07fee666eb086c91182ad25 (MISP Attribute #821)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 05b5cf94f07fee666eb086c91182ad25 (MISP Attribute #821)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac07-868c-41f0-85c2-49798e96ca05">
<cybox:Object id=":File-5820ac07-868c-41f0-85c2-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">05b5cf94f07fee666eb086c91182ad25</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:29:59+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac58-8a88-4011-b491-497a8e96ca05" timestamp="2016-11-07T11:31:20+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 8846d109b457a2ee44ddbf54d1cf7944 (MISP Attribute #826)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 8846d109b457a2ee44ddbf54d1cf7944 (MISP Attribute #826)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac58-8a88-4011-b491-497a8e96ca05">
<cybox:Object id=":File-5820ac58-8a88-4011-b491-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">8846d109b457a2ee44ddbf54d1cf7944</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:31:20+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582c8ecf-e830-4d88-bbda-497a8e96ca05" timestamp="2016-11-16T11:52:31+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 913b82ff8f090670fc6387e3a7bea12d (MISP Attribute #1879)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 913b82ff8f090670fc6387e3a7bea12d (MISP Attribute #1879)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582c8ecf-e830-4d88-bbda-497a8e96ca05">
<cybox:Object id=":File-582c8ecf-e830-4d88-bbda-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">913b82ff8f090670fc6387e3a7bea12d</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-16T11:52:31+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5823990b-db7c-45c9-9afb-69fe8e96ca05" timestamp="2016-11-09T16:46:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 23d284245e53ae4fe05c517d807ffccf (MISP Attribute #1370)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 23d284245e53ae4fe05c517d807ffccf (MISP Attribute #1370)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5823990b-db7c-45c9-9afb-69fe8e96ca05">
<cybox:Object id=":File-5823990b-db7c-45c9-9afb-69fe8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">23d284245e53ae4fe05c517d807ffccf</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T16:46:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5823989b-68f0-4831-b1d8-49798e96ca05" timestamp="2016-11-09T16:43:55+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 5f24a5ee9ecfd4a8e5f967ffcf24580a83942cd7b09d310b9525962ed2614a49 (MISP Attribute #1367)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 5f24a5ee9ecfd4a8e5f967ffcf24580a83942cd7b09d310b9525962ed2614a49 (MISP Attribute #1367)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5823989b-68f0-4831-b1d8-49798e96ca05">
<cybox:Object id=":File-5823989b-68f0-4831-b1d8-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">5f24a5ee9ecfd4a8e5f967ffcf24580a83942cd7b09d310b9525962ed2614a49</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T16:43:55+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5823995f-701c-4616-84f5-49798e96ca05" timestamp="2016-11-09T16:47:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 542c85fda8df8510c1b66a122e459aac8c0919f1fe9fa2c43fd87899cffa05bf (MISP Attribute #1371)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 542c85fda8df8510c1b66a122e459aac8c0919f1fe9fa2c43fd87899cffa05bf (MISP Attribute #1371)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5823995f-701c-4616-84f5-49798e96ca05">
<cybox:Object id=":File-5823995f-701c-4616-84f5-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">542c85fda8df8510c1b66a122e459aac8c0919f1fe9fa2c43fd87899cffa05bf</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T16:47:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:Leveraged_TTPs>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload type</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
</incident:Leveraged_TTPs>
<incident:History>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">Event Threat Level: Medium</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TLP:AMBER</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: SOURCE:CITIZENLAB</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: NOTPUBLISHED</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: DETECT</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TARGET:TIBETAN</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: import "pe"
rule new_keyboy_export
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the new 2016 sample's export"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize &lt; 200KB and
//The malware family seems to share many exports
//but this is the new kid on the block.
