Files
autarch/data/ioc/spyware/citizen_lab/201605_Stealth_Falcon/stix.xml

845 lines
83 KiB
XML
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:="https://rufus.citlab.utoronto.ca"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-7e377b3f-5c5a-403a-9575-64593685b0a8" version="1.1.1" timestamp="2016-11-08T21:57:05.578284+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-581c05a7-1888-402a-b435-49798e96ca05" version="1.1.1" timestamp="2016-11-08T16:56:04+00:00">
<stix:STIX_Header>
<stix:Title>Keep Calm and (Dont) Enable Macros: A New Threat Actor Targets UAE Dissidents (MISP Event #8)</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Incidents>
<stix:Incident id=":incident-581c05a7-1888-402a-b435-49798e96ca05" timestamp="2016-11-08T16:56:19+00:00" xsi:type='incident:IncidentType'>
<incident:Title>Keep Calm and (Dont) Enable Macros: A New Threat Actor Targets UAE Dissidents</incident:Title>
<incident:External_ID source="MISP Event">8</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2016-05-29T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2016-11-08T16:56:19+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">Closed</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58224765-51f8-4d28-9040-49798e96ca05" timestamp="2016-11-08T16:45:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: Stealth Falcon (MISP Attribute #1354)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: Stealth Falcon (MISP Attribute #1354)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2016-11-08T16:45:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822492e-087c-4fa8-afe1-49798e96ca05" timestamp="2016-11-08T16:52:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: simpleadbanners.com (MISP Attribute #1358)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: simpleadbanners.com (MISP Attribute #1358)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822492e-087c-4fa8-afe1-49798e96ca05">
<cybox:Object id=":DomainName-5822492e-087c-4fa8-afe1-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">simpleadbanners.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:52:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822492e-1d40-4098-a87b-49798e96ca05" timestamp="2016-11-08T16:52:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: clickstatistic.com (MISP Attribute #1359)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: clickstatistic.com (MISP Attribute #1359)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822492e-1d40-4098-a87b-49798e96ca05">
<cybox:Object id=":DomainName-5822492e-1d40-4098-a87b-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">clickstatistic.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:52:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822492e-7490-4c3f-9a10-49798e96ca05" timestamp="2016-11-08T16:52:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: bestairlinepricetags.com (MISP Attribute #1360)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: bestairlinepricetags.com (MISP Attribute #1360)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822492e-7490-4c3f-9a10-49798e96ca05">
<cybox:Object id=":DomainName-5822492e-7490-4c3f-9a10-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">bestairlinepricetags.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:52:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822492e-d888-418e-906d-49798e96ca05" timestamp="2016-11-08T16:52:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: fasttravelclearance.com (MISP Attribute #1361)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: fasttravelclearance.com (MISP Attribute #1361)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822492e-d888-418e-906d-49798e96ca05">
<cybox:Object id=":DomainName-5822492e-d888-418e-906d-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">fasttravelclearance.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:52:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822494d-792c-4d8c-9be0-49798e96ca05" timestamp="2016-11-08T16:53:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: airlineadverts.com (MISP Attribute #1362)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: airlineadverts.com (MISP Attribute #1362)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822494d-792c-4d8c-9be0-49798e96ca05">
<cybox:Object id=":DomainName-5822494d-792c-4d8c-9be0-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">airlineadverts.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:53:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822494d-7ab0-42bd-bd9d-49798e96ca05" timestamp="2016-11-08T16:53:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: ministrynewschannel.com (MISP Attribute #1363)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: ministrynewschannel.com (MISP Attribute #1363)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822494d-7ab0-42bd-bd9d-49798e96ca05">
<cybox:Object id=":DomainName-5822494d-7ab0-42bd-bd9d-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">ministrynewschannel.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:53:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5822494d-bf14-4b41-803a-49798e96ca05" timestamp="2016-11-08T16:53:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: ministrynewsinfo.com (MISP Attribute #1364)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: ministrynewsinfo.com (MISP Attribute #1364)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5822494d-bf14-4b41-803a-49798e96ca05">
