Add Android forensics, IOC threat-intel DB, Compose companion; scrub secrets from configs

This commit is contained in:
SsSnake
2026-07-13 15:45:47 -07:00
parent 925216290f
commit e48d577bd5
387 changed files with 211976 additions and 921 deletions

View File

@@ -0,0 +1,8 @@
## UAE Threat Actor IOCs
This directory contains IOC from the Citizen Lab report ["Keep Calm and (Dont) Enable Macros: A New Threat Actor Targets UAE Dissidents"](https://citizenlab.org/2016/05/stealth-falcon/) published the 29th of May 2016.
Files included in this directory:
* openioc.ioc : IOCs in OpenIOC format
* stix.xml : IOCs in STIX XML format
* iocs.csv : IOCs in csv format

View File

@@ -0,0 +1,35 @@
uuid,event_id,category,type,value,comment,to_ids,date
007694f1-b73a-40a5-bcf5-dded27746669,8,Network activity,url,"http://aax.me/0b152","",0,20161108
19e97c58-4992-4f0b-8f49-6a6378a289eb,8,Payload delivery,sha256,"4320204d577ef8b939115d16110e97ff04cb4f7d1e77ba5ce011d43f74abc7be","message_032456944343.docm",0,20161108
280056b8-69aa-432c-9826-6d5b820eb44e,8,Payload delivery,email-src,"andrew.dwight389@outlook.com","The Case of the Fake Journalist",0,20161108
35aa025c-2f62-4f9d-9fb7-391542226a7a,8,Network activity,domain,"optimizedimghosting.com","The documents macro was identical to the one sent to Donaghy, except it reported back to, and downloaded Stage Two from a different URL",1,20161108
3813bc78-21d9-40a2-b76e-61016eb71ccb,8,Network activity,domain,"adhostingcache.com","",1,20161108
41c48554-6911-48eb-88a0-411dc4bd9047,8,Payload delivery,sha1,"1c3757006f972ca957d925accf8bbb3023550d1b","message_032456944343.docm",0,20161108
45dbee97-3aa0-487d-bd73-a3c10a511403,8,Network activity,ip-dst,"95.215.44.37","IP linked to adhostingcache.com",0,20161108
537df72e-b2b9-4016-b337-06930c42c455,8,Network activity,url,"http://goo.gl/60HAqJ","redirects to http://aax.me/0b152",0,20161108
58224765-51f8-4d28-9040-49798e96ca05,8,Attribution,threat-actor,"Stealth Falcon","",0,20161108
582247a8-11b4-4da0-9ca1-69fe8e96ca05,8,Payload delivery,domain,"aax.me","",1,20161108
582247d0-d7a0-49c3-a6ae-69fe8e96ca05,8,Payload delivery,url,"http://aax.me/a6faa","Link sent in a phishing email",1,20161108
582247f6-eeec-47b0-b6d8-69fe8e96ca05,8,Payload delivery,url,"https://cloud.openmailbox.org/index.php/s/ujDNWMmg8pdG3AL/authenticate","ownCloud15 instance",0,20161108
5822492e-087c-4fa8-afe1-49798e96ca05,8,Network activity,domain,"simpleadbanners.com","Domains linked to adhostingcache.com",0,20161108
5822492e-1d40-4098-a87b-49798e96ca05,8,Network activity,domain,"clickstatistic.com","Domains linked to adhostingcache.com",0,20161108
5822492e-7490-4c3f-9a10-49798e96ca05,8,Network activity,domain,"bestairlinepricetags.com","Domains linked to adhostingcache.com",0,20161108
5822492e-d888-418e-906d-49798e96ca05,8,Network activity,domain,"fasttravelclearance.com","Domains linked to adhostingcache.com",0,20161108
5822494d-792c-4d8c-9be0-49798e96ca05,8,Network activity,domain,"airlineadverts.com","Domain linked to incapsulawebcache.com",0,20161108
5822494d-7ab0-42bd-bd9d-49798e96ca05,8,Network activity,domain,"ministrynewschannel.com","Domain linked to incapsulawebcache.com",0,20161108
5822494d-bf14-4b41-803a-49798e96ca05,8,Network activity,domain,"ministrynewsinfo.com","Domain linked to incapsulawebcache.com",0,20161108
62fcd7b4-5d95-49bd-a9ff-3c2e1854839b,8,Network activity,url,"http://optimizedimghosting.com/wddf/hrrw/ggrr.txt","The documents macro was identical to the one sent to Donaghy, except it reported back to, and downloaded Stage Two from a different URL",0,20161108
6c1856f6-0068-4c83-8aba-9fd4bb4277a1,8,Payload delivery,url,"http://aax.me/d0dde","loaded a page containing a redirect to the website of Al Jazeera. Before completing the redirect, it invoked JavaScript to profile the targets computer.",0,20161108
707eed9b-bb2c-4951-af0d-060b4c860e89,8,External analysis,link,"https://citizenlab.org/2016/05/stealth-falcon/","",0,20161108
70881ae4-3da1-409e-8bd3-7f508092a2c9,8,Payload delivery,sha256,"5a372b45285fe6f3df3ba277ee2de55d4a30fc8ef05de729cf464103632db40f","right2fight.docm (malicious document)",0,20161108
7fd6e683-9615-4f4e-b901-03e7dbb81337,8,Network activity,url,"https://incapsulawebcache.com/cache/cache.nfo","",0,20161108
