Add Android forensics, IOC threat-intel DB, Compose companion; scrub secrets from configs

This commit is contained in:
SsSnake
2026-07-13 15:45:47 -07:00
parent 925216290f
commit e48d577bd5
387 changed files with 211976 additions and 921 deletions

View File

@@ -0,0 +1,8 @@
## Attacks on NGO in Burma IOCs
This directory contains IOC from the Citizen Lab report [Targeted Malware Attacks against NGO Linked to Attacks on Burmese Government Websites](https://citizenlab.org/2015/10/targeted-attacks-ngo-burma/) published the 16th of October 2015.
Files included in this directory:
* openioc.ioc : IOCs in OpenIOC format
* stix.xml : IOCs in STIX XML format
* iocs.csv : IOCs in csv format

View File

@@ -0,0 +1,24 @@
uuid,event_id,category,type,value,comment,to_ids,date
581bacca-464c-4997-8812-49798e96ca05,4,Network activity,domain,"usacia.websecexp.com","c2 server from Palo Alto study",1,20151016
581bacca-5998-41ad-afb4-49798e96ca05,4,Network activity,domain,"webhttps.websecexp.com","c2 server from Palo Alto study",1,20151016
581bacca-ad18-4ff6-b8b5-49798e96ca05,4,Network activity,domain,"appeur.gnway.cc","c2 server from Palo Alto study",1,20151016
581bacca-eb70-4443-a7d1-49798e96ca05,4,Network activity,domain,"usafbi.websecexp.com","c2 server from Palo Alto study",1,20151016
581bace8-59d0-4c6e-859a-497a8e96ca05,4,Payload type,text,"9002","",0,20151016
581bacf2-d924-45bd-a930-49798e96ca05,4,Payload type,text,"3102","The variant is labeled 3102, because it always uses the string “3102” in its first communications with a C2 server",0,20151016
581bad0a-7524-46f8-9d57-497a8e96ca05,4,Network activity,ip-dst,"198.44.190.85","This IP is a Virtual Private Server (VPS) hosted in the US and owned by VpsQuan",1,20151016
581bad2c-3a60-4be9-8d21-49798e96ca05,4,Payload delivery,md5,"53f81415ccedf453d6e3ebcdc142b966","Attachments",0,20151016
581bad2c-d2d4-46f4-b0cb-49798e96ca05,4,Payload delivery,md5,"699b3d90b050cae37f65c855ec7f616a","Attachments",0,20151016
581bad2c-e744-4a48-ae12-49798e96ca05,4,Payload delivery,md5,"6701662097e274f3cd089ceec35471d2","Attachments",0,20151016
581bad50-2488-429a-b001-497a8e96ca05,4,Artifacts dropped,md5,"c4c147bdfddffec2eea6bf99661e69ee","ca-bundle.exe",1,20151016
581bad50-7890-4dcf-8436-497a8e96ca05,4,Artifacts dropped,md5,"cec071424d417a095221bf8992819388","XLBugHandler.dll",1,20151016
581bad50-8998-4012-926d-497a8e96ca05,4,Artifacts dropped,md5,"5710d567d98a8f4a6682859ce3a35336","lsass.exe",1,20151016
581bad50-a014-4095-a054-497a8e96ca05,4,Artifacts dropped,md5,"56f0e67d981024ddcc215543698f44fb","mcutil.dll",1,20151016
581bad50-aea8-4d5f-8e0c-497a8e96ca05,4,Artifacts dropped,md5,"884d46c01c762ad6ddd2759fd921bf71","mcf.exe",1,20151016
581bad50-d494-4e55-aa91-497a8e96ca05,4,Artifacts dropped,md5,"7e0081fba718fcd71753d3199a290f03","mcf.ep",1,20151016
581bad60-2a18-44cc-ac40-49798e96ca05,4,Artifacts dropped,md5,"49ceba3347d39870f15f2ab0391af234","xlbug.dat",1,20151016
581bad77-2c58-479e-833e-497a8e96ca05,4,Network activity,domain,"t1.mailsecurityservice.com","",1,20151016
581bad77-cde8-4c65-9449-497a8e96ca05,4,Network activity,domain,"t2.mailsecurityservice.com","",1,20151016
581bad90-56b0-4c8b-ba6b-497a8e96ca05,4,Internal reference,link,"https://citizenlab.org/2015/10/targeted-attacks-ngo-burma/","",0,20151016
