Add Android forensics, IOC threat-intel DB, Compose companion; scrub secrets from configs

This commit is contained in:
SsSnake
2026-07-13 15:45:47 -07:00
parent 925216290f
commit e48d577bd5
387 changed files with 211976 additions and 921 deletions

View File

@@ -0,0 +1,8 @@
## Shifting Tactics IOCs
This directory contains IOC from the Citizen Lab report [Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetans](https://citizenlab.org/2016/03/shifting-tactics/) published the 10th of May 2016.
Files included in this directory:
* openioc.ioc : IOCs in OpenIOC format
* stix.xml : IOCs in STIX XML format
* iocs.csv : IOCs in csv format

View File

@@ -0,0 +1,37 @@
uuid,event_id,category,type,value,comment,to_ids,date
11bb35af-5ad7-4a10-844c-fb4482603b0b,11,Network activity,url,"http://accountgoogle.firewall-gateway.com/serviclogin","Decoy webpage",0,20160310
11cf9c54-4d35-4a58-8128-a1076025ff25,11,Network activity,domain,"sys.firewall-gateway.net","C2 domain",1,20160310
1f0bc371-f681-4049-855d-235e6bc5eb8e,11,Network activity,ip-dst,"5.54.19.17","",1,20160310
228f765c-d5ab-4fcf-a190-775b9ed2ad70,11,Network activity,domain,"firewallupdate.firewall-gateway.com","Domain found through passive DNS",1,20160310
23403344-c52e-4c19-9f7b-f5291b451bee,11,Payload delivery,md5,"fef27f432e0ae8218143bc410fda340e","",1,20160310
26fb914b-1601-4049-a8b5-c9afc3a16bc0,11,Network activity,domain,"accountgoogle.firewall-gateway.com","Phishing Campaign Infrastructure",1,20160310
318dd748-c9d9-4f7b-9b42-75a60001f9e1,11,Network activity,ip-dst,"95.154.195.171","",1,20160310
35a7486a-38a7-4d3a-bdd8-1284d464484b,11,Network activity,domain,"firewallupdate.firewall-gateway.net","Domain found through passive DNS",1,20160310
3baf841e-c377-44ba-ba20-dcfd7aa8ba22,11,Network activity,domain,"accounts-google.firewall-gateway.com","Domain found through passive DNS",1,20160310
40edc447-3aaa-4f79-8268-16eddff19b33,11,Network activity,domain,"accountsgoogles.firewall-gateway.com","Domain found through passive DNS",1,20160310
53477c01-59ad-47be-b808-4c6b518523fc,11,Network activity,ip-dst,"109.169.77.230","Resolve domain news[.]firewall-gateway[.]com",1,20160310
581c1169-35f8-439b-ad90-49798e96ca05,11,External analysis,link,"https://citizenlab.org/2016/03/shifting-tactics/","",0,20161104
5824e149-ba7c-4e04-b905-69fe8e96ca05,11,Artifacts dropped,md5,"ea45265fe98b25e719d5a9cc3b412d66","uroyh.exe",1,20160310
5824e1e5-e340-40b0-b3fa-69fe8e96ca05,11,Attribution,threat-actor,"Scarlet Mimic","",0,20160310
5824e33f-4c08-4b5f-8092-497a8e96ca05,11,Payload type,text,"FakeM","",0,20160310
6308d2e1-a83a-44b2-b96f-267bc24efbd1,11,Network activity,domain,"filegoogle.firewall-gateway.com","Phishing Campaign Infrastructure",1,20160310
633179a0-3d6e-4ca5-9b89-02d8522ef275,11,Payload delivery,filename,"Reappraisal_of_India_Tibet_Policy.doc","",0,20160310
6d15c4fe-2de7-4abc-9593-c9eeae9b928f,11,Payload delivery,md5,"3b869c8e23d66ad0527882fc79ff7237","",1,20160310
712c9cc1-2b2b-4636-87d2-12bd313376dc,11,Payload delivery,md5,"1bf438b5744db73eea58379a3b9f30e5","",1,20160310
73e5412a-1252-495d-956d-28cfdd8edaed,11,Network activity,domain,"news.firewall-gateway.com","",1,20160310
86627daf-07c8-467f-babc-426d586e7d4a,11,Network activity,domain,"detail43.myfirewall.org","",1,20160310
8b0a371b-0c73-455d-a7ae-d0a530f23b04,11,Network activity,domain,"drivgoogle.firewall-gateway.com","Domain found through passive DNS",1,20160310
8ce49cb3-e458-4568-b560-04a314ce9539,11,Network activity,ip-dst,"192.253.251.118","",1,20160310
99702482-486a-4b63-8fa9-f094835827b2,11,Payload delivery,md5,"5c030802ad411fea059cc9cc4c118125","uroyh-unpacked.exe",1,20160310
a31a03ec-f99e-4bec-95dc-3574c3512217,11,Network activity,ip-dst,"95.154.195.159","",1,20160310
a95b5c9c-7ec9-42ff-a12c-075b3255de77,11,Payload delivery,md5,"7735e571d0450e2a31e97e4f8e0f66fa","Attached file",1,20160310
ad5c4c3d-6194-4059-9aa1-1593b62d32a9,11,Network activity,ip-dst,"109.169.40.172","",1,20160310
b2cebdea-e90b-416f-9a0f-94a566b32a2a,11,Network activity,ip-dst,"46.127.56.109","",1,20160310
b84e33b7-1958-4507-b7bb-6bb63304842c,11,Network activity,domain,"googlefile.firewall-gateway.net","Domain found through passive DNS",1,20160310
baf16087-e811-438d-bcdd-9779043dfb06,11,Payload delivery,md5,"d2e9412428c3bcf3ec98dba8a78adb7b","iph.bat",1,20160310
c379b263-55d3-464d-b94f-178f02f883a8,11,Network activity,ip-dst,"87.117.229.109","",1,20160310