8010c934-027b-40c5-ba1e-3efca8e52d5a,8,Network activity,domain,"incapsulawebcache.com","stage two server",1,20161108
8682a3ad-80da-4732-bf5a-e675e27c56fe,8,Network activity,domain,"edgecacheimagehosting.com","stage two server",1,20161108
9ca61973-d717-496a-a158-82d9b2e37965,8,Payload delivery,md5,"87e1df6f36b96b56186444e37e2a1ef5","message_032456944343.docm",0,20161108
bc8e2ca7-cd3c-4205-9028-b8b106f12389,8,Payload delivery,email-src,"the_right_to_fight@openmailbox.org","Fake invitation",0,20161108
cd191e4e-a5a1-4009-93b7-92cc6a3d6984,8,Payload delivery,sha1,"f25466e4820404c817eaf75818b7177891735886","right2fight.docm (malicious document)",0,20161108
d9a62cda-db4c-4d70-858c-6bbaaa041e63,8,Network activity,domain,"adhostingcaches.com","registered on December 3rd",1,20161108
decfcbf1-1331-4624-88b7-a88c94637dd0,8,Network activity,url,"http://adhostingcache.com/ehhe/eh4g4/adcache.txt","Gathered information is returned to and the servers response is executed as a PowerShell command.",0,20161108
e8f3b924-1221-4d08-8fef-f689529a7b6d,8,Network activity,url,"http://aax.me/redirect.js","to profile a users system, perhaps to gather intelligence about potentially exploitable vulnerabilities.",0,20161108
f0215c0c-b708-43d8-873e-80a3e8e54cfa,8,Network activity,url,"https://edgecacheimagehosting.com/images/image.nfo","The Stage Two in this case reported back to",0,20161108
f4f40c31-dd17-4dc6-baa3-6beb35c04c00,8,Payload delivery,md5,"80e8ef78b9e28015cde4205aaa65da97","right2fight.docm (malicious document)",0,20161108
1 uuid event_id category type value comment to_ids date
2 007694f1-b73a-40a5-bcf5-dded27746669 8 Network activity url http://aax.me/0b152 0 20161108
3 19e97c58-4992-4f0b-8f49-6a6378a289eb 8 Payload delivery sha256 4320204d577ef8b939115d16110e97ff04cb4f7d1e77ba5ce011d43f74abc7be message_032456944343.docm 0 20161108
4 280056b8-69aa-432c-9826-6d5b820eb44e 8 Payload delivery email-src andrew.dwight389@outlook.com The Case of the Fake Journalist 0 20161108
5 35aa025c-2f62-4f9d-9fb7-391542226a7a 8 Network activity domain optimizedimghosting.com The document’s macro was identical to the one sent to Donaghy, except it reported back to, and downloaded Stage Two from a different URL 1 20161108
6 3813bc78-21d9-40a2-b76e-61016eb71ccb 8 Network activity domain adhostingcache.com 1 20161108
7 41c48554-6911-48eb-88a0-411dc4bd9047 8 Payload delivery sha1 1c3757006f972ca957d925accf8bbb3023550d1b message_032456944343.docm 0 20161108
8 45dbee97-3aa0-487d-bd73-a3c10a511403 8 Network activity ip-dst 95.215.44.37 IP linked to adhostingcache.com 0 20161108
9 537df72e-b2b9-4016-b337-06930c42c455 8 Network activity url http://goo.gl/60HAqJ redirects to http://aax.me/0b152 0 20161108
10 58224765-51f8-4d28-9040-49798e96ca05 8 Attribution threat-actor Stealth Falcon 0 20161108
11 582247a8-11b4-4da0-9ca1-69fe8e96ca05 8 Payload delivery domain aax.me 1 20161108
12 582247d0-d7a0-49c3-a6ae-69fe8e96ca05 8 Payload delivery url http://aax.me/a6faa Link sent in a phishing email 1 20161108
13 582247f6-eeec-47b0-b6d8-69fe8e96ca05 8 Payload delivery url https://cloud.openmailbox.org/index.php/s/ujDNWMmg8pdG3AL/authenticate ownCloud15 instance 0 20161108
14 5822492e-087c-4fa8-afe1-49798e96ca05 8 Network activity domain simpleadbanners.com Domains linked to adhostingcache.com 0 20161108
15 5822492e-1d40-4098-a87b-49798e96ca05 8 Network activity domain clickstatistic.com Domains linked to adhostingcache.com 0 20161108
16 5822492e-7490-4c3f-9a10-49798e96ca05 8 Network activity domain bestairlinepricetags.com Domains linked to adhostingcache.com 0 20161108
17 5822492e-d888-418e-906d-49798e96ca05 8 Network activity domain fasttravelclearance.com Domains linked to adhostingcache.com 0 20161108
18 5822494d-792c-4d8c-9be0-49798e96ca05 8 Network activity domain airlineadverts.com Domain linked to incapsulawebcache.com 0 20161108
19 5822494d-7ab0-42bd-bd9d-49798e96ca05 8 Network activity domain ministrynewschannel.com Domain linked to incapsulawebcache.com 0 20161108
20 5822494d-bf14-4b41-803a-49798e96ca05 8 Network activity domain ministrynewsinfo.com Domain linked to incapsulawebcache.com 0 20161108
21 62fcd7b4-5d95-49bd-a9ff-3c2e1854839b 8 Network activity url http://optimizedimghosting.com/wddf/hrrw/ggrr.txt The document’s macro was identical to the one sent to Donaghy, except it reported back to, and downloaded Stage Two from a different URL 0 20161108
