Files

1682 lines
148 KiB
XML
Raw Permalink Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:="https://rufus.citlab.utoronto.ca"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-7cef25ee-341b-4d14-a63b-2af874baade1" version="1.1.1" timestamp="2016-11-16T20:25:14.935544+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-5820aa49-6a40-4e51-86f9-497a8e96ca05" version="1.1.1" timestamp="2016-11-16T15:02:43+00:00">
<stix:STIX_Header>
<stix:Title>Its Parliamentary: KeyBoy and the targeting of the Tibetan Community (MISP Event #17)</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:TTPs>
<stix:TTP id=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload delivery: CVE-2012-0158 (MISP Attribute #811)</ttp:Title>
<ttp:Description>8307e444cad98b1b59568ad2eba5f201</ttp:Description>
<ttp:Exploit_Targets>
<ttp:Exploit_Target>
<stixCommon:Exploit_Target id=":et-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='et:ExploitTargetType'>
<et:Title>8307e444cad98b1b59568ad2eba5f201</et:Title>
<et:Vulnerability>
<et:CVE_ID>CVE-2012-0158</et:CVE_ID>
</et:Vulnerability>
</stixCommon:Exploit_Target>
</ttp:Exploit_Target>
</ttp:Exploit_Targets>
</stix:TTP>
<stix:TTP id=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload delivery: CVE-2014-4114 (MISP Attribute #832)</ttp:Title>
<ttp:Exploit_Targets>
<ttp:Exploit_Target>
<stixCommon:Exploit_Target id=":et-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='et:ExploitTargetType'>
<et:Title>Vulnerability CVE-2014-4114</et:Title>
<et:Vulnerability>
<et:CVE_ID>CVE-2014-4114</et:CVE_ID>
</et:Vulnerability>
</stixCommon:Exploit_Target>
</ttp:Exploit_Target>
</ttp:Exploit_Targets>
</stix:TTP>
<stix:TTP id=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload delivery: CVE-2015-1641 (MISP Attribute #1374)</ttp:Title>
<ttp:Exploit_Targets>
<ttp:Exploit_Target>
<stixCommon:Exploit_Target id=":et-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='et:ExploitTargetType'>
<et:Title>Vulnerability CVE-2015-1641</et:Title>
<et:Vulnerability>
<et:CVE_ID>CVE-2015-1641</et:CVE_ID>
</et:Vulnerability>
</stixCommon:Exploit_Target>
</ttp:Exploit_Target>
</ttp:Exploit_Targets>
</stix:TTP>
<stix:TTP id=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload type: KeyBoy (MISP Attribute #809)</ttp:Title>
<ttp:Behavior>
<ttp:Malware>
<ttp:Malware_Instance>
<ttp:Name>KeyBoy</ttp:Name>
</ttp:Malware_Instance>
</ttp:Malware>
</ttp:Behavior>
</stix:TTP>
</stix:TTPs>
<stix:Incidents>
<stix:Incident id=":incident-5820aa49-6a40-4e51-86f9-497a8e96ca05" timestamp="2016-11-16T15:02:57+00:00" xsi:type='incident:IncidentType'>
<incident:Title>Its Parliamentary: KeyBoy and the targeting of the Tibetan Community</incident:Title>
<incident:External_ID source="MISP Event">17</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2016-11-07T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2016-11-16T15:02:57+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">Open</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ab69-8e78-4925-8f07-497a8e96ca05" timestamp="2016-11-07T11:27:21+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 8f08609e4e0b3d26814b3073a42df415 (MISP Attribute #813)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 8f08609e4e0b3d26814b3073a42df415 (MISP Attribute #813)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ab69-8e78-4925-8f07-497a8e96ca05">
<cybox:Object id=":File-5820ab69-8e78-4925-8f07-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">8f08609e4e0b3d26814b3073a42df415</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:27:21+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ab7b-5a8c-4164-8113-49798e96ca05" timestamp="2016-11-07T11:37:43+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 495adb1b9777002ecfe22aaf52fcee93 (MISP Attribute #814)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 495adb1b9777002ecfe22aaf52fcee93 (MISP Attribute #814)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ab7b-5a8c-4164-8113-49798e96ca05">
<cybox:Object id=":File-5820ab7b-5a8c-4164-8113-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">495adb1b9777002ecfe22aaf52fcee93</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:37:43+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac1b-05c0-4d60-8fc5-497a8e96ca05" timestamp="2016-11-07T11:33:10+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 0c7e55509e0b6d4277b3facf864af018 (MISP Attribute #822)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 0c7e55509e0b6d4277b3facf864af018 (MISP Attribute #822)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac1b-05c0-4d60-8fc5-497a8e96ca05">