cda51492-e33b-4521-be3b-35ec4b8bc9b4,11,Network activity,url,"http://accountgoogle.firewall-gateway.com/servicclogin","Decoy webpage",0,20160310
dbabd2ee-213d-4b02-951f-a020cfc3582e,11,Payload delivery,md5,"8b83fc5d3a6a80281269f9e337fe3fff","pshvb.exe",1,20160310
ebbe87e2-7f84-4f68-b766-f63820da7966,11,Network activity,domain,"accountsgoogle.firewall-gateway.com","Domain found through passive DNS",1,20160310
f48470fd-c782-4831-a20d-4704b62f1358,11,Network activity,ip-dst,"78.129.252.159","",1,20160310
fc6d0f74-9e43-44a7-b7b8-0ca5c7c487e6,11,Network activity,url,"http://filegoogle.firewall-gateway.com/servicelogin","Decoy webpage",1,20160310
1 uuid event_id category type value comment to_ids date
2 11bb35af-5ad7-4a10-844c-fb4482603b0b 11 Network activity url http://accountgoogle.firewall-gateway.com/serviclogin Decoy webpage 0 20160310
3 11cf9c54-4d35-4a58-8128-a1076025ff25 11 Network activity domain sys.firewall-gateway.net C2 domain 1 20160310
4 1f0bc371-f681-4049-855d-235e6bc5eb8e 11 Network activity ip-dst 5.54.19.17 1 20160310
5 228f765c-d5ab-4fcf-a190-775b9ed2ad70 11 Network activity domain firewallupdate.firewall-gateway.com Domain found through passive DNS 1 20160310
6 23403344-c52e-4c19-9f7b-f5291b451bee 11 Payload delivery md5 fef27f432e0ae8218143bc410fda340e 1 20160310
7 26fb914b-1601-4049-a8b5-c9afc3a16bc0 11 Network activity domain accountgoogle.firewall-gateway.com Phishing Campaign Infrastructure 1 20160310
8 318dd748-c9d9-4f7b-9b42-75a60001f9e1 11 Network activity ip-dst 95.154.195.171 1 20160310
9 35a7486a-38a7-4d3a-bdd8-1284d464484b 11 Network activity domain firewallupdate.firewall-gateway.net Domain found through passive DNS 1 20160310
10 3baf841e-c377-44ba-ba20-dcfd7aa8ba22 11 Network activity domain accounts-google.firewall-gateway.com Domain found through passive DNS 1 20160310
11 40edc447-3aaa-4f79-8268-16eddff19b33 11 Network activity domain accountsgoogles.firewall-gateway.com Domain found through passive DNS 1 20160310
12 53477c01-59ad-47be-b808-4c6b518523fc 11 Network activity ip-dst 109.169.77.230 Resolve domain news[.]firewall-gateway[.]com 1 20160310
13 581c1169-35f8-439b-ad90-49798e96ca05 11 External analysis link https://citizenlab.org/2016/03/shifting-tactics/ 0 20161104
14 5824e149-ba7c-4e04-b905-69fe8e96ca05 11 Artifacts dropped md5 ea45265fe98b25e719d5a9cc3b412d66 uroyh.exe 1 20160310
15 5824e1e5-e340-40b0-b3fa-69fe8e96ca05 11 Attribution threat-actor Scarlet Mimic 0 20160310
16 5824e33f-4c08-4b5f-8092-497a8e96ca05 11 Payload type text FakeM 0 20160310
17 6308d2e1-a83a-44b2-b96f-267bc24efbd1 11 Network activity domain filegoogle.firewall-gateway.com Phishing Campaign Infrastructure 1 20160310
18 633179a0-3d6e-4ca5-9b89-02d8522ef275 11 Payload delivery filename Reappraisal_of_India_Tibet_Policy.doc 0 20160310
19 6d15c4fe-2de7-4abc-9593-c9eeae9b928f 11 Payload delivery md5 3b869c8e23d66ad0527882fc79ff7237 1 20160310
20 712c9cc1-2b2b-4636-87d2-12bd313376dc 11 Payload delivery md5 1bf438b5744db73eea58379a3b9f30e5 1 20160310
21 73e5412a-1252-495d-956d-28cfdd8edaed 11 Network activity domain news.firewall-gateway.com 1 20160310
22 86627daf-07c8-467f-babc-426d586e7d4a 11 Network activity domain detail43.myfirewall.org 1 20160310
23 8b0a371b-0c73-455d-a7ae-d0a530f23b04 11 Network activity domain drivgoogle.firewall-gateway.com Domain found through passive DNS 1 20160310
24 8ce49cb3-e458-4568-b560-04a314ce9539 11 Network activity ip-dst 192.253.251.118 1 20160310
25 99702482-486a-4b63-8fa9-f094835827b2 11 Payload delivery md5 5c030802ad411fea059cc9cc4c118125 uroyh-unpacked.exe 1 20160310
26 a31a03ec-f99e-4bec-95dc-3574c3512217 11 Network activity ip-dst 95.154.195.159 1 20160310
27 a95b5c9c-7ec9-42ff-a12c-075b3255de77 11 Payload delivery md5 7735e571d0450e2a31e97e4f8e0f66fa Attached file 1 20160310
28 ad5c4c3d-6194-4059-9aa1-1593b62d32a9 11 Network activity ip-dst 109.169.40.172 1 20160310
29 b2cebdea-e90b-416f-9a0f-94a566b32a2a 11 Network activity ip-dst 46.127.56.109 1 20160310
30 b84e33b7-1958-4507-b7bb-6bb63304842c 11 Network activity domain googlefile.firewall-gateway.net Domain found through passive DNS 1 20160310
31 baf16087-e811-438d-bcdd-9779043dfb06 11 Payload delivery md5 d2e9412428c3bcf3ec98dba8a78adb7b iph.bat 1 20160310
32 c379b263-55d3-464d-b94f-178f02f883a8 11 Network activity ip-dst 87.117.229.109 1 20160310
