@@ -0,0 +1,844 @@
<stix:STIX_Package
xmlns:cyboxCommon= "http://cybox.mitre.org/common-2"
xmlns:cybox= "http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs= "http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj= "http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj= "http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj= "http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj= "http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj= "http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj= "http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj= "http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj= "http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj= "http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj= "http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj= "http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking= "http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking= "http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et= "http://stix.mitre.org/ExploitTarget-1"
xmlns:incident= "http://stix.mitre.org/Incident-1"
xmlns:indicator= "http://stix.mitre.org/Indicator-2"
xmlns:ttp= "http://stix.mitre.org/TTP-1"
xmlns:ta= "http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon= "http://stix.mitre.org/common-1"
xmlns:stixVocabs= "http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity= "http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM= "http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix= "http://stix.mitre.org/stix-1"
xmlns:xsi= "http://www.w3.org/2001/XMLSchema-instance"
xmlns:= "https://rufus.citlab.utoronto.ca"
xmlns:xal= "urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl= "urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil= "urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation= "
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id= ":Package-7e377b3f-5c5a-403a-9575-64593685b0a8" version= "1.1.1" timestamp= "2016-11-08T21:57:05.578284+00:00" >
<stix:STIX_Header >
<stix:Title > Export from MISP</stix:Title>
<stix:Package_Intent xsi:type= "stixVocabs:PackageIntentVocab-1.0" > Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages >
<stix:Related_Package >
<stix:Package id= ":STIXPackage-581c05a7-1888-402a-b435-49798e96ca05" version= "1.1.1" timestamp= "2016-11-08T16:56:04+00:00" >
<stix:STIX_Header >
<stix:Title > Keep Calm and (Don’ t) Enable Macros: A New Threat Actor Targets UAE Dissidents (MISP Event #8)</stix:Title>
<stix:Package_Intent xsi:type= "stixVocabs:PackageIntentVocab-1.0" > Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Incidents >
<stix:Incident id= ":incident-581c05a7-1888-402a-b435-49798e96ca05" timestamp= "2016-11-08T16:56:19+00:00" xsi:type= 'incident:IncidentType' >
<incident:Title > Keep Calm and (Don’ t) Enable Macros: A New Threat Actor Targets UAE Dissidents</incident:Title>
<incident:External_ID source= "MISP Event" > 8</incident:External_ID>
<incident:Time >
<incident:Incident_Discovery precision= "second" > 2016-05-29T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision= "second" > 2016-11-08T16:56:19+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type= "stixVocabs:IncidentStatusVocab-1.0" > Closed</incident:Status>
<incident:Related_Indicators >
<incident:Related_Indicator >
<stixCommon:Relationship > Attribution</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-58224765-51f8-4d28-9040-49798e96ca05" timestamp= "2016-11-08T16:45:09+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Attribution: Stealth Falcon (MISP Attribute #1354)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Description > Attribution: Stealth Falcon (MISP Attribute #1354)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Confidence timestamp= "2016-11-08T16:45:09+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-5822492e-087c-4fa8-afe1-49798e96ca05" timestamp= "2016-11-08T16:52:46+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: simpleadbanners.com (MISP Attribute #1358)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Domain Watchlist</indicator:Type>
<indicator:Description > Network activity: simpleadbanners.com (MISP Attribute #1358)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-5822492e-087c-4fa8-afe1-49798e96ca05" >
<cybox:Object id= ":DomainName-5822492e-087c-4fa8-afe1-49798e96ca05" >
<cybox:Properties xsi:type= "DomainNameObj:DomainNameObjectType" >