22 6c1856f6-0068-4c83-8aba-9fd4bb4277a1 8 Payload delivery url http://aax.me/d0dde loaded a page containing a redirect to the website of Al Jazeera. Before completing the redirect, it invoked JavaScript to profile the target’s computer. 0 20161108
23 707eed9b-bb2c-4951-af0d-060b4c860e89 8 External analysis link https://citizenlab.org/2016/05/stealth-falcon/ 0 20161108
24 70881ae4-3da1-409e-8bd3-7f508092a2c9 8 Payload delivery sha256 5a372b45285fe6f3df3ba277ee2de55d4a30fc8ef05de729cf464103632db40f right2fight.docm (malicious document) 0 20161108
25 7fd6e683-9615-4f4e-b901-03e7dbb81337 8 Network activity url https://incapsulawebcache.com/cache/cache.nfo 0 20161108
26 8010c934-027b-40c5-ba1e-3efca8e52d5a 8 Network activity domain incapsulawebcache.com stage two server 1 20161108
27 8682a3ad-80da-4732-bf5a-e675e27c56fe 8 Network activity domain edgecacheimagehosting.com stage two server 1 20161108
28 9ca61973-d717-496a-a158-82d9b2e37965 8 Payload delivery md5 87e1df6f36b96b56186444e37e2a1ef5 message_032456944343.docm 0 20161108
29 bc8e2ca7-cd3c-4205-9028-b8b106f12389 8 Payload delivery email-src the_right_to_fight@openmailbox.org Fake invitation 0 20161108
30 cd191e4e-a5a1-4009-93b7-92cc6a3d6984 8 Payload delivery sha1 f25466e4820404c817eaf75818b7177891735886 right2fight.docm (malicious document) 0 20161108
31 d9a62cda-db4c-4d70-858c-6bbaaa041e63 8 Network activity domain adhostingcaches.com registered on December 3rd 1 20161108
32 decfcbf1-1331-4624-88b7-a88c94637dd0 8 Network activity url http://adhostingcache.com/ehhe/eh4g4/adcache.txt Gathered information is returned to and the server’s response is executed as a PowerShell command. 0 20161108
33 e8f3b924-1221-4d08-8fef-f689529a7b6d 8 Network activity url http://aax.me/redirect.js to profile a user’s system, perhaps to gather intelligence about potentially exploitable vulnerabilities. 0 20161108
34 f0215c0c-b708-43d8-873e-80a3e8e54cfa 8 Network activity url https://edgecacheimagehosting.com/images/image.nfo The Stage Two in this case reported back to 0 20161108
35 f4f40c31-dd17-4dc6-baa3-6beb35c04c00 8 Payload delivery md5 80e8ef78b9e28015cde4205aaa65da97 right2fight.docm (malicious document) 0 20161108

View File

@@ -0,0 +1,41 @@
<?xml version="1.0" encoding="utf-8"?>
<ioc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" id="581c05a7-1888-402a-b435-49798e96ca05" last-modified="2016-05-29T00:00:00" xmlns="http://schemas.mandiant.com/2010/ioc">
<short_description>Event #8</short_description>
<description>Keep Calm and (Dont) Enable Macros: A New Threat Actor Targets UAE Dissidents</description>
<keywords />
<authored_by>citizenlab</authored_by>
<authored_date>2016-05-29T00:00:00</authored_date>
<links />
<definition>
<Indicator operator="OR" id="581c05a7-1888-402a-b435-49798e96ca05">
<IndicatorItem id="adhostingcache.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="adhostingcaches.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="optimizedimghosting.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="edgecacheimagehosting.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="incapsulawebcache.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="aax.me" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="http://aax.me/a6faa" condition="is">
<Context document="UrlHistoryItem" search="UrlHistoryItem/URL" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
</Indicator>
</definition>
</ioc>

View File

@@ -0,0 +1,844 @@
<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:="https://rufus.citlab.utoronto.ca"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-7e377b3f-5c5a-403a-9575-64593685b0a8" version="1.1.1" timestamp="2016-11-08T21:57:05.578284+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-581c05a7-1888-402a-b435-49798e96ca05" version="1.1.1" timestamp="2016-11-08T16:56:04+00:00">
<stix:STIX_Header>
<stix:Title>Keep Calm and (Dont) Enable Macros: A New Threat Actor Targets UAE Dissidents (MISP Event #8)</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Incidents>
<stix:Incident id=":incident-581c05a7-1888-402a-b435-49798e96ca05" timestamp="2016-11-08T16:56:19+00:00" xsi:type='incident:IncidentType'>
<incident:Title>Keep Calm and (Dont) Enable Macros: A New Threat Actor Targets UAE Dissidents</incident:Title>