33 cda51492-e33b-4521-be3b-35ec4b8bc9b4 11 Network activity url http://accountgoogle.firewall-gateway.com/servicclogin Decoy webpage 0 20160310
34 dbabd2ee-213d-4b02-951f-a020cfc3582e 11 Payload delivery md5 8b83fc5d3a6a80281269f9e337fe3fff pshvb.exe 1 20160310
35 ebbe87e2-7f84-4f68-b766-f63820da7966 11 Network activity domain accountsgoogle.firewall-gateway.com Domain found through passive DNS 1 20160310
36 f48470fd-c782-4831-a20d-4704b62f1358 11 Network activity ip-dst 78.129.252.159 1 20160310
37 fc6d0f74-9e43-44a7-b7b8-0ca5c7c487e6 11 Network activity url http://filegoogle.firewall-gateway.com/servicelogin Decoy webpage 1 20160310

View File

@@ -0,0 +1,133 @@
<?xml version="1.0" encoding="utf-8"?>
<ioc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" id="581c1131-3fec-4068-bb74-49798e96ca05" last-modified="2016-03-10T00:00:00" xmlns="http://schemas.mandiant.com/2010/ioc">
<short_description>Event #11</short_description>
<description>Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetans</description>
<keywords />
<authored_by>citizenlab</authored_by>
<authored_date>2016-03-10T00:00:00</authored_date>
<links />
<definition>
<Indicator operator="OR" id="581c1131-3fec-4068-bb74-49798e96ca05">
<IndicatorItem id="ea45265fe98b25e719d5a9cc3b412d66" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="filegoogle.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="accountgoogle.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="sys.firewall-gateway.net" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="news.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="accountsgoogle.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="accounts-google.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="accountsgoogles.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="googlefile.firewall-gateway.net" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="firewallupdate.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="firewallupdate.firewall-gateway.net" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="drivgoogle.firewall-gateway.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="detail43.myfirewall.org" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="95.154.195.159" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="95.154.195.171" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="5.54.19.17" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="78.129.252.159" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="87.117.229.109" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="109.169.40.172" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="46.127.56.109" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="192.253.251.118" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="109.169.77.230" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="http://filegoogle.firewall-gateway.com/servicelogin" condition="is">
<Context document="UrlHistoryItem" search="UrlHistoryItem/URL" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="5c030802ad411fea059cc9cc4c118125" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="7735e571d0450e2a31e97e4f8e0f66fa" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="d2e9412428c3bcf3ec98dba8a78adb7b" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="1bf438b5744db73eea58379a3b9f30e5" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="3b869c8e23d66ad0527882fc79ff7237" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="fef27f432e0ae8218143bc410fda340e" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
<IndicatorItem id="8b83fc5d3a6a80281269f9e337fe3fff" condition="is">
<Context document="FileItem" search="FileItem/Md5sum" type="mir" />
<Content type="md5"></Content>
</IndicatorItem>
</Indicator>
</definition>
</ioc>

View File

@@ -0,0 +1,982 @@
<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:="https://rufus.citlab.utoronto.ca"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-dab87d63-6901-4da5-b7ba-2088de90f322" version="1.1.1" timestamp="2016-11-10T21:17:23.793648+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-581c1131-3fec-4068-bb74-49798e96ca05" version="1.1.1" timestamp="2016-11-10T16:14:39+00:00">
<stix:STIX_Header>
<stix:Title>Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetans (MISP Event #11)</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:TTPs>