<DomainNameObj:Value condition= "Equals" > simpleadbanners.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:52:46+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-5822492e-1d40-4098-a87b-49798e96ca05" timestamp= "2016-11-08T16:52:46+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: clickstatistic.com (MISP Attribute #1359)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Domain Watchlist</indicator:Type>
<indicator:Description > Network activity: clickstatistic.com (MISP Attribute #1359)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-5822492e-1d40-4098-a87b-49798e96ca05" >
<cybox:Object id= ":DomainName-5822492e-1d40-4098-a87b-49798e96ca05" >
<cybox:Properties xsi:type= "DomainNameObj:DomainNameObjectType" >
<DomainNameObj:Value condition= "Equals" > clickstatistic.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:52:46+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-5822492e-7490-4c3f-9a10-49798e96ca05" timestamp= "2016-11-08T16:52:46+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: bestairlinepricetags.com (MISP Attribute #1360)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Domain Watchlist</indicator:Type>
<indicator:Description > Network activity: bestairlinepricetags.com (MISP Attribute #1360)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-5822492e-7490-4c3f-9a10-49798e96ca05" >
<cybox:Object id= ":DomainName-5822492e-7490-4c3f-9a10-49798e96ca05" >
<cybox:Properties xsi:type= "DomainNameObj:DomainNameObjectType" >
<DomainNameObj:Value condition= "Equals" > bestairlinepricetags.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:52:46+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-5822492e-d888-418e-906d-49798e96ca05" timestamp= "2016-11-08T16:52:46+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: fasttravelclearance.com (MISP Attribute #1361)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Domain Watchlist</indicator:Type>
<indicator:Description > Network activity: fasttravelclearance.com (MISP Attribute #1361)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-5822492e-d888-418e-906d-49798e96ca05" >
<cybox:Object id= ":DomainName-5822492e-d888-418e-906d-49798e96ca05" >
<cybox:Properties xsi:type= "DomainNameObj:DomainNameObjectType" >
<DomainNameObj:Value condition= "Equals" > fasttravelclearance.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:52:46+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-5822494d-792c-4d8c-9be0-49798e96ca05" timestamp= "2016-11-08T16:53:17+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: airlineadverts.com (MISP Attribute #1362)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Domain Watchlist</indicator:Type>
<indicator:Description > Network activity: airlineadverts.com (MISP Attribute #1362)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-5822494d-792c-4d8c-9be0-49798e96ca05" >
<cybox:Object id= ":DomainName-5822494d-792c-4d8c-9be0-49798e96ca05" >
<cybox:Properties xsi:type= "DomainNameObj:DomainNameObjectType" >
<DomainNameObj:Value condition= "Equals" > airlineadverts.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:53:17+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-5822494d-7ab0-42bd-bd9d-49798e96ca05" timestamp= "2016-11-08T16:53:17+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: ministrynewschannel.com (MISP Attribute #1363)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Domain Watchlist</indicator:Type>
<indicator:Description > Network activity: ministrynewschannel.com (MISP Attribute #1363)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-5822494d-7ab0-42bd-bd9d-49798e96ca05" >
<cybox:Object id= ":DomainName-5822494d-7ab0-42bd-bd9d-49798e96ca05" >
<cybox:Properties xsi:type= "DomainNameObj:DomainNameObjectType" >
<DomainNameObj:Value condition= "Equals" > ministrynewschannel.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:53:17+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-5822494d-bf14-4b41-803a-49798e96ca05" timestamp= "2016-11-08T16:53:17+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: ministrynewsinfo.com (MISP Attribute #1364)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Domain Watchlist</indicator:Type>
<indicator:Description > Network activity: ministrynewsinfo.com (MISP Attribute #1364)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-5822494d-bf14-4b41-803a-49798e96ca05" >
<cybox:Object id= ":DomainName-5822494d-bf14-4b41-803a-49798e96ca05" >
<cybox:Properties xsi:type= "DomainNameObj:DomainNameObjectType" >
<DomainNameObj:Value condition= "Equals" > ministrynewsinfo.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:53:17+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-3813bc78-21d9-40a2-b76e-61016eb71ccb" timestamp= "2016-11-08T16:48:19+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: adhostingcache.com (MISP Attribute #425)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Domain Watchlist</indicator:Type>