<cybox:Object id=":File-5820ac1b-05c0-4d60-8fc5-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">0c7e55509e0b6d4277b3facf864af018</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:33:10+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac71-ff98-486d-b2e6-49798e96ca05" timestamp="2016-11-07T11:32:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 98977426d544bd145979f65f0322ae30 (MISP Attribute #827)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 98977426d544bd145979f65f0322ae30 (MISP Attribute #827)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac71-ff98-486d-b2e6-49798e96ca05">
<cybox:Object id=":File-5820ac71-ff98-486d-b2e6-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">98977426d544bd145979f65f0322ae30</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:32:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ad9c-c3c4-455e-a5f2-497a8e96ca05" timestamp="2016-11-07T11:36:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: c5b5f01ba24d6c02636388809f44472e (MISP Attribute #833)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: c5b5f01ba24d6c02636388809f44472e (MISP Attribute #833)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ad9c-c3c4-455e-a5f2-497a8e96ca05">
<cybox:Object id=":File-5820ad9c-c3c4-455e-a5f2-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">c5b5f01ba24d6c02636388809f44472e</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:36:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820adb2-5520-499c-95d3-49798e96ca05" timestamp="2016-11-07T11:37:06+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 371bc132499f455f06fa80696db0df27 (MISP Attribute #834)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 371bc132499f455f06fa80696db0df27 (MISP Attribute #834)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820adb2-5520-499c-95d3-49798e96ca05">
<cybox:Object id=":File-5820adb2-5520-499c-95d3-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">371bc132499f455f06fa80696db0df27</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:37:06+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58239987-0038-44ba-997f-49798e96ca05" timestamp="2016-11-09T16:47:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 087bffa8a570079948310dc9731c5709 (MISP Attribute #1372)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 087bffa8a570079948310dc9731c5709 (MISP Attribute #1372)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58239987-0038-44ba-997f-49798e96ca05">
<cybox:Object id=":File-58239987-0038-44ba-997f-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">087bffa8a570079948310dc9731c5709</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T16:47:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58235402-9d54-437c-b845-69fe8e96ca05" timestamp="2016-11-16T11:56:27+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ver (MISP Attribute #1365)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Host Characteristics</indicator:Type>
<indicator:Description>Artifacts dropped: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ver (MISP Attribute #1365)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58235402-9d54-437c-b845-69fe8e96ca05">
<cybox:Object id=":WinRegistryKey-58235402-9d54-437c-b845-69fe8e96ca05">
<cybox:Properties xsi:type="WinRegistryKeyObj:WindowsRegistryKeyObjectType">
<WinRegistryKeyObj:Key condition="Equals">Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ver</WinRegistryKeyObj:Key>
<WinRegistryKeyObj:Hive condition="Equals">HKEY_CURRENT_USER</WinRegistryKeyObj:Hive>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-16T11:56:27+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582398b8-c1b4-418a-8fe7-49798e96ca05" timestamp="2016-11-09T16:44:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 58105e9772f6befbc319c147a97faded4fbacf839947b34fe3695ae72771da5d (MISP Attribute #1368)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 58105e9772f6befbc319c147a97faded4fbacf839947b34fe3695ae72771da5d (MISP Attribute #1368)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582398b8-c1b4-418a-8fe7-49798e96ca05">
<cybox:Object id=":File-582398b8-c1b4-418a-8fe7-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">58105e9772f6befbc319c147a97faded4fbacf839947b34fe3695ae72771da5d</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T16:44:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582398da-78c0-47ed-8bb9-49798e96ca05" timestamp="2016-11-09T16:44:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 9a55577d357922711ab0821bf5379289293c8517ae1d94d48c389f306af57a04 (MISP Attribute #1369)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 9a55577d357922711ab0821bf5379289293c8517ae1d94d48c389f306af57a04 (MISP Attribute #1369)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582398da-78c0-47ed-8bb9-49798e96ca05">