<stix:TTP id=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload type: FakeM (MISP Attribute #1875)</ttp:Title>
<ttp:Behavior>
<ttp:Malware>
<ttp:Malware_Instance>
<ttp:Name>FakeM</ttp:Name>
</ttp:Malware_Instance>
</ttp:Malware>
</ttp:Behavior>
</stix:TTP>
</stix:TTPs>
<stix:Incidents>
<stix:Incident id=":incident-581c1131-3fec-4068-bb74-49798e96ca05" timestamp="2016-11-10T16:15:08+00:00" xsi:type='incident:IncidentType'>
<incident:Title>Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetans</incident:Title>
<incident:External_ID source="MISP Event">11</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2016-03-10T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2016-11-10T16:15:08+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">Closed</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5824e149-ba7c-4e04-b905-69fe8e96ca05" timestamp="2016-11-10T16:06:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: ea45265fe98b25e719d5a9cc3b412d66 (MISP Attribute #1873)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: ea45265fe98b25e719d5a9cc3b412d66 (MISP Attribute #1873)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5824e149-ba7c-4e04-b905-69fe8e96ca05">
<cybox:Object id=":File-5824e149-ba7c-4e04-b905-69fe8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">ea45265fe98b25e719d5a9cc3b412d66</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:06:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5824e1e5-e340-40b0-b3fa-69fe8e96ca05" timestamp="2016-11-10T16:08:53+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: Scarlet Mimic (MISP Attribute #1874)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: Scarlet Mimic (MISP Attribute #1874)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:08:53+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-6308d2e1-a83a-44b2-b96f-267bc24efbd1" timestamp="2016-11-10T16:07:04+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: filegoogle.firewall-gateway.com (MISP Attribute #499)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: filegoogle.firewall-gateway.com (MISP Attribute #499)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-6308d2e1-a83a-44b2-b96f-267bc24efbd1">
<cybox:Object id=":DomainName-6308d2e1-a83a-44b2-b96f-267bc24efbd1">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">filegoogle.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:07:04+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-26fb914b-1601-4049-a8b5-c9afc3a16bc0" timestamp="2016-11-10T16:07:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accountgoogle.firewall-gateway.com (MISP Attribute #500)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accountgoogle.firewall-gateway.com (MISP Attribute #500)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-26fb914b-1601-4049-a8b5-c9afc3a16bc0">
<cybox:Object id=":DomainName-26fb914b-1601-4049-a8b5-c9afc3a16bc0">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accountgoogle.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:07:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-11cf9c54-4d35-4a58-8128-a1076025ff25" timestamp="2016-11-10T16:06:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: sys.firewall-gateway.net (MISP Attribute #501)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: sys.firewall-gateway.net (MISP Attribute #501)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-11cf9c54-4d35-4a58-8128-a1076025ff25">
<cybox:Object id=":DomainName-11cf9c54-4d35-4a58-8128-a1076025ff25">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">sys.firewall-gateway.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:06:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-73e5412a-1252-495d-956d-28cfdd8edaed" timestamp="2016-11-10T16:04:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: news.firewall-gateway.com (MISP Attribute #502)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: news.firewall-gateway.com (MISP Attribute #502)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-73e5412a-1252-495d-956d-28cfdd8edaed">
<cybox:Object id=":DomainName-73e5412a-1252-495d-956d-28cfdd8edaed">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">news.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:04:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-ebbe87e2-7f84-4f68-b766-f63820da7966" timestamp="2016-11-10T16:09:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accountsgoogle.firewall-gateway.com (MISP Attribute #503)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accountsgoogle.firewall-gateway.com (MISP Attribute #503)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-ebbe87e2-7f84-4f68-b766-f63820da7966">