<indicator:Description > Network activity: adhostingcache.com (MISP Attribute #425)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-3813bc78-21d9-40a2-b76e-61016eb71ccb" >
<cybox:Object id= ":DomainName-3813bc78-21d9-40a2-b76e-61016eb71ccb" >
<cybox:Properties xsi:type= "DomainNameObj:DomainNameObjectType" >
<DomainNameObj:Value condition= "Equals" > adhostingcache.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:48:19+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > High</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-d9a62cda-db4c-4d70-858c-6bbaaa041e63" timestamp= "2016-11-08T16:49:00+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: adhostingcaches.com (MISP Attribute #426)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Domain Watchlist</indicator:Type>
<indicator:Description > Network activity: adhostingcaches.com (MISP Attribute #426)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-d9a62cda-db4c-4d70-858c-6bbaaa041e63" >
<cybox:Object id= ":DomainName-d9a62cda-db4c-4d70-858c-6bbaaa041e63" >
<cybox:Properties xsi:type= "DomainNameObj:DomainNameObjectType" >
<DomainNameObj:Value condition= "Equals" > adhostingcaches.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:49:00+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > High</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-35aa025c-2f62-4f9d-9fb7-391542226a7a" timestamp= "2016-11-08T16:54:01+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: optimizedimghosting.com (MISP Attribute #427)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Domain Watchlist</indicator:Type>
<indicator:Description > Network activity: optimizedimghosting.com (MISP Attribute #427)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-35aa025c-2f62-4f9d-9fb7-391542226a7a" >
<cybox:Object id= ":DomainName-35aa025c-2f62-4f9d-9fb7-391542226a7a" >
<cybox:Properties xsi:type= "DomainNameObj:DomainNameObjectType" >
<DomainNameObj:Value condition= "Equals" > optimizedimghosting.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:54:01+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > High</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-8682a3ad-80da-4732-bf5a-e675e27c56fe" timestamp= "2016-11-08T16:54:09+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: edgecacheimagehosting.com (MISP Attribute #428)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Domain Watchlist</indicator:Type>
<indicator:Description > Network activity: edgecacheimagehosting.com (MISP Attribute #428)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-8682a3ad-80da-4732-bf5a-e675e27c56fe" >
<cybox:Object id= ":DomainName-8682a3ad-80da-4732-bf5a-e675e27c56fe" >
<cybox:Properties xsi:type= "DomainNameObj:DomainNameObjectType" >
<DomainNameObj:Value condition= "Equals" > edgecacheimagehosting.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:54:09+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > High</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-8010c934-027b-40c5-ba1e-3efca8e52d5a" timestamp= "2016-11-08T16:49:14+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: incapsulawebcache.com (MISP Attribute #429)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Domain Watchlist</indicator:Type>
<indicator:Description > Network activity: incapsulawebcache.com (MISP Attribute #429)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-8010c934-027b-40c5-ba1e-3efca8e52d5a" >
<cybox:Object id= ":DomainName-8010c934-027b-40c5-ba1e-3efca8e52d5a" >
<cybox:Properties xsi:type= "DomainNameObj:DomainNameObjectType" >
<DomainNameObj:Value condition= "Equals" > incapsulawebcache.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:49:14+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > High</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-45dbee97-3aa0-487d-bd73-a3c10a511403" timestamp= "2016-11-08T16:48:42+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: 95.215.44.37 (MISP Attribute #430)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > IP Watchlist</indicator:Type>
<indicator:Description > Network activity: 95.215.44.37 (MISP Attribute #430)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-45dbee97-3aa0-487d-bd73-a3c10a511403" >
<cybox:Object id= ":Address-45dbee97-3aa0-487d-bd73-a3c10a511403" >
<cybox:Properties xsi:type= "AddressObj:AddressObjectType" category= "ipv4-addr" is_source= "false" >
