Add Android forensics, IOC threat-intel DB, Compose companion; scrub secrets from configs

This commit is contained in:
SsSnake
2026-07-13 15:45:47 -07:00
parent 925216290f
commit e48d577bd5
387 changed files with 211976 additions and 921 deletions

View File

@@ -0,0 +1,13 @@
uuid,event_id,category,type,value,comment,to_ids,date
5926f463-45f0-45c6-bf0a-53928e96ca05,100,Network activity,domain,mail-google-login.blogspot.com,,1,20170525
5926f463-8944-4fcc-b570-53928e96ca05,100,Network activity,domain,id9954.gq,,1,20170525
5926f463-9b30-4133-9f8a-53928e96ca05,100,Network activity,domain,id834.ga,,1,20170525
5926f463-a1dc-4042-a982-53928e96ca05,100,Network activity,domain,id4242.ga,,1,20170525
5926f463-dc78-4a45-ba38-53928e96ca05,100,Network activity,domain,id833.ga,,1,20170525
5926f463-f7d4-432d-b56a-53928e96ca05,100,Network activity,domain,com-securitysettingpage.tk,,1,20170525
5926f4a8-cb10-4528-89f8-5d828e96ca05,100,Network activity,ip-dst,80.255.12.237,,1,20170525
5926f4a8-cf18-4416-b85d-5d828e96ca05,100,Network activity,ip-dst,89.40.181.119,,1,20170525
5926f4a8-e18c-4b39-b0ac-5d828e96ca05,100,Network activity,ip-dst,89.32.40.238,,1,20170525
5926f504-4e00-4343-9488-5d828e96ca05,100,Payload delivery,email-src,g.mail2017@yandex.com,,1,20170525
5926f504-53f4-4700-8a2b-5d828e96ca05,100,Payload delivery,email-src,annaablony@mail.com,,1,20170525
5926f504-a840-4d0e-8d26-5d828e96ca05,100,Payload delivery,email-src,myprimaryreger@gmail.com,,1,20170525
1 uuid event_id category type value comment to_ids date
2 5926f463-45f0-45c6-bf0a-53928e96ca05 100 Network activity domain mail-google-login.blogspot.com 1 20170525
3 5926f463-8944-4fcc-b570-53928e96ca05 100 Network activity domain id9954.gq 1 20170525
4 5926f463-9b30-4133-9f8a-53928e96ca05 100 Network activity domain id834.ga 1 20170525
5 5926f463-a1dc-4042-a982-53928e96ca05 100 Network activity domain id4242.ga 1 20170525
6 5926f463-dc78-4a45-ba38-53928e96ca05 100 Network activity domain id833.ga 1 20170525
7 5926f463-f7d4-432d-b56a-53928e96ca05 100 Network activity domain com-securitysettingpage.tk 1 20170525
8 5926f4a8-cb10-4528-89f8-5d828e96ca05 100 Network activity ip-dst 80.255.12.237 1 20170525
9 5926f4a8-cf18-4416-b85d-5d828e96ca05 100 Network activity ip-dst 89.40.181.119 1 20170525
10 5926f4a8-e18c-4b39-b0ac-5d828e96ca05 100 Network activity ip-dst 89.32.40.238 1 20170525
11 5926f504-4e00-4343-9488-5d828e96ca05 100 Payload delivery email-src g.mail2017@yandex.com 1 20170525
12 5926f504-53f4-4700-8a2b-5d828e96ca05 100 Payload delivery email-src annaablony@mail.com 1 20170525
13 5926f504-a840-4d0e-8d26-5d828e96ca05 100 Payload delivery email-src myprimaryreger@gmail.com 1 20170525