<incident:External_ID source="MISP Event">8</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2016-05-29T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2016-11-08T16:56:19+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">Closed</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58224765-51f8-4d28-9040-49798e96ca05" timestamp="2016-11-08T16:45:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: Stealth Falcon (MISP Attribute #1354)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: Stealth Falcon (MISP Attribute #1354)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2016-11-08T16:45:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822492e-087c-4fa8-afe1-49798e96ca05" timestamp="2016-11-08T16:52:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: simpleadbanners.com (MISP Attribute #1358)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: simpleadbanners.com (MISP Attribute #1358)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822492e-087c-4fa8-afe1-49798e96ca05">
<cybox:Object id=":DomainName-5822492e-087c-4fa8-afe1-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">simpleadbanners.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:52:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822492e-1d40-4098-a87b-49798e96ca05" timestamp="2016-11-08T16:52:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: clickstatistic.com (MISP Attribute #1359)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: clickstatistic.com (MISP Attribute #1359)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822492e-1d40-4098-a87b-49798e96ca05">
<cybox:Object id=":DomainName-5822492e-1d40-4098-a87b-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">clickstatistic.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:52:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822492e-7490-4c3f-9a10-49798e96ca05" timestamp="2016-11-08T16:52:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: bestairlinepricetags.com (MISP Attribute #1360)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: bestairlinepricetags.com (MISP Attribute #1360)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822492e-7490-4c3f-9a10-49798e96ca05">
<cybox:Object id=":DomainName-5822492e-7490-4c3f-9a10-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">bestairlinepricetags.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:52:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822492e-d888-418e-906d-49798e96ca05" timestamp="2016-11-08T16:52:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: fasttravelclearance.com (MISP Attribute #1361)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: fasttravelclearance.com (MISP Attribute #1361)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822492e-d888-418e-906d-49798e96ca05">
<cybox:Object id=":DomainName-5822492e-d888-418e-906d-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">fasttravelclearance.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:52:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822494d-792c-4d8c-9be0-49798e96ca05" timestamp="2016-11-08T16:53:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: airlineadverts.com (MISP Attribute #1362)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: airlineadverts.com (MISP Attribute #1362)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822494d-792c-4d8c-9be0-49798e96ca05">
<cybox:Object id=":DomainName-5822494d-792c-4d8c-9be0-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">airlineadverts.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:53:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822494d-7ab0-42bd-bd9d-49798e96ca05" timestamp="2016-11-08T16:53:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: ministrynewschannel.com (MISP Attribute #1363)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: ministrynewschannel.com (MISP Attribute #1363)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822494d-7ab0-42bd-bd9d-49798e96ca05">
<cybox:Object id=":DomainName-5822494d-7ab0-42bd-bd9d-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">ministrynewschannel.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:53:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822494d-bf14-4b41-803a-49798e96ca05" timestamp="2016-11-08T16:53:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: ministrynewsinfo.com (MISP Attribute #1364)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: ministrynewsinfo.com (MISP Attribute #1364)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822494d-bf14-4b41-803a-49798e96ca05">