<AddressObj:Address_Value condition= "Equals" > 95.215.44.37</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:48:42+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-decfcbf1-1331-4624-88b7-a88c94637dd0" timestamp= "2016-11-08T16:55:41+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: http://adhostingcache.com/ehhe/eh4g4/adcache.txt (MISP Attribute #432)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > URL Watchlist</indicator:Type>
<indicator:Description > Network activity: http://adhostingcache.com/ehhe/eh4g4/adcache.txt (MISP Attribute #432)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-decfcbf1-1331-4624-88b7-a88c94637dd0" >
<cybox:Object id= ":URI-decfcbf1-1331-4624-88b7-a88c94637dd0" >
<cybox:Properties xsi:type= "URIObj:URIObjectType" >
<URIObj:Value condition= "Equals" > http://adhostingcache.com/ehhe/eh4g4/adcache.txt</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:55:41+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-7fd6e683-9615-4f4e-b901-03e7dbb81337" timestamp= "2016-11-08T16:49:23+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: https://incapsulawebcache.com/cache/cache.nfo (MISP Attribute #433)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > URL Watchlist</indicator:Type>
<indicator:Description > Network activity: https://incapsulawebcache.com/cache/cache.nfo (MISP Attribute #433)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-7fd6e683-9615-4f4e-b901-03e7dbb81337" >
<cybox:Object id= ":URI-7fd6e683-9615-4f4e-b901-03e7dbb81337" >
<cybox:Properties xsi:type= "URIObj:URIObjectType" >
<URIObj:Value condition= "Equals" > https://incapsulawebcache.com/cache/cache.nfo</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:49:23+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-e8f3b924-1221-4d08-8fef-f689529a7b6d" timestamp= "2016-11-08T16:49:42+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: http://aax.me/redirect.js (MISP Attribute #434)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > URL Watchlist</indicator:Type>
<indicator:Description > Network activity: http://aax.me/redirect.js (MISP Attribute #434)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-e8f3b924-1221-4d08-8fef-f689529a7b6d" >
<cybox:Object id= ":URI-e8f3b924-1221-4d08-8fef-f689529a7b6d" >
<cybox:Properties xsi:type= "URIObj:URIObjectType" >
<URIObj:Value condition= "Equals" > http://aax.me/redirect.js</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:49:42+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-537df72e-b2b9-4016-b337-06930c42c455" timestamp= "2016-11-08T16:50:51+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: http://goo.gl/60HAqJ (MISP Attribute #435)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > URL Watchlist</indicator:Type>
<indicator:Description > Network activity: http://goo.gl/60HAqJ (MISP Attribute #435)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-537df72e-b2b9-4016-b337-06930c42c455" >
<cybox:Object id= ":URI-537df72e-b2b9-4016-b337-06930c42c455" >
<cybox:Properties xsi:type= "URIObj:URIObjectType" >
<URIObj:Value condition= "Equals" > http://goo.gl/60HAqJ</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:50:51+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-007694f1-b73a-40a5-bcf5-dded27746669" timestamp= "2016-11-08T16:51:04+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: http://aax.me/0b152 (MISP Attribute #436)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > URL Watchlist</indicator:Type>
<indicator:Description > Network activity: http://aax.me/0b152 (MISP Attribute #436)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-007694f1-b73a-40a5-bcf5-dded27746669" >
<cybox:Object id= ":URI-007694f1-b73a-40a5-bcf5-dded27746669" >
<cybox:Properties xsi:type= "URIObj:URIObjectType" >
<URIObj:Value condition= "Equals" > http://aax.me/0b152</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:51:04+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-62fcd7b4-5d95-49bd-a9ff-3c2e1854839b" timestamp= "2016-11-08T16:55:52+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: http://optimizedimghosting.com/wddf/hrrw/ggrr.txt (MISP Attribute #437)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > URL Watchlist</indicator:Type>
<indicator:Description > Network activity: http://optimizedimghosting.com/wddf/hrrw/ggrr.txt (MISP Attribute #437)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-62fcd7b4-5d95-49bd-a9ff-3c2e1854839b" >
<cybox:Object id= ":URI-62fcd7b4-5d95-49bd-a9ff-3c2e1854839b" >
<cybox:Properties xsi:type= "URIObj:URIObjectType" >
