Files

1011 lines
100 KiB
XML
Raw Permalink Normal View History

<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-38927f2c-b91d-45e7-9f74-d2cb50509a6b" version="1.1.1" timestamp="2018-08-04T10:27:32.017919+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-5a71edc8-26a8-43fb-8271-5c948e96ca05" version="1.1.1" timestamp="2018-08-04T06:17:18+00:00">
<stix:STIX_Header>
<stix:Title>Familiar Feeling: A Malware Campaign Targeting the Tibetan Diaspora Resurfaces</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Incidents>
<stix:Incident id=":incident-5a71edc8-26a8-43fb-8271-5c948e96ca05" timestamp="2018-08-04T06:25:10+00:00" xsi:type='incident:IncidentType'>
<incident:Title>Familiar Feeling: A Malware Campaign Targeting the Tibetan Diaspora Resurfaces</incident:Title>
<incident:External_ID source="MISP Event">133</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2018-01-31T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2018-08-04T06:25:10+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">Closed</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c65-f658-4b36-9ac8-15688064ab0b" timestamp="2018-08-04T06:13:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 91e976f76cc027931fed4cf70702efff (MISP Attribute #18346)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 91e976f76cc027931fed4cf70702efff (MISP Attribute #18346)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c65-f658-4b36-9ac8-15688064ab0b">
<cybox:Object id=":File-5b657c65-f658-4b36-9ac8-15688064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">91e976f76cc027931fed4cf70702efff</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:13:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c65-7f80-448a-992b-15688064ab0b" timestamp="2018-08-04T06:13:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 57ffde3504934e25904bcc57d27f9217 (MISP Attribute #18347)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 57ffde3504934e25904bcc57d27f9217 (MISP Attribute #18347)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c65-7f80-448a-992b-15688064ab0b">
<cybox:Object id=":File-5b657c65-7f80-448a-992b-15688064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">57ffde3504934e25904bcc57d27f9217</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:13:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c65-3318-46b2-9cd8-15688064ab0b" timestamp="2018-08-04T06:13:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 75b86a01196854919626e87d5bd45a38 (MISP Attribute #18348)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 75b86a01196854919626e87d5bd45a38 (MISP Attribute #18348)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c65-3318-46b2-9cd8-15688064ab0b">
<cybox:Object id=":File-5b657c65-3318-46b2-9cd8-15688064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">75b86a01196854919626e87d5bd45a38</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:13:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c65-9788-4a4c-b5a9-15688064ab0b" timestamp="2018-08-04T06:13:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: c25acaa45b0cf65a39c8413fa99e1fe8 (MISP Attribute #18349)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: c25acaa45b0cf65a39c8413fa99e1fe8 (MISP Attribute #18349)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c65-9788-4a4c-b5a9-15688064ab0b">
<cybox:Object id=":File-5b657c65-9788-4a4c-b5a9-15688064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">c25acaa45b0cf65a39c8413fa99e1fe8</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:13:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c65-86ec-442d-b077-15688064ab0b" timestamp="2018-08-04T06:13:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 4d85904b15c0adc8664f71bc2c5496bf (MISP Attribute #18350)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 4d85904b15c0adc8664f71bc2c5496bf (MISP Attribute #18350)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c65-86ec-442d-b077-15688064ab0b">
<cybox:Object id=":File-5b657c65-86ec-442d-b077-15688064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">4d85904b15c0adc8664f71bc2c5496bf</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:13:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c65-5c00-46f9-b147-15688064ab0b" timestamp="2018-08-04T06:13:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 88e85fb6074ae50a3ccc9b410805ffe5 (MISP Attribute #18351)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 88e85fb6074ae50a3ccc9b410805ffe5 (MISP Attribute #18351)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c65-5c00-46f9-b147-15688064ab0b">
<cybox:Object id=":File-5b657c65-5c00-46f9-b147-15688064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">88e85fb6074ae50a3ccc9b410805ffe5</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:13:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c65-7318-4bf3-8278-15688064ab0b" timestamp="2018-08-04T06:13:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 058a5d47f8834fccfff8971f0544e387 (MISP Attribute #18352)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 058a5d47f8834fccfff8971f0544e387 (MISP Attribute #18352)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c65-7318-4bf3-8278-15688064ab0b">
<cybox:Object id=":File-5b657c65-7318-4bf3-8278-15688064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">058a5d47f8834fccfff8971f0544e387</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:13:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c65-8bcc-4a7e-aa47-15688064ab0b" timestamp="2018-08-04T06:13:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 124c475d67aa8391f5220efcc64ca5b3 (MISP Attribute #18353)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 124c475d67aa8391f5220efcc64ca5b3 (MISP Attribute #18353)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c65-8bcc-4a7e-aa47-15688064ab0b">
<cybox:Object id=":File-5b657c65-8bcc-4a7e-aa47-15688064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">124c475d67aa8391f5220efcc64ca5b3</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:13:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c65-56dc-4bb8-800d-15688064ab0b" timestamp="2018-08-04T06:13:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 054bad7ec0e19cec931078d45382fee6 (MISP Attribute #18354)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 054bad7ec0e19cec931078d45382fee6 (MISP Attribute #18354)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c65-56dc-4bb8-800d-15688064ab0b">
