Files
autarch/data/ioc/spyware/citizen_lab/201801_SpyingOnABudget/stix.xml

4464 lines
453 KiB
XML

<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:="https://rufus.citlab.utoronto.ca"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-40b66a4e-c1fc-4384-9166-cee0d655e858" version="1.1.1" timestamp="2018-01-16T21:37:25.459683+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-584942e2-93e0-4626-ad82-0bbb8e96ca05" version="1.1.1" timestamp="2018-01-16T16:34:15+00:00">
<stix:STIX_Header>
<stix:Title>Spying on a Budget: Inside a Phishing Operation Targeting the Tibetan Community</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Incidents>
<stix:Incident id=":incident-584942e2-93e0-4626-ad82-0bbb8e96ca05" timestamp="2018-01-16T16:34:45+00:00" xsi:type='incident:IncidentType'>
<incident:Title>Spying on a Budget: Inside a Phishing Operation Targeting the Tibetan Community</incident:Title>
<incident:External_ID source="MISP Event">57</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2016-12-08T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2018-01-16T16:34:45+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">Open</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5a1c-a8c4-46ff-a05d-06df8e96ca05" timestamp="2018-01-16T15:01:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 0963bee29e797ea7481be5f18f354029 (MISP Attribute #17923)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 0963bee29e797ea7481be5f18f354029 (MISP Attribute #17923)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e5a1c-a8c4-46ff-a05d-06df8e96ca05">
<cybox:Object id=":File-5a5e5a1c-a8c4-46ff-a05d-06df8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">0963bee29e797ea7481be5f18f354029</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:01:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5a2e-56e4-470b-81ab-06df8e96ca05" timestamp="2018-01-16T15:01:50+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 2ab43fc90a1928684b8590375643da52285b8625 (MISP Attribute #17924)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 2ab43fc90a1928684b8590375643da52285b8625 (MISP Attribute #17924)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e5a2e-56e4-470b-81ab-06df8e96ca05">
<cybox:Object id=":File-5a5e5a2e-56e4-470b-81ab-06df8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA1</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">2ab43fc90a1928684b8590375643da52285b8625</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:01:50+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5a36-8794-40c1-8259-06df8e96ca05" timestamp="2018-01-16T15:01:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: f5967a8f3db4f4f33e89976e39914fceff46401bd2243b29162e1ddeb61f8dd3 (MISP Attribute #17925)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: f5967a8f3db4f4f33e89976e39914fceff46401bd2243b29162e1ddeb61f8dd3 (MISP Attribute #17925)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e5a36-8794-40c1-8259-06df8e96ca05">
<cybox:Object id=":File-5a5e5a36-8794-40c1-8259-06df8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">f5967a8f3db4f4f33e89976e39914fceff46401bd2243b29162e1ddeb61f8dd3</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:01:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5b10-e044-472f-8835-06df8e96ca05" timestamp="2018-01-16T15:05:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: deepcliff@sina.com (MISP Attribute #17926)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: deepcliff@sina.com (MISP Attribute #17926)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2018-01-16T15:05:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5b26-6a78-436a-94a7-06df8e96ca05" timestamp="2018-01-16T15:05:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: liang007@outlook.com (MISP Attribute #17927)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: liang007@outlook.com (MISP Attribute #17927)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2018-01-16T15:05:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5b53-0674-48b2-832d-06df8e96ca05" timestamp="2018-01-16T15:06:43+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: directoriaffairs@outlook.com (MISP Attribute #17928)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: directoriaffairs@outlook.com (MISP Attribute #17928)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2018-01-16T15:06:43+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5b62-f8a0-4b4c-b538-06df8e96ca05" timestamp="2018-01-16T15:06:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: leungguodong@outlook.com (MISP Attribute #17929)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: leungguodong@outlook.com (MISP Attribute #17929)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2018-01-16T15:06:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5b7c-3644-4d50-8705-06df8e96ca05" timestamp="2018-01-16T15:07:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: zhuchangzi@outlook.com (MISP Attribute #17930)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: zhuchangzi@outlook.com (MISP Attribute #17930)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2018-01-16T15:07:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5bdd-90b0-487e-9c6f-06df8e96ca05" timestamp="2018-01-16T15:09:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: uglybeeking@hotmail.com (MISP Attribute #17931)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: uglybeeking@hotmail.com (MISP Attribute #17931)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2018-01-16T15:09:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5bdd-9c1c-442e-8380-06df8e96ca05" timestamp="2018-01-16T15:09:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: styloveyou@163.com (MISP Attribute #17932)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: styloveyou@163.com (MISP Attribute #17932)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2018-01-16T15:09:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5bdd-dd78-44b0-9462-06df8e96ca05" timestamp="2018-01-16T15:09:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: evalliang@163.com (MISP Attribute #17933)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: evalliang@163.com (MISP Attribute #17933)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2018-01-16T15:09:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5bdd-9d24-45f0-9bf5-06df8e96ca05" timestamp="2018-01-16T15:09:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: pangchokpa@gmail.com (MISP Attribute #17934)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: pangchokpa@gmail.com (MISP Attribute #17934)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2018-01-16T15:09:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5bdd-0a64-4079-b69d-06df8e96ca05" timestamp="2018-01-16T15:09:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: 6060841@qq.com (MISP Attribute #17935)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: 6060841@qq.com (MISP Attribute #17935)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2018-01-16T15:09:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-3004-4276-9bde-07298e96ca05" timestamp="2018-01-16T16:31:37+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https-drive-google.cf (MISP Attribute #15616)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: https-drive-google.cf (MISP Attribute #15616)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-3004-4276-9bde-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-3004-4276-9bde-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">https-drive-google.cf</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:31:37+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-323c-4ba6-8fd6-07298e96ca05" timestamp="2018-01-16T16:34:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mydrive-accounts-google.ml (MISP Attribute #15617)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mydrive-accounts-google.ml (MISP Attribute #15617)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-323c-4ba6-8fd6-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-323c-4ba6-8fd6-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mydrive-accounts-google.ml</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-fb10-4ec5-8f06-07298e96ca05" timestamp="2018-01-16T16:34:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https-drive-accounts-goog1e.cf (MISP Attribute #15618)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: https-drive-accounts-goog1e.cf (MISP Attribute #15618)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-fb10-4ec5-8f06-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-fb10-4ec5-8f06-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">https-drive-accounts-goog1e.cf</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-d7c0-431d-935e-07298e96ca05" timestamp="2018-01-16T16:34:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: google-drive.gq (MISP Attribute #15619)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: google-drive.gq (MISP Attribute #15619)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-d7c0-431d-935e-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-d7c0-431d-935e-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">google-drive.