Files

2303 lines
224 KiB
XML
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:="https://rufus.citlab.utoronto.ca"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-d63348c4-4789-48f2-9a41-ede3e7dfe251" version="1.1.1" timestamp="2016-11-08T20:32:24.541089+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-581c1022-5c68-4617-9ea4-497a8e96ca05" version="1.1.1" timestamp="2016-11-08T15:29:20+00:00">
<stix:STIX_Header>
<stix:Title>The Million Dollar Dissident: NSO Groups iPhone Zero-Days used against a UAE Human Rights Defender (MISP Event #10)</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:TTPs>
<stix:TTP id=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>External analysis: CVE-2016-4656 (MISP Attribute #463)</ttp:Title>
<ttp:Description>An application may be able to execute arbitrary code with kernel privileges</ttp:Description>
<ttp:Exploit_Targets>
<ttp:Exploit_Target>
<stixCommon:Exploit_Target id=":et-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='et:ExploitTargetType'>
<et:Title>An application may be able to execute arbitrary code with kernel privileges</et:Title>
<et:Vulnerability>
<et:CVE_ID>CVE-2016-4656</et:CVE_ID>
</et:Vulnerability>
</stixCommon:Exploit_Target>
</ttp:Exploit_Target>
</ttp:Exploit_Targets>
</stix:TTP>
<stix:TTP id=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>External analysis: CVE-2016-4655 (MISP Attribute #464)</ttp:Title>
<ttp:Description>An application may be able to disclose kernel memory</ttp:Description>
<ttp:Exploit_Targets>
<ttp:Exploit_Target>
<stixCommon:Exploit_Target id=":et-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='et:ExploitTargetType'>
<et:Title>An application may be able to disclose kernel memory</et:Title>
<et:Vulnerability>
<et:CVE_ID>CVE-2016-4655</et:CVE_ID>
</et:Vulnerability>
</stixCommon:Exploit_Target>
</ttp:Exploit_Target>
</ttp:Exploit_Targets>
</stix:TTP>
<stix:TTP id=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>External analysis: CVE-2016-4657 (MISP Attribute #465)</ttp:Title>
<ttp:Description>Visiting a maliciously crafted website may lead to arbitrary code execution</ttp:Description>
<ttp:Exploit_Targets>
<ttp:Exploit_Target>
<stixCommon:Exploit_Target id=":et-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='et:ExploitTargetType'>
<et:Title>Visiting a maliciously crafted website may lead to arbitrary code execution</et:Title>
<et:Vulnerability>
<et:CVE_ID>CVE-2016-4657</et:CVE_ID>
</et:Vulnerability>
</stixCommon:Exploit_Target>
</ttp:Exploit_Target>
</ttp:Exploit_Targets>
</stix:TTP>
<stix:TTP id=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload type: Pegasus (MISP Attribute #1313)</ttp:Title>
<ttp:Description>NSO Group product</ttp:Description>
<ttp:Behavior>
<ttp:Malware>
<ttp:Malware_Instance>
<ttp:Name>Pegasus</ttp:Name>
</ttp:Malware_Instance>
</ttp:Malware>
</ttp:Behavior>
</stix:TTP>
</stix:TTPs>
<stix:Incidents>
<stix:Incident id=":incident-581c1022-5c68-4617-9ea4-497a8e96ca05" timestamp="2016-11-08T15:31:51+00:00" xsi:type='incident:IncidentType'>
<incident:Title>The Million Dollar Dissident: NSO Groups iPhone Zero-Days used against a UAE Human Rights Defender</incident:Title>
<incident:External_ID source="MISP Event">10</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2016-08-24T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2016-11-08T15:31:51+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">Closed</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-581c106f-cf04-43a6-88e8-497a8e96ca05" timestamp="2016-11-04T00:37:03+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: NSO Group (MISP Attribute #498)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: NSO Group (MISP Attribute #498)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-04T00:37:03+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58223036-8d6c-4c3e-a427-497a8e96ca05" timestamp="2016-11-08T15:06:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: alljazeera.co (MISP Attribute #1314)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: alljazeera.co (MISP Attribute #1314)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58223036-8d6c-4c3e-a427-497a8e96ca05">
<cybox:Object id=":DomainName-58223036-8d6c-4c3e-a427-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">alljazeera.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:06:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-6748-496e-a951-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: bbc-africa.com (MISP Attribute #1315)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: bbc-africa.com (MISP Attribute #1315)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-6748-496e-a951-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-6748-496e-a951-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">bbc-africa.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-839c-4f04-949e-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: cnn-africa.co (MISP Attribute #1316)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: cnn-africa.co (MISP Attribute #1316)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-839c-4f04-949e-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-839c-4f04-949e-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">cnn-africa.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-e9e0-4a50-b94c-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: unonoticias.net (MISP Attribute #1317)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: unonoticias.net (MISP Attribute #1317)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-e9e0-4a50-b94c-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-e9e0-4a50-b94c-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">unonoticias.