Files
autarch/data/ioc/spyware/citizen_lab/201608_NSO_Group/stix.xml

2303 lines
224 KiB
XML
Raw Normal View History

<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:="https://rufus.citlab.utoronto.ca"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-d63348c4-4789-48f2-9a41-ede3e7dfe251" version="1.1.1" timestamp="2016-11-08T20:32:24.541089+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-581c1022-5c68-4617-9ea4-497a8e96ca05" version="1.1.1" timestamp="2016-11-08T15:29:20+00:00">
<stix:STIX_Header>
<stix:Title>The Million Dollar Dissident: NSO Groups iPhone Zero-Days used against a UAE Human Rights Defender (MISP Event #10)</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:TTPs>
<stix:TTP id=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>External analysis: CVE-2016-4656 (MISP Attribute #463)</ttp:Title>
<ttp:Description>An application may be able to execute arbitrary code with kernel privileges</ttp:Description>
<ttp:Exploit_Targets>
<ttp:Exploit_Target>
<stixCommon:Exploit_Target id=":et-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='et:ExploitTargetType'>
<et:Title>An application may be able to execute arbitrary code with kernel privileges</et:Title>
<et:Vulnerability>
<et:CVE_ID>CVE-2016-4656</et:CVE_ID>
</et:Vulnerability>
</stixCommon:Exploit_Target>
</ttp:Exploit_Target>
</ttp:Exploit_Targets>
</stix:TTP>
<stix:TTP id=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>External analysis: CVE-2016-4655 (MISP Attribute #464)</ttp:Title>
<ttp:Description>An application may be able to disclose kernel memory</ttp:Description>
<ttp:Exploit_Targets>
<ttp:Exploit_Target>
<stixCommon:Exploit_Target id=":et-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='et:ExploitTargetType'>
<et:Title>An application may be able to disclose kernel memory</et:Title>
<et:Vulnerability>
<et:CVE_ID>CVE-2016-4655</et:CVE_ID>
</et:Vulnerability>
</stixCommon:Exploit_Target>
</ttp:Exploit_Target>
</ttp:Exploit_Targets>
</stix:TTP>
<stix:TTP id=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>External analysis: CVE-2016-4657 (MISP Attribute #465)</ttp:Title>
<ttp:Description>Visiting a maliciously crafted website may lead to arbitrary code execution</ttp:Description>
<ttp:Exploit_Targets>
<ttp:Exploit_Target>
<stixCommon:Exploit_Target id=":et-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='et:ExploitTargetType'>
<et:Title>Visiting a maliciously crafted website may lead to arbitrary code execution</et:Title>
<et:Vulnerability>
<et:CVE_ID>CVE-2016-4657</et:CVE_ID>
</et:Vulnerability>
</stixCommon:Exploit_Target>
</ttp:Exploit_Target>
</ttp:Exploit_Targets>
</stix:TTP>
<stix:TTP id=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload type: Pegasus (MISP Attribute #1313)</ttp:Title>
<ttp:Description>NSO Group product</ttp:Description>
<ttp:Behavior>
<ttp:Malware>
<ttp:Malware_Instance>
<ttp:Name>Pegasus</ttp:Name>
</ttp:Malware_Instance>
</ttp:Malware>
</ttp:Behavior>
</stix:TTP>
</stix:TTPs>
<stix:Incidents>
<stix:Incident id=":incident-581c1022-5c68-4617-9ea4-497a8e96ca05" timestamp="2016-11-08T15:31:51+00:00" xsi:type='incident:IncidentType'>
<incident:Title>The Million Dollar Dissident: NSO Groups iPhone Zero-Days used against a UAE Human Rights Defender</incident:Title>
<incident:External_ID source="MISP Event">10</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2016-08-24T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2016-11-08T15:31:51+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">Closed</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581c106f-cf04-43a6-88e8-497a8e96ca05" timestamp="2016-11-04T00:37:03+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: NSO Group (MISP Attribute #498)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: NSO Group (MISP Attribute #498)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-04T00:37:03+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58223036-8d6c-4c3e-a427-497a8e96ca05" timestamp="2016-11-08T15:06:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: alljazeera.co (MISP Attribute #1314)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: alljazeera.co (MISP Attribute #1314)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58223036-8d6c-4c3e-a427-497a8e96ca05">
<cybox:Object id=":DomainName-58223036-8d6c-4c3e-a427-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">alljazeera.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:06:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-6748-496e-a951-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: bbc-africa.com (MISP Attribute #1315)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: bbc-africa.com (MISP Attribute #1315)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-6748-496e-a951-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-6748-496e-a951-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">bbc-africa.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-839c-4f04-949e-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: cnn-africa.co (MISP Attribute #1316)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: cnn-africa.co (MISP Attribute #1316)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-839c-4f04-949e-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-839c-4f04-949e-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">cnn-africa.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-e9e0-4a50-b94c-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: unonoticias.net (MISP Attribute #1317)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: unonoticias.net (MISP Attribute #1317)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-e9e0-4a50-b94c-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-e9e0-4a50-b94c-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">unonoticias.