Files
autarch/data/ioc/spyware/citizen_lab/201603_Shifting_Tactics/stix.xml

983 lines
96 KiB
XML

<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:="https://rufus.citlab.utoronto.ca"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-dab87d63-6901-4da5-b7ba-2088de90f322" version="1.1.1" timestamp="2016-11-10T21:17:23.793648+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-581c1131-3fec-4068-bb74-49798e96ca05" version="1.1.1" timestamp="2016-11-10T16:14:39+00:00">
<stix:STIX_Header>
<stix:Title>Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetans (MISP Event #11)</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:TTPs>
<stix:TTP id=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'>
<ttp:Title>Payload type: FakeM (MISP Attribute #1875)</ttp:Title>
<ttp:Behavior>
<ttp:Malware>
<ttp:Malware_Instance>
<ttp:Name>FakeM</ttp:Name>
</ttp:Malware_Instance>
</ttp:Malware>
</ttp:Behavior>
</stix:TTP>
</stix:TTPs>
<stix:Incidents>
<stix:Incident id=":incident-581c1131-3fec-4068-bb74-49798e96ca05" timestamp="2016-11-10T16:15:08+00:00" xsi:type='incident:IncidentType'>
<incident:Title>Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetans</incident:Title>
<incident:External_ID source="MISP Event">11</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2016-03-10T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2016-11-10T16:15:08+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">Closed</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5824e149-ba7c-4e04-b905-69fe8e96ca05" timestamp="2016-11-10T16:06:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: ea45265fe98b25e719d5a9cc3b412d66 (MISP Attribute #1873)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: ea45265fe98b25e719d5a9cc3b412d66 (MISP Attribute #1873)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5824e149-ba7c-4e04-b905-69fe8e96ca05">
<cybox:Object id=":File-5824e149-ba7c-4e04-b905-69fe8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">ea45265fe98b25e719d5a9cc3b412d66</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:06:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5824e1e5-e340-40b0-b3fa-69fe8e96ca05" timestamp="2016-11-10T16:08:53+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: Scarlet Mimic (MISP Attribute #1874)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: Scarlet Mimic (MISP Attribute #1874)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:08:53+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-6308d2e1-a83a-44b2-b96f-267bc24efbd1" timestamp="2016-11-10T16:07:04+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: filegoogle.firewall-gateway.com (MISP Attribute #499)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: filegoogle.firewall-gateway.com (MISP Attribute #499)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-6308d2e1-a83a-44b2-b96f-267bc24efbd1">
<cybox:Object id=":DomainName-6308d2e1-a83a-44b2-b96f-267bc24efbd1">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">filegoogle.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:07:04+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-26fb914b-1601-4049-a8b5-c9afc3a16bc0" timestamp="2016-11-10T16:07:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accountgoogle.firewall-gateway.com (MISP Attribute #500)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accountgoogle.firewall-gateway.com (MISP Attribute #500)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-26fb914b-1601-4049-a8b5-c9afc3a16bc0">
<cybox:Object id=":DomainName-26fb914b-1601-4049-a8b5-c9afc3a16bc0">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accountgoogle.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:07:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-11cf9c54-4d35-4a58-8128-a1076025ff25" timestamp="2016-11-10T16:06:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: sys.firewall-gateway.net (MISP Attribute #501)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: sys.firewall-gateway.net (MISP Attribute #501)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-11cf9c54-4d35-4a58-8128-a1076025ff25">
<cybox:Object id=":DomainName-11cf9c54-4d35-4a58-8128-a1076025ff25">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">sys.firewall-gateway.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:06:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-73e5412a-1252-495d-956d-28cfdd8edaed" timestamp="2016-11-10T16:04:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: news.firewall-gateway.com (MISP Attribute #502)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: news.firewall-gateway.com (MISP Attribute #502)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-73e5412a-1252-495d-956d-28cfdd8edaed">
<cybox:Object id=":DomainName-73e5412a-1252-495d-956d-28cfdd8edaed">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">news.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:04:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-ebbe87e2-7f84-4f68-b766-f63820da7966" timestamp="2016-11-10T16:09:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accountsgoogle.firewall-gateway.com (MISP Attribute #503)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accountsgoogle.firewall-gateway.com (MISP Attribute #503)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-ebbe87e2-7f84-4f68-b766-f63820da7966">
<cybox:Object id=":DomainName-ebbe87e2-7f84-4f68-b766-f63820da7966">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accountsgoogle.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-3baf841e-c377-44ba-ba20-dcfd7aa8ba22" timestamp="2016-11-10T16:09:27+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-google.firewall-gateway.com (MISP Attribute #504)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-google.firewall-gateway.com (MISP Attribute #504)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-3baf841e-c377-44ba-ba20-dcfd7aa8ba22">