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-2670-47d2-8389-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: univision.click (MISP Attribute #1318)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: univision.click (MISP Attribute #1318)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-2670-47d2-8389-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-2670-47d2-8389-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">univision.click</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-ceec-4dcb-8c51-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: track-your-fedex-package.org (MISP Attribute #1319)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: track-your-fedex-package.org (MISP Attribute #1319)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-ceec-4dcb-8c51-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-ceec-4dcb-8c51-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">track-your-fedex-package.org</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-8640-4db9-8cdf-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mz-vodacom.info (MISP Attribute #1320)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mz-vodacom.info (MISP Attribute #1320)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-8640-4db9-8cdf-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-8640-4db9-8cdf-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mz-vodacom.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-93cc-4f2b-8ae4-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: iusacell-movil.com.mx (MISP Attribute #1321)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: iusacell-movil.com.mx (MISP Attribute #1321)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-93cc-4f2b-8ae4-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-93cc-4f2b-8ae4-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">iusacell-movil.com.mx</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-c5ac-4743-862b-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: sabafon.info (MISP Attribute #1322)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: sabafon.info (MISP Attribute #1322)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-c5ac-4743-862b-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-c5ac-4743-862b-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">sabafon.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-3754-42c7-af73-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: newtarrifs.net (MISP Attribute #1323)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: newtarrifs.net (MISP Attribute #1323)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-3754-42c7-af73-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-3754-42c7-af73-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">newtarrifs.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-aa70-4ee9-8fad-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: y0utube.com.mx (MISP Attribute #1324)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: y0utube.com.mx (MISP Attribute #1324)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-aa70-4ee9-8fad-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-aa70-4ee9-8fad-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">y0utube.com.mx</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-7c38-47df-b3b1-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: fb-accounts.com (MISP Attribute #1325)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: fb-accounts.com (MISP Attribute #1325)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-7c38-47df-b3b1-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-7c38-47df-b3b1-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">fb-accounts.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-049c-47ec-90e2-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: googleplay-store.com (MISP Attribute #1326)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: googleplay-store.com (MISP Attribute #1326)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-049c-47ec-90e2-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-049c-47ec-90e2-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">googleplay-store.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-fbc0-42e5-b56c-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: whatsapp-app.com (MISP Attribute #1327)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: whatsapp-app.com (MISP Attribute #1327)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-fbc0-42e5-b56c-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-fbc0-42e5-b56c-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">whatsapp-app.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-e524-449e-8e0c-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts.mx (MISP Attribute #1328)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts.mx (MISP Attribute #1328)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-e524-449e-8e0c-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-e524-449e-8e0c-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts.mx</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-ecc8-4bce-966d-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: adjust-local-settings.com (MISP Attribute #1329)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: adjust-local-settings.com (MISP Attribute #1329)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-ecc8-4bce-966d-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-ecc8-4bce-966d-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">adjust-local-settings.