5824e57b-8458-4669-b6a0-497a8e96ca05,4,Attribution,whois-registrant-email,"wojiaojilao2@sohu.com","",0,20151016
5824e58f-be40-407d-b91b-497a8e96ca05,4,Network activity,domain,"iyouthen.com","Identified through passive DNS",1,20151016
5824e5f1-d174-487e-9156-497a8e96ca05,4,Payload delivery,url,"http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe","",1,20151016
1 uuid event_id category type value comment to_ids date
2 581bacca-464c-4997-8812-49798e96ca05 4 Network activity domain usacia.websecexp.com c2 server from Palo Alto study 1 20151016
3 581bacca-5998-41ad-afb4-49798e96ca05 4 Network activity domain webhttps.websecexp.com c2 server from Palo Alto study 1 20151016
4 581bacca-ad18-4ff6-b8b5-49798e96ca05 4 Network activity domain appeur.gnway.cc c2 server from Palo Alto study 1 20151016
5 581bacca-eb70-4443-a7d1-49798e96ca05 4 Network activity domain usafbi.websecexp.com c2 server from Palo Alto study 1 20151016
6 581bace8-59d0-4c6e-859a-497a8e96ca05 4 Payload type text 9002 0 20151016
7 581bacf2-d924-45bd-a930-49798e96ca05 4 Payload type text 3102 The variant is labeled 3102, because it always uses the string “3102” in its first communications with a C2 server 0 20151016
8 581bad0a-7524-46f8-9d57-497a8e96ca05 4 Network activity ip-dst 198.44.190.85 This IP is a Virtual Private Server (VPS) hosted in the US and owned by VpsQuan 1 20151016
9 581bad2c-3a60-4be9-8d21-49798e96ca05 4 Payload delivery md5 53f81415ccedf453d6e3ebcdc142b966 Attachments 0 20151016
10 581bad2c-d2d4-46f4-b0cb-49798e96ca05 4 Payload delivery md5 699b3d90b050cae37f65c855ec7f616a Attachments 0 20151016
11 581bad2c-e744-4a48-ae12-49798e96ca05 4 Payload delivery md5 6701662097e274f3cd089ceec35471d2 Attachments 0 20151016
12 581bad50-2488-429a-b001-497a8e96ca05 4 Artifacts dropped md5 c4c147bdfddffec2eea6bf99661e69ee ca-bundle.exe 1 20151016
13 581bad50-7890-4dcf-8436-497a8e96ca05 4 Artifacts dropped md5 cec071424d417a095221bf8992819388 XLBugHandler.dll 1 20151016
14 581bad50-8998-4012-926d-497a8e96ca05 4 Artifacts dropped md5 5710d567d98a8f4a6682859ce3a35336 lsass.exe 1 20151016
15 581bad50-a014-4095-a054-497a8e96ca05 4 Artifacts dropped md5 56f0e67d981024ddcc215543698f44fb mcutil.dll 1 20151016
16 581bad50-aea8-4d5f-8e0c-497a8e96ca05 4 Artifacts dropped md5 884d46c01c762ad6ddd2759fd921bf71 mcf.exe 1 20151016
17 581bad50-d494-4e55-aa91-497a8e96ca05 4 Artifacts dropped md5 7e0081fba718fcd71753d3199a290f03 mcf.ep 1 20151016
18 581bad60-2a18-44cc-ac40-49798e96ca05 4 Artifacts dropped md5 49ceba3347d39870f15f2ab0391af234 xlbug.dat 1 20151016
19 581bad77-2c58-479e-833e-497a8e96ca05 4 Network activity domain t1.mailsecurityservice.com 1 20151016
20 581bad77-cde8-4c65-9449-497a8e96ca05 4 Network activity domain t2.mailsecurityservice.com 1 20151016
21 581bad90-56b0-4c8b-ba6b-497a8e96ca05 4 Internal reference link https://citizenlab.org/2015/10/targeted-attacks-ngo-burma/ 0 20151016
22 5824e57b-8458-4669-b6a0-497a8e96ca05 4 Attribution whois-registrant-email wojiaojilao2@sohu.com 0 20151016
23 5824e58f-be40-407d-b91b-497a8e96ca05 4 Network activity domain iyouthen.com Identified through passive DNS 1 20151016
24 5824e5f1-d174-487e-9156-497a8e96ca05 4 Payload delivery url http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe 1 20151016