<cybox:Object id=":File-582398da-78c0-47ed-8bb9-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">9a55577d357922711ab0821bf5379289293c8517ae1d94d48c389f306af57a04</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T16:44:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582399a3-04f8-4542-b205-49798e96ca05" timestamp="2016-11-09T16:48:19+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 5da2f14c382d7cac8dfa6c86e528a646a81f0b40cfee9611c8cfb4b5d589aa88 (MISP Attribute #1373)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 5da2f14c382d7cac8dfa6c86e528a646a81f0b40cfee9611c8cfb4b5d589aa88 (MISP Attribute #1373)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582399a3-04f8-4542-b205-49798e96ca05">
<cybox:Object id=":File-582399a3-04f8-4542-b205-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">5da2f14c382d7cac8dfa6c86e528a646a81f0b40cfee9611c8cfb4b5d589aa88</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T16:48:19+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820aba7-e398-41cb-939b-49798e96ca05" timestamp="2016-11-07T11:28:23+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: tibetvoices.com (MISP Attribute #817)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: tibetvoices.com (MISP Attribute #817)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820aba7-e398-41cb-939b-49798e96ca05">
<cybox:Object id=":DomainName-5820aba7-e398-41cb-939b-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">tibetvoices.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:28:23+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac33-aa80-4d97-99a2-49798e96ca05" timestamp="2016-11-07T11:35:42+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.about.jkub.com (MISP Attribute #823)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.about.jkub.com (MISP Attribute #823)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac33-aa80-4d97-99a2-49798e96ca05">
<cybox:Object id=":DomainName-5820ac33-aa80-4d97-99a2-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.about.jkub.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:35:42+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac33-586c-4674-b96d-49798e96ca05" timestamp="2016-11-16T12:10:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.eleven.mypop3.org (MISP Attribute #824)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.eleven.mypop3.org (MISP Attribute #824)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac33-586c-4674-b96d-49798e96ca05">
<cybox:Object id=":DomainName-5820ac33-586c-4674-b96d-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.eleven.mypop3.org</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-16T12:10:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac34-dfc4-4772-8fb6-49798e96ca05" timestamp="2016-11-16T12:10:21+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.backus.myftp.name (MISP Attribute #825)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.backus.myftp.name (MISP Attribute #825)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac34-dfc4-4772-8fb6-49798e96ca05">
<cybox:Object id=":DomainName-5820ac34-dfc4-4772-8fb6-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.backus.myftp.name</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-16T12:10:21+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ab93-ca00-4627-a8e9-497a8e96ca05" timestamp="2016-11-10T12:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 45.125.12.147 (MISP Attribute #815)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 45.125.12.147 (MISP Attribute #815)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ab93-ca00-4627-a8e9-497a8e96ca05">
<cybox:Object id=":Address-5820ab93-ca00-4627-a8e9-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">45.125.12.147</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T12:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ab93-8b90-4f61-8591-497a8e96ca05" timestamp="2016-11-16T11:56:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 103.40.102.233 (MISP Attribute #816)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 103.40.102.233 (MISP Attribute #816)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ab93-8b90-4f61-8591-497a8e96ca05">