<URIObj:Value condition= "Equals" > http://optimizedimghosting.com/wddf/hrrw/ggrr.txt</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:55:52+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Network activity</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-f0215c0c-b708-43d8-873e-80a3e8e54cfa" timestamp= "2016-11-08T16:56:04+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Network activity: https://edgecacheimagehosting.com/images/image.nfo (MISP Attribute #438)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > URL Watchlist</indicator:Type>
<indicator:Description > Network activity: https://edgecacheimagehosting.com/images/image.nfo (MISP Attribute #438)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-f0215c0c-b708-43d8-873e-80a3e8e54cfa" >
<cybox:Object id= ":URI-f0215c0c-b708-43d8-873e-80a3e8e54cfa" >
<cybox:Properties xsi:type= "URIObj:URIObjectType" >
<URIObj:Value condition= "Equals" > https://edgecacheimagehosting.com/images/image.nfo</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:56:04+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-582247a8-11b4-4da0-9ca1-69fe8e96ca05" timestamp= "2016-11-08T16:46:16+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Payload delivery: aax.me (MISP Attribute #1355)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Domain Watchlist</indicator:Type>
<indicator:Description > Payload delivery: aax.me (MISP Attribute #1355)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-582247a8-11b4-4da0-9ca1-69fe8e96ca05" >
<cybox:Object id= ":DomainName-582247a8-11b4-4da0-9ca1-69fe8e96ca05" >
<cybox:Properties xsi:type= "DomainNameObj:DomainNameObjectType" >
<DomainNameObj:Value condition= "Equals" > aax.me</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:46:16+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > High</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-bc8e2ca7-cd3c-4205-9028-b8b106f12389" timestamp= "2016-11-08T16:45:32+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Payload delivery: the_right_to_fight@openmailbox.org (MISP Attribute #439)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malicious E-mail</indicator:Type>
<indicator:Description > Payload delivery: the_right_to_fight@openmailbox.org (MISP Attribute #439)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-bc8e2ca7-cd3c-4205-9028-b8b106f12389" >
<cybox:Object id= ":EmailMessage-bc8e2ca7-cd3c-4205-9028-b8b106f12389" >
<cybox:Properties xsi:type= "EmailMessageObj:EmailMessageObjectType" >
<EmailMessageObj:Header >
<EmailMessageObj:From xsi:type= "AddressObj:AddressObjectType" category= "e-mail" >
<AddressObj:Address_Value condition= "Equals" > the_right_to_fight@openmailbox.org</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:45:32+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-280056b8-69aa-432c-9826-6d5b820eb44e" timestamp= "2016-11-08T16:50:35+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Payload delivery: andrew.dwight389@outlook.com (MISP Attribute #440)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malicious E-mail</indicator:Type>
<indicator:Description > Payload delivery: andrew.dwight389@outlook.com (MISP Attribute #440)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-280056b8-69aa-432c-9826-6d5b820eb44e" >
<cybox:Object id= ":EmailMessage-280056b8-69aa-432c-9826-6d5b820eb44e" >
<cybox:Properties xsi:type= "EmailMessageObj:EmailMessageObjectType" >
<EmailMessageObj:Header >
<EmailMessageObj:From xsi:type= "AddressObj:AddressObjectType" category= "e-mail" >
<AddressObj:Address_Value condition= "Equals" > andrew.dwight389@outlook.com</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:50:35+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-f4f40c31-dd17-4dc6-baa3-6beb35c04c00" timestamp= "2016-11-08T16:47:46+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Payload delivery: 80e8ef78b9e28015cde4205aaa65da97 (MISP Attribute #441)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > File Hash Watchlist</indicator:Type>
<indicator:Description > Payload delivery: 80e8ef78b9e28015cde4205aaa65da97 (MISP Attribute #441)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-f4f40c31-dd17-4dc6-baa3-6beb35c04c00" >
<cybox:Object id= ":File-f4f40c31-dd17-4dc6-baa3-6beb35c04c00" >
<cybox:Properties xsi:type= "FileObj:FileObjectType" >
<FileObj:Hashes >
<cyboxCommon:Hash >