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-2670-47d2-8389-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: univision.click (MISP Attribute #1318)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: univision.click (MISP Attribute #1318)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-2670-47d2-8389-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-2670-47d2-8389-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">univision.click</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-ceec-4dcb-8c51-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: track-your-fedex-package.org (MISP Attribute #1319)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: track-your-fedex-package.org (MISP Attribute #1319)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-ceec-4dcb-8c51-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-ceec-4dcb-8c51-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">track-your-fedex-package.org</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-8640-4db9-8cdf-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mz-vodacom.info (MISP Attribute #1320)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mz-vodacom.info (MISP Attribute #1320)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-8640-4db9-8cdf-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-8640-4db9-8cdf-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mz-vodacom.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-93cc-4f2b-8ae4-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: iusacell-movil.com.mx (MISP Attribute #1321)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: iusacell-movil.com.mx (MISP Attribute #1321)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-93cc-4f2b-8ae4-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-93cc-4f2b-8ae4-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">iusacell-movil.com.mx</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-c5ac-4743-862b-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: sabafon.info (MISP Attribute #1322)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: sabafon.info (MISP Attribute #1322)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-c5ac-4743-862b-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-c5ac-4743-862b-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">sabafon.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-3754-42c7-af73-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: newtarrifs.net (MISP Attribute #1323)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: newtarrifs.net (MISP Attribute #1323)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-3754-42c7-af73-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-3754-42c7-af73-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">newtarrifs.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-aa70-4ee9-8fad-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: y0utube.com.mx (MISP Attribute #1324)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: y0utube.com.mx (MISP Attribute #1324)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-aa70-4ee9-8fad-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-aa70-4ee9-8fad-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">y0utube.com.mx</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-7c38-47df-b3b1-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: fb-accounts.com (MISP Attribute #1325)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: fb-accounts.com (MISP Attribute #1325)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-7c38-47df-b3b1-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-7c38-47df-b3b1-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">fb-accounts.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-049c-47ec-90e2-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: googleplay-store.com (MISP Attribute #1326)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: googleplay-store.com (MISP Attribute #1326)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-049c-47ec-90e2-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-049c-47ec-90e2-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">googleplay-store.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-fbc0-42e5-b56c-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: whatsapp-app.com (MISP Attribute #1327)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: whatsapp-app.com (MISP Attribute #1327)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-fbc0-42e5-b56c-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-fbc0-42e5-b56c-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">whatsapp-app.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-e524-449e-8e0c-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts.mx (MISP Attribute #1328)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts.mx (MISP Attribute #1328)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-e524-449e-8e0c-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-e524-449e-8e0c-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts.mx</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-ecc8-4bce-966d-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: adjust-local-settings.com (MISP Attribute #1329)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: adjust-local-settings.com (MISP Attribute #1329)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-ecc8-4bce-966d-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-ecc8-4bce-966d-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">adjust-local-settings.