<cybox:Object id=":DomainName-5822494d-bf14-4b41-803a-49798e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">ministrynewsinfo.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:53:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-3813bc78-21d9-40a2-b76e-61016eb71ccb" timestamp="2016-11-08T16:48:19+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: adhostingcache.com (MISP Attribute #425)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: adhostingcache.com (MISP Attribute #425)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-3813bc78-21d9-40a2-b76e-61016eb71ccb">
<cybox:Object id=":DomainName-3813bc78-21d9-40a2-b76e-61016eb71ccb">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">adhostingcache.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:48:19+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-d9a62cda-db4c-4d70-858c-6bbaaa041e63" timestamp="2016-11-08T16:49:00+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: adhostingcaches.com (MISP Attribute #426)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: adhostingcaches.com (MISP Attribute #426)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-d9a62cda-db4c-4d70-858c-6bbaaa041e63">
<cybox:Object id=":DomainName-d9a62cda-db4c-4d70-858c-6bbaaa041e63">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">adhostingcaches.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:49:00+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-35aa025c-2f62-4f9d-9fb7-391542226a7a" timestamp="2016-11-08T16:54:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: optimizedimghosting.com (MISP Attribute #427)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: optimizedimghosting.com (MISP Attribute #427)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-35aa025c-2f62-4f9d-9fb7-391542226a7a">
<cybox:Object id=":DomainName-35aa025c-2f62-4f9d-9fb7-391542226a7a">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">optimizedimghosting.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:54:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-8682a3ad-80da-4732-bf5a-e675e27c56fe" timestamp="2016-11-08T16:54:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: edgecacheimagehosting.com (MISP Attribute #428)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: edgecacheimagehosting.com (MISP Attribute #428)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-8682a3ad-80da-4732-bf5a-e675e27c56fe">
<cybox:Object id=":DomainName-8682a3ad-80da-4732-bf5a-e675e27c56fe">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">edgecacheimagehosting.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:54:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-8010c934-027b-40c5-ba1e-3efca8e52d5a" timestamp="2016-11-08T16:49:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: incapsulawebcache.com (MISP Attribute #429)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: incapsulawebcache.com (MISP Attribute #429)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-8010c934-027b-40c5-ba1e-3efca8e52d5a">
<cybox:Object id=":DomainName-8010c934-027b-40c5-ba1e-3efca8e52d5a">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">incapsulawebcache.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:49:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-45dbee97-3aa0-487d-bd73-a3c10a511403" timestamp="2016-11-08T16:48:42+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 95.215.44.37 (MISP Attribute #430)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 95.215.44.37 (MISP Attribute #430)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-45dbee97-3aa0-487d-bd73-a3c10a511403">
<cybox:Object id=":Address-45dbee97-3aa0-487d-bd73-a3c10a511403">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">95.215.44.37</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:48:42+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-decfcbf1-1331-4624-88b7-a88c94637dd0" timestamp="2016-11-08T16:55:41+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://adhostingcache.com/ehhe/eh4g4/adcache.txt (MISP Attribute #432)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://adhostingcache.com/ehhe/eh4g4/adcache.txt (MISP Attribute #432)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-decfcbf1-1331-4624-88b7-a88c94637dd0">
<cybox:Object id=":URI-decfcbf1-1331-4624-88b7-a88c94637dd0">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://adhostingcache.com/ehhe/eh4g4/adcache.txt</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:55:41+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-7fd6e683-9615-4f4e-b901-03e7dbb81337" timestamp="2016-11-08T16:49:23+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https://incapsulawebcache.com/cache/cache.nfo (MISP Attribute #433)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: https://incapsulawebcache.com/cache/cache.nfo (MISP Attribute #433)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-7fd6e683-9615-4f4e-b901-03e7dbb81337">
<cybox:Object id=":URI-7fd6e683-9615-4f4e-b901-03e7dbb81337">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://incapsulawebcache.com/cache/cache.nfo</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:49:23+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-e8f3b924-1221-4d08-8fef-f689529a7b6d" timestamp="2016-11-08T16:49:42+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://aax.me/redirect.js (MISP Attribute #434)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://aax.me/redirect.js (MISP Attribute #434)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-e8f3b924-1221-4d08-8fef-f689529a7b6d">