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-8440-4d71-97b4-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: emiratesfoundation.net (MISP Attribute #1330)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: emiratesfoundation.net (MISP Attribute #1330)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-8440-4d71-97b4-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-8440-4d71-97b4-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">emiratesfoundation.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-0cf8-4c54-8e57-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: checkinonlinehere.com (MISP Attribute #1331)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: checkinonlinehere.com (MISP Attribute #1331)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-0cf8-4c54-8e57-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-0cf8-4c54-8e57-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">checkinonlinehere.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-36e4-4843-93db-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: turkishairines.info (MISP Attribute #1332)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: turkishairines.info (MISP Attribute #1332)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-36e4-4843-93db-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-36e4-4843-93db-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">turkishairines.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-0880-4c1c-a507-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: bulbazaur.com (MISP Attribute #1333)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: bulbazaur.com (MISP Attribute #1333)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-0880-4c1c-a507-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-0880-4c1c-a507-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">bulbazaur.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582230b8-a9f4-4590-bb10-497a8e96ca05" timestamp="2016-11-08T15:08:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: pickuchu.com (MISP Attribute #1334)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: pickuchu.com (MISP Attribute #1334)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582230b8-a9f4-4590-bb10-497a8e96ca05">
<cybox:Object id=":DomainName-582230b8-a9f4-4590-bb10-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">pickuchu.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:08:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58223264-6050-4883-8676-497a8e96ca05" timestamp="2016-11-08T15:15:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: damanhealth.online (MISP Attribute #1335)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: damanhealth.online (MISP Attribute #1335)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58223264-6050-4883-8676-497a8e96ca05">
<cybox:Object id=":DomainName-58223264-6050-4883-8676-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">damanhealth.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:15:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822327c-2050-46cb-b310-497a8e96ca05" timestamp="2016-11-08T15:15:56+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: uaenews.online (MISP Attribute #1336)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: uaenews.online (MISP Attribute #1336)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822327c-2050-46cb-b310-497a8e96ca05">
<cybox:Object id=":DomainName-5822327c-2050-46cb-b310-497a8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">uaenews.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:15:56+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582233c5-8108-41eb-ba12-49798e96ca05" timestamp="2016-11-08T15:21:25+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: ideas-telcel.com.mx (MISP Attribute #1340)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: ideas-telcel.com.mx (MISP Attribute #1340)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582233c5-8108-41eb-ba12-49798e96ca05">
<cybox:Object id=":DomainName-582233c5-8108-41eb-ba12-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">ideas-telcel.com.mx</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:21:25+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582235a0-ea0c-4301-b87b-49798e96ca05" timestamp="2016-11-08T15:29:20+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: nation-news.com (MISP Attribute #1342)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: nation-news.com (MISP Attribute #1342)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582235a0-ea0c-4301-b87b-49798e96ca05">
<cybox:Object id=":DomainName-582235a0-ea0c-4301-b87b-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">nation-news.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:29:20+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-f13b8f95-e6ca-47a8-8c25-fe1f4817a439" timestamp="2016-11-08T14:28:07+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: webadv.co (MISP Attribute #466)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: webadv.co (MISP Attribute #466)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-f13b8f95-e6ca-47a8-8c25-fe1f4817a439">
<cybox:Object id=":DomainName-f13b8f95-e6ca-47a8-8c25-fe1f4817a439">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">webadv.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:28:07+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-2ad610a4-2177-4e7f-b525-8621a80e2ebe" timestamp="2016-11-08T14:29:23+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: icloudcacher.com (MISP Attribute #469)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: icloudcacher.com (MISP Attribute #469)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-2ad610a4-2177-4e7f-b525-8621a80e2ebe">