View File

@@ -0,0 +1,294 @@
{"response":[{
"Event": {
"id": "100",
"orgc_id": "2",
"org_id": "2",
"date": "2017-05-25",
"threat_level_id": "2",
"info": "TAINTED LEAKS: Disinformation and Phishing With a Russian Nexus",
"published": true,
"uuid": "5926f385-8a58-4fc0-a075-5d828e96ca05",
"attribute_count": "12",
"analysis": "2",
"timestamp": "1495725316",
"distribution": "1",
"proposal_email_lock": false,
"locked": false,
"publish_timestamp": "1495725350",
"sharing_group_id": "0",
"Org": {
"id": "2",
"name": "citizenlab",
"uuid": "581b5fea-818c-441a-bd1d-49798e96ca05"
},
"Orgc": {
"id": "2",
"name": "citizenlab",
"uuid": "581b5fea-818c-441a-bd1d-49798e96ca05"
},
"Attribute": [
{
"id": "16046",
"type": "domain",
"category": "Network activity",
"to_ids": true,
"uuid": "5926f463-dc78-4a45-ba38-53928e96ca05",
"event_id": "100",
"distribution": "5",
"timestamp": "1495725155",
"comment": "",
"sharing_group_id": "0",
"deleted": false,
"value": "id833.ga",
"SharingGroup": [
],
"ShadowAttribute": [
]
},
{
"id": "16047",
"type": "domain",
"category": "Network activity",
"to_ids": true,
"uuid": "5926f463-9b30-4133-9f8a-53928e96ca05",
"event_id": "100",
"distribution": "5",
"timestamp": "1495725155",
"comment": "",
"sharing_group_id": "0",
"deleted": false,
"value": "id834.ga",
"SharingGroup": [
],
"ShadowAttribute": [
]
},
{
"id": "16048",
"type": "domain",
"category": "Network activity",
"to_ids": true,
"uuid": "5926f463-8944-4fcc-b570-53928e96ca05",
"event_id": "100",
"distribution": "5",
"timestamp": "1495725155",
"comment": "",
"sharing_group_id": "0",
"deleted": false,
"value": "id9954.gq",
"SharingGroup": [
],
"ShadowAttribute": [
]
},
{
"id": "16049",
"type": "domain",
"category": "Network activity",
"to_ids": true,
"uuid": "5926f463-a1dc-4042-a982-53928e96ca05",
"event_id": "100",
"distribution": "5",
"timestamp": "1495725155",
"comment": "",
"sharing_group_id": "0",
"deleted": false,
"value": "id4242.ga",
"SharingGroup": [
],
"ShadowAttribute": [
]
},
{
"id": "16050",
"type": "domain",
"category": "Network activity",
"to_ids": true,
"uuid": "5926f463-45f0-45c6-bf0a-53928e96ca05",
"event_id": "100",
"distribution": "5",
"timestamp": "1495725155",
"comment": "",
"sharing_group_id": "0",
"deleted": false,
"value": "mail-google-login.blogspot.com",
"SharingGroup": [
],
"ShadowAttribute": [
]
},
{
"id": "16051",
"type": "domain",
"category": "Network activity",
"to_ids": true,
"uuid": "5926f463-f7d4-432d-b56a-53928e96ca05",
"event_id": "100",
"distribution": "5",
"timestamp": "1495725155",
"comment": "",
"sharing_group_id": "0",
"deleted": false,
"value": "com-securitysettingpage.tk",
"SharingGroup": [
],
"ShadowAttribute": [
]
},
{
"id": "16055",
"type": "ip-dst",
"category": "Network activity",
"to_ids": true,
"uuid": "5926f4a8-cf18-4416-b85d-5d828e96ca05",
"event_id": "100",
"distribution": "5",
"timestamp": "1495725224",
"comment": "",
"sharing_group_id": "0",
"deleted": false,
"value": "89.40.181.119",
"SharingGroup": [
],
"ShadowAttribute": [
]
},
{
"id": "16056",
"type": "ip-dst",
"category": "Network activity",
"to_ids": true,
"uuid": "5926f4a8-e18c-4b39-b0ac-5d828e96ca05",
"event_id": "100",
"distribution": "5",
"timestamp": "1495725224",
"comment": "",
"sharing_group_id": "0",
"deleted": false,
"value": "89.32.40.238",
"SharingGroup": [
],
"ShadowAttribute": [
]
},
{
"id": "16057",
"type": "ip-dst",
"category": "Network activity",
"to_ids": true,
"uuid": "5926f4a8-cb10-4528-89f8-5d828e96ca05",
"event_id": "100",
"distribution": "5",
"timestamp": "1495725224",
"comment": "",
"sharing_group_id": "0",
"deleted": false,
"value": "80.255.12.237",
"SharingGroup": [
],
"ShadowAttribute": [
]
},
{
"id": "16058",
"type": "email-src",
"category": "Payload delivery",
"to_ids": true,
"uuid": "5926f504-4e00-4343-9488-5d828e96ca05",
"event_id": "100",
"distribution": "5",
"timestamp": "1495725316",
"comment": "",
"sharing_group_id": "0",
"deleted": false,
"value": "g.mail2017@yandex.com",
"SharingGroup": [
],
"ShadowAttribute": [
]
},
{
"id": "16059",
"type": "email-src",
"category": "Payload delivery",
"to_ids": true,
"uuid": "5926f504-53f4-4700-8a2b-5d828e96ca05",
"event_id": "100",
"distribution": "5",
"timestamp": "1495725316",
"comment": "",
"sharing_group_id": "0",
"deleted": false,
"value": "annaablony@mail.com",
"SharingGroup": [
],
"ShadowAttribute": [
]
},
{
"id": "16060",
"type": "email-src",
"category": "Payload delivery",
"to_ids": true,
"uuid": "5926f504-a840-4d0e-8d26-5d828e96ca05",
"event_id": "100",
"distribution": "5",
"timestamp": "1495725316",
"comment": "",
"sharing_group_id": "0",
"deleted": false,
"value": "myprimaryreger@gmail.com",
"SharingGroup": [
],
"ShadowAttribute": [
]
}
],
"ShadowAttribute": [
],
"RelatedEvent": [
],
"Tag": [
{
"id": "5",
"name": "SOURCE:CITIZENLAB",
"colour": "#ffad0d",
"exportable": true,
"org_id": false
},
{
"id": "8",
"name": "PUBLISHED",
"colour": "#91caff",
"exportable": true,
"org_id": false
}
]
}
}]}