<cybox:Object id=":DomainName-3baf841e-c377-44ba-ba20-dcfd7aa8ba22">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-google.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:27+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-40edc447-3aaa-4f79-8268-16eddff19b33" timestamp="2016-11-10T16:09:38+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accountsgoogles.firewall-gateway.com (MISP Attribute #505)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accountsgoogles.firewall-gateway.com (MISP Attribute #505)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-40edc447-3aaa-4f79-8268-16eddff19b33">
<cybox:Object id=":DomainName-40edc447-3aaa-4f79-8268-16eddff19b33">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accountsgoogles.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:38+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-b84e33b7-1958-4507-b7bb-6bb63304842c" timestamp="2016-11-10T16:09:47+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: googlefile.firewall-gateway.net (MISP Attribute #506)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: googlefile.firewall-gateway.net (MISP Attribute #506)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-b84e33b7-1958-4507-b7bb-6bb63304842c">
<cybox:Object id=":DomainName-b84e33b7-1958-4507-b7bb-6bb63304842c">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">googlefile.firewall-gateway.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:47+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-228f765c-d5ab-4fcf-a190-775b9ed2ad70" timestamp="2016-11-10T16:09:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: firewallupdate.firewall-gateway.com (MISP Attribute #507)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: firewallupdate.firewall-gateway.com (MISP Attribute #507)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-228f765c-d5ab-4fcf-a190-775b9ed2ad70">
<cybox:Object id=":DomainName-228f765c-d5ab-4fcf-a190-775b9ed2ad70">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">firewallupdate.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:09:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-35a7486a-38a7-4d3a-bdd8-1284d464484b" timestamp="2016-11-10T16:10:06+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: firewallupdate.firewall-gateway.net (MISP Attribute #508)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: firewallupdate.firewall-gateway.net (MISP Attribute #508)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-35a7486a-38a7-4d3a-bdd8-1284d464484b">
<cybox:Object id=":DomainName-35a7486a-38a7-4d3a-bdd8-1284d464484b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">firewallupdate.firewall-gateway.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:10:06+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-8b0a371b-0c73-455d-a7ae-d0a530f23b04" timestamp="2016-11-10T16:10:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drivgoogle.firewall-gateway.com (MISP Attribute #509)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drivgoogle.firewall-gateway.com (MISP Attribute #509)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-8b0a371b-0c73-455d-a7ae-d0a530f23b04">
<cybox:Object id=":DomainName-8b0a371b-0c73-455d-a7ae-d0a530f23b04">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drivgoogle.firewall-gateway.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:10:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-86627daf-07c8-467f-babc-426d586e7d4a" timestamp="2016-11-10T16:05:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: detail43.myfirewall.org (MISP Attribute #510)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: detail43.myfirewall.org (MISP Attribute #510)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-86627daf-07c8-467f-babc-426d586e7d4a">
<cybox:Object id=":DomainName-86627daf-07c8-467f-babc-426d586e7d4a">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">detail43.myfirewall.org</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-a31a03ec-f99e-4bec-95dc-3574c3512217" timestamp="2016-11-10T16:11:07+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 95.154.195.159 (MISP Attribute #512)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 95.154.195.159 (MISP Attribute #512)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-a31a03ec-f99e-4bec-95dc-3574c3512217">
<cybox:Object id=":Address-a31a03ec-f99e-4bec-95dc-3574c3512217">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">95.154.195.159</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:11:07+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-318dd748-c9d9-4f7b-9b42-75a60001f9e1" timestamp="2016-11-10T16:11:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 95.154.195.171 (MISP Attribute #513)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 95.154.195.171 (MISP Attribute #513)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-318dd748-c9d9-4f7b-9b42-75a60001f9e1">
<cybox:Object id=":Address-318dd748-c9d9-4f7b-9b42-75a60001f9e1">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">95.154.195.171</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:11:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-1f0bc371-f681-4049-855d-235e6bc5eb8e" timestamp="2016-11-10T16:11:20+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 5.54.19.17 (MISP Attribute #514)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 5.54.19.17 (MISP Attribute #514)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-1f0bc371-f681-4049-855d-235e6bc5eb8e">