<cybox:Object id=":DomainName-ebbe87e2-7f84-4f68-b766-f63820da7966">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accountsgoogle.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-3baf841e-c377-44ba-ba20-dcfd7aa8ba22" timestamp="2016-11-10T16:09:27+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-google.firewall-gateway.com (MISP Attribute #504)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-google.firewall-gateway.com (MISP Attribute #504)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-3baf841e-c377-44ba-ba20-dcfd7aa8ba22">
<cybox:Object id=":DomainName-3baf841e-c377-44ba-ba20-dcfd7aa8ba22">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-google.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:27+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-40edc447-3aaa-4f79-8268-16eddff19b33" timestamp="2016-11-10T16:09:38+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accountsgoogles.firewall-gateway.com (MISP Attribute #505)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accountsgoogles.firewall-gateway.com (MISP Attribute #505)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-40edc447-3aaa-4f79-8268-16eddff19b33">
<cybox:Object id=":DomainName-40edc447-3aaa-4f79-8268-16eddff19b33">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accountsgoogles.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:38+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-b84e33b7-1958-4507-b7bb-6bb63304842c" timestamp="2016-11-10T16:09:47+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: googlefile.firewall-gateway.net (MISP Attribute #506)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: googlefile.firewall-gateway.net (MISP Attribute #506)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-b84e33b7-1958-4507-b7bb-6bb63304842c">
<cybox:Object id=":DomainName-b84e33b7-1958-4507-b7bb-6bb63304842c">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">googlefile.firewall-gateway.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:47+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-228f765c-d5ab-4fcf-a190-775b9ed2ad70" timestamp="2016-11-10T16:09:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: firewallupdate.firewall-gateway.com (MISP Attribute #507)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: firewallupdate.firewall-gateway.com (MISP Attribute #507)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-228f765c-d5ab-4fcf-a190-775b9ed2ad70">
<cybox:Object id=":DomainName-228f765c-d5ab-4fcf-a190-775b9ed2ad70">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">firewallupdate.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-35a7486a-38a7-4d3a-bdd8-1284d464484b" timestamp="2016-11-10T16:10:06+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: firewallupdate.firewall-gateway.net (MISP Attribute #508)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: firewallupdate.firewall-gateway.net (MISP Attribute #508)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-35a7486a-38a7-4d3a-bdd8-1284d464484b">
<cybox:Object id=":DomainName-35a7486a-38a7-4d3a-bdd8-1284d464484b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">firewallupdate.firewall-gateway.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:10:06+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-8b0a371b-0c73-455d-a7ae-d0a530f23b04" timestamp="2016-11-10T16:10:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drivgoogle.firewall-gateway.com (MISP Attribute #509)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drivgoogle.firewall-gateway.com (MISP Attribute #509)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-8b0a371b-0c73-455d-a7ae-d0a530f23b04">
<cybox:Object id=":DomainName-8b0a371b-0c73-455d-a7ae-d0a530f23b04">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drivgoogle.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:10:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-86627daf-07c8-467f-babc-426d586e7d4a" timestamp="2016-11-10T16:05:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: detail43.myfirewall.org (MISP Attribute #510)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: detail43.myfirewall.org (MISP Attribute #510)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-86627daf-07c8-467f-babc-426d586e7d4a">