<cybox:Object id=":DomainName-5822494d-bf14-4b41-803a-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">ministrynewsinfo.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:53:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-3813bc78-21d9-40a2-b76e-61016eb71ccb" timestamp="2016-11-08T16:48:19+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: adhostingcache.com (MISP Attribute #425)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: adhostingcache.com (MISP Attribute #425)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-3813bc78-21d9-40a2-b76e-61016eb71ccb">
<cybox:Object id=":DomainName-3813bc78-21d9-40a2-b76e-61016eb71ccb">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">adhostingcache.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:48:19+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-d9a62cda-db4c-4d70-858c-6bbaaa041e63" timestamp="2016-11-08T16:49:00+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: adhostingcaches.com (MISP Attribute #426)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: adhostingcaches.com (MISP Attribute #426)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-d9a62cda-db4c-4d70-858c-6bbaaa041e63">
<cybox:Object id=":DomainName-d9a62cda-db4c-4d70-858c-6bbaaa041e63">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">adhostingcaches.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:49:00+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-35aa025c-2f62-4f9d-9fb7-391542226a7a" timestamp="2016-11-08T16:54:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: optimizedimghosting.com (MISP Attribute #427)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: optimizedimghosting.com (MISP Attribute #427)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-35aa025c-2f62-4f9d-9fb7-391542226a7a">
<cybox:Object id=":DomainName-35aa025c-2f62-4f9d-9fb7-391542226a7a">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">optimizedimghosting.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:54:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-8682a3ad-80da-4732-bf5a-e675e27c56fe" timestamp="2016-11-08T16:54:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: edgecacheimagehosting.com (MISP Attribute #428)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: edgecacheimagehosting.com (MISP Attribute #428)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-8682a3ad-80da-4732-bf5a-e675e27c56fe">
<cybox:Object id=":DomainName-8682a3ad-80da-4732-bf5a-e675e27c56fe">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">edgecacheimagehosting.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:54:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-8010c934-027b-40c5-ba1e-3efca8e52d5a" timestamp="2016-11-08T16:49:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: incapsulawebcache.com (MISP Attribute #429)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: incapsulawebcache.com (MISP Attribute #429)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-8010c934-027b-40c5-ba1e-3efca8e52d5a">
<cybox:Object id=":DomainName-8010c934-027b-40c5-ba1e-3efca8e52d5a">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">incapsulawebcache.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:49:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-45dbee97-3aa0-487d-bd73-a3c10a511403" timestamp="2016-11-08T16:48:42+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 95.215.44.37 (MISP Attribute #430)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 95.215.44.37 (MISP Attribute #430)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-45dbee97-3aa0-487d-bd73-a3c10a511403">
<cybox:Object id=":Address-45dbee97-3aa0-487d-bd73-a3c10a511403">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">95.215.44.37</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:48:42+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-decfcbf1-1331-4624-88b7-a88c94637dd0" timestamp="2016-11-08T16:55:41+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://adhostingcache.com/ehhe/eh4g4/adcache.txt (MISP Attribute #432)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://adhostingcache.com/ehhe/eh4g4/adcache.txt (MISP Attribute #432)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-decfcbf1-1331-4624-88b7-a88c94637dd0">