<cybox:Object id=":DomainName-2ad610a4-2177-4e7f-b525-8621a80e2ebe">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">icloudcacher.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:29:23+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-9c494d42-797d-4c62-978a-8a888fb179c8" timestamp="2016-11-08T14:31:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: asrarrarabiya.com (MISP Attribute #470)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: asrarrarabiya.com (MISP Attribute #470)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-9c494d42-797d-4c62-978a-8a888fb179c8">
<cybox:Object id=":DomainName-9c494d42-797d-4c62-978a-8a888fb179c8">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">asrarrarabiya.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:31:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-325e4a00-7b2f-4c27-bff2-89f390e3c13c" timestamp="2016-11-08T14:35:10+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: asrararabiya.co (MISP Attribute #471)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: asrararabiya.co (MISP Attribute #471)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-325e4a00-7b2f-4c27-bff2-89f390e3c13c">
<cybox:Object id=":DomainName-325e4a00-7b2f-4c27-bff2-89f390e3c13c">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">asrararabiya.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:35:10+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-9a804548-73c4-4258-9b88-51f952f75d17" timestamp="2016-11-08T14:45:48+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: asrararablya.com (MISP Attribute #472)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: asrararablya.com (MISP Attribute #472)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-9a804548-73c4-4258-9b88-51f952f75d17">
<cybox:Object id=":DomainName-9a804548-73c4-4258-9b88-51f952f75d17">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">asrararablya.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:45:48+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-cd9ef05f-b3ea-41c2-a750-a431f9dfb508" timestamp="2016-11-08T14:46:00+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: smser.net (MISP Attribute #473)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: smser.net (MISP Attribute #473)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-cd9ef05f-b3ea-41c2-a750-a431f9dfb508">
<cybox:Object id=":DomainName-cd9ef05f-b3ea-41c2-a750-a431f9dfb508">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">smser.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:00+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-17a374eb-20d6-4790-bee4-45b7073115f1" timestamp="2016-11-08T14:46:06+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: icrcworld.com (MISP Attribute #474)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: icrcworld.com (MISP Attribute #474)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-17a374eb-20d6-4790-bee4-45b7073115f1">
<cybox:Object id=":DomainName-17a374eb-20d6-4790-bee4-45b7073115f1">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">icrcworld.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:06+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-0d1164d5-7670-41da-8857-1247d0b67561" timestamp="2016-11-08T14:46:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: redcrossworld.com (MISP Attribute #475)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: redcrossworld.com (MISP Attribute #475)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-0d1164d5-7670-41da-8857-1247d0b67561">
<cybox:Object id=":DomainName-0d1164d5-7670-41da-8857-1247d0b67561">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">redcrossworld.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-0f203872-71ec-4b51-ba56-c50918f71f39" timestamp="2016-11-08T14:46:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: topcontactco.com (MISP Attribute #476)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: topcontactco.com (MISP Attribute #476)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-0f203872-71ec-4b51-ba56-c50918f71f39">
<cybox:Object id=":DomainName-0f203872-71ec-4b51-ba56-c50918f71f39">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">topcontactco.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-a2f8ef48-d6f7-46b1-9ee0-71fcb1c65cb9" timestamp="2016-11-08T14:46:26+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: thainews.asia (MISP Attribute #477)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: thainews.asia (MISP Attribute #477)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-a2f8ef48-d6f7-46b1-9ee0-71fcb1c65cb9">
<cybox:Object id=":DomainName-a2f8ef48-d6f7-46b1-9ee0-71fcb1c65cb9">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">thainews.asia</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:26+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-126c3480-6ad3-417f-9855-4e915b9ae528" timestamp="2016-11-08T14:46:34+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: kenyasms.org (MISP Attribute #478)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: kenyasms.org (MISP Attribute #478)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-126c3480-6ad3-417f-9855-4e915b9ae528">
<cybox:Object id=":DomainName-126c3480-6ad3-417f-9855-4e915b9ae528">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">kenyasms.org</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:34+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-7d63d6cb-90dc-454c-a505-a313150c1426" timestamp="2016-11-08T14:46:41+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: qaintqa.com (MISP Attribute #479)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: qaintqa.com (MISP Attribute #479)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-7d63d6cb-90dc-454c-a505-a313150c1426">