<cybox:Object id=":Address-5820ab93-8b90-4f61-8591-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">103.40.102.233</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-16T11:56:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820abec-8b88-4398-ba31-497a8e96ca05" timestamp="2016-11-07T11:29:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 116.193.154.69 (MISP Attribute #820)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 116.193.154.69 (MISP Attribute #820)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820abec-8b88-4398-ba31-497a8e96ca05">
<cybox:Object id=":Address-5820abec-8b88-4398-ba31-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">116.193.154.69</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:29:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac98-f508-4869-9701-497a8e96ca05" timestamp="2016-11-16T15:02:43+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 103.242.134.243 (MISP Attribute #828)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 103.242.134.243 (MISP Attribute #828)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac98-f508-4869-9701-497a8e96ca05">
<cybox:Object id=":Address-5820ac98-f508-4869-9701-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">103.242.134.243</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-16T15:02:43+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ad1d-a7c0-4f84-9d29-497a8e96ca05" timestamp="2016-11-07T11:35:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 45.32.47.148 (MISP Attribute #829)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 45.32.47.148 (MISP Attribute #829)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ad1d-a7c0-4f84-9d29-497a8e96ca05">
<cybox:Object id=":Address-5820ad1d-a7c0-4f84-9d29-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">45.32.47.148</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:35:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ad1d-5d34-489f-97b8-497a8e96ca05" timestamp="2016-11-07T11:35:48+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 157.7.84.81 (MISP Attribute #830)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 157.7.84.81 (MISP Attribute #830)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ad1d-5d34-489f-97b8-497a8e96ca05">
<cybox:Object id=":Address-5820ad1d-5d34-489f-97b8-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">157.7.84.81</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:35:48+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ad50-de2c-4f26-bd5c-497a8e96ca05" timestamp="2016-11-07T11:35:28+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 192.241.149.43 (MISP Attribute #831)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 192.241.149.43 (MISP Attribute #831)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ad50-de2c-4f26-bd5c-497a8e96ca05">
<cybox:Object id=":Address-5820ad50-de2c-4f26-bd5c-497a8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">192.241.149.43</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:35:28+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582c9016-1a1c-471e-890f-69fe8e96ca05" timestamp="2016-11-16T11:57:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 112.10.117.47 (MISP Attribute #1880)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 112.10.117.47 (MISP Attribute #1880)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582c9016-1a1c-471e-890f-69fe8e96ca05">
<cybox:Object id=":Address-582c9016-1a1c-471e-890f-69fe8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">112.10.117.47</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-16T11:57:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58238a80-e5bc-449f-9440-497a8e96ca05" timestamp="2016-11-09T15:43:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: tibetanparliarnent@yahoo.com (MISP Attribute #1366)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: tibetanparliarnent@yahoo.com (MISP Attribute #1366)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58238a80-e5bc-449f-9440-497a8e96ca05">
<cybox:Object id=":EmailMessage-58238a80-e5bc-449f-9440-497a8e96ca05">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">tibetanparliarnent@yahoo.com</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T15:43:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820aafa-d53c-4131-8582-497a8e96ca05" timestamp="2016-11-07T11:25:30+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 8307e444cad98b1b59568ad2eba5f201 (MISP Attribute #810)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 8307e444cad98b1b59568ad2eba5f201 (MISP Attribute #810)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820aafa-d53c-4131-8582-497a8e96ca05">