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-8440-4d71-97b4-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: emiratesfoundation.net (MISP Attribute #1330)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: emiratesfoundation.net (MISP Attribute #1330)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-8440-4d71-97b4-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-8440-4d71-97b4-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">emiratesfoundation.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-0cf8-4c54-8e57-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: checkinonlinehere.com (MISP Attribute #1331)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: checkinonlinehere.com (MISP Attribute #1331)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-0cf8-4c54-8e57-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-0cf8-4c54-8e57-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">checkinonlinehere.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-36e4-4843-93db-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: turkishairines.info (MISP Attribute #1332)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: turkishairines.info (MISP Attribute #1332)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-36e4-4843-93db-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-36e4-4843-93db-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">turkishairines.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-0880-4c1c-a507-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: bulbazaur.com (MISP Attribute #1333)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: bulbazaur.com (MISP Attribute #1333)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-0880-4c1c-a507-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-0880-4c1c-a507-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">bulbazaur.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-a9f4-4590-bb10-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: pickuchu.com (MISP Attribute #1334)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: pickuchu.com (MISP Attribute #1334)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-a9f4-4590-bb10-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-a9f4-4590-bb10-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">pickuchu.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58223264-6050-4883-8676-497a8e96ca05" timestamp="2016-11-08T15:15:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: damanhealth.online (MISP Attribute #1335)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: damanhealth.online (MISP Attribute #1335)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58223264-6050-4883-8676-497a8e96ca05">
<cybox:Object id=":DomainName-58223264-6050-4883-8676-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">damanhealth.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:15:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822327c-2050-46cb-b310-497a8e96ca05" timestamp="2016-11-08T15:15:56+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: uaenews.online (MISP Attribute #1336)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: uaenews.online (MISP Attribute #1336)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822327c-2050-46cb-b310-497a8e96ca05">
<cybox:Object id=":DomainName-5822327c-2050-46cb-b310-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">uaenews.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:15:56+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582233c5-8108-41eb-ba12-49798e96ca05" timestamp="2016-11-08T15:21:25+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: ideas-telcel.com.mx (MISP Attribute #1340)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: ideas-telcel.com.mx (MISP Attribute #1340)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582233c5-8108-41eb-ba12-49798e96ca05">
<cybox:Object id=":DomainName-582233c5-8108-41eb-ba12-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">ideas-telcel.com.mx</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:21:25+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582235a0-ea0c-4301-b87b-49798e96ca05" timestamp="2016-11-08T15:29:20+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: nation-news.com (MISP Attribute #1342)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: nation-news.com (MISP Attribute #1342)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582235a0-ea0c-4301-b87b-49798e96ca05">
<cybox:Object id=":DomainName-582235a0-ea0c-4301-b87b-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">nation-news.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:29:20+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-f13b8f95-e6ca-47a8-8c25-fe1f4817a439" timestamp="2016-11-08T14:28:07+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: webadv.co (MISP Attribute #466)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: webadv.co (MISP Attribute #466)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-f13b8f95-e6ca-47a8-8c25-fe1f4817a439">
<cybox:Object id=":DomainName-f13b8f95-e6ca-47a8-8c25-fe1f4817a439">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">webadv.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:28:07+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-2ad610a4-2177-4e7f-b525-8621a80e2ebe" timestamp="2016-11-08T14:29:23+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: icloudcacher.com (MISP Attribute #469)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: icloudcacher.com (MISP Attribute #469)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-2ad610a4-2177-4e7f-b525-8621a80e2ebe">