View File

@@ -0,0 +1,61 @@
<?xml version="1.0" encoding="utf-8"?>
<ioc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" id="5926f385-8a58-4fc0-a075-5d828e96ca05" last-modified="2017-05-25T00:00:00" xmlns="http://schemas.mandiant.com/2010/ioc">
<short_description>Event #100</short_description>
<description>TAINTED LEAKS: Disinformation and Phishing With a Russian Nexus</description>
<keywords />
<authored_by>citizenlab</authored_by>
<authored_date>2017-05-25T00:00:00</authored_date>
<links />
<definition>
<Indicator operator="OR" id="5926f385-8a58-4fc0-a075-5d828e96ca05">
<IndicatorItem id="id833.ga" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="id834.ga" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="id9954.gq" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="id4242.ga" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="mail-google-login.blogspot.com" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="com-securitysettingpage.tk" condition="is">
<Context document="Network" search="Network/DNS" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="89.40.181.119" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="89.32.40.238" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="80.255.12.237" condition="is">
<Context document="RouteEntryItem" search="RouteEntryItem/Destination" type="mir" />
<Content type="IP"></Content>
</IndicatorItem>
<IndicatorItem id="g.mail2017@yandex.com" condition="is">
<Context document="Email" search="Email/From" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="annaablony@mail.com" condition="is">
<Context document="Email" search="Email/From" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
<IndicatorItem id="myprimaryreger@gmail.com" condition="is">
<Context document="Email" search="Email/From" type="mir" />
<Content type="string"></Content>
</IndicatorItem>
</Indicator>
</definition>
</ioc>