<cybox:Object id=":File-5820aafa-d53c-4131-8582-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">8307e444cad98b1b59568ad2eba5f201</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:25:30+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ab43-0ce0-46a9-bc84-49798e96ca05" timestamp="2016-11-07T11:26:43+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 0b4d45db323f68b465ae052d3a872068 (MISP Attribute #812)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 0b4d45db323f68b465ae052d3a872068 (MISP Attribute #812)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ab43-0ce0-46a9-bc84-49798e96ca05">
<cybox:Object id=":File-5820ab43-0ce0-46a9-bc84-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">0b4d45db323f68b465ae052d3a872068</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:26:43+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820abc0-979c-4a84-8800-497a8e96ca05" timestamp="2016-11-07T11:28:48+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: beadf21b923600554b0ce54df42e78f5 (MISP Attribute #818)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: beadf21b923600554b0ce54df42e78f5 (MISP Attribute #818)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820abc0-979c-4a84-8800-497a8e96ca05">
<cybox:Object id=":File-5820abc0-979c-4a84-8800-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">beadf21b923600554b0ce54df42e78f5</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:28:48+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820abd0-acb8-474a-bbf0-49798e96ca05" timestamp="2016-11-07T11:29:04+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 69df3d3df4d99bc6045d073d89c68697 (MISP Attribute #819)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 69df3d3df4d99bc6045d073d89c68697 (MISP Attribute #819)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820abd0-acb8-474a-bbf0-49798e96ca05">
<cybox:Object id=":File-5820abd0-acb8-474a-bbf0-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">69df3d3df4d99bc6045d073d89c68697</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:29:04+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac07-868c-41f0-85c2-49798e96ca05" timestamp="2016-11-07T11:29:59+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 05b5cf94f07fee666eb086c91182ad25 (MISP Attribute #821)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 05b5cf94f07fee666eb086c91182ad25 (MISP Attribute #821)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac07-868c-41f0-85c2-49798e96ca05">
<cybox:Object id=":File-5820ac07-868c-41f0-85c2-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">05b5cf94f07fee666eb086c91182ad25</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:29:59+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5820ac58-8a88-4011-b491-497a8e96ca05" timestamp="2016-11-07T11:31:20+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 8846d109b457a2ee44ddbf54d1cf7944 (MISP Attribute #826)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 8846d109b457a2ee44ddbf54d1cf7944 (MISP Attribute #826)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5820ac58-8a88-4011-b491-497a8e96ca05">
<cybox:Object id=":File-5820ac58-8a88-4011-b491-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">8846d109b457a2ee44ddbf54d1cf7944</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-07T11:31:20+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582c8ecf-e830-4d88-bbda-497a8e96ca05" timestamp="2016-11-16T11:52:31+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 913b82ff8f090670fc6387e3a7bea12d (MISP Attribute #1879)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 913b82ff8f090670fc6387e3a7bea12d (MISP Attribute #1879)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582c8ecf-e830-4d88-bbda-497a8e96ca05">
<cybox:Object id=":File-582c8ecf-e830-4d88-bbda-497a8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">913b82ff8f090670fc6387e3a7bea12d</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-16T11:52:31+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5823990b-db7c-45c9-9afb-69fe8e96ca05" timestamp="2016-11-09T16:46:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 23d284245e53ae4fe05c517d807ffccf (MISP Attribute #1370)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 23d284245e53ae4fe05c517d807ffccf (MISP Attribute #1370)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5823990b-db7c-45c9-9afb-69fe8e96ca05">