View File

@@ -0,0 +1,77 @@
<?xml version="1.0" encoding="utf-8"?>
<ioc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" id="581bac8e-b478-474a-a013-49798e96ca05" last-modified="2015-10-16T00:00:00" xmlns="http://schemas.mandiant.com/2010/ioc">
<short_description>Event #4</short_description>
<description>Targeted Malware Attacks against NGO Linked to Attacks on Burmese Government Websites</description>
<keywords />
<authored_by>citizenlab</authored_by>
<authored_date>2015-10-16T00:00:00</authored_date>
<links />
<definition>
<Indicator operator="OR" id="581bac8e-b478-474a-a013-49798e96ca05">
<IndicatorItem id="c4c147bdfddffec2eea6bf99661e69ee" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="884d46c01c762ad6ddd2759fd921bf71" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="56f0e67d981024ddcc215543698f44fb" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="7e0081fba718fcd71753d3199a290f03" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="5710d567d98a8f4a6682859ce3a35336" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="cec071424d417a095221bf8992819388" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="49ceba3347d39870f15f2ab0391af234" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="usafbi.websecexp.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="usacia.websecexp.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="webhttps.websecexp.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="iyouthen.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="appeur.gnway.cc" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="t1.mailsecurityservice.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="t2.mailsecurityservice.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="198.44.190.85" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe" condition="is">
<Context document="UrlHistoryItem" search="UrlHistoryItem/URL" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
</Indicator>
</definition>
</ioc>