View File

@@ -0,0 +1,366 @@
<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-b84be256-86f6-4616-905c-063f6f7bc5b7" version="1.1.1" timestamp="2017-05-25T15:20:50.437054+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-5926f385-8a58-4fc0-a075-5d828e96ca05" version="1.1.1" timestamp="2017-05-25T11:15:16+00:00">
<stix:STIX_Header>
<stix:Title>TAINTED LEAKS: Disinformation and Phishing With a Russian Nexus (MISP Event #100)</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Incidents>
<stix:Incident id=":incident-5926f385-8a58-4fc0-a075-5d828e96ca05" timestamp="2017-05-25T11:15:50+00:00" xsi:type='incident:IncidentType'>
<incident:Title>TAINTED LEAKS: Disinformation and Phishing With a Russian Nexus</incident:Title>
<incident:External_ID source="MISP Event">100</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2017-05-25T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2017-05-25T11:15:50+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">Closed</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5926f463-dc78-4a45-ba38-53928e96ca05" timestamp="2017-05-25T11:12:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: id833.ga (MISP Attribute #16046)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: id833.ga (MISP Attribute #16046)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5926f463-dc78-4a45-ba38-53928e96ca05">
<cybox:Object id=":DomainName-5926f463-dc78-4a45-ba38-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">id833.ga</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-25T11:12:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5926f463-9b30-4133-9f8a-53928e96ca05" timestamp="2017-05-25T11:12:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: id834.ga (MISP Attribute #16047)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: id834.ga (MISP Attribute #16047)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5926f463-9b30-4133-9f8a-53928e96ca05">
<cybox:Object id=":DomainName-5926f463-9b30-4133-9f8a-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">id834.ga</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-25T11:12:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5926f463-8944-4fcc-b570-53928e96ca05" timestamp="2017-05-25T11:12:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: id9954.gq (MISP Attribute #16048)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: id9954.gq (MISP Attribute #16048)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5926f463-8944-4fcc-b570-53928e96ca05">
<cybox:Object id=":DomainName-5926f463-8944-4fcc-b570-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">id9954.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-25T11:12:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5926f463-a1dc-4042-a982-53928e96ca05" timestamp="2017-05-25T11:12:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: id4242.ga (MISP Attribute #16049)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: id4242.ga (MISP Attribute #16049)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5926f463-a1dc-4042-a982-53928e96ca05">
<cybox:Object id=":DomainName-5926f463-a1dc-4042-a982-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">id4242.ga</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-25T11:12:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5926f463-45f0-45c6-bf0a-53928e96ca05" timestamp="2017-05-25T11:12:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-google-login.blogspot.com (MISP Attribute #16050)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-google-login.blogspot.com (MISP Attribute #16050)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5926f463-45f0-45c6-bf0a-53928e96ca05">
<cybox:Object id=":DomainName-5926f463-45f0-45c6-bf0a-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-google-login.blogspot.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-25T11:12:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5926f463-f7d4-432d-b56a-53928e96ca05" timestamp="2017-05-25T11:12:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: com-securitysettingpage.tk (MISP Attribute #16051)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: com-securitysettingpage.tk (MISP Attribute #16051)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5926f463-f7d4-432d-b56a-53928e96ca05">
<cybox:Object id=":DomainName-5926f463-f7d4-432d-b56a-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">com-securitysettingpage.tk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-25T11:12:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5926f4a8-cf18-4416-b85d-5d828e96ca05" timestamp="2017-05-25T11:13:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 89.40.181.119 (MISP Attribute #16055)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 89.40.181.119 (MISP Attribute #16055)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5926f4a8-cf18-4416-b85d-5d828e96ca05">
<cybox:Object id=":Address-5926f4a8-cf18-4416-b85d-5d828e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">89.40.181.119</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-25T11:13:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5926f4a8-e18c-4b39-b0ac-5d828e96ca05" timestamp="2017-05-25T11:13:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 89.32.40.238 (MISP Attribute #16056)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 89.32.40.238 (MISP Attribute #16056)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5926f4a8-e18c-4b39-b0ac-5d828e96ca05">
<cybox:Object id=":Address-5926f4a8-e18c-4b39-b0ac-5d828e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">89.32.40.238</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-25T11:13:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5926f4a8-cb10-4528-89f8-5d828e96ca05" timestamp="2017-05-25T11:13:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 80.255.12.237 (MISP Attribute #16057)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 80.255.12.237 (MISP Attribute #16057)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5926f4a8-cb10-4528-89f8-5d828e96ca05">
<cybox:Object id=":Address-5926f4a8-cb10-4528-89f8-5d828e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">80.255.12.237</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-25T11:13:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5926f504-4e00-4343-9488-5d828e96ca05" timestamp="2017-05-25T11:15:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: g.mail2017@yandex.com (MISP Attribute #16058)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: g.mail2017@yandex.com (MISP Attribute #16058)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5926f504-4e00-4343-9488-5d828e96ca05">
<cybox:Object id=":EmailMessage-5926f504-4e00-4343-9488-5d828e96ca05">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">g.mail2017@yandex.com</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-25T11:15:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5926f504-53f4-4700-8a2b-5d828e96ca05" timestamp="2017-05-25T11:15:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: annaablony@mail.com (MISP Attribute #16059)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: annaablony@mail.com (MISP Attribute #16059)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5926f504-53f4-4700-8a2b-5d828e96ca05">
<cybox:Object id=":EmailMessage-5926f504-53f4-4700-8a2b-5d828e96ca05">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">annaablony@mail.com</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-25T11:15:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5926f504-a840-4d0e-8d26-5d828e96ca05" timestamp="2017-05-25T11:15:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: myprimaryreger@gmail.com (MISP Attribute #16060)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: myprimaryreger@gmail.com (MISP Attribute #16060)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5926f504-a840-4d0e-8d26-5d828e96ca05">
<cybox:Object id=":EmailMessage-5926f504-a840-4d0e-8d26-5d828e96ca05">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">myprimaryreger@gmail.com</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-25T11:15:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:History>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>