<cybox:Object id=":File-5823990b-db7c-45c9-9afb-69fe8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">23d284245e53ae4fe05c517d807ffccf</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T16:46:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5823989b-68f0-4831-b1d8-49798e96ca05" timestamp="2016-11-09T16:43:55+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 5f24a5ee9ecfd4a8e5f967ffcf24580a83942cd7b09d310b9525962ed2614a49 (MISP Attribute #1367)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 5f24a5ee9ecfd4a8e5f967ffcf24580a83942cd7b09d310b9525962ed2614a49 (MISP Attribute #1367)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5823989b-68f0-4831-b1d8-49798e96ca05">
<cybox:Object id=":File-5823989b-68f0-4831-b1d8-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">5f24a5ee9ecfd4a8e5f967ffcf24580a83942cd7b09d310b9525962ed2614a49</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T16:43:55+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5823995f-701c-4616-84f5-49798e96ca05" timestamp="2016-11-09T16:47:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 542c85fda8df8510c1b66a122e459aac8c0919f1fe9fa2c43fd87899cffa05bf (MISP Attribute #1371)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 542c85fda8df8510c1b66a122e459aac8c0919f1fe9fa2c43fd87899cffa05bf (MISP Attribute #1371)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5823995f-701c-4616-84f5-49798e96ca05">
<cybox:Object id=":File-5823995f-701c-4616-84f5-49798e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">542c85fda8df8510c1b66a122e459aac8c0919f1fe9fa2c43fd87899cffa05bf</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-09T16:47:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:Leveraged_TTPs>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-5820ab2e-591c-456f-b2d4-497a8e96ca05" timestamp="2016-11-07T11:26:22+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-5820ad80-c82c-43f9-bece-49798e96ca05" timestamp="2016-11-07T11:36:16+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-5824ad47-8e68-49cd-854f-49798e96ca05" timestamp="2016-11-10T12:24:23+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload type</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-5820aae1-a8d4-4f70-86f5-49798e96ca05" timestamp="2016-11-07T11:25:05+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
</incident:Leveraged_TTPs>
<incident:History>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">Event Threat Level: Medium</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TLP:AMBER</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: SOURCE:CITIZENLAB</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: NOTPUBLISHED</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: DETECT</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TARGET:TIBETAN</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: import "pe"
rule new_keyboy_export
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the new 2016 sample's export"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize &lt; 200KB and
//The malware family seems to share many exports
//but this is the new kid on the block.
pe.exports("cfsUpdate")
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule new_keyboy_header_codes
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the 2016 sample's header codes"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
strings:
$s1 = "*l*" wide fullword
$s2 = "*a*" wide fullword
$s3 = "*s*" wide fullword
$s4 = "*d*" wide fullword
$s5 = "*f*" wide fullword
$s6 = "*g*" wide fullword
$s7 = "*h*" wide fullword
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize &lt; 200KB and
all of them
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule keyboy_commands
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the 2016 sample's sent and received commands"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
strings:
$s1 = "Update" wide fullword
$s2 = "UpdateAndRun" wide fullword
$s3 = "Refresh" wide fullword
$s4 = "OnLine" wide fullword
$s5 = "Disconnect" wide fullword
$s6 = "Pw_Error" wide fullword
$s7 = "Pw_OK" wide fullword
$s8 = "Sysinfo" wide fullword
$s9 = "Download" wide fullword
$s10 = "UploadFileOk" wide fullword
$s11 = "RemoteRun" wide fullword
$s12 = "FileManager" wide fullword
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize &lt; 200KB and
6 of them
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule keyboy_errors
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the sample's shell error2 log statements"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
strings:
//These strings are in ASCII pre-2015 and UNICODE in 2016
$error = "Error2" ascii wide
//2016 specific:
$s1 = "Can't find [%s]!Check the file name and try again!" ascii wide
$s2 = "Open [%s] error! %d" ascii wide
$s3 = "The Size of [%s] is zero!" ascii wide