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-34fc-4f71-a8ba-07298e96ca05" timestamp="2018-01-16T16:34:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https-drive-google.ml (MISP Attribute #15620)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: https-drive-google.ml (MISP Attribute #15620)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-34fc-4f71-a8ba-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-34fc-4f71-a8ba-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">https-drive-google.ml</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-970c-4966-abc9-07298e96ca05" timestamp="2018-01-16T16:34:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-accounts-goog1e.cf (MISP Attribute #15621)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-accounts-goog1e.cf (MISP Attribute #15621)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-970c-4966-abc9-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-970c-4966-abc9-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-accounts-goog1e.cf</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-c2c8-4f33-89b8-07298e96ca05" timestamp="2018-01-16T16:34:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsmydrive-accounts-goog1e.gq (MISP Attribute #15622)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsmydrive-accounts-goog1e.gq (MISP Attribute #15622)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-c2c8-4f33-89b8-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-c2c8-4f33-89b8-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsmydrive-accounts-goog1e.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-e5d0-40eb-bbc4-07298e96ca05" timestamp="2018-01-16T16:34:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-accounts-google.ml (MISP Attribute #15623)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-accounts-google.ml (MISP Attribute #15623)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-e5d0-40eb-bbc4-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-e5d0-40eb-bbc4-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-accounts-google.ml</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-2b9c-4091-89e8-07298e96ca05" timestamp="2018-01-16T16:34:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsgoogle-drive.gq (MISP Attribute #15624)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsgoogle-drive.gq (MISP Attribute #15624)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-2b9c-4091-89e8-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-2b9c-4091-89e8-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsgoogle-drive.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-7ae4-4613-b3d5-07298e96ca05" timestamp="2018-01-16T16:34:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsaccounts-google.ga (MISP Attribute #15625)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsaccounts-google.ga (MISP Attribute #15625)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-7ae4-4613-b3d5-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-7ae4-4613-b3d5-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsaccounts-google.ga</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-b494-40f5-844b-07298e96ca05" timestamp="2018-01-16T16:34:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-goog1e.in (MISP Attribute #15626)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-goog1e.in (MISP Attribute #15626)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-b494-40f5-844b-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-b494-40f5-844b-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-goog1e.in</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-d4e0-46cf-b549-07298e96ca05" timestamp="2018-01-16T16:34:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: microsoft-inc.us (MISP Attribute #15627)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: microsoft-inc.us (MISP Attribute #15627)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-d4e0-46cf-b549-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-d4e0-46cf-b549-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">microsoft-inc.us</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-1618-4702-9a3e-07298e96ca05" timestamp="2018-01-16T16:34:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: goog1e.space (MISP Attribute #15628)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: goog1e.space (MISP Attribute #15628)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-1618-4702-9a3e-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-1618-4702-9a3e-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">goog1e.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-5e3c-415c-96c9-07298e96ca05" timestamp="2018-01-16T16:34:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-secret.com (MISP Attribute #15629)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-secret.com (MISP Attribute #15629)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-5e3c-415c-96c9-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-5e3c-415c-96c9-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-secret.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58828772-b108-4592-a9e2-0bbb8e96ca05" timestamp="2018-01-16T16:34:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: files-mail-google.ml (MISP Attribute #15630)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: files-mail-google.ml (MISP Attribute #15630)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58828772-b108-4592-a9e2-0bbb8e96ca05">
<cybox:Object id=":DomainName-58828772-b108-4592-a9e2-0bbb8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">files-mail-google.ml</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58828772-603c-4ccc-ab02-0bbb8e96ca05" timestamp="2018-01-16T16:34:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: google-authorize.gq (MISP Attribute #15631)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: google-authorize.gq (MISP Attribute #15631)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58828772-603c-4ccc-ab02-0bbb8e96ca05">
<cybox:Object id=":DomainName-58828772-603c-4ccc-ab02-0bbb8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">google-authorize.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58828772-0390-4cbb-a763-0bbb8e96ca05" timestamp="2018-01-16T16:34:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-google.gq (MISP Attribute #15632)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-google.gq (MISP Attribute #15632)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58828772-0390-4cbb-a763-0bbb8e96ca05">
<cybox:Object id=":DomainName-58828772-0390-4cbb-a763-0bbb8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-google.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-593ee83f-77c8-4e61-8dc0-53928e96ca05" timestamp="2017-06-12T15:15:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: myaccounts-gooog1e.com (MISP Attribute #16144)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: myaccounts-gooog1e.com (MISP Attribute #16144)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-593ee83f-77c8-4e61-8dc0-53928e96ca05">
<cybox:Object id=":DomainName-593ee83f-77c8-4e61-8dc0-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">myaccounts-gooog1e.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-06-12T15:15:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6617-9f1c-4e58-add8-09238e96ca05" timestamp="2018-01-16T15:52:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.gmail-profile.com (MISP Attribute #17936)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.gmail-profile.com (MISP Attribute #17936)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6617-9f1c-4e58-add8-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6617-9f1c-4e58-add8-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.gmail-profile.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58828772-cac4-4aff-a5cc-0bbb8e96ca05" timestamp="2018-01-16T16:34:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: google-settings.ml (MISP Attribute #15633)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: google-settings.ml (MISP Attribute #15633)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58828772-cac4-4aff-a5cc-0bbb8e96ca05">