<cybox:Object id=":URI-decfcbf1-1331-4624-88b7-a88c94637dd0">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://adhostingcache.com/ehhe/eh4g4/adcache.txt</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:55:41+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-7fd6e683-9615-4f4e-b901-03e7dbb81337" timestamp="2016-11-08T16:49:23+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https://incapsulawebcache.com/cache/cache.nfo (MISP Attribute #433)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: https://incapsulawebcache.com/cache/cache.nfo (MISP Attribute #433)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-7fd6e683-9615-4f4e-b901-03e7dbb81337">
<cybox:Object id=":URI-7fd6e683-9615-4f4e-b901-03e7dbb81337">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://incapsulawebcache.com/cache/cache.nfo</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:49:23+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-e8f3b924-1221-4d08-8fef-f689529a7b6d" timestamp="2016-11-08T16:49:42+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://aax.me/redirect.js (MISP Attribute #434)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://aax.me/redirect.js (MISP Attribute #434)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-e8f3b924-1221-4d08-8fef-f689529a7b6d">
<cybox:Object id=":URI-e8f3b924-1221-4d08-8fef-f689529a7b6d">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://aax.me/redirect.js</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:49:42+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-537df72e-b2b9-4016-b337-06930c42c455" timestamp="2016-11-08T16:50:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://goo.gl/60HAqJ (MISP Attribute #435)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://goo.gl/60HAqJ (MISP Attribute #435)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-537df72e-b2b9-4016-b337-06930c42c455">
<cybox:Object id=":URI-537df72e-b2b9-4016-b337-06930c42c455">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://goo.gl/60HAqJ</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:50:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-007694f1-b73a-40a5-bcf5-dded27746669" timestamp="2016-11-08T16:51:04+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://aax.me/0b152 (MISP Attribute #436)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://aax.me/0b152 (MISP Attribute #436)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-007694f1-b73a-40a5-bcf5-dded27746669">
<cybox:Object id=":URI-007694f1-b73a-40a5-bcf5-dded27746669">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://aax.me/0b152</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:51:04+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-62fcd7b4-5d95-49bd-a9ff-3c2e1854839b" timestamp="2016-11-08T16:55:52+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://optimizedimghosting.com/wddf/hrrw/ggrr.txt (MISP Attribute #437)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://optimizedimghosting.com/wddf/hrrw/ggrr.txt (MISP Attribute #437)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-62fcd7b4-5d95-49bd-a9ff-3c2e1854839b">
<cybox:Object id=":URI-62fcd7b4-5d95-49bd-a9ff-3c2e1854839b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://optimizedimghosting.com/wddf/hrrw/ggrr.txt</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:55:52+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-f0215c0c-b708-43d8-873e-80a3e8e54cfa" timestamp="2016-11-08T16:56:04+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https://edgecacheimagehosting.com/images/image.nfo (MISP Attribute #438)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: https://edgecacheimagehosting.com/images/image.nfo (MISP Attribute #438)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-f0215c0c-b708-43d8-873e-80a3e8e54cfa">