<cybox:Object id=":DomainName-86627daf-07c8-467f-babc-426d586e7d4a">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">detail43.myfirewall.org</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-a31a03ec-f99e-4bec-95dc-3574c3512217" timestamp="2016-11-10T16:11:07+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 95.154.195.159 (MISP Attribute #512)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 95.154.195.159 (MISP Attribute #512)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-a31a03ec-f99e-4bec-95dc-3574c3512217">
<cybox:Object id=":Address-a31a03ec-f99e-4bec-95dc-3574c3512217">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">95.154.195.159</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:11:07+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-318dd748-c9d9-4f7b-9b42-75a60001f9e1" timestamp="2016-11-10T16:11:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 95.154.195.171 (MISP Attribute #513)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 95.154.195.171 (MISP Attribute #513)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-318dd748-c9d9-4f7b-9b42-75a60001f9e1">
<cybox:Object id=":Address-318dd748-c9d9-4f7b-9b42-75a60001f9e1">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">95.154.195.171</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:11:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-1f0bc371-f681-4049-855d-235e6bc5eb8e" timestamp="2016-11-10T16:11:20+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 5.54.19.17 (MISP Attribute #514)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 5.54.19.17 (MISP Attribute #514)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-1f0bc371-f681-4049-855d-235e6bc5eb8e">
<cybox:Object id=":Address-1f0bc371-f681-4049-855d-235e6bc5eb8e">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">5.54.19.17</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:11:20+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-f48470fd-c782-4831-a20d-4704b62f1358" timestamp="2016-11-10T16:12:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 78.129.252.159 (MISP Attribute #515)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 78.129.252.159 (MISP Attribute #515)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-f48470fd-c782-4831-a20d-4704b62f1358">
<cybox:Object id=":Address-f48470fd-c782-4831-a20d-4704b62f1358">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">78.129.252.159</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-c379b263-55d3-464d-b94f-178f02f883a8" timestamp="2016-11-10T16:12:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 87.117.229.109 (MISP Attribute #516)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 87.117.229.109 (MISP Attribute #516)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-c379b263-55d3-464d-b94f-178f02f883a8">
<cybox:Object id=":Address-c379b263-55d3-464d-b94f-178f02f883a8">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">87.117.229.109</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-ad5c4c3d-6194-4059-9aa1-1593b62d32a9" timestamp="2016-11-10T16:13:04+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 109.169.40.172 (MISP Attribute #517)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 109.169.40.172 (MISP Attribute #517)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-ad5c4c3d-6194-4059-9aa1-1593b62d32a9">
<cybox:Object id=":Address-ad5c4c3d-6194-4059-9aa1-1593b62d32a9">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">109.169.40.172</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:13:04+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-b2cebdea-e90b-416f-9a0f-94a566b32a2a" timestamp="2016-11-10T16:13:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 46.127.56.109 (MISP Attribute #518)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 46.127.56.109 (MISP Attribute #518)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-b2cebdea-e90b-416f-9a0f-94a566b32a2a">