<cybox:Object id=":DomainName-2ad610a4-2177-4e7f-b525-8621a80e2ebe">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">icloudcacher.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:29:23+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-9c494d42-797d-4c62-978a-8a888fb179c8" timestamp="2016-11-08T14:31:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: asrarrarabiya.com (MISP Attribute #470)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: asrarrarabiya.com (MISP Attribute #470)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-9c494d42-797d-4c62-978a-8a888fb179c8">
<cybox:Object id=":DomainName-9c494d42-797d-4c62-978a-8a888fb179c8">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">asrarrarabiya.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:31:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-325e4a00-7b2f-4c27-bff2-89f390e3c13c" timestamp="2016-11-08T14:35:10+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: asrararabiya.co (MISP Attribute #471)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: asrararabiya.co (MISP Attribute #471)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-325e4a00-7b2f-4c27-bff2-89f390e3c13c">
<cybox:Object id=":DomainName-325e4a00-7b2f-4c27-bff2-89f390e3c13c">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">asrararabiya.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:35:10+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-9a804548-73c4-4258-9b88-51f952f75d17" timestamp="2016-11-08T14:45:48+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: asrararablya.com (MISP Attribute #472)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: asrararablya.com (MISP Attribute #472)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-9a804548-73c4-4258-9b88-51f952f75d17">
<cybox:Object id=":DomainName-9a804548-73c4-4258-9b88-51f952f75d17">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">asrararablya.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:45:48+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-cd9ef05f-b3ea-41c2-a750-a431f9dfb508" timestamp="2016-11-08T14:46:00+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: smser.net (MISP Attribute #473)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: smser.net (MISP Attribute #473)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-cd9ef05f-b3ea-41c2-a750-a431f9dfb508">
<cybox:Object id=":DomainName-cd9ef05f-b3ea-41c2-a750-a431f9dfb508">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">smser.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:00+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-17a374eb-20d6-4790-bee4-45b7073115f1" timestamp="2016-11-08T14:46:06+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: icrcworld.com (MISP Attribute #474)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: icrcworld.com (MISP Attribute #474)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-17a374eb-20d6-4790-bee4-45b7073115f1">
<cybox:Object id=":DomainName-17a374eb-20d6-4790-bee4-45b7073115f1">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">icrcworld.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:06+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-0d1164d5-7670-41da-8857-1247d0b67561" timestamp="2016-11-08T14:46:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: redcrossworld.com (MISP Attribute #475)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: redcrossworld.com (MISP Attribute #475)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-0d1164d5-7670-41da-8857-1247d0b67561">
<cybox:Object id=":DomainName-0d1164d5-7670-41da-8857-1247d0b67561">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">redcrossworld.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-0f203872-71ec-4b51-ba56-c50918f71f39" timestamp="2016-11-08T14:46:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: topcontactco.com (MISP Attribute #476)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: topcontactco.com (MISP Attribute #476)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-0f203872-71ec-4b51-ba56-c50918f71f39">
<cybox:Object id=":DomainName-0f203872-71ec-4b51-ba56-c50918f71f39">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">topcontactco.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-a2f8ef48-d6f7-46b1-9ee0-71fcb1c65cb9" timestamp="2016-11-08T14:46:26+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: thainews.asia (MISP Attribute #477)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: thainews.asia (MISP Attribute #477)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-a2f8ef48-d6f7-46b1-9ee0-71fcb1c65cb9">
<cybox:Object id=":DomainName-a2f8ef48-d6f7-46b1-9ee0-71fcb1c65cb9">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">thainews.asia</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:26+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-126c3480-6ad3-417f-9855-4e915b9ae528" timestamp="2016-11-08T14:46:34+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: kenyasms.org (MISP Attribute #478)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: kenyasms.org (MISP Attribute #478)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-126c3480-6ad3-417f-9855-4e915b9ae528">
<cybox:Object id=":DomainName-126c3480-6ad3-417f-9855-4e915b9ae528">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">kenyasms.org</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:34+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-7d63d6cb-90dc-454c-a505-a313150c1426" timestamp="2016-11-08T14:46:41+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: qaintqa.com (MISP Attribute #479)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: qaintqa.com (MISP Attribute #479)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-7d63d6cb-90dc-454c-a505-a313150c1426">