<cybox:Object id=":URI-f0215c0c-b708-43d8-873e-80a3e8e54cfa">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://edgecacheimagehosting.com/images/image.nfo</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:56:04+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582247a8-11b4-4da0-9ca1-69fe8e96ca05" timestamp="2016-11-08T16:46:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: aax.me (MISP Attribute #1355)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Payload delivery: aax.me (MISP Attribute #1355)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582247a8-11b4-4da0-9ca1-69fe8e96ca05">
<cybox:Object id=":DomainName-582247a8-11b4-4da0-9ca1-69fe8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">aax.me</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:46:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-bc8e2ca7-cd3c-4205-9028-b8b106f12389" timestamp="2016-11-08T16:45:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: the_right_to_fight@openmailbox.org (MISP Attribute #439)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: the_right_to_fight@openmailbox.org (MISP Attribute #439)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-bc8e2ca7-cd3c-4205-9028-b8b106f12389">
<cybox:Object id=":EmailMessage-bc8e2ca7-cd3c-4205-9028-b8b106f12389">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">the_right_to_fight@openmailbox.org</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:45:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-280056b8-69aa-432c-9826-6d5b820eb44e" timestamp="2016-11-08T16:50:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: andrew.dwight389@outlook.com (MISP Attribute #440)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: andrew.dwight389@outlook.com (MISP Attribute #440)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-280056b8-69aa-432c-9826-6d5b820eb44e">
<cybox:Object id=":EmailMessage-280056b8-69aa-432c-9826-6d5b820eb44e">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">andrew.dwight389@outlook.com</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:50:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-f4f40c31-dd17-4dc6-baa3-6beb35c04c00" timestamp="2016-11-08T16:47:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 80e8ef78b9e28015cde4205aaa65da97 (MISP Attribute #441)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 80e8ef78b9e28015cde4205aaa65da97 (MISP Attribute #441)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-f4f40c31-dd17-4dc6-baa3-6beb35c04c00">
<cybox:Object id=":File-f4f40c31-dd17-4dc6-baa3-6beb35c04c00">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">80e8ef78b9e28015cde4205aaa65da97</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:47:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-9ca61973-d717-496a-a158-82d9b2e37965" timestamp="2016-11-08T16:53:31+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 87e1df6f36b96b56186444e37e2a1ef5 (MISP Attribute #442)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 87e1df6f36b96b56186444e37e2a1ef5 (MISP Attribute #442)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-9ca61973-d717-496a-a158-82d9b2e37965">
<cybox:Object id=":File-9ca61973-d717-496a-a158-82d9b2e37965">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">87e1df6f36b96b56186444e37e2a1ef5</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:53:31+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-cd191e4e-a5a1-4009-93b7-92cc6a3d6984" timestamp="2016-11-08T16:47:54+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: f25466e4820404c817eaf75818b7177891735886 (MISP Attribute #443)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: f25466e4820404c817eaf75818b7177891735886 (MISP Attribute #443)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-cd191e4e-a5a1-4009-93b7-92cc6a3d6984">
<cybox:Object id=":File-cd191e4e-a5a1-4009-93b7-92cc6a3d6984">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA1</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">f25466e4820404c817eaf75818b7177891735886</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:47:54+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-41c48554-6911-48eb-88a0-411dc4bd9047" timestamp="2016-11-08T16:53:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 1c3757006f972ca957d925accf8bbb3023550d1b (MISP Attribute #444)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 1c3757006f972ca957d925accf8bbb3023550d1b (MISP Attribute #444)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-41c48554-6911-48eb-88a0-411dc4bd9047">