<cybox:Object id=":DomainName-58828772-cac4-4aff-a5cc-0bbb8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">google-settings.ml</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6617-8fb0-45a7-b730-09238e96ca05" timestamp="2018-01-16T15:52:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.google-sign.tk (MISP Attribute #17937)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.google-sign.tk (MISP Attribute #17937)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6617-8fb0-45a7-b730-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6617-8fb0-45a7-b730-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.google-sign.tk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6617-9444-4079-ad77-09238e96ca05" timestamp="2018-01-16T15:52:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive.postmailsecret.com (MISP Attribute #17938)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive.postmailsecret.com (MISP Attribute #17938)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6617-9444-4079-ad77-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6617-9444-4079-ad77-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive.postmailsecret.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58828772-5bd0-410b-87bf-0bbb8e96ca05" timestamp="2018-01-16T16:34:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-google-com.gq (MISP Attribute #15635)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-google-com.gq (MISP Attribute #15635)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58828772-5bd0-410b-87bf-0bbb8e96ca05">
<cybox:Object id=":DomainName-58828772-5bd0-410b-87bf-0bbb8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-google-com.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6617-cab0-4c5c-b2d3-09238e96ca05" timestamp="2018-01-16T15:52:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.drive-mail.online (MISP Attribute #17939)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.drive-mail.online (MISP Attribute #17939)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6617-cab0-4c5c-b2d3-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6617-cab0-4c5c-b2d3-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.drive-mail.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6617-b918-45a8-a427-09238e96ca05" timestamp="2018-01-16T15:52:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: webmail.postmailsecret.com (MISP Attribute #17940)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: webmail.postmailsecret.com (MISP Attribute #17940)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6617-b918-45a8-a427-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6617-b918-45a8-a427-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">webmail.postmailsecret.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58828772-d120-4619-b0a2-0bbb8e96ca05" timestamp="2018-01-16T16:34:13+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-mg16-yahoo.cf (MISP Attribute #15637)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-mg16-yahoo.cf (MISP Attribute #15637)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58828772-d120-4619-b0a2-0bbb8e96ca05">
<cybox:Object id=":DomainName-58828772-d120-4619-b0a2-0bbb8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-mg16-yahoo.cf</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:13+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6617-c6e4-4925-b6ef-09238e96ca05" timestamp="2018-01-16T15:52:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.yahoo-verification.us (MISP Attribute #17941)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.yahoo-verification.us (MISP Attribute #17941)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6617-c6e4-4925-b6ef-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6617-c6e4-4925-b6ef-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.yahoo-verification.us</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6617-3c34-41c1-9a1d-09238e96ca05" timestamp="2018-01-16T15:52:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.drive-mail.us (MISP Attribute #17942)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.drive-mail.us (MISP Attribute #17942)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6617-3c34-41c1-9a1d-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6617-3c34-41c1-9a1d-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.drive-mail.us</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58828772-5f6c-4ee7-adb7-0bbb8e96ca05" timestamp="2018-01-16T16:34:13+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: yahoo-noreply.tk (MISP Attribute #15639)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: yahoo-noreply.tk (MISP Attribute #15639)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58828772-5f6c-4ee7-adb7-0bbb8e96ca05">
<cybox:Object id=":DomainName-58828772-5f6c-4ee7-adb7-0bbb8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">yahoo-noreply.tk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:13+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6617-ed6c-4dc4-9ef0-09238e96ca05" timestamp="2018-01-16T15:52:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.login-live.us (MISP Attribute #17943)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.login-live.us (MISP Attribute #17943)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6617-ed6c-4dc4-9ef0-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6617-ed6c-4dc4-9ef0-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.login-live.us</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58828772-4ec0-4888-a537-0bbb8e96ca05" timestamp="2018-01-16T16:34:13+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: yahoo-secure.tk (MISP Attribute #15640)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: yahoo-secure.tk (MISP Attribute #15640)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58828772-4ec0-4888-a537-0bbb8e96ca05">
<cybox:Object id=":DomainName-58828772-4ec0-4888-a537-0bbb8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">yahoo-secure.tk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:13+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6617-de24-4be4-989c-09238e96ca05" timestamp="2018-01-16T15:52:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.drive-mail.info (MISP Attribute #17944)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.drive-mail.info (MISP Attribute #17944)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6617-de24-4be4-989c-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6617-de24-4be4-989c-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.drive-mail.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-59511af6-6c28-42aa-b561-06b28e96ca05" timestamp="2017-06-26T10:32:22+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-mailbox.space (MISP Attribute #16153)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-mailbox.space (MISP Attribute #16153)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-59511af6-6c28-42aa-b561-06b28e96ca05">
<cybox:Object id=":DomainName-59511af6-6c28-42aa-b561-06b28e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-mailbox.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-06-26T10:32:22+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6617-6b6c-4c4e-8981-09238e96ca05" timestamp="2018-01-16T15:52:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts.gooog1e.com (MISP Attribute #17945)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts.gooog1e.com (MISP Attribute #17945)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6617-6b6c-4c4e-8981-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6617-6b6c-4c4e-8981-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts.gooog1e.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-595120ce-76a0-4dc0-852e-06b38e96ca05" timestamp="2017-06-26T10:57:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-defense.tk (MISP Attribute #16154)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-defense.tk (MISP Attribute #16154)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-595120ce-76a0-4dc0-852e-06b38e96ca05">
<cybox:Object id=":DomainName-595120ce-76a0-4dc0-852e-06b38e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-defense.tk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-06-26T10:57:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6618-7c7c-4624-8a90-09238e96ca05" timestamp="2018-01-16T15:52:40+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive.gooog1e.com (MISP Attribute #17946)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive.gooog1e.com (MISP Attribute #17946)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6618-7c7c-4624-8a90-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6618-7c7c-4624-8a90-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive.gooog1e.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:40+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6618-e678-425a-bb9f-09238e96ca05" timestamp="2018-01-16T15:52:40+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive.mail-status.com (MISP Attribute #17947)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive.mail-status.com (MISP Attribute #17947)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6618-e678-425a-bb9f-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6618-e678-425a-bb9f-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive.mail-status.