<cybox:Object id=":File-5b657c65-56dc-4bb8-800d-15688064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">054bad7ec0e19cec931078d45382fee6</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:13:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c65-b82c-4e03-aa1b-15688064ab0b" timestamp="2018-08-04T06:13:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: b1c114ae9172a3bacc5c6b30c410f354 (MISP Attribute #18355)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: b1c114ae9172a3bacc5c6b30c410f354 (MISP Attribute #18355)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c65-b82c-4e03-aa1b-15688064ab0b">
<cybox:Object id=":File-5b657c65-b82c-4e03-aa1b-15688064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">b1c114ae9172a3bacc5c6b30c410f354</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:13:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c65-cb5c-4c8a-b8db-15688064ab0b" timestamp="2018-08-04T06:13:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 72c88c4a9d2316b266a6702374411a99 (MISP Attribute #18356)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 72c88c4a9d2316b266a6702374411a99 (MISP Attribute #18356)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c65-cb5c-4c8a-b8db-15688064ab0b">
<cybox:Object id=":File-5b657c65-cb5c-4c8a-b8db-15688064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">72c88c4a9d2316b266a6702374411a99</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:13:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657d14-2854-4f64-9d64-72cf8064ab0b" timestamp="2018-08-04T06:16:52+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 67e866c461c285853b225d2b2c850c4f (MISP Attribute #18357)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 67e866c461c285853b225d2b2c850c4f (MISP Attribute #18357)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657d14-2854-4f64-9d64-72cf8064ab0b">
<cybox:Object id=":File-5b657d14-2854-4f64-9d64-72cf8064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">67e866c461c285853b225d2b2c850c4f</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:16:52+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657d14-0654-4e9b-b833-72cf8064ab0b" timestamp="2018-08-04T06:16:52+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: e1b03f5837533ecc9a05e19650d68e1d (MISP Attribute #18358)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: e1b03f5837533ecc9a05e19650d68e1d (MISP Attribute #18358)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657d14-0654-4e9b-b833-72cf8064ab0b">
<cybox:Object id=":File-5b657d14-0654-4e9b-b833-72cf8064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">e1b03f5837533ecc9a05e19650d68e1d</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:16:52+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657d14-8f34-41e0-ba68-72cf8064ab0b" timestamp="2018-08-04T06:16:52+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 11e0f3e1c7d8855ed7f1dcfce4b7702a (MISP Attribute #18359)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 11e0f3e1c7d8855ed7f1dcfce4b7702a (MISP Attribute #18359)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657d14-8f34-41e0-ba68-72cf8064ab0b">
<cybox:Object id=":File-5b657d14-8f34-41e0-ba68-72cf8064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">11e0f3e1c7d8855ed7f1dcfce4b7702a</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:16:52+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c33-0f28-4582-acc2-72cd8064ab0b" timestamp="2018-08-04T06:13:07+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: bqfkdrmnhh0623@gmail.com (MISP Attribute #18343)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: bqfkdrmnhh0623@gmail.com (MISP Attribute #18343)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2018-08-04T06:13:07+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c43-9d0c-49d7-97a8-72cc8064ab0b" timestamp="2018-08-04T06:13:23+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: huang ning (MISP Attribute #18344)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: huang ning (MISP Attribute #18344)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2018-08-04T06:13:23+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c55-0d84-46ef-9e3b-167e8064ab0b" timestamp="2018-08-04T06:13:41+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: 8677687877 (MISP Attribute #18345)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: 8677687877 (MISP Attribute #18345)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2018-08-04T06:13:41+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a71edfd-5044-404c-8b48-09238e96ca05" timestamp="2018-01-31T11:25:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: commail.co (MISP Attribute #18048)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: commail.co (MISP Attribute #18048)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a71edfd-5044-404c-8b48-09238e96ca05">
<cybox:Object id=":DomainName-5a71edfd-5044-404c-8b48-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">commail.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-31T11:25:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a71edfd-f620-4e5f-bc15-09238e96ca05" timestamp="2018-01-31T11:25:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: tibetfrum.info (MISP Attribute #18049)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: tibetfrum.info (MISP Attribute #18049)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a71edfd-f620-4e5f-bc15-09238e96ca05">
<cybox:Object id=":DomainName-5a71edfd-f620-4e5f-bc15-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">tibetfrum.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-31T11:25:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a71edfd-6f60-4192-8e0f-09238e96ca05" timestamp="2018-01-31T11:25:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: tibethouse.info (MISP Attribute #18050)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: tibethouse.info (MISP Attribute #18050)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a71edfd-6f60-4192-8e0f-09238e96ca05">