<cybox:Object id=":File-41c48554-6911-48eb-88a0-411dc4bd9047">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA1</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">1c3757006f972ca957d925accf8bbb3023550d1b</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:53:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-70881ae4-3da1-409e-8bd3-7f508092a2c9" timestamp="2016-11-08T16:48:02+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 5a372b45285fe6f3df3ba277ee2de55d4a30fc8ef05de729cf464103632db40f (MISP Attribute #445)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 5a372b45285fe6f3df3ba277ee2de55d4a30fc8ef05de729cf464103632db40f (MISP Attribute #445)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-70881ae4-3da1-409e-8bd3-7f508092a2c9">
<cybox:Object id=":File-70881ae4-3da1-409e-8bd3-7f508092a2c9">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">5a372b45285fe6f3df3ba277ee2de55d4a30fc8ef05de729cf464103632db40f</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:48:02+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-19e97c58-4992-4f0b-8f49-6a6378a289eb" timestamp="2016-11-08T16:53:48+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 4320204d577ef8b939115d16110e97ff04cb4f7d1e77ba5ce011d43f74abc7be (MISP Attribute #446)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 4320204d577ef8b939115d16110e97ff04cb4f7d1e77ba5ce011d43f74abc7be (MISP Attribute #446)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-19e97c58-4992-4f0b-8f49-6a6378a289eb">
<cybox:Object id=":File-19e97c58-4992-4f0b-8f49-6a6378a289eb">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">4320204d577ef8b939115d16110e97ff04cb4f7d1e77ba5ce011d43f74abc7be</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:53:48+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582247d0-d7a0-49c3-a6ae-69fe8e96ca05" timestamp="2016-11-08T16:46:56+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: http://aax.me/a6faa (MISP Attribute #1356)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: http://aax.me/a6faa (MISP Attribute #1356)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582247d0-d7a0-49c3-a6ae-69fe8e96ca05">
<cybox:Object id=":URI-582247d0-d7a0-49c3-a6ae-69fe8e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://aax.me/a6faa</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:46:56+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582247f6-eeec-47b0-b6d8-69fe8e96ca05" timestamp="2016-11-08T16:47:34+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: https://cloud.openmailbox.org/index.php/s/ujDNWMmg8pdG3AL/authenticate (MISP Attribute #1357)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: https://cloud.openmailbox.org/index.php/s/ujDNWMmg8pdG3AL/authenticate (MISP Attribute #1357)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582247f6-eeec-47b0-b6d8-69fe8e96ca05">
<cybox:Object id=":URI-582247f6-eeec-47b0-b6d8-69fe8e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://cloud.openmailbox.org/index.php/s/ujDNWMmg8pdG3AL/authenticate</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:47:34+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-6c1856f6-0068-4c83-8aba-9fd4bb4277a1" timestamp="2016-11-08T16:45:55+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: http://aax.me/d0dde (MISP Attribute #447)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: http://aax.me/d0dde (MISP Attribute #447)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-6c1856f6-0068-4c83-8aba-9fd4bb4277a1">
<cybox:Object id=":URI-6c1856f6-0068-4c83-8aba-9fd4bb4277a1">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://aax.me/d0dde</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:45:55+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:History>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">Event Threat Level: Medium</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TLP:GREEN</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: SOURCE:CITIZENLAB</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: DETECT</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: PUBLISHED</incident:Journal_Entry>
</incident:History_Item>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
<stixCommon:References>
<stixCommon:Reference>https://citizenlab.org/2016/05/stealth-falcon/</stixCommon:Reference>
</stixCommon:References>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>