<cybox:Object id=":DomainName-7d63d6cb-90dc-454c-a505-a313150c1426">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">qaintqa.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:41+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-812c4cbf-60a7-431d-ae7a-a9fd1d6044aa" timestamp="2016-11-08T14:46:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: nsoqa.com (MISP Attribute #480)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: nsoqa.com (MISP Attribute #480)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-812c4cbf-60a7-431d-ae7a-a9fd1d6044aa">
<cybox:Object id=":DomainName-812c4cbf-60a7-431d-ae7a-a9fd1d6044aa">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">nsoqa.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-9be3a48f-e540-43f8-a2c0-8dc915a3dd48" timestamp="2016-11-08T14:54:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: ooredoodeals.com (MISP Attribute #481)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: ooredoodeals.com (MISP Attribute #481)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-9be3a48f-e540-43f8-a2c0-8dc915a3dd48">
<cybox:Object id=":DomainName-9be3a48f-e540-43f8-a2c0-8dc915a3dd48">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">ooredoodeals.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:54:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-252cc33c-8786-4dee-b77a-af52acb1661b" timestamp="2016-11-08T14:54:21+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: alawaeltech.com (MISP Attribute #482)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: alawaeltech.com (MISP Attribute #482)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-252cc33c-8786-4dee-b77a-af52acb1661b">
<cybox:Object id=":DomainName-252cc33c-8786-4dee-b77a-af52acb1661b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">alawaeltech.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:54:21+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-14df3986-e958-4612-ba2f-daa9fd95b868" timestamp="2016-11-08T14:54:27+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: bahrainsms.co (MISP Attribute #483)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: bahrainsms.co (MISP Attribute #483)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-14df3986-e958-4612-ba2f-daa9fd95b868">
<cybox:Object id=":DomainName-14df3986-e958-4612-ba2f-daa9fd95b868">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">bahrainsms.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:54:27+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-6540311c-8872-47a3-ada2-24757eaa35ee" timestamp="2016-11-08T14:54:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: turkeynewsupdates.com (MISP Attribute #484)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: turkeynewsupdates.com (MISP Attribute #484)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-6540311c-8872-47a3-ada2-24757eaa35ee">
<cybox:Object id=":DomainName-6540311c-8872-47a3-ada2-24757eaa35ee">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">turkeynewsupdates.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:54:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-340ccd5a-2520-4ccb-abeb-b264fb2bf645" timestamp="2016-11-08T15:13:37+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail1.nsogroup.com (MISP Attribute #486)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail1.nsogroup.com (MISP Attribute #486)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-340ccd5a-2520-4ccb-abeb-b264fb2bf645">
<cybox:Object id=":DomainName-340ccd5a-2520-4ccb-abeb-b264fb2bf645">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail1.nsogroup.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:13:37+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-029c89df-139e-463a-b1f1-c259b913d05f" timestamp="2016-11-08T15:09:41+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 52.8.153.44 (MISP Attribute #487)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 52.8.153.44 (MISP Attribute #487)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-029c89df-139e-463a-b1f1-c259b913d05f">
<cybox:Object id=":Address-029c89df-139e-463a-b1f1-c259b913d05f">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">52.8.153.44</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:09:41+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-2f6d312b-8db7-4fa0-9522-cc68090b4a3b" timestamp="2016-11-08T15:10:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 52.8.52.166 (MISP Attribute #488)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 52.8.52.166 (MISP Attribute #488)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-2f6d312b-8db7-4fa0-9522-cc68090b4a3b">
<cybox:Object id=":Address-2f6d312b-8db7-4fa0-9522-cc68090b4a3b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">52.8.52.166</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:10:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-cb442bf4-0d18-4d60-b1a7-e0fe5c7614fa" timestamp="2016-11-08T15:10:28+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 162.209.103.68 (MISP Attribute #489)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 162.209.103.68 (MISP Attribute #489)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-cb442bf4-0d18-4d60-b1a7-e0fe5c7614fa">
<cybox:Object id=":Address-cb442bf4-0d18-4d60-b1a7-e0fe5c7614fa">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">162.209.103.68</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:10:28+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-7db51886-46b4-496f-86fd-6b75a7b5f8c8" timestamp="2016-11-08T15:11:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 82.80.202.200 (MISP Attribute #490)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 82.80.202.200 (MISP Attribute #490)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-7db51886-46b4-496f-86fd-6b75a7b5f8c8">