<cyboxCommon:Type condition= "Equals" xsi:type= "cyboxVocabs:HashNameVocab-1.0" > MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition= "Equals" > 80e8ef78b9e28015cde4205aaa65da97</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:47:46+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-9ca61973-d717-496a-a158-82d9b2e37965" timestamp= "2016-11-08T16:53:31+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Payload delivery: 87e1df6f36b96b56186444e37e2a1ef5 (MISP Attribute #442)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > File Hash Watchlist</indicator:Type>
<indicator:Description > Payload delivery: 87e1df6f36b96b56186444e37e2a1ef5 (MISP Attribute #442)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-9ca61973-d717-496a-a158-82d9b2e37965" >
<cybox:Object id= ":File-9ca61973-d717-496a-a158-82d9b2e37965" >
<cybox:Properties xsi:type= "FileObj:FileObjectType" >
<FileObj:Hashes >
<cyboxCommon:Hash >
<cyboxCommon:Type condition= "Equals" xsi:type= "cyboxVocabs:HashNameVocab-1.0" > MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition= "Equals" > 87e1df6f36b96b56186444e37e2a1ef5</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:53:31+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-cd191e4e-a5a1-4009-93b7-92cc6a3d6984" timestamp= "2016-11-08T16:47:54+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Payload delivery: f25466e4820404c817eaf75818b7177891735886 (MISP Attribute #443)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > File Hash Watchlist</indicator:Type>
<indicator:Description > Payload delivery: f25466e4820404c817eaf75818b7177891735886 (MISP Attribute #443)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-cd191e4e-a5a1-4009-93b7-92cc6a3d6984" >
<cybox:Object id= ":File-cd191e4e-a5a1-4009-93b7-92cc6a3d6984" >
<cybox:Properties xsi:type= "FileObj:FileObjectType" >
<FileObj:Hashes >
<cyboxCommon:Hash >
<cyboxCommon:Type condition= "Equals" xsi:type= "cyboxVocabs:HashNameVocab-1.0" > SHA1</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition= "Equals" > f25466e4820404c817eaf75818b7177891735886</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:47:54+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-41c48554-6911-48eb-88a0-411dc4bd9047" timestamp= "2016-11-08T16:53:39+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Payload delivery: 1c3757006f972ca957d925accf8bbb3023550d1b (MISP Attribute #444)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > File Hash Watchlist</indicator:Type>
<indicator:Description > Payload delivery: 1c3757006f972ca957d925accf8bbb3023550d1b (MISP Attribute #444)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-41c48554-6911-48eb-88a0-411dc4bd9047" >
<cybox:Object id= ":File-41c48554-6911-48eb-88a0-411dc4bd9047" >
<cybox:Properties xsi:type= "FileObj:FileObjectType" >
<FileObj:Hashes >
<cyboxCommon:Hash >
<cyboxCommon:Type condition= "Equals" xsi:type= "cyboxVocabs:HashNameVocab-1.0" > SHA1</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition= "Equals" > 1c3757006f972ca957d925accf8bbb3023550d1b</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:53:39+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-70881ae4-3da1-409e-8bd3-7f508092a2c9" timestamp= "2016-11-08T16:48:02+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Payload delivery: 5a372b45285fe6f3df3ba277ee2de55d4a30fc8ef05de729cf464103632db40f (MISP Attribute #445)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > File Hash Watchlist</indicator:Type>
<indicator:Description > Payload delivery: 5a372b45285fe6f3df3ba277ee2de55d4a30fc8ef05de729cf464103632db40f (MISP Attribute #445)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-70881ae4-3da1-409e-8bd3-7f508092a2c9" >
<cybox:Object id= ":File-70881ae4-3da1-409e-8bd3-7f508092a2c9" >
<cybox:Properties xsi:type= "FileObj:FileObjectType" >
<FileObj:Hashes >
<cyboxCommon:Hash >
<cyboxCommon:Type condition= "Equals" xsi:type= "cyboxVocabs:HashNameVocab-1.0" > SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition= "Equals" > 5a372b45285fe6f3df3ba277ee2de55d4a30fc8ef05de729cf464103632db40f</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:48:02+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-19e97c58-4992-4f0b-8f49-6a6378a289eb" timestamp= "2016-11-08T16:53:48+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Payload delivery: 4320204d577ef8b939115d16110e97ff04cb4f7d1e77ba5ce011d43f74abc7be (MISP Attribute #446)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > File Hash Watchlist</indicator:Type>
<indicator:Description > Payload delivery: 4320204d577ef8b939115d16110e97ff04cb4f7d1e77ba5ce011d43f74abc7be (MISP Attribute #446)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-19e97c58-4992-4f0b-8f49-6a6378a289eb" >