<cybox:Object id=":DomainName-7d63d6cb-90dc-454c-a505-a313150c1426">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">qaintqa.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:41+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-812c4cbf-60a7-431d-ae7a-a9fd1d6044aa" timestamp="2016-11-08T14:46:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: nsoqa.com (MISP Attribute #480)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: nsoqa.com (MISP Attribute #480)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-812c4cbf-60a7-431d-ae7a-a9fd1d6044aa">
<cybox:Object id=":DomainName-812c4cbf-60a7-431d-ae7a-a9fd1d6044aa">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">nsoqa.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:46:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-9be3a48f-e540-43f8-a2c0-8dc915a3dd48" timestamp="2016-11-08T14:54:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: ooredoodeals.com (MISP Attribute #481)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: ooredoodeals.com (MISP Attribute #481)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-9be3a48f-e540-43f8-a2c0-8dc915a3dd48">
<cybox:Object id=":DomainName-9be3a48f-e540-43f8-a2c0-8dc915a3dd48">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">ooredoodeals.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:54:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-252cc33c-8786-4dee-b77a-af52acb1661b" timestamp="2016-11-08T14:54:21+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: alawaeltech.com (MISP Attribute #482)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: alawaeltech.com (MISP Attribute #482)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-252cc33c-8786-4dee-b77a-af52acb1661b">
<cybox:Object id=":DomainName-252cc33c-8786-4dee-b77a-af52acb1661b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">alawaeltech.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:54:21+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-14df3986-e958-4612-ba2f-daa9fd95b868" timestamp="2016-11-08T14:54:27+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: bahrainsms.co (MISP Attribute #483)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: bahrainsms.co (MISP Attribute #483)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-14df3986-e958-4612-ba2f-daa9fd95b868">
<cybox:Object id=":DomainName-14df3986-e958-4612-ba2f-daa9fd95b868">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">bahrainsms.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:54:27+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-6540311c-8872-47a3-ada2-24757eaa35ee" timestamp="2016-11-08T14:54:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: turkeynewsupdates.com (MISP Attribute #484)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: turkeynewsupdates.com (MISP Attribute #484)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-6540311c-8872-47a3-ada2-24757eaa35ee">
<cybox:Object id=":DomainName-6540311c-8872-47a3-ada2-24757eaa35ee">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">turkeynewsupdates.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:54:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-340ccd5a-2520-4ccb-abeb-b264fb2bf645" timestamp="2016-11-08T15:13:37+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail1.nsogroup.com (MISP Attribute #486)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail1.nsogroup.com (MISP Attribute #486)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-340ccd5a-2520-4ccb-abeb-b264fb2bf645">
<cybox:Object id=":DomainName-340ccd5a-2520-4ccb-abeb-b264fb2bf645">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail1.nsogroup.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:13:37+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-029c89df-139e-463a-b1f1-c259b913d05f" timestamp="2016-11-08T15:09:41+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 52.8.153.44 (MISP Attribute #487)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 52.8.153.44 (MISP Attribute #487)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-029c89df-139e-463a-b1f1-c259b913d05f">
<cybox:Object id=":Address-029c89df-139e-463a-b1f1-c259b913d05f">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">52.8.153.44</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:09:41+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-2f6d312b-8db7-4fa0-9522-cc68090b4a3b" timestamp="2016-11-08T15:10:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 52.8.52.166 (MISP Attribute #488)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 52.8.52.166 (MISP Attribute #488)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-2f6d312b-8db7-4fa0-9522-cc68090b4a3b">
<cybox:Object id=":Address-2f6d312b-8db7-4fa0-9522-cc68090b4a3b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">52.8.52.166</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:10:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-cb442bf4-0d18-4d60-b1a7-e0fe5c7614fa" timestamp="2016-11-08T15:10:28+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 162.209.103.68 (MISP Attribute #489)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 162.209.103.68 (MISP Attribute #489)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-cb442bf4-0d18-4d60-b1a7-e0fe5c7614fa">
<cybox:Object id=":Address-cb442bf4-0d18-4d60-b1a7-e0fe5c7614fa">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">162.209.103.68</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:10:28+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-7db51886-46b4-496f-86fd-6b75a7b5f8c8" timestamp="2016-11-08T15:11:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 82.80.202.200 (MISP Attribute #490)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 82.80.202.200 (MISP Attribute #490)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-7db51886-46b4-496f-86fd-6b75a7b5f8c8">