<cybox:Object id=":Address-7db51886-46b4-496f-86fd-6b75a7b5f8c8">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">82.80.202.200</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:11:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-27a5b383-3c23-4f93-9341-8dd8d90575f6" timestamp="2016-11-08T15:12:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 82.80.202.204 (MISP Attribute #491)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 82.80.202.204 (MISP Attribute #491)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-27a5b383-3c23-4f93-9341-8dd8d90575f6">
<cybox:Object id=":Address-27a5b383-3c23-4f93-9341-8dd8d90575f6">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">82.80.202.204</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:12:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-208dbaaf-39c3-4930-8304-1c76e9b1e7b8" timestamp="2016-11-08T15:12:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 54.251.49.214 (MISP Attribute #492)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 54.251.49.214 (MISP Attribute #492)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-208dbaaf-39c3-4930-8304-1c76e9b1e7b8">
<cybox:Object id=":Address-208dbaaf-39c3-4930-8304-1c76e9b1e7b8">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">54.251.49.214</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:12:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-96bd845b-b8a7-4c91-92e1-c9060cc01239" timestamp="2016-11-08T15:05:00+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https://smser.net/9918216t/ (MISP Attribute #493)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: https://smser.net/9918216t/ (MISP Attribute #493)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-96bd845b-b8a7-4c91-92e1-c9060cc01239">
<cybox:Object id=":URI-96bd845b-b8a7-4c91-92e1-c9060cc01239">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://smser.net/9918216t/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:05:00+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-c9181cb8-1400-47e1-b45b-fc4d17cebe52" timestamp="2016-11-08T15:04:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https://smser.net/redirect.aspx (MISP Attribute #494)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: https://smser.net/redirect.aspx (MISP Attribute #494)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-c9181cb8-1400-47e1-b45b-fc4d17cebe52">
<cybox:Object id=":URI-c9181cb8-1400-47e1-b45b-fc4d17cebe52">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://smser.net/redirect.aspx</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:04:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-cdde7699-d231-458d-80a5-338b9e985702" timestamp="2016-11-08T15:01:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: aalaan.tv (MISP Attribute #467)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Payload delivery: aalaan.tv (MISP Attribute #467)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-cdde7699-d231-458d-80a5-338b9e985702">
<cybox:Object id=":DomainName-cdde7699-d231-458d-80a5-338b9e985702">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">aalaan.tv</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:01:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-73293a7a-acd5-47a0-81b6-a73f6dde67e1" timestamp="2016-11-08T15:01:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: manoraonline.net (MISP Attribute #468)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Payload delivery: manoraonline.net (MISP Attribute #468)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-73293a7a-acd5-47a0-81b6-a73f6dde67e1">
<cybox:Object id=":DomainName-73293a7a-acd5-47a0-81b6-a73f6dde67e1">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">manoraonline.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:01:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-ca1121b7-d273-4aac-83e8-e69b4bce5604" timestamp="2016-11-08T14:57:37+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: sms.webadv.co (MISP Attribute #485)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Payload delivery: sms.webadv.co (MISP Attribute #485)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-ca1121b7-d273-4aac-83e8-e69b4bce5604">
<cybox:Object id=":DomainName-ca1121b7-d273-4aac-83e8-e69b4bce5604">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">sms.webadv.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:57:37+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-6fad387c-a58a-4689-97d0-f87a42dee5b0" timestamp="2016-11-08T15:04:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: pn1g3p@sigaint.org (MISP Attribute #497)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: pn1g3p@sigaint.org (MISP Attribute #497)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-6fad387c-a58a-4689-97d0-f87a42dee5b0">
<cybox:Object id=":EmailMessage-6fad387c-a58a-4689-97d0-f87a42dee5b0">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">pn1g3p@sigaint.org</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:04:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58222e62-1020-4d67-b83f-49798e96ca05" timestamp="2016-11-08T14:58:26+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: https://sms.webadv.co/3589003s/ (MISP Attribute #1311)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: https://sms.webadv.co/3589003s/ (MISP Attribute #1311)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58222e62-1020-4d67-b83f-49798e96ca05">