<cybox:Object id=":Address-b2cebdea-e90b-416f-9a0f-94a566b32a2a">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">46.127.56.109</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:13:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-8ce49cb3-e458-4568-b560-04a314ce9539" timestamp="2016-11-10T16:13:20+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 192.253.251.118 (MISP Attribute #519)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 192.253.251.118 (MISP Attribute #519)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-8ce49cb3-e458-4568-b560-04a314ce9539">
<cybox:Object id=":Address-8ce49cb3-e458-4568-b560-04a314ce9539">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">192.253.251.118</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:13:20+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-53477c01-59ad-47be-b808-4c6b518523fc" timestamp="2016-11-10T16:08:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 109.169.77.230 (MISP Attribute #511)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 109.169.77.230 (MISP Attribute #511)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-53477c01-59ad-47be-b808-4c6b518523fc">
<cybox:Object id=":Address-53477c01-59ad-47be-b808-4c6b518523fc">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">109.169.77.230</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:08:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-fc6d0f74-9e43-44a7-b7b8-0ca5c7c487e6" timestamp="2016-11-10T16:12:23+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://filegoogle.firewall-gateway.com/servicelogin (MISP Attribute #520)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://filegoogle.firewall-gateway.com/servicelogin (MISP Attribute #520)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-fc6d0f74-9e43-44a7-b7b8-0ca5c7c487e6">
<cybox:Object id=":URI-fc6d0f74-9e43-44a7-b7b8-0ca5c7c487e6">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://filegoogle.firewall-gateway.com/servicelogin</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:23+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-11bb35af-5ad7-4a10-844c-fb4482603b0b" timestamp="2016-11-10T16:12:41+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://accountgoogle.firewall-gateway.com/serviclogin (MISP Attribute #521)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://accountgoogle.firewall-gateway.com/serviclogin (MISP Attribute #521)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-11bb35af-5ad7-4a10-844c-fb4482603b0b">
<cybox:Object id=":URI-11bb35af-5ad7-4a10-844c-fb4482603b0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://accountgoogle.firewall-gateway.com/serviclogin</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:41+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-cda51492-e33b-4521-be3b-35ec4b8bc9b4" timestamp="2016-11-10T16:12:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://accountgoogle.firewall-gateway.com/servicclogin (MISP Attribute #522)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://accountgoogle.firewall-gateway.com/servicclogin (MISP Attribute #522)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-cda51492-e33b-4521-be3b-35ec4b8bc9b4">
<cybox:Object id=":URI-cda51492-e33b-4521-be3b-35ec4b8bc9b4">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://accountgoogle.firewall-gateway.com/servicclogin</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-633179a0-3d6e-4ca5-9b89-02d8522ef275" timestamp="2016-11-10T16:10:34+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: Reappraisal_of_India_Tibet_Policy.doc (MISP Attribute #530)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Payload delivery: Reappraisal_of_India_Tibet_Policy.doc (MISP Attribute #530)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:10:34+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-99702482-486a-4b63-8fa9-f094835827b2" timestamp="2016-11-10T16:06:29+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 5c030802ad411fea059cc9cc4c118125 (MISP Attribute #531)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 5c030802ad411fea059cc9cc4c118125 (MISP Attribute #531)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-99702482-486a-4b63-8fa9-f094835827b2">
<cybox:Object id=":File-99702482-486a-4b63-8fa9-f094835827b2">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">5c030802ad411fea059cc9cc4c118125</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:06:29+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-a95b5c9c-7ec9-42ff-a12c-075b3255de77" timestamp="2016-11-10T16:05:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 7735e571d0450e2a31e97e4f8e0f66fa (MISP Attribute #532)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 7735e571d0450e2a31e97e4f8e0f66fa (MISP Attribute #532)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-a95b5c9c-7ec9-42ff-a12c-075b3255de77">