pe.exports("cfsUpdate")
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule new_keyboy_header_codes
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the 2016 sample's header codes"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
strings:
$s1 = "*l*" wide fullword
$s2 = "*a*" wide fullword
$s3 = "*s*" wide fullword
$s4 = "*d*" wide fullword
$s5 = "*f*" wide fullword
$s6 = "*g*" wide fullword
$s7 = "*h*" wide fullword
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize &lt; 200KB and
all of them
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule keyboy_commands
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the 2016 sample's sent and received commands"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
strings:
$s1 = "Update" wide fullword
$s2 = "UpdateAndRun" wide fullword
$s3 = "Refresh" wide fullword
$s4 = "OnLine" wide fullword
$s5 = "Disconnect" wide fullword
$s6 = "Pw_Error" wide fullword
$s7 = "Pw_OK" wide fullword
$s8 = "Sysinfo" wide fullword
$s9 = "Download" wide fullword
$s10 = "UploadFileOk" wide fullword
$s11 = "RemoteRun" wide fullword
$s12 = "FileManager" wide fullword
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize &lt; 200KB and
6 of them
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule keyboy_errors
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the sample's shell error2 log statements"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
strings:
//These strings are in ASCII pre-2015 and UNICODE in 2016
$error = "Error2" ascii wide
//2016 specific:
$s1 = "Can't find [%s]!Check the file name and try again!" ascii wide
$s2 = "Open [%s] error! %d" ascii wide
$s3 = "The Size of [%s] is zero!" ascii wide
$s4 = "CreateThread DownloadFile[%s] Error!" ascii wide
$s5 = "UploadFile [%s] Error:Connect Server Failed!" ascii wide
$s6 = "Receive [%s] Error(Recved[%d] != Send[%d])!" ascii wide
$s7 = "Receive [%s] ok! Use %2.2f seconds, Average speed %2.2f k/s" ascii wide
$s8 = "CreateThread UploadFile[%s] Error!" ascii wide
//Pre-2016:
$s9 = "Ready Download [%s] ok!" ascii wide
$s10 = "Get ControlInfo from FileClient error!" ascii wide
$s11 = "FileClient has a error!" ascii wide
$s12 = "VirtualAlloc SendBuff Error(%d)" ascii wide
$s13 = "ReadFile [%s] Error(%d)..." ascii wide
$s14 = "ReadFile [%s] Data[Readed(%d) != FileSize(%d)] Error..." ascii wide
$s15 = "CreateThread DownloadFile[%s] Error!" ascii wide
$s16 = "RecvData MyRecv_Info Size Error!" ascii wide
$s17 = "RecvData MyRecv_Info Tag Error!" ascii wide
$s18 = "SendData szControlInfo_1 Error!" ascii wide
$s19 = "SendData szControlInfo_3 Error!" ascii wide
$s20 = "VirtualAlloc RecvBuff Error(%d)" ascii wide
$s21 = "RecvData Error!" ascii wide
$s22 = "WriteFile [%s} Error(%d)..." ascii wide
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize &lt; 200KB and
$error and 3 of ($s*)
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule keyboy_systeminfo
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the system information format before sending to C2"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
strings:
//These strings are ASCII pre-2015 and UNICODE in 2016
$s1 = "SystemVersion: %s" ascii wide
$s2 = "Product ID: %s" ascii wide
$s3 = "InstallPath: %s" ascii wide
$s4 = "InstallTime: %d-%d-%d, %02d:%02d:%02d" ascii wide
$s5 = "ResgisterGroup: %s" ascii wide
$s6 = "RegisterUser: %s" ascii wide
$s7 = "ComputerName: %s" ascii wide
$s8 = "WindowsDirectory: %s" ascii wide
$s9 = "System Directory: %s" ascii wide
$s10 = "Number of Processors: %d" ascii wide
$s11 = "CPU[%d]: %s: %sMHz" ascii wide
$s12 = "RAM: %dMB Total, %dMB Free." ascii wide
$s13 = "DisplayMode: %d x %d, %dHz, %dbit" ascii wide
$s14 = "Uptime: %d Days %02u:%02u:%02u" ascii wide
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize &lt; 200KB and
7 of them
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: import "pe"
rule keyboy_related_exports
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the new 2016 sample's export"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize &lt; 200KB and
//The malware family seems to share many exports
//but this is the new kid on the block.
pe.exports("Embedding") or
pe.exports("SSSS") or
pe.exports("GetUP")
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: import "pe"
rule keyboy_init_config_section
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the Init section where the config is stored"
date = "2016-08-28"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
//Payloads are normally smaller but the new dropper we spotted
//is a bit larger.
filesize &lt; 300KB and
//Observed virtual sizes of the .Init section vary but they've
//always been 1024, 2048, or 4096 bytes.
for any i in (0..pe.number_of_sections - 1):
(
pe.sections[i].name == ".Init" and
pe.sections[i].virtual_size % 1024 == 0
)
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Payload delivery][yara]: rule CVE_2012_0158_KeyBoy {
meta:
author = "Etienne Maynier &lt;etienne@citizenlab.ca&gt;"
description = "CVE-2012-0158 variant"
file = "8307e444cad98b1b59568ad2eba5f201"
strings:
$a = "d0cf11e0a1b11ae1000000000000000000000000000000003e000300feff09000600000000000000000000000100000001" nocase // OLE header
$b = "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" nocase // junk data
$c = /5(\{\\b0\}|)[ ]*2006F00(\{\\b0\}|)[ ]*6F007(\{\\b0\}|)[ ]*400200045(\{\\b0\}|)[ ]*006(\{\\b0\}|)[ ]*E007(\{\\b0\}|)[ ]*400720079/ nocase
$d = "MSComctlLib.ListViewCtrl.2"
$e = "ac38c874503c307405347aaaebf2ac2c31ebf6e8e3" nocase //decoding shellcode
condition:
all of them
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Payload delivery][yara]: rule keyboy_exploit_doc_meta{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the meta associated with these exploit docs"
date = "2016-09-30"
strings:
$role = "{\\author Master}{\\operator Master}"
$creatim = "{\\creatim\\yr2015\\mo10\\dy16\\hr11\\min37}"
$revtim = "{\\revtim\\yr2015\\mo10\\dy16\\hr13\\min54}"
condition:
uint32be(0) == 0x7B5C7274 and
filesize &lt; 1MB and
all of them
}</incident:Journal_Entry>
</incident:History_Item>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>