$s4 = "CreateThread DownloadFile[%s] Error!" ascii wide
$s5 = "UploadFile [%s] Error:Connect Server Failed!" ascii wide
$s6 = "Receive [%s] Error(Recved[%d] != Send[%d])!" ascii wide
$s7 = "Receive [%s] ok! Use %2.2f seconds, Average speed %2.2f k/s" ascii wide
$s8 = "CreateThread UploadFile[%s] Error!" ascii wide
//Pre-2016:
$s9 = "Ready Download [%s] ok!" ascii wide
$s10 = "Get ControlInfo from FileClient error!" ascii wide
$s11 = "FileClient has a error!" ascii wide
$s12 = "VirtualAlloc SendBuff Error(%d)" ascii wide
$s13 = "ReadFile [%s] Error(%d)..." ascii wide
$s14 = "ReadFile [%s] Data[Readed(%d) != FileSize(%d)] Error..." ascii wide
$s15 = "CreateThread DownloadFile[%s] Error!" ascii wide
$s16 = "RecvData MyRecv_Info Size Error!" ascii wide
$s17 = "RecvData MyRecv_Info Tag Error!" ascii wide
$s18 = "SendData szControlInfo_1 Error!" ascii wide
$s19 = "SendData szControlInfo_3 Error!" ascii wide
$s20 = "VirtualAlloc RecvBuff Error(%d)" ascii wide
$s21 = "RecvData Error!" ascii wide
$s22 = "WriteFile [%s} Error(%d)..." ascii wide
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize &lt; 200KB and
$error and 3 of ($s*)
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule keyboy_systeminfo
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the system information format before sending to C2"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
strings:
//These strings are ASCII pre-2015 and UNICODE in 2016
$s1 = "SystemVersion: %s" ascii wide
$s2 = "Product ID: %s" ascii wide
$s3 = "InstallPath: %s" ascii wide
$s4 = "InstallTime: %d-%d-%d, %02d:%02d:%02d" ascii wide
$s5 = "ResgisterGroup: %s" ascii wide
$s6 = "RegisterUser: %s" ascii wide
$s7 = "ComputerName: %s" ascii wide
$s8 = "WindowsDirectory: %s" ascii wide
$s9 = "System Directory: %s" ascii wide
$s10 = "Number of Processors: %d" ascii wide
$s11 = "CPU[%d]: %s: %sMHz" ascii wide
$s12 = "RAM: %dMB Total, %dMB Free." ascii wide
$s13 = "DisplayMode: %d x %d, %dHz, %dbit" ascii wide
$s14 = "Uptime: %d Days %02u:%02u:%02u" ascii wide
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize &lt; 200KB and
7 of them
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: import "pe"
rule keyboy_related_exports
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the new 2016 sample's export"
date = "2016-08-28"
md5 = "495adb1b9777002ecfe22aaf52fcee93"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
filesize &lt; 200KB and
//The malware family seems to share many exports
//but this is the new kid on the block.
pe.exports("Embedding") or
pe.exports("SSSS") or
pe.exports("GetUP")
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: import "pe"
rule keyboy_init_config_section
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the Init section where the config is stored"
date = "2016-08-28"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
//Payloads are normally smaller but the new dropper we spotted
//is a bit larger.
filesize &lt; 300KB and
//Observed virtual sizes of the .Init section vary but they've
//always been 1024, 2048, or 4096 bytes.
for any i in (0..pe.number_of_sections - 1):
(
pe.sections[i].name == ".Init" and
pe.sections[i].virtual_size % 1024 == 0
)
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Payload delivery][yara]: rule CVE_2012_0158_KeyBoy {
meta:
author = "Etienne Maynier &lt;etienne@citizenlab.ca&gt;"
description = "CVE-2012-0158 variant"
file = "8307e444cad98b1b59568ad2eba5f201"
strings:
$a = "d0cf11e0a1b11ae1000000000000000000000000000000003e000300feff09000600000000000000000000000100000001" nocase // OLE header
$b = "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" nocase // junk data
$c = /5(\{\\b0\}|)[ ]*2006F00(\{\\b0\}|)[ ]*6F007(\{\\b0\}|)[ ]*400200045(\{\\b0\}|)[ ]*006(\{\\b0\}|)[ ]*E007(\{\\b0\}|)[ ]*400720079/ nocase
$d = "MSComctlLib.ListViewCtrl.2"
$e = "ac38c874503c307405347aaaebf2ac2c31ebf6e8e3" nocase //decoding shellcode
condition:
all of them
}</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">!Not implemented attribute category/type combination caught! attribute[Payload delivery][yara]: rule keyboy_exploit_doc_meta{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches the meta associated with these exploit docs"
date = "2016-09-30"
strings:
$role = "{\\author Master}{\\operator Master}"
$creatim = "{\\creatim\\yr2015\\mo10\\dy16\\hr11\\min37}"
$revtim = "{\\revtim\\yr2015\\mo10\\dy16\\hr13\\min54}"
condition:
uint32be(0) == 0x7B5C7274 and
filesize &lt; 1MB and
all of them
}</incident:Journal_Entry>
</incident:History_Item>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>