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:40+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6618-be5c-43ac-9491-09238e96ca05" timestamp="2018-01-16T15:52:40+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive.myaccount-mail.com (MISP Attribute #17948)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive.myaccount-mail.com (MISP Attribute #17948)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6618-be5c-43ac-9491-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6618-be5c-43ac-9491-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive.myaccount-mail.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:40+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6618-8c7c-4664-9f5a-09238e96ca05" timestamp="2018-01-16T15:52:40+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: myaccount-mail.com (MISP Attribute #17949)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: myaccount-mail.com (MISP Attribute #17949)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6618-8c7c-4664-9f5a-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6618-8c7c-4664-9f5a-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">myaccount-mail.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:40+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58828ebd-afe8-46f2-9782-07298e96ca05" timestamp="2017-01-20T17:27:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: gmail-retry.tk (MISP Attribute #15646)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: gmail-retry.tk (MISP Attribute #15646)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58828ebd-afe8-46f2-9782-07298e96ca05">
<cybox:Object id=":DomainName-58828ebd-afe8-46f2-9782-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">gmail-retry.tk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-01-20T17:27:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6618-545c-4112-8d51-09238e96ca05" timestamp="2018-01-16T15:52:40+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https.drive-google.gq (MISP Attribute #17950)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: https.drive-google.gq (MISP Attribute #17950)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6618-545c-4112-8d51-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6618-545c-4112-8d51-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">https.drive-google.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:40+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58828ebd-e824-48c2-888e-07298e96ca05" timestamp="2017-01-20T17:27:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-163.tk (MISP Attribute #15647)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-163.tk (MISP Attribute #15647)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58828ebd-e824-48c2-888e-07298e96ca05">
<cybox:Object id=":DomainName-58828ebd-e824-48c2-888e-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-163.tk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-01-20T17:27:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb13-5758-40af-b0d2-5f708e96ca05" timestamp="2017-11-22T16:24:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-google.co.in (MISP Attribute #17439)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-google.co.in (MISP Attribute #17439)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb13-5758-40af-b0d2-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb13-5758-40af-b0d2-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-google.co.in</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6618-37a8-4ec6-88ca-09238e96ca05" timestamp="2018-01-16T15:52:40+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive.accounts-gooog1e.online (MISP Attribute #17951)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive.accounts-gooog1e.online (MISP Attribute #17951)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6618-37a8-4ec6-88ca-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6618-37a8-4ec6-88ca-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive.accounts-gooog1e.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:40+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58828ebd-ef30-4937-b5f0-07298e96ca05" timestamp="2017-01-20T17:27:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: gmail-secure.tk (MISP Attribute #15648)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: gmail-secure.tk (MISP Attribute #15648)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58828ebd-ef30-4937-b5f0-07298e96ca05">
<cybox:Object id=":DomainName-58828ebd-ef30-4937-b5f0-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">gmail-secure.tk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-01-20T17:27:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb13-8b7c-47c4-9bca-5f708e96ca05" timestamp="2017-11-22T16:24:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: dalailama.space (MISP Attribute #17440)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: dalailama.space (MISP Attribute #17440)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb13-8b7c-47c4-9bca-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb13-8b7c-47c4-9bca-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">dalailama.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6618-0500-41e5-b930-09238e96ca05" timestamp="2018-01-16T15:52:40+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: webmail.dalailama.space (MISP Attribute #17952)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: webmail.dalailama.space (MISP Attribute #17952)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6618-0500-41e5-b930-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6618-0500-41e5-b930-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">webmail.dalailama.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:40+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb13-7720-47c6-8c44-5f708e96ca05" timestamp="2017-11-22T16:24:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: docs-mail.space (MISP Attribute #17441)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: docs-mail.space (MISP Attribute #17441)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb13-7720-47c6-8c44-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb13-7720-47c6-8c44-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">docs-mail.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6618-e1f8-4f65-b342-09238e96ca05" timestamp="2018-01-16T15:52:40+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.mail-protect.space (MISP Attribute #17953)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.mail-protect.space (MISP Attribute #17953)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6618-e1f8-4f65-b342-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6618-e1f8-4f65-b342-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.mail-protect.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:40+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb13-28c8-45b7-934a-5f708e96ca05" timestamp="2017-11-22T16:24:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-accounts-google.ga (MISP Attribute #17442)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-accounts-google.ga (MISP Attribute #17442)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb13-28c8-45b7-934a-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb13-28c8-45b7-934a-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-accounts-google.ga</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6618-baa4-404c-842e-09238e96ca05" timestamp="2018-01-16T15:52:40+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.mail-attachment-usercontent.space (MISP Attribute #17954)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.mail-attachment-usercontent.space (MISP Attribute #17954)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6618-baa4-404c-842e-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6618-baa4-404c-842e-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.mail-attachment-usercontent.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:40+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb13-82fc-4c1c-b200-5f708e96ca05" timestamp="2017-11-22T16:24:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-google.cf (MISP Attribute #17443)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-google.cf (MISP Attribute #17443)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb13-82fc-4c1c-b200-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb13-82fc-4c1c-b200-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-google.cf</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e6618-3184-4bb3-8947-09238e96ca05" timestamp="2018-01-16T15:52:40+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.drlve-gooog1e.com (MISP Attribute #17955)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.drlve-gooog1e.com (MISP Attribute #17955)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e6618-3184-4bb3-8947-09238e96ca05">