<cybox:Object id=":Address-1f0bc371-f681-4049-855d-235e6bc5eb8e">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">5.54.19.17</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:11:20+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-f48470fd-c782-4831-a20d-4704b62f1358" timestamp="2016-11-10T16:12:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 78.129.252.159 (MISP Attribute #515)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 78.129.252.159 (MISP Attribute #515)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-f48470fd-c782-4831-a20d-4704b62f1358">
<cybox:Object id=":Address-f48470fd-c782-4831-a20d-4704b62f1358">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">78.129.252.159</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-c379b263-55d3-464d-b94f-178f02f883a8" timestamp="2016-11-10T16:12:57+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 87.117.229.109 (MISP Attribute #516)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 87.117.229.109 (MISP Attribute #516)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-c379b263-55d3-464d-b94f-178f02f883a8">
<cybox:Object id=":Address-c379b263-55d3-464d-b94f-178f02f883a8">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">87.117.229.109</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:57+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-ad5c4c3d-6194-4059-9aa1-1593b62d32a9" timestamp="2016-11-10T16:13:04+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 109.169.40.172 (MISP Attribute #517)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 109.169.40.172 (MISP Attribute #517)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-ad5c4c3d-6194-4059-9aa1-1593b62d32a9">
<cybox:Object id=":Address-ad5c4c3d-6194-4059-9aa1-1593b62d32a9">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">109.169.40.172</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:13:04+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-b2cebdea-e90b-416f-9a0f-94a566b32a2a" timestamp="2016-11-10T16:13:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 46.127.56.109 (MISP Attribute #518)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 46.127.56.109 (MISP Attribute #518)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-b2cebdea-e90b-416f-9a0f-94a566b32a2a">
<cybox:Object id=":Address-b2cebdea-e90b-416f-9a0f-94a566b32a2a">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">46.127.56.109</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:13:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-8ce49cb3-e458-4568-b560-04a314ce9539" timestamp="2016-11-10T16:13:20+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 192.253.251.118 (MISP Attribute #519)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 192.253.251.118 (MISP Attribute #519)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-8ce49cb3-e458-4568-b560-04a314ce9539">
<cybox:Object id=":Address-8ce49cb3-e458-4568-b560-04a314ce9539">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">192.253.251.118</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:13:20+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-53477c01-59ad-47be-b808-4c6b518523fc" timestamp="2016-11-10T16:08:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 109.169.77.230 (MISP Attribute #511)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 109.169.77.230 (MISP Attribute #511)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-53477c01-59ad-47be-b808-4c6b518523fc">
<cybox:Object id=":Address-53477c01-59ad-47be-b808-4c6b518523fc">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">109.169.77.230</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:08:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-fc6d0f74-9e43-44a7-b7b8-0ca5c7c487e6" timestamp="2016-11-10T16:12:23+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://filegoogle.firewall-gateway.com/servicelogin (MISP Attribute #520)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://filegoogle.firewall-gateway.com/servicelogin (MISP Attribute #520)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-fc6d0f74-9e43-44a7-b7b8-0ca5c7c487e6">
<cybox:Object id=":URI-fc6d0f74-9e43-44a7-b7b8-0ca5c7c487e6">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://filegoogle.firewall-gateway.com/servicelogin</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:23+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-11bb35af-5ad7-4a10-844c-fb4482603b0b" timestamp="2016-11-10T16:12:41+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://accountgoogle.firewall-gateway.com/serviclogin (MISP Attribute #521)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://accountgoogle.firewall-gateway.com/serviclogin (MISP Attribute #521)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-11bb35af-5ad7-4a10-844c-fb4482603b0b">
<cybox:Object id=":URI-11bb35af-5ad7-4a10-844c-fb4482603b0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://accountgoogle.firewall-gateway.com/serviclogin</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:41+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-cda51492-e33b-4521-be3b-35ec4b8bc9b4" timestamp="2016-11-10T16:12:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://accountgoogle.firewall-gateway.com/servicclogin (MISP Attribute #522)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://accountgoogle.firewall-gateway.com/servicclogin (MISP Attribute #522)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-cda51492-e33b-4521-be3b-35ec4b8bc9b4">