View File

@@ -0,0 +1,736 @@
<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:="https://rufus.citlab.utoronto.ca"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-a3126f94-8e7e-48d3-ad30-dcc198ba7c78" version="1.1.1" timestamp="2016-11-10T21:28:56.977467+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-581bac8e-b478-474a-a013-49798e96ca05" version="1.1.1" timestamp="2016-11-10T16:26:09+00:00">
<stix:STIX_Header>
<stix:Title>Targeted Malware Attacks against NGO Linked to Attacks on Burmese Government Websites (MISP Event #4)</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:TTPs>
<stix:TTP id=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload type: 9002 (MISP Attribute #87)</ttp:Title>
<ttp:Behavior>
<ttp:Malware>
<ttp:Malware_Instance>
<ttp:Name>9002</ttp:Name>
</ttp:Malware_Instance>
</ttp:Malware>
</ttp:Behavior>
</stix:TTP>
<stix:TTP id=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload type: 3102 (MISP Attribute #88)</ttp:Title>
<ttp:Description>The variant is labeled 3102, because it always uses the string “3102” in its first communications with a C2 server</ttp:Description>
<ttp:Behavior>
<ttp:Malware>
<ttp:Malware_Instance>
<ttp:Name>3102</ttp:Name>
</ttp:Malware_Instance>
</ttp:Malware>
</ttp:Behavior>
</stix:TTP>
</stix:TTPs>
<stix:Incidents>
<stix:Incident id=":incident-581bac8e-b478-474a-a013-49798e96ca05" timestamp="2016-11-10T16:26:30+00:00" xsi:type='incident:IncidentType'>
<incident:Title>Targeted Malware Attacks against NGO Linked to Attacks on Burmese Government Websites</incident:Title>
<incident:External_ID source="MISP Event">4</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2015-10-16T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2016-11-10T16:26:30+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">New</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad50-2488-429a-b001-497a8e96ca05" timestamp="2016-11-10T16:22:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: c4c147bdfddffec2eea6bf99661e69ee (MISP Attribute #93)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: c4c147bdfddffec2eea6bf99661e69ee (MISP Attribute #93)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad50-2488-429a-b001-497a8e96ca05">
<cybox:Object id=":File-581bad50-2488-429a-b001-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">c4c147bdfddffec2eea6bf99661e69ee</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:22:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad50-aea8-4d5f-8e0c-497a8e96ca05" timestamp="2016-11-10T16:22:25+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 884d46c01c762ad6ddd2759fd921bf71 (MISP Attribute #94)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 884d46c01c762ad6ddd2759fd921bf71 (MISP Attribute #94)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad50-aea8-4d5f-8e0c-497a8e96ca05">
<cybox:Object id=":File-581bad50-aea8-4d5f-8e0c-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">884d46c01c762ad6ddd2759fd921bf71</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:22:25+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad50-a014-4095-a054-497a8e96ca05" timestamp="2016-11-10T16:22:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 56f0e67d981024ddcc215543698f44fb (MISP Attribute #95)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 56f0e67d981024ddcc215543698f44fb (MISP Attribute #95)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad50-a014-4095-a054-497a8e96ca05">
<cybox:Object id=":File-581bad50-a014-4095-a054-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">56f0e67d981024ddcc215543698f44fb</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:22:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad50-d494-4e55-aa91-497a8e96ca05" timestamp="2016-11-10T16:22:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 7e0081fba718fcd71753d3199a290f03 (MISP Attribute #96)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 7e0081fba718fcd71753d3199a290f03 (MISP Attribute #96)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad50-d494-4e55-aa91-497a8e96ca05">
<cybox:Object id=":File-581bad50-d494-4e55-aa91-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">7e0081fba718fcd71753d3199a290f03</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:22:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad50-8998-4012-926d-497a8e96ca05" timestamp="2016-11-10T16:23:13+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 5710d567d98a8f4a6682859ce3a35336 (MISP Attribute #97)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 5710d567d98a8f4a6682859ce3a35336 (MISP Attribute #97)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad50-8998-4012-926d-497a8e96ca05">
<cybox:Object id=":File-581bad50-8998-4012-926d-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">5710d567d98a8f4a6682859ce3a35336</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:23:13+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad50-7890-4dcf-8436-497a8e96ca05" timestamp="2016-11-10T16:23:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: cec071424d417a095221bf8992819388 (MISP Attribute #98)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: cec071424d417a095221bf8992819388 (MISP Attribute #98)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad50-7890-4dcf-8436-497a8e96ca05">
<cybox:Object id=":File-581bad50-7890-4dcf-8436-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">cec071424d417a095221bf8992819388</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:23:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad60-2a18-44cc-ac40-49798e96ca05" timestamp="2016-11-10T16:23:34+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 49ceba3347d39870f15f2ab0391af234 (MISP Attribute #99)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 49ceba3347d39870f15f2ab0391af234 (MISP Attribute #99)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad60-2a18-44cc-ac40-49798e96ca05">
<cybox:Object id=":File-581bad60-2a18-44cc-ac40-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">49ceba3347d39870f15f2ab0391af234</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:23:34+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5824e57b-8458-4669-b6a0-497a8e96ca05" timestamp="2016-11-10T16:24:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: wojiaojilao2@sohu.com (MISP Attribute #1876)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: wojiaojilao2@sohu.com (MISP Attribute #1876)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:24:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bacca-eb70-4443-a7d1-49798e96ca05" timestamp="2016-11-03T17:31:54+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: usafbi.websecexp.com (MISP Attribute #83)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: usafbi.websecexp.com (MISP Attribute #83)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bacca-eb70-4443-a7d1-49798e96ca05">
<cybox:Object id=":DomainName-581bacca-eb70-4443-a7d1-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">usafbi.websecexp.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:31:54+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bacca-464c-4997-8812-49798e96ca05" timestamp="2016-11-03T17:31:54+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: usacia.websecexp.com (MISP Attribute #84)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: usacia.websecexp.com (MISP Attribute #84)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bacca-464c-4997-8812-49798e96ca05">