<cybox:Object id=":DomainName-5a71edfd-6f60-4192-8e0f-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">tibethouse.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-31T11:25:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a71edfd-1054-4f90-b881-09238e96ca05" timestamp="2018-01-31T11:25:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: tibetnews.info (MISP Attribute #18051)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: tibetnews.info (MISP Attribute #18051)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a71edfd-1054-4f90-b881-09238e96ca05">
<cybox:Object id=":DomainName-5a71edfd-1054-4f90-b881-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">tibetnews.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-31T11:25:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a71edfd-2d74-416f-b7f1-09238e96ca05" timestamp="2018-01-31T11:25:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: daynew.today (MISP Attribute #18052)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: daynew.today (MISP Attribute #18052)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a71edfd-2d74-416f-b7f1-09238e96ca05">
<cybox:Object id=":DomainName-5a71edfd-2d74-416f-b7f1-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">daynew.today</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-31T11:25:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a71edfd-3760-46ea-ac88-09238e96ca05" timestamp="2018-01-31T11:25:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: daynews.today (MISP Attribute #18053)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: daynews.today (MISP Attribute #18053)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a71edfd-3760-46ea-ac88-09238e96ca05">
<cybox:Object id=":DomainName-5a71edfd-3760-46ea-ac88-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">daynews.today</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-31T11:25:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a71edfd-1460-419f-bf27-09238e96ca05" timestamp="2018-01-31T11:25:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: tibetnews.today (MISP Attribute #18054)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: tibetnews.today (MISP Attribute #18054)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a71edfd-1460-419f-bf27-09238e96ca05">
<cybox:Object id=":DomainName-5a71edfd-1460-419f-bf27-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">tibetnews.today</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-31T11:25:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a71edfd-f73c-4213-9784-09238e96ca05" timestamp="2018-01-31T11:25:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: comemails.email (MISP Attribute #18055)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: comemails.email (MISP Attribute #18055)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a71edfd-f73c-4213-9784-09238e96ca05">
<cybox:Object id=":DomainName-5a71edfd-f73c-4213-9784-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">comemails.email</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-31T11:25:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a71edfd-65f0-498f-8143-09238e96ca05" timestamp="2018-01-31T11:25:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: comemail.email (MISP Attribute #18056)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: comemail.email (MISP Attribute #18056)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a71edfd-65f0-498f-8143-09238e96ca05">
<cybox:Object id=":DomainName-5a71edfd-65f0-498f-8143-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">comemail.email</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-31T11:25:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c1b-de48-4c26-a83a-72cb8064ab0b" timestamp="2018-08-04T06:12:43+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: google.comemail.email (MISP Attribute #18336)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: google.comemail.email (MISP Attribute #18336)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c1b-de48-4c26-a83a-72cb8064ab0b">
<cybox:Object id=":DomainName-5b657c1b-de48-4c26-a83a-72cb8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">google.comemail.email</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:12:43+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c1b-46f4-4103-9646-72cb8064ab0b" timestamp="2018-08-04T06:12:43+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: google.comemails.email (MISP Attribute #18337)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: google.comemails.email (MISP Attribute #18337)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c1b-46f4-4103-9646-72cb8064ab0b">
<cybox:Object id=":DomainName-5b657c1b-46f4-4103-9646-72cb8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">google.comemails.email</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:12:43+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c1b-7ab4-4be5-bdfa-72cb8064ab0b" timestamp="2018-08-04T06:12:43+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: google.commail.co (MISP Attribute #18338)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: google.commail.co (MISP Attribute #18338)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c1b-7ab4-4be5-bdfa-72cb8064ab0b">
<cybox:Object id=":DomainName-5b657c1b-7ab4-4be5-bdfa-72cb8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">google.commail.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:12:43+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c1b-9da8-4d2a-be4e-72cb8064ab0b" timestamp="2018-08-04T06:12:43+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: google.commail.email (MISP Attribute #18339)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: google.commail.email (MISP Attribute #18339)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c1b-9da8-4d2a-be4e-72cb8064ab0b">
<cybox:Object id=":DomainName-5b657c1b-9da8-4d2a-be4e-72cb8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">google.commail.email</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:12:43+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c1b-8868-476a-ad15-72cb8064ab0b" timestamp="2018-08-04T06:12:43+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail.google.commail.co (MISP Attribute #18340)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail.google.commail.co (MISP Attribute #18340)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c1b-8868-476a-ad15-72cb8064ab0b">