<cybox:Object id=":URI-e8f3b924-1221-4d08-8fef-f689529a7b6d">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://aax.me/redirect.js</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:49:42+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-537df72e-b2b9-4016-b337-06930c42c455" timestamp="2016-11-08T16:50:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://goo.gl/60HAqJ (MISP Attribute #435)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://goo.gl/60HAqJ (MISP Attribute #435)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-537df72e-b2b9-4016-b337-06930c42c455">
<cybox:Object id=":URI-537df72e-b2b9-4016-b337-06930c42c455">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://goo.gl/60HAqJ</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:50:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-007694f1-b73a-40a5-bcf5-dded27746669" timestamp="2016-11-08T16:51:04+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://aax.me/0b152 (MISP Attribute #436)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://aax.me/0b152 (MISP Attribute #436)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-007694f1-b73a-40a5-bcf5-dded27746669">
<cybox:Object id=":URI-007694f1-b73a-40a5-bcf5-dded27746669">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://aax.me/0b152</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:51:04+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-62fcd7b4-5d95-49bd-a9ff-3c2e1854839b" timestamp="2016-11-08T16:55:52+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://optimizedimghosting.com/wddf/hrrw/ggrr.txt (MISP Attribute #437)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://optimizedimghosting.com/wddf/hrrw/ggrr.txt (MISP Attribute #437)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-62fcd7b4-5d95-49bd-a9ff-3c2e1854839b">
<cybox:Object id=":URI-62fcd7b4-5d95-49bd-a9ff-3c2e1854839b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://optimizedimghosting.com/wddf/hrrw/ggrr.txt</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:55:52+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-f0215c0c-b708-43d8-873e-80a3e8e54cfa" timestamp="2016-11-08T16:56:04+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https://edgecacheimagehosting.com/images/image.nfo (MISP Attribute #438)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: https://edgecacheimagehosting.com/images/image.nfo (MISP Attribute #438)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-f0215c0c-b708-43d8-873e-80a3e8e54cfa">
<cybox:Object id=":URI-f0215c0c-b708-43d8-873e-80a3e8e54cfa">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://edgecacheimagehosting.com/images/image.nfo</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:56:04+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582247a8-11b4-4da0-9ca1-69fe8e96ca05" timestamp="2016-11-08T16:46:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: aax.me (MISP Attribute #1355)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Payload delivery: aax.me (MISP Attribute #1355)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582247a8-11b4-4da0-9ca1-69fe8e96ca05">
<cybox:Object id=":DomainName-582247a8-11b4-4da0-9ca1-69fe8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">aax.me</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:46:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-bc8e2ca7-cd3c-4205-9028-b8b106f12389" timestamp="2016-11-08T16:45:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: the_right_to_fight@openmailbox.org (MISP Attribute #439)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: the_right_to_fight@openmailbox.org (MISP Attribute #439)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-bc8e2ca7-cd3c-4205-9028-b8b106f12389">
<cybox:Object id=":EmailMessage-bc8e2ca7-cd3c-4205-9028-b8b106f12389">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">the_right_to_fight@openmailbox.org</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:45:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-280056b8-69aa-432c-9826-6d5b820eb44e" timestamp="2016-11-08T16:50:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: andrew.dwight389@outlook.com (MISP Attribute #440)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: andrew.dwight389@outlook.com (MISP Attribute #440)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-280056b8-69aa-432c-9826-6d5b820eb44e">
<cybox:Object id=":EmailMessage-280056b8-69aa-432c-9826-6d5b820eb44e">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">andrew.dwight389@outlook.com</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:50:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-f4f40c31-dd17-4dc6-baa3-6beb35c04c00" timestamp="2016-11-08T16:47:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 80e8ef78b9e28015cde4205aaa65da97 (MISP Attribute #441)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 80e8ef78b9e28015cde4205aaa65da97 (MISP Attribute #441)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-f4f40c31-dd17-4dc6-baa3-6beb35c04c00">
<cybox:Object id=":File-f4f40c31-dd17-4dc6-baa3-6beb35c04c00">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">80e8ef78b9e28015cde4205aaa65da97</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:47:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-9ca61973-d717-496a-a158-82d9b2e37965" timestamp="2016-11-08T16:53:31+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 87e1df6f36b96b56186444e37e2a1ef5 (MISP Attribute #442)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 87e1df6f36b96b56186444e37e2a1ef5 (MISP Attribute #442)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-9ca61973-d717-496a-a158-82d9b2e37965">