<cybox:Object id=":DomainName-581bacca-464c-4997-8812-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">usacia.websecexp.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:31:54+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bacca-5998-41ad-afb4-49798e96ca05" timestamp="2016-11-03T17:31:54+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: webhttps.websecexp.com (MISP Attribute #85)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: webhttps.websecexp.com (MISP Attribute #85)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bacca-5998-41ad-afb4-49798e96ca05">
<cybox:Object id=":DomainName-581bacca-5998-41ad-afb4-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">webhttps.websecexp.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:31:54+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5824e58f-be40-407d-b91b-497a8e96ca05" timestamp="2016-11-10T16:24:31+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: iyouthen.com (MISP Attribute #1877)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: iyouthen.com (MISP Attribute #1877)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5824e58f-be40-407d-b91b-497a8e96ca05">
<cybox:Object id=":DomainName-5824e58f-be40-407d-b91b-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">iyouthen.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:24:31+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bacca-ad18-4ff6-b8b5-49798e96ca05" timestamp="2016-11-03T17:31:54+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: appeur.gnway.cc (MISP Attribute #86)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: appeur.gnway.cc (MISP Attribute #86)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bacca-ad18-4ff6-b8b5-49798e96ca05">
<cybox:Object id=":DomainName-581bacca-ad18-4ff6-b8b5-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">appeur.gnway.cc</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:31:54+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad77-2c58-479e-833e-497a8e96ca05" timestamp="2016-11-03T17:34:47+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: t1.mailsecurityservice.com (MISP Attribute #100)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: t1.mailsecurityservice.com (MISP Attribute #100)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad77-2c58-479e-833e-497a8e96ca05">
<cybox:Object id=":DomainName-581bad77-2c58-479e-833e-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">t1.mailsecurityservice.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:34:47+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad77-cde8-4c65-9449-497a8e96ca05" timestamp="2016-11-03T17:34:47+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: t2.mailsecurityservice.com (MISP Attribute #101)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: t2.mailsecurityservice.com (MISP Attribute #101)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad77-cde8-4c65-9449-497a8e96ca05">
<cybox:Object id=":DomainName-581bad77-cde8-4c65-9449-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">t2.mailsecurityservice.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:34:47+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad0a-7524-46f8-9d57-497a8e96ca05" timestamp="2016-11-03T17:32:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 198.44.190.85 (MISP Attribute #89)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 198.44.190.85 (MISP Attribute #89)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad0a-7524-46f8-9d57-497a8e96ca05">
<cybox:Object id=":Address-581bad0a-7524-46f8-9d57-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">198.44.190.85</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:32:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad2c-3a60-4be9-8d21-49798e96ca05" timestamp="2016-11-03T17:33:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 53f81415ccedf453d6e3ebcdc142b966 (MISP Attribute #90)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 53f81415ccedf453d6e3ebcdc142b966 (MISP Attribute #90)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad2c-3a60-4be9-8d21-49798e96ca05">
<cybox:Object id=":File-581bad2c-3a60-4be9-8d21-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">53f81415ccedf453d6e3ebcdc142b966</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:33:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad2c-e744-4a48-ae12-49798e96ca05" timestamp="2016-11-03T17:33:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 6701662097e274f3cd089ceec35471d2 (MISP Attribute #91)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 6701662097e274f3cd089ceec35471d2 (MISP Attribute #91)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad2c-e744-4a48-ae12-49798e96ca05">
<cybox:Object id=":File-581bad2c-e744-4a48-ae12-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">6701662097e274f3cd089ceec35471d2</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:33:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581bad2c-d2d4-46f4-b0cb-49798e96ca05" timestamp="2016-11-03T17:33:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 699b3d90b050cae37f65c855ec7f616a (MISP Attribute #92)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 699b3d90b050cae37f65c855ec7f616a (MISP Attribute #92)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-581bad2c-d2d4-46f4-b0cb-49798e96ca05">
<cybox:Object id=":File-581bad2c-d2d4-46f4-b0cb-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">699b3d90b050cae37f65c855ec7f616a</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-03T17:33:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5824e5f1-d174-487e-9156-497a8e96ca05" timestamp="2016-11-10T16:26:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe (MISP Attribute #1878)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe (MISP Attribute #1878)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5824e5f1-d174-487e-9156-497a8e96ca05">
<cybox:Object id=":URI-5824e5f1-d174-487e-9156-497a8e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:26:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:Leveraged_TTPs>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload type</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-581bace8-59d0-4c6e-859a-497a8e96ca05" timestamp="2016-11-03T17:32:24+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload type</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-581bacf2-d924-45bd-a930-49798e96ca05" timestamp="2016-11-03T17:32:34+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
</incident:Leveraged_TTPs>
<incident:History>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">Event Threat Level: High</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TLP:GREEN</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: SOURCE:CITIZENLAB</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: DETECT</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: PUBLISHED</incident:Journal_Entry>
</incident:History_Item>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
<stixCommon:References>
<stixCommon:Reference>https://citizenlab.org/2015/10/targeted-attacks-ngo-burma/</stixCommon:Reference>
</stixCommon:References>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>