<cybox:Object id=":DomainName-5a5e6618-3184-4bb3-8947-09238e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.drlve-gooog1e.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:52:40+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb13-ef74-4ea4-9173-5f708e96ca05" timestamp="2017-11-22T16:24:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-google.gq (MISP Attribute #17444)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-google.gq (MISP Attribute #17444)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb13-ef74-4ea4-9173-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb13-ef74-4ea4-9173-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-google.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb13-a0ac-44d1-97d8-5f708e96ca05" timestamp="2017-11-22T16:24:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-google.me (MISP Attribute #17445)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-google.me (MISP Attribute #17445)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb13-a0ac-44d1-97d8-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb13-a0ac-44d1-97d8-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-google.me</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb13-336c-4698-bda5-5f708e96ca05" timestamp="2017-11-22T16:24:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-google.ml (MISP Attribute #17446)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-google.ml (MISP Attribute #17446)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb13-336c-4698-bda5-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb13-336c-4698-bda5-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-google.ml</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-595d4924-1ce8-45be-b051-06e38e96ca05" timestamp="2018-01-16T16:34:13+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: myapp-gooog1e.com (MISP Attribute #16423)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: myapp-gooog1e.com (MISP Attribute #16423)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-595d4924-1ce8-45be-b051-06e38e96ca05">
<cybox:Object id=":DomainName-595d4924-1ce8-45be-b051-06e38e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">myapp-gooog1e.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:13+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb13-d054-4b3d-8577-5f708e96ca05" timestamp="2017-11-22T16:24:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-google.space (MISP Attribute #17447)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-google.space (MISP Attribute #17447)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb13-d054-4b3d-8577-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb13-d054-4b3d-8577-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-google.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-595d4924-e9ec-4caa-be6f-06e38e96ca05" timestamp="2018-01-16T16:34:13+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: email-netvigator.info (MISP Attribute #16424)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: email-netvigator.info (MISP Attribute #16424)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-595d4924-e9ec-4caa-be6f-06e38e96ca05">
<cybox:Object id=":DomainName-595d4924-e9ec-4caa-be6f-06e38e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">email-netvigator.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:13+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb13-eb0c-48d0-a98d-5f708e96ca05" timestamp="2017-11-22T16:24:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: epochtimes.space (MISP Attribute #17448)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: epochtimes.space (MISP Attribute #17448)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb13-eb0c-48d0-a98d-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb13-eb0c-48d0-a98d-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">epochtimes.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-595dc225-f7b0-4818-a102-06e38e96ca05" timestamp="2017-07-06T00:52:53+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-dsi-go.space (MISP Attribute #16425)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-dsi-go.space (MISP Attribute #16425)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-595dc225-f7b0-4818-a102-06e38e96ca05">
<cybox:Object id=":DomainName-595dc225-f7b0-4818-a102-06e38e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-dsi-go.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-07-06T00:52:53+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb13-7070-44b6-a867-5f708e96ca05" timestamp="2017-11-22T16:24:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: gmail-relation.tk (MISP Attribute #17449)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: gmail-relation.tk (MISP Attribute #17449)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb13-7070-44b6-a867-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb13-7070-44b6-a867-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">gmail-relation.tk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-595dc260-a7f4-4875-b35b-06e28e96ca05" timestamp="2017-07-06T00:53:52+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-continue.space (MISP Attribute #16426)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-continue.space (MISP Attribute #16426)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-595dc260-a7f4-4875-b35b-06e28e96ca05">
<cybox:Object id=":DomainName-595dc260-a7f4-4875-b35b-06e28e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-continue.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-07-06T00:53:52+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-314c-4df1-a63c-5f708e96ca05" timestamp="2017-11-22T16:24:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: gmail-ssl.tk (MISP Attribute #17450)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: gmail-ssl.tk (MISP Attribute #17450)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-314c-4df1-a63c-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-314c-4df1-a63c-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">gmail-ssl.tk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-595dc260-e70c-4de7-aac2-06e28e96ca05" timestamp="2017-07-06T00:53:52+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-package.space (MISP Attribute #16427)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-package.space (MISP Attribute #16427)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-595dc260-e70c-4de7-aac2-06e28e96ca05">
<cybox:Object id=":DomainName-595dc260-e70c-4de7-aac2-06e28e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-package.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-07-06T00:53:52+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-9ed0-4a34-ae55-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: google-issue.tk (MISP Attribute #17451)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: google-issue.tk (MISP Attribute #17451)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-9ed0-4a34-ae55-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-9ed0-4a34-ae55-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">google-issue.tk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-0558-4518-ac84-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: google-sign.tk (MISP Attribute #17452)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: google-sign.tk (MISP Attribute #17452)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-0558-4518-ac84-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-0558-4518-ac84-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">google-sign.tk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-b3ec-4060-a321-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsaccounts-google.cf (MISP Attribute #17453)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsaccounts-google.cf (MISP Attribute #17453)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-b3ec-4060-a321-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-b3ec-4060-a321-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsaccounts-google.cf</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-853c-4a10-a97f-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsdrive-google.gq (MISP Attribute #17454)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsdrive-google.gq (MISP Attribute #17454)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-853c-4a10-a97f-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-853c-4a10-a97f-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsdrive-google.