<cybox:Object id=":File-9ca61973-d717-496a-a158-82d9b2e37965">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">87e1df6f36b96b56186444e37e2a1ef5</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:53:31+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-cd191e4e-a5a1-4009-93b7-92cc6a3d6984" timestamp="2016-11-08T16:47:54+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: f25466e4820404c817eaf75818b7177891735886 (MISP Attribute #443)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: f25466e4820404c817eaf75818b7177891735886 (MISP Attribute #443)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-cd191e4e-a5a1-4009-93b7-92cc6a3d6984">
<cybox:Object id=":File-cd191e4e-a5a1-4009-93b7-92cc6a3d6984">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA1</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">f25466e4820404c817eaf75818b7177891735886</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:47:54+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-41c48554-6911-48eb-88a0-411dc4bd9047" timestamp="2016-11-08T16:53:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 1c3757006f972ca957d925accf8bbb3023550d1b (MISP Attribute #444)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 1c3757006f972ca957d925accf8bbb3023550d1b (MISP Attribute #444)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-41c48554-6911-48eb-88a0-411dc4bd9047">
<cybox:Object id=":File-41c48554-6911-48eb-88a0-411dc4bd9047">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA1</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">1c3757006f972ca957d925accf8bbb3023550d1b</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:53:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-70881ae4-3da1-409e-8bd3-7f508092a2c9" timestamp="2016-11-08T16:48:02+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 5a372b45285fe6f3df3ba277ee2de55d4a30fc8ef05de729cf464103632db40f (MISP Attribute #445)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 5a372b45285fe6f3df3ba277ee2de55d4a30fc8ef05de729cf464103632db40f (MISP Attribute #445)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-70881ae4-3da1-409e-8bd3-7f508092a2c9">
<cybox:Object id=":File-70881ae4-3da1-409e-8bd3-7f508092a2c9">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">5a372b45285fe6f3df3ba277ee2de55d4a30fc8ef05de729cf464103632db40f</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:48:02+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-19e97c58-4992-4f0b-8f49-6a6378a289eb" timestamp="2016-11-08T16:53:48+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 4320204d577ef8b939115d16110e97ff04cb4f7d1e77ba5ce011d43f74abc7be (MISP Attribute #446)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 4320204d577ef8b939115d16110e97ff04cb4f7d1e77ba5ce011d43f74abc7be (MISP Attribute #446)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-19e97c58-4992-4f0b-8f49-6a6378a289eb">
<cybox:Object id=":File-19e97c58-4992-4f0b-8f49-6a6378a289eb">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">4320204d577ef8b939115d16110e97ff04cb4f7d1e77ba5ce011d43f74abc7be</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:53:48+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582247d0-d7a0-49c3-a6ae-69fe8e96ca05" timestamp="2016-11-08T16:46:56+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: http://aax.me/a6faa (MISP Attribute #1356)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: http://aax.me/a6faa (MISP Attribute #1356)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582247d0-d7a0-49c3-a6ae-69fe8e96ca05">
<cybox:Object id=":URI-582247d0-d7a0-49c3-a6ae-69fe8e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://aax.me/a6faa</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:46:56+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-582247f6-eeec-47b0-b6d8-69fe8e96ca05" timestamp="2016-11-08T16:47:34+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: https://cloud.openmailbox.org/index.php/s/ujDNWMmg8pdG3AL/authenticate (MISP Attribute #1357)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: https://cloud.openmailbox.org/index.php/s/ujDNWMmg8pdG3AL/authenticate (MISP Attribute #1357)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-582247f6-eeec-47b0-b6d8-69fe8e96ca05">
<cybox:Object id=":URI-582247f6-eeec-47b0-b6d8-69fe8e96ca05">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://cloud.openmailbox.org/index.php/s/ujDNWMmg8pdG3AL/authenticate</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:47:34+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-6c1856f6-0068-4c83-8aba-9fd4bb4277a1" timestamp="2016-11-08T16:45:55+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: http://aax.me/d0dde (MISP Attribute #447)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Payload delivery: http://aax.me/d0dde (MISP Attribute #447)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-6c1856f6-0068-4c83-8aba-9fd4bb4277a1">
<cybox:Object id=":URI-6c1856f6-0068-4c83-8aba-9fd4bb4277a1">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://aax.me/d0dde</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2016-11-08T16:45:55+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:History>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">Event Threat Level: Medium</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: TLP:GREEN</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: SOURCE:CITIZENLAB</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: DETECT</incident:Journal_Entry>
</incident:History_Item>
<incident:History_Item>
<incident:Journal_Entry time_precision="second">MISP Tag: PUBLISHED</incident:Journal_Entry>
</incident:History_Item>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
<stixCommon:References>
<stixCommon:Reference>https://citizenlab.org/2016/05/stealth-falcon/</stixCommon:Reference>
</stixCommon:References>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>