<cybox:Object id= ":File-19e97c58-4992-4f0b-8f49-6a6378a289eb" >
<cybox:Properties xsi:type= "FileObj:FileObjectType" >
<FileObj:Hashes >
<cyboxCommon:Hash >
<cyboxCommon:Type condition= "Equals" xsi:type= "cyboxVocabs:HashNameVocab-1.0" > SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition= "Equals" > 4320204d577ef8b939115d16110e97ff04cb4f7d1e77ba5ce011d43f74abc7be</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:53:48+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-582247d0-d7a0-49c3-a6ae-69fe8e96ca05" timestamp= "2016-11-08T16:46:56+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Payload delivery: http://aax.me/a6faa (MISP Attribute #1356)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > URL Watchlist</indicator:Type>
<indicator:Description > Payload delivery: http://aax.me/a6faa (MISP Attribute #1356)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-582247d0-d7a0-49c3-a6ae-69fe8e96ca05" >
<cybox:Object id= ":URI-582247d0-d7a0-49c3-a6ae-69fe8e96ca05" >
<cybox:Properties xsi:type= "URIObj:URIObjectType" >
<URIObj:Value condition= "Equals" > http://aax.me/a6faa</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:46:56+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > High</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-582247f6-eeec-47b0-b6d8-69fe8e96ca05" timestamp= "2016-11-08T16:47:34+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Payload delivery: https://cloud.openmailbox.org/index.php/s/ujDNWMmg8pdG3AL/authenticate (MISP Attribute #1357)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > URL Watchlist</indicator:Type>
<indicator:Description > Payload delivery: https://cloud.openmailbox.org/index.php/s/ujDNWMmg8pdG3AL/authenticate (MISP Attribute #1357)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-582247f6-eeec-47b0-b6d8-69fe8e96ca05" >
<cybox:Object id= ":URI-582247f6-eeec-47b0-b6d8-69fe8e96ca05" >
<cybox:Properties xsi:type= "URIObj:URIObjectType" >
<URIObj:Value condition= "Equals" > https://cloud.openmailbox.org/index.php/s/ujDNWMmg8pdG3AL/authenticate</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:47:34+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator >
<stixCommon:Relationship > Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id= ":indicator-6c1856f6-0068-4c83-8aba-9fd4bb4277a1" timestamp= "2016-11-08T16:45:55+00:00" xsi:type= 'indicator:IndicatorType' >
<indicator:Title > Payload delivery: http://aax.me/d0dde (MISP Attribute #447)</indicator:Title>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > Malware Artifacts</indicator:Type>
<indicator:Type xsi:type= "stixVocabs:IndicatorTypeVocab-1.1" > URL Watchlist</indicator:Type>
<indicator:Description > Payload delivery: http://aax.me/d0dde (MISP Attribute #447)</indicator:Description>
<indicator:Valid_Time_Position />
<indicator:Observable id= ":observable-6c1856f6-0068-4c83-8aba-9fd4bb4277a1" >
<cybox:Object id= ":URI-6c1856f6-0068-4c83-8aba-9fd4bb4277a1" >
<cybox:Properties xsi:type= "URIObj:URIObjectType" >
<URIObj:Value condition= "Equals" > http://aax.me/d0dde</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp= "2016-11-08T16:45:55+00:00" >
<stixCommon:Value xsi:type= "stixVocabs:HighMediumLowVocab-1.0" > None</stixCommon:Value>
<stixCommon:Description > Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:History >
<incident:History_Item >
<incident:Journal_Entry time_precision= "second" > Event Threat Level: Medium</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item >
<incident:Journal_Entry time_precision= "second" > MISP Tag: TLP:GREEN</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item >
<incident:Journal_Entry time_precision= "second" > MISP Tag: SOURCE:CITIZENLAB</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item >
<incident:Journal_Entry time_precision= "second" > MISP Tag: DETECT</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item >
<incident:Journal_Entry time_precision= "second" > MISP Tag: PUBLISHED</incident:Journal_Entry>
</incident:History_Item>
</incident:History>
<incident:Information_Source >
<stixCommon:Identity >
<stixCommon:Name > citizenlab</stixCommon:Name>
</stixCommon:Identity>
<stixCommon:References >
<stixCommon:Reference > https://citizenlab.org/2016/05/stealth-falcon/</stixCommon:Reference>
</stixCommon:References>
</incident:Information_Source>
<incident:Handling >
<marking:Marking >
<marking:Controlled_Structure > ../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type= 'tlpMarking:TLPMarkingStructureType' color= "GREEN" />
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>