<cybox:Object id=":URI-cda51492-e33b-4521-be3b-35ec4b8bc9b4">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://accountgoogle.firewall-gateway.com/servicclogin</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:12:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-633179a0-3d6e-4ca5-9b89-02d8522ef275" timestamp="2016-11-10T16:10:34+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: Reappraisal_of_India_Tibet_Policy.doc (MISP Attribute #530)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Payload delivery: Reappraisal_of_India_Tibet_Policy.doc (MISP Attribute #530)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:10:34+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-99702482-486a-4b63-8fa9-f094835827b2" timestamp="2016-11-10T16:06:29+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 5c030802ad411fea059cc9cc4c118125 (MISP Attribute #531)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 5c030802ad411fea059cc9cc4c118125 (MISP Attribute #531)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-99702482-486a-4b63-8fa9-f094835827b2">
<cybox:Object id=":File-99702482-486a-4b63-8fa9-f094835827b2">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">5c030802ad411fea059cc9cc4c118125</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:06:29+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-a95b5c9c-7ec9-42ff-a12c-075b3255de77" timestamp="2016-11-10T16:05:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 7735e571d0450e2a31e97e4f8e0f66fa (MISP Attribute #532)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 7735e571d0450e2a31e97e4f8e0f66fa (MISP Attribute #532)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-a95b5c9c-7ec9-42ff-a12c-075b3255de77">
<cybox:Object id=":File-a95b5c9c-7ec9-42ff-a12c-075b3255de77">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">7735e571d0450e2a31e97e4f8e0f66fa</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-baf16087-e811-438d-bcdd-9779043dfb06" timestamp="2016-11-10T16:05:33+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: d2e9412428c3bcf3ec98dba8a78adb7b (MISP Attribute #533)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: d2e9412428c3bcf3ec98dba8a78adb7b (MISP Attribute #533)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-baf16087-e811-438d-bcdd-9779043dfb06">
<cybox:Object id=":File-baf16087-e811-438d-bcdd-9779043dfb06">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">d2e9412428c3bcf3ec98dba8a78adb7b</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:33+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-712c9cc1-2b2b-4636-87d2-12bd313376dc" timestamp="2016-11-10T16:05:20+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 1bf438b5744db73eea58379a3b9f30e5 (MISP Attribute #534)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 1bf438b5744db73eea58379a3b9f30e5 (MISP Attribute #534)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-712c9cc1-2b2b-4636-87d2-12bd313376dc">
<cybox:Object id=":File-712c9cc1-2b2b-4636-87d2-12bd313376dc">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">1bf438b5744db73eea58379a3b9f30e5</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:20+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-6d15c4fe-2de7-4abc-9593-c9eeae9b928f" timestamp="2016-11-10T16:05:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 3b869c8e23d66ad0527882fc79ff7237 (MISP Attribute #535)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 3b869c8e23d66ad0527882fc79ff7237 (MISP Attribute #535)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-6d15c4fe-2de7-4abc-9593-c9eeae9b928f">
<cybox:Object id=":File-6d15c4fe-2de7-4abc-9593-c9eeae9b928f">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">3b869c8e23d66ad0527882fc79ff7237</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:05:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-23403344-c52e-4c19-9f7b-f5291b451bee" timestamp="2016-11-10T16:04:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: fef27f432e0ae8218143bc410fda340e (MISP Attribute #536)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: fef27f432e0ae8218143bc410fda340e (MISP Attribute #536)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-23403344-c52e-4c19-9f7b-f5291b451bee">
<cybox:Object id=":File-23403344-c52e-4c19-9f7b-f5291b451bee">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">fef27f432e0ae8218143bc410fda340e</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:04:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-dbabd2ee-213d-4b02-951f-a020cfc3582e" timestamp="2016-11-10T16:07:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 8b83fc5d3a6a80281269f9e337fe3fff (MISP Attribute #537)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 8b83fc5d3a6a80281269f9e337fe3fff (MISP Attribute #537)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-dbabd2ee-213d-4b02-951f-a020cfc3582e">
<cybox:Object id=":File-dbabd2ee-213d-4b02-951f-a020cfc3582e">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">8b83fc5d3a6a80281269f9e337fe3fff</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Indicated_TTP>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</indicator:Indicated_TTP>
<indicator:Confidence timestamp="2016-11-10T16:07:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:Leveraged_TTPs>
<incident:Leveraged_TTP>
<stixCommon:Relationship>Payload type</stixCommon:Relationship>
<stixCommon:TTP idref=":ttp-5824e33f-4c08-4b5f-8092-497a8e96ca05" timestamp="2016-11-10T16:14:39+00:00" xsi:type='ttp:TTPType'/>
</incident:Leveraged_TTP>
</incident:Leveraged_TTPs>
<incident:History>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">Event Threat Level: Medium</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TLP:GREEN</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: SOURCE:CITIZENLAB</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: DETECT</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: PUBLISHED</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TARGET:TIBETAN</incident:Journal_Entry>
</incident:History_Item>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
<stixCommon:References>
<stixCommon:Reference>https://citizenlab.org/2016/03/shifting-tactics/</stixCommon:Reference>
</stixCommon:References>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>