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-595c-4990-a1e2-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsdrive-myaccounts-google.cf (MISP Attribute #17455)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsdrive-myaccounts-google.cf (MISP Attribute #17455)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-595c-4990-a1e2-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-595c-4990-a1e2-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsdrive-myaccounts-google.cf</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-1170-4c82-a6d3-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https-google-drive.ml (MISP Attribute #17456)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: https-google-drive.ml (MISP Attribute #17456)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-1170-4c82-a6d3-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-1170-4c82-a6d3-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">https-google-drive.ml</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-1884-4430-8e51-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https-my-accounts-google.gq (MISP Attribute #17457)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: https-my-accounts-google.gq (MISP Attribute #17457)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-1884-4430-8e51-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-1884-4430-8e51-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">https-my-accounts-google.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-c00c-4bab-83dc-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-guazi.com (MISP Attribute #17458)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-guazi.com (MISP Attribute #17458)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-c00c-4bab-83dc-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-c00c-4bab-83dc-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-guazi.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-b000-4b12-af5f-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-secret.online (MISP Attribute #17459)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-secret.online (MISP Attribute #17459)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-b000-4b12-af5f-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-b000-4b12-af5f-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-secret.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-755c-4d9e-9a18-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-status.com (MISP Attribute #17460)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-status.com (MISP Attribute #17460)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-755c-4d9e-9a18-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-755c-4d9e-9a18-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-status.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-5bd8-4238-ae27-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: myaccounts-google.space (MISP Attribute #17461)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: myaccounts-google.space (MISP Attribute #17461)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-5bd8-4238-ae27-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-5bd8-4238-ae27-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">myaccounts-google.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-a634-40f6-9cc0-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mydrive-google.space (MISP Attribute #17462)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mydrive-google.space (MISP Attribute #17462)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-a634-40f6-9cc0-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-a634-40f6-9cc0-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mydrive-google.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-9ebc-4d27-89de-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: my-office.cf (MISP Attribute #17463)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: my-office.cf (MISP Attribute #17463)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-9ebc-4d27-89de-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-9ebc-4d27-89de-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">my-office.cf</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-7acc-436d-a895-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: tibet-office.net (MISP Attribute #17464)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: tibet-office.net (MISP Attribute #17464)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-7acc-436d-a895-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-7acc-436d-a895-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">tibet-office.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a15eb14-9f00-4534-a69f-5f708e96ca05" timestamp="2017-11-22T16:24:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: yahoo-device.tk (MISP Attribute #17465)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: yahoo-device.tk (MISP Attribute #17465)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a15eb14-9f00-4534-a69f-5f708e96ca05">
<cybox:Object id=":DomainName-5a15eb14-9f00-4534-a69f-5f708e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">yahoo-device.tk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-11-22T16:24:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-588a5521-f080-4aad-93b1-0bbb8e96ca05" timestamp="2018-01-16T16:34:13+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-google.cc (MISP Attribute #15684)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-google.cc (MISP Attribute #15684)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-588a5521-f080-4aad-93b1-0bbb8e96ca05">
<cybox:Object id=":DomainName-588a5521-f080-4aad-93b1-0bbb8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-google.cc</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:13+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5893a06c-4bd4-4112-97a8-0bbb8e96ca05" timestamp="2018-01-16T16:34:13+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsdocs-google.info (MISP Attribute #15689)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsdocs-google.info (MISP Attribute #15689)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5893a06c-4bd4-4112-97a8-0bbb8e96ca05">
<cybox:Object id=":DomainName-5893a06c-4bd4-4112-97a8-0bbb8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsdocs-google.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:13+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5907849c-97a4-4d52-aca1-5d828e96ca05" timestamp="2017-05-01T14:55:24+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drlve-gooog1e.com (MISP Attribute #15961)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drlve-gooog1e.com (MISP Attribute #15961)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5907849c-97a4-4d52-aca1-5d828e96ca05">
<cybox:Object id=":DomainName-5907849c-97a4-4d52-aca1-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drlve-gooog1e.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-01T14:55:24+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-59078a5c-50a0-44b8-be71-53928e96ca05" timestamp="2017-05-01T15:19:56+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-youxinpai.com (MISP Attribute #15962)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-youxinpai.com (MISP Attribute #15962)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-59078a5c-50a0-44b8-be71-53928e96ca05">
<cybox:Object id=":DomainName-59078a5c-50a0-44b8-be71-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-youxinpai.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-01T15:19:56+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-590cd842-783c-4e0d-9d45-53928e96ca05" timestamp="2017-05-05T15:53:38+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-gooog1e.asia (MISP Attribute #15963)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-gooog1e.asia (MISP Attribute #15963)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-590cd842-783c-4e0d-9d45-53928e96ca05">
<cybox:Object id=":DomainName-590cd842-783c-4e0d-9d45-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-gooog1e.asia</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-05T15:53:38+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-590cd918-792c-4c08-a3f7-53928e96ca05" timestamp="2017-05-05T15:57:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-gooog1e.online (MISP Attribute #15964)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-gooog1e.online (MISP Attribute #15964)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-590cd918-792c-4c08-a3f7-53928e96ca05">
<cybox:Object id=":DomainName-590cd918-792c-4c08-a3f7-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-gooog1e.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-05T15:57:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-590cdccf-e228-4406-84c2-5d828e96ca05" timestamp="2017-05-05T16:13:03+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-guazi.space (MISP Attribute #15965)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-guazi.space (MISP Attribute #15965)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-590cdccf-e228-4406-84c2-5d828e96ca05">
<cybox:Object id=":DomainName-590cdccf-e228-4406-84c2-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-guazi.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-05T16:13:03+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-590cdff8-7884-467e-88d4-53938e96ca05" timestamp="2017-05-05T16:26:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-sina.space (MISP Attribute #15966)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-sina.space (MISP Attribute #15966)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-590cdff8-7884-467e-88d4-53938e96ca05">