<cybox:Object id=":File-a95b5c9c-7ec9-42ff-a12c-075b3255de77">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">7735e571d0450e2a31e97e4f8e0f66fa</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-baf16087-e811-438d-bcdd-9779043dfb06" timestamp="2016-11-10T16:05:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: d2e9412428c3bcf3ec98dba8a78adb7b (MISP Attribute #533)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: d2e9412428c3bcf3ec98dba8a78adb7b (MISP Attribute #533)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-baf16087-e811-438d-bcdd-9779043dfb06">
<cybox:Object id=":File-baf16087-e811-438d-bcdd-9779043dfb06">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">d2e9412428c3bcf3ec98dba8a78adb7b</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-712c9cc1-2b2b-4636-87d2-12bd313376dc" timestamp="2016-11-10T16:05:20+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 1bf438b5744db73eea58379a3b9f30e5 (MISP Attribute #534)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 1bf438b5744db73eea58379a3b9f30e5 (MISP Attribute #534)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-712c9cc1-2b2b-4636-87d2-12bd313376dc">
<cybox:Object id=":File-712c9cc1-2b2b-4636-87d2-12bd313376dc">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">1bf438b5744db73eea58379a3b9f30e5</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:20+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-6d15c4fe-2de7-4abc-9593-c9eeae9b928f" timestamp="2016-11-10T16:05:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 3b869c8e23d66ad0527882fc79ff7237 (MISP Attribute #535)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 3b869c8e23d66ad0527882fc79ff7237 (MISP Attribute #535)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-6d15c4fe-2de7-4abc-9593-c9eeae9b928f">
<cybox:Object id=":File-6d15c4fe-2de7-4abc-9593-c9eeae9b928f">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">3b869c8e23d66ad0527882fc79ff7237</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-23403344-c52e-4c19-9f7b-f5291b451bee" timestamp="2016-11-10T16:04:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: fef27f432e0ae8218143bc410fda340e (MISP Attribute #536)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: fef27f432e0ae8218143bc410fda340e (MISP Attribute #536)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-23403344-c52e-4c19-9f7b-f5291b451bee">
<cybox:Object id=":File-23403344-c52e-4c19-9f7b-f5291b451bee">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">fef27f432e0ae8218143bc410fda340e</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:04:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-dbabd2ee-213d-4b02-951f-a020cfc3582e" timestamp="2016-11-10T16:07:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 8b83fc5d3a6a80281269f9e337fe3fff (MISP Attribute #537)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 8b83fc5d3a6a80281269f9e337fe3fff (MISP Attribute #537)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-dbabd2ee-213d-4b02-951f-a020cfc3582e">
<cybox:Object id=":File-dbabd2ee-213d-4b02-951f-a020cfc3582e">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">8b83fc5d3a6a80281269f9e337fe3fff</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:07:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:Leveraged_TTPs>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload type</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
</incident:Leveraged_TTPs>
<incident:History>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">Event Threat Level: Medium</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TLP:GREEN</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: SOURCE:CITIZENLAB</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: DETECT</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: PUBLISHED</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TARGET:TIBETAN</incident:Journal_Entry>
</incident:History_Item>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
<stixCommon:References>
<stixCommon:Reference>https://citizenlab.org/2016/03/shifting-tactics/</stixCommon:Reference>
</stixCommon:References>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>