<cybox:Object id=":Address-7db51886-46b4-496f-86fd-6b75a7b5f8c8">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">82.80.202.200</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:11:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-27a5b383-3c23-4f93-9341-8dd8d90575f6" timestamp="2016-11-08T15:12:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 82.80.202.204 (MISP Attribute #491)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 82.80.202.204 (MISP Attribute #491)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-27a5b383-3c23-4f93-9341-8dd8d90575f6">
<cybox:Object id=":Address-27a5b383-3c23-4f93-9341-8dd8d90575f6">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">82.80.202.204</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:12:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-208dbaaf-39c3-4930-8304-1c76e9b1e7b8" timestamp="2016-11-08T15:12:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 54.251.49.214 (MISP Attribute #492)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 54.251.49.214 (MISP Attribute #492)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-208dbaaf-39c3-4930-8304-1c76e9b1e7b8">
<cybox:Object id=":Address-208dbaaf-39c3-4930-8304-1c76e9b1e7b8">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">54.251.49.214</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:12:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-96bd845b-b8a7-4c91-92e1-c9060cc01239" timestamp="2016-11-08T15:05:00+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https://smser.net/9918216t/ (MISP Attribute #493)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: https://smser.net/9918216t/ (MISP Attribute #493)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-96bd845b-b8a7-4c91-92e1-c9060cc01239">
<cybox:Object id=":URI-96bd845b-b8a7-4c91-92e1-c9060cc01239">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://smser.net/9918216t/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:05:00+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-c9181cb8-1400-47e1-b45b-fc4d17cebe52" timestamp="2016-11-08T15:04:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https://smser.net/redirect.aspx (MISP Attribute #494)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: https://smser.net/redirect.aspx (MISP Attribute #494)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-c9181cb8-1400-47e1-b45b-fc4d17cebe52">
<cybox:Object id=":URI-c9181cb8-1400-47e1-b45b-fc4d17cebe52">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://smser.net/redirect.aspx</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:04:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-cdde7699-d231-458d-80a5-338b9e985702" timestamp="2016-11-08T15:01:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: aalaan.tv (MISP Attribute #467)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Payload delivery: aalaan.tv (MISP Attribute #467)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-cdde7699-d231-458d-80a5-338b9e985702">
<cybox:Object id=":DomainName-cdde7699-d231-458d-80a5-338b9e985702">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">aalaan.tv</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:01:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-73293a7a-acd5-47a0-81b6-a73f6dde67e1" timestamp="2016-11-08T15:01:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: manoraonline.net (MISP Attribute #468)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Payload delivery: manoraonline.net (MISP Attribute #468)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-73293a7a-acd5-47a0-81b6-a73f6dde67e1">
<cybox:Object id=":DomainName-73293a7a-acd5-47a0-81b6-a73f6dde67e1">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">manoraonline.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:01:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-ca1121b7-d273-4aac-83e8-e69b4bce5604" timestamp="2016-11-08T14:57:37+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: sms.webadv.co (MISP Attribute #485)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Payload delivery: sms.webadv.co (MISP Attribute #485)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-ca1121b7-d273-4aac-83e8-e69b4bce5604">
<cybox:Object id=":DomainName-ca1121b7-d273-4aac-83e8-e69b4bce5604">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">sms.webadv.co</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:57:37+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-6fad387c-a58a-4689-97d0-f87a42dee5b0" timestamp="2016-11-08T15:04:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: pn1g3p@sigaint.org (MISP Attribute #497)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: pn1g3p@sigaint.org (MISP Attribute #497)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-6fad387c-a58a-4689-97d0-f87a42dee5b0">
<cybox:Object id=":EmailMessage-6fad387c-a58a-4689-97d0-f87a42dee5b0">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">pn1g3p@sigaint.org</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:04:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58222e62-1020-4d67-b83f-49798e96ca05" timestamp="2016-11-08T14:58:26+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: https://sms.webadv.co/3589003s/ (MISP Attribute #1311)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: https://sms.webadv.co/3589003s/ (MISP Attribute #1311)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58222e62-1020-4d67-b83f-49798e96ca05">
<cybox:Object id=":URI-58222e62-1020-4d67-b83f-49798e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://sms.webadv.co/3589003s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:58:26+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58222e78-135c-434e-966e-49798e96ca05" timestamp="2016-11-08T14:58:48+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: https://sms.webadv.co/9573305s/ (MISP Attribute #1312)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: https://sms.webadv.co/9573305s/ (MISP Attribute #1312)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58222e78-135c-434e-966e-49798e96ca05">