<cybox:Object id=":DomainName-5b657c1b-8868-476a-ad15-72cb8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail.google.commail.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:12:43+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c1b-7b50-4ccb-8487-72cb8064ab0b" timestamp="2018-08-04T06:12:43+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.comemail.email (MISP Attribute #18341)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.comemail.email (MISP Attribute #18341)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c1b-7b50-4ccb-8487-72cb8064ab0b">
<cybox:Object id=":DomainName-5b657c1b-7b50-4ccb-8487-72cb8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.comemail.email</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:12:43+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657c1b-5dc0-4f64-8569-72cb8064ab0b" timestamp="2018-08-04T06:12:43+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.google.comemails.email (MISP Attribute #18342)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.google.comemails.email (MISP Attribute #18342)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657c1b-5dc0-4f64-8569-72cb8064ab0b">
<cybox:Object id=":DomainName-5b657c1b-5dc0-4f64-8569-72cb8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.google.comemails.email</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:12:43+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657bbb-48f4-4cc2-a236-72cf8064ab0b" timestamp="2018-08-04T06:11:07+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 27.126.186.222 (MISP Attribute #18330)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 27.126.186.222 (MISP Attribute #18330)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657bbb-48f4-4cc2-a236-72cf8064ab0b">
<cybox:Object id=":Address-5b657bbb-48f4-4cc2-a236-72cf8064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">27.126.186.222</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:11:07+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657bbb-e338-4722-af6a-72cf8064ab0b" timestamp="2018-08-04T06:11:07+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 103.55.24.196 (MISP Attribute #18331)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 103.55.24.196 (MISP Attribute #18331)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657bbb-e338-4722-af6a-72cf8064ab0b">
<cybox:Object id=":Address-5b657bbb-e338-4722-af6a-72cf8064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">103.55.24.196</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:11:07+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657bbb-eed0-4569-a919-72cf8064ab0b" timestamp="2018-08-04T06:11:07+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 203.189.232.207 (MISP Attribute #18332)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 203.189.232.207 (MISP Attribute #18332)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657bbb-eed0-4569-a919-72cf8064ab0b">
<cybox:Object id=":Address-5b657bbb-eed0-4569-a919-72cf8064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">203.189.232.207</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:11:07+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657bbb-d594-49ae-8e85-72cf8064ab0b" timestamp="2018-08-04T06:11:07+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 45.127.97.222 (MISP Attribute #18333)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 45.127.97.222 (MISP Attribute #18333)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657bbb-d594-49ae-8e85-72cf8064ab0b">
<cybox:Object id=":Address-5b657bbb-d594-49ae-8e85-72cf8064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">45.127.97.222</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:11:07+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657bbb-9bdc-4b23-b160-72cf8064ab0b" timestamp="2018-08-04T06:11:07+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 115.126.86.151 (MISP Attribute #18334)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 115.126.86.151 (MISP Attribute #18334)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657bbb-9bdc-4b23-b160-72cf8064ab0b">
<cybox:Object id=":Address-5b657bbb-9bdc-4b23-b160-72cf8064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">115.126.86.151</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:11:07+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657bbb-f600-4013-bb4b-72cf8064ab0b" timestamp="2018-08-04T06:11:07+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 27.126.176.169 (MISP Attribute #18335)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 27.126.176.169 (MISP Attribute #18335)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657bbb-f600-4013-bb4b-72cf8064ab0b">
<cybox:Object id=":Address-5b657bbb-f600-4013-bb4b-72cf8064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">27.126.176.169</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:11:07+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5b657d2e-f628-4a1e-b142-72cb8064ab0b" timestamp="2018-08-04T06:17:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: tibetanparliarnent@yahoo.com (MISP Attribute #18360)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: tibetanparliarnent@yahoo.com (MISP Attribute #18360)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5b657d2e-f628-4a1e-b142-72cb8064ab0b">
<cybox:Object id=":EmailMessage-5b657d2e-f628-4a1e-b142-72cb8064ab0b">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">tibetanparliarnent@yahoo.com</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-08-04T06:17:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:History>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">Event Threat Level: Medium</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TLP:RED</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: SOURCE:CITIZENLAB</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: NOTPUBLISHED</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: DETECT</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TARGET:TIBETAN</incident:Journal_Entry>
</incident:History_Item>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>