<cybox:Object id=":URI-58222e62-1020-4d67-b83f-49798e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://sms.webadv.co/3589003s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:58:26+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58222e78-135c-434e-966e-49798e96ca05" timestamp="2016-11-08T14:58:48+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: https://sms.webadv.co/9573305s/ (MISP Attribute #1312)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: https://sms.webadv.co/9573305s/ (MISP Attribute #1312)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58222e78-135c-434e-966e-49798e96ca05">
<cybox:Object id=":URI-58222e78-135c-434e-966e-49798e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://sms.webadv.co/9573305s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:58:48+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58223346-c23c-4751-9d82-69fe8e96ca05" timestamp="2016-11-08T15:19:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: http://fb-accounts.com/2408931s/ (MISP Attribute #1337)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: http://fb-accounts.com/2408931s/ (MISP Attribute #1337)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58223346-c23c-4751-9d82-69fe8e96ca05">
<cybox:Object id=":URI-58223346-c23c-4751-9d82-69fe8e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://fb-accounts.com/2408931s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:19:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58223375-b860-4462-9d5a-49798e96ca05" timestamp="2016-11-08T15:20:05+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: http://unonoticias.net/1867745s/ (MISP Attribute #1338)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: http://unonoticias.net/1867745s/ (MISP Attribute #1338)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58223375-b860-4462-9d5a-49798e96ca05">
<cybox:Object id=":URI-58223375-b860-4462-9d5a-49798e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://unonoticias.net/1867745s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:20:05+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582233be-b3c8-4238-82b5-49798e96ca05" timestamp="2016-11-08T15:21:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: https://ideas-telcel.com.mx/3975827s/ (MISP Attribute #1339)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: https://ideas-telcel.com.mx/3975827s/ (MISP Attribute #1339)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582233be-b3c8-4238-82b5-49798e96ca05">
<cybox:Object id=":URI-582233be-b3c8-4238-82b5-49798e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://ideas-telcel.com.mx/3975827s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:21:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58223592-ad84-44d5-9e29-49798e96ca05" timestamp="2016-11-08T15:29:06+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: nation-news.com/4077017s/ (MISP Attribute #1341)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: nation-news.com/4077017s/ (MISP Attribute #1341)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58223592-ad84-44d5-9e29-49798e96ca05">
<cybox:Object id=":URI-58223592-ad84-44d5-9e29-49798e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">nation-news.com/4077017s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:29:06+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-7dd57279-a151-44d4-a21d-bb62ee3435aa" timestamp="2016-11-08T15:18:53+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: http://fb-accounts.com/1074139s/ (MISP Attribute #495)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: http://fb-accounts.com/1074139s/ (MISP Attribute #495)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-7dd57279-a151-44d4-a21d-bb62ee3435aa">
<cybox:Object id=":URI-7dd57279-a151-44d4-a21d-bb62ee3435aa">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://fb-accounts.com/1074139s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:18:53+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-eed4deb8-c8a8-4722-8e29-8ba5772e3059" timestamp="2016-11-08T15:19:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: http://unonoticias.net/3423768s/ (MISP Attribute #496)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: http://unonoticias.net/3423768s/ (MISP Attribute #496)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-eed4deb8-c8a8-4722-8e29-8ba5772e3059">
<cybox:Object id=":URI-eed4deb8-c8a8-4722-8e29-8ba5772e3059">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://unonoticias.net/3423768s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:19:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:Leveraged_TTPs>
<incident:Leveraged_TTP>
<stixCommon:Relationship>External analysis</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>External analysis</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>External analysis</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload type</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
</incident:Leveraged_TTPs>
<incident:History>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">Event Threat Level: High</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TLP:GREEN</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: SOURCE:CITIZENLAB</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: DETECT</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: PUBLISHED</incident:Journal_Entry>
</incident:History_Item>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
<stixCommon:References>
<stixCommon:Reference>https://citizenlab.org/2016/08/million-dollar-dissident-iphone-zero-day-nso-group-uae/</stixCommon:Reference>
</stixCommon:References>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>