<cybox:Object id=":URI-58222e78-135c-434e-966e-49798e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://sms.webadv.co/9573305s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T14:58:48+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58223346-c23c-4751-9d82-69fe8e96ca05" timestamp="2016-11-08T15:19:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: http://fb-accounts.com/2408931s/ (MISP Attribute #1337)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: http://fb-accounts.com/2408931s/ (MISP Attribute #1337)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58223346-c23c-4751-9d82-69fe8e96ca05">
<cybox:Object id=":URI-58223346-c23c-4751-9d82-69fe8e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://fb-accounts.com/2408931s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:19:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58223375-b860-4462-9d5a-49798e96ca05" timestamp="2016-11-08T15:20:05+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: http://unonoticias.net/1867745s/ (MISP Attribute #1338)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: http://unonoticias.net/1867745s/ (MISP Attribute #1338)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58223375-b860-4462-9d5a-49798e96ca05">
<cybox:Object id=":URI-58223375-b860-4462-9d5a-49798e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://unonoticias.net/1867745s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:20:05+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582233be-b3c8-4238-82b5-49798e96ca05" timestamp="2016-11-08T15:21:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: https://ideas-telcel.com.mx/3975827s/ (MISP Attribute #1339)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: https://ideas-telcel.com.mx/3975827s/ (MISP Attribute #1339)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582233be-b3c8-4238-82b5-49798e96ca05">
<cybox:Object id=":URI-582233be-b3c8-4238-82b5-49798e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://ideas-telcel.com.mx/3975827s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:21:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58223592-ad84-44d5-9e29-49798e96ca05" timestamp="2016-11-08T15:29:06+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: nation-news.com/4077017s/ (MISP Attribute #1341)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: nation-news.com/4077017s/ (MISP Attribute #1341)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58223592-ad84-44d5-9e29-49798e96ca05">
<cybox:Object id=":URI-58223592-ad84-44d5-9e29-49798e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">nation-news.com/4077017s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:29:06+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-7dd57279-a151-44d4-a21d-bb62ee3435aa" timestamp="2016-11-08T15:18:53+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: http://fb-accounts.com/1074139s/ (MISP Attribute #495)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: http://fb-accounts.com/1074139s/ (MISP Attribute #495)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-7dd57279-a151-44d4-a21d-bb62ee3435aa">
<cybox:Object id=":URI-7dd57279-a151-44d4-a21d-bb62ee3435aa">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://fb-accounts.com/1074139s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:18:53+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-eed4deb8-c8a8-4722-8e29-8ba5772e3059" timestamp="2016-11-08T15:19:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: http://unonoticias.net/3423768s/ (MISP Attribute #496)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: http://unonoticias.net/3423768s/ (MISP Attribute #496)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-eed4deb8-c8a8-4722-8e29-8ba5772e3059">
<cybox:Object id=":URI-eed4deb8-c8a8-4722-8e29-8ba5772e3059">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://unonoticias.net/3423768s/</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-08T15:19:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:Leveraged_TTPs>
<incident:Leveraged_TTP>
<stixCommon:Relationship>External analysis</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-268f13bd-3b4b-4ff5-88c1-bbf33405bb3c" timestamp="2016-11-08T14:28:46+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>External analysis</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-aa080850-113d-4a41-bb48-5be41d23061d" timestamp="2016-11-08T14:28:41+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>External analysis</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-4d37d443-08ae-4c04-a8d7-9e27a8b73e35" timestamp="2016-11-08T14:28:36+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload type</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-58222ea5-3130-41cc-a8e2-49798e96ca05" timestamp="2016-11-08T14:59:39+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
</incident:Leveraged_TTPs>
<incident:History>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">Event Threat Level: High</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TLP:GREEN</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: SOURCE:CITIZENLAB</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: DETECT</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: PUBLISHED</incident:Journal_Entry>
</incident:History_Item>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
<stixCommon:References>
<stixCommon:Reference>https://citizenlab.org/2016/08/million-dollar-dissident-iphone-zero-day-nso-group-uae/</stixCommon:Reference>
</stixCommon:References>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>