<cybox:Object id=":DomainName-590cdff8-7884-467e-88d4-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-sina.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-05T16:26:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-590ce0f7-43d0-4e1e-9c10-53938e96ca05" timestamp="2017-05-05T16:30:47+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: winupdate.space (MISP Attribute #15967)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: winupdate.space (MISP Attribute #15967)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-590ce0f7-43d0-4e1e-9c10-53938e96ca05">
<cybox:Object id=":DomainName-590ce0f7-43d0-4e1e-9c10-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">winupdate.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-05T16:30:47+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-590ce20b-83b4-4cba-9dc7-53938e96ca05" timestamp="2017-05-05T16:35:23+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: ymail-settings.space (MISP Attribute #15968)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: ymail-settings.space (MISP Attribute #15968)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-590ce20b-83b4-4cba-9dc7-53938e96ca05">
<cybox:Object id=":DomainName-590ce20b-83b4-4cba-9dc7-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">ymail-settings.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-05T16:35:23+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-59109412-5e18-4f66-be68-53928e96ca05" timestamp="2017-05-08T11:51:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-modular.space (MISP Attribute #15970)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-modular.space (MISP Attribute #15970)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-59109412-5e18-4f66-be68-53928e96ca05">
<cybox:Object id=":DomainName-59109412-5e18-4f66-be68-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-modular.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-08T11:51:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5910c536-b214-46e2-9385-5d828e96ca05" timestamp="2017-05-08T15:21:26+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: login-live.space (MISP Attribute #15972)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: login-live.space (MISP Attribute #15972)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5910c536-b214-46e2-9385-5d828e96ca05">
<cybox:Object id=":DomainName-5910c536-b214-46e2-9385-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">login-live.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-08T15:21:26+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5910c63a-bc38-4957-b1f0-5d828e96ca05" timestamp="2017-05-08T15:25:46+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: logln-yahoo.com (MISP Attribute #15973)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: logln-yahoo.com (MISP Attribute #15973)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5910c63a-bc38-4957-b1f0-5d828e96ca05">
<cybox:Object id=":DomainName-5910c63a-bc38-4957-b1f0-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">logln-yahoo.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-08T15:25:46+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5910cb7b-bf90-463b-aba2-5d828e96ca05" timestamp="2017-05-08T15:48:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: webmail-mpt.space (MISP Attribute #15974)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: webmail-mpt.space (MISP Attribute #15974)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5910cb7b-bf90-463b-aba2-5d828e96ca05">
<cybox:Object id=":DomainName-5910cb7b-bf90-463b-aba2-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">webmail-mpt.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-08T15:48:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-59123c8a-948c-4abd-b79b-5d828e96ca05" timestamp="2017-05-09T18:02:50+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: wengiguowengui.space (MISP Attribute #15975)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: wengiguowengui.space (MISP Attribute #15975)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-59123c8a-948c-4abd-b79b-5d828e96ca05">
<cybox:Object id=":DomainName-59123c8a-948c-4abd-b79b-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">wengiguowengui.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-09T18:02:50+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58b44b3a-c44c-4104-9ec1-53938e96ca05" timestamp="2018-01-16T16:34:13+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: yahoo-verification.us (MISP Attribute #15730)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: yahoo-verification.us (MISP Attribute #15730)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58b44b3a-c44c-4104-9ec1-53938e96ca05">
<cybox:Object id=":DomainName-58b44b3a-c44c-4104-9ec1-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">yahoo-verification.us</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:13+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58b83e4a-9e80-4357-b4ef-53928e96ca05" timestamp="2017-03-02T10:46:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-mail.us (MISP Attribute #15736)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-mail.us (MISP Attribute #15736)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58b83e4a-9e80-4357-b4ef-53928e96ca05">
<cybox:Object id=":DomainName-58b83e4a-9e80-4357-b4ef-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-mail.us</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-03-02T10:46:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58b84631-6960-41b3-b7a4-53938e96ca05" timestamp="2017-03-02T11:20:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: docs-mail-google.us (MISP Attribute #15738)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: docs-mail-google.us (MISP Attribute #15738)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58b84631-6960-41b3-b7a4-53938e96ca05">
<cybox:Object id=":DomainName-58b84631-6960-41b3-b7a4-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">docs-mail-google.us</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-03-02T11:20:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58b98d25-6d24-4081-abae-53928e96ca05" timestamp="2017-03-03T10:35:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: login-live.us (MISP Attribute #15739)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: login-live.us (MISP Attribute #15739)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58b98d25-6d24-4081-abae-53928e96ca05">
<cybox:Object id=":DomainName-58b98d25-6d24-4081-abae-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">login-live.us</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-03-03T10:35:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58c2ce5b-4d04-488d-a6c5-53938e96ca05" timestamp="2017-03-10T11:03:39+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-mail.info (MISP Attribute #15780)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-mail.info (MISP Attribute #15780)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58c2ce5b-4d04-488d-a6c5-53938e96ca05">
<cybox:Object id=":DomainName-58c2ce5b-4d04-488d-a6c5-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-mail.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-03-10T11:03:39+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58c676e9-d594-4dcc-8daf-53928e96ca05" timestamp="2017-03-13T06:39:37+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: gooog1e.com (MISP Attribute #15786)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: gooog1e.com (MISP Attribute #15786)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58c676e9-d594-4dcc-8daf-53928e96ca05">
<cybox:Object id=":DomainName-58c676e9-d594-4dcc-8daf-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">gooog1e.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-03-13T06:39:37+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5919cd19-cb28-413f-9b83-53928e96ca05" timestamp="2017-05-15T11:45:29+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-defense.space (MISP Attribute #16043)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-defense.space (MISP Attribute #16043)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5919cd19-cb28-413f-9b83-53928e96ca05">
<cybox:Object id=":DomainName-5919cd19-cb28-413f-9b83-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-defense.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-15T11:45:29+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58c67caf-8e54-40a7-be8a-53928e96ca05" timestamp="2017-03-13T07:04:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-goog1e.com (MISP Attribute #15788)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-goog1e.com (MISP Attribute #15788)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58c67caf-8e54-40a7-be8a-53928e96ca05">
<cybox:Object id=":DomainName-58c67caf-8e54-40a7-be8a-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-goog1e.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-03-13T07:04:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-591e040b-ce60-45df-ba1e-5d828e96ca05" timestamp="2017-05-18T16:28:59+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: files-gooog1e.space (MISP Attribute #16044)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: files-gooog1e.space (MISP Attribute #16044)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-591e040b-ce60-45df-ba1e-5d828e96ca05">
<cybox:Object id=":DomainName-591e040b-ce60-45df-ba1e-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">files-gooog1e.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-18T16:28:59+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58c91f4c-dfe8-4639-9ded-53938e96ca05" timestamp="2017-03-15T07:02:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mydrive-mail.asia (MISP Attribute #15789)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mydrive-mail.asia (MISP Attribute #15789)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58c91f4c-dfe8-4639-9ded-53938e96ca05">
<cybox:Object id=":DomainName-58c91f4c-dfe8-4639-9ded-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mydrive-mail.asia</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-03-15T07:02:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-591e0d44-e8b8-4c0e-a959-5d828e96ca05" timestamp="2017-05-18T17:08:20+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-extend.space (MISP Attribute #16045)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-extend.space (MISP Attribute #16045)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-591e0d44-e8b8-4c0e-a959-5d828e96ca05">
<cybox:Object id=":DomainName-591e0d44-e8b8-4c0e-a959-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-extend.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-18T17:08:20+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58dbfa91-0c20-4d50-83d8-53938e96ca05" timestamp="2018-01-16T16:34:13+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-gooog1e.info (MISP Attribute #15790)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-gooog1e.info (MISP Attribute #15790)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58dbfa91-0c20-4d50-83d8-53938e96ca05">
<cybox:Object id=":DomainName-58dbfa91-0c20-4d50-83d8-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-gooog1e.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:13+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58dbfa91-d540-4a8b-a255-53938e96ca05" timestamp="2018-01-16T16:34:13+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-secret.info (MISP Attribute #15792)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-secret.info (MISP Attribute #15792)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58dbfa91-d540-4a8b-a255-53938e96ca05">
<cybox:Object id=":DomainName-58dbfa91-d540-4a8b-a255-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-secret.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:13+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58dbfabb-3344-4411-ba5c-53938e96ca05" timestamp="2018-01-16T16:34:13+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: myaccounts-mail.com (MISP Attribute #15793)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: myaccounts-mail.com (MISP Attribute #15793)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58dbfabb-3344-4411-ba5c-53938e96ca05">
<cybox:Object id=":DomainName-58dbfabb-3344-4411-ba5c-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">myaccounts-mail.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:13+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58dbfada-dd70-4742-8b09-53928e96ca05" timestamp="2018-01-16T16:34:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: yahoo-edit.us (MISP Attribute #15794)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: yahoo-edit.us (MISP Attribute #15794)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58dbfada-dd70-4742-8b09-53928e96ca05">
<cybox:Object id=":DomainName-58dbfada-dd70-4742-8b09-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">yahoo-edit.us</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58dd97e8-ed28-4f49-811e-53938e96ca05" timestamp="2017-03-30T19:42:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: account-gooogle.info (MISP Attribute #15796)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: account-gooogle.info (MISP Attribute #15796)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58dd97e8-ed28-4f49-811e-53938e96ca05">
<cybox:Object id=":DomainName-58dd97e8-ed28-4f49-811e-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">account-gooogle.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-03-30T19:42:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58dd97e8-44dc-4bc3-ad48-53938e96ca05" timestamp="2017-03-30T19:42:32+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: outlook-login.com (MISP Attribute #15797)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: outlook-login.com (MISP Attribute #15797)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58dd97e8-44dc-4bc3-ad48-53938e96ca05">
<cybox:Object id=":DomainName-58dd97e8-44dc-4bc3-ad48-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">outlook-login.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-03-30T19:42:32+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58e2afc8-fb0c-40f7-9da1-53928e96ca05" timestamp="2017-04-03T16:25:44+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-mail.space (MISP Attribute #15799)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-mail.space (MISP Attribute #15799)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58e2afc8-fb0c-40f7-9da1-53928e96ca05">
<cybox:Object id=":DomainName-58e2afc8-fb0c-40f7-9da1-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-mail.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-03T16:25:44+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-59272a06-6768-4f85-b5f9-5d828e96ca05" timestamp="2017-05-25T15:01:26+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-platform.space (MISP Attribute #16064)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-platform.space (MISP Attribute #16064)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-59272a06-6768-4f85-b5f9-5d828e96ca05">
<cybox:Object id=":DomainName-59272a06-6768-4f85-b5f9-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-platform.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-25T15:01:26+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-03c8-4bfd-9152-07298e96ca05" timestamp="2018-01-16T16:34:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: google-protected.gq (MISP Attribute #15553)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: google-protected.gq (MISP Attribute #15553)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-03c8-4bfd-9152-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-03c8-4bfd-9152-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">google-protected.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-592c726a-2c78-4466-8ed6-53938e96ca05" timestamp="2017-05-29T15:11:38+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-info.space (MISP Attribute #16065)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-info.space (MISP Attribute #16065)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-592c726a-2c78-4466-8ed6-53938e96ca05">
<cybox:Object id=":DomainName-592c726a-2c78-4466-8ed6-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-info.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-29T15:11:38+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-a574-41cd-932a-07298e96ca05" timestamp="2018-01-16T16:34:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https-mail-google.ml (MISP Attribute #15554)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: https-mail-google.ml (MISP Attribute #15554)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-a574-41cd-932a-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-a574-41cd-932a-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">https-mail-google.ml</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-592c7284-ab6c-4d44-9ff1-53938e96ca05" timestamp="2017-05-29T15:12:04+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-goo.space (MISP Attribute #16066)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-goo.space (MISP Attribute #16066)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-592c7284-ab6c-4d44-9ff1-53938e96ca05">
<cybox:Object id=":DomainName-592c7284-ab6c-4d44-9ff1-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-goo.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-05-29T15:12:04+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-4ab0-4b27-9e1e-07298e96ca05" timestamp="2018-01-16T16:34:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsmail-google.cf (MISP Attribute #15555)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsmail-google.cf (MISP Attribute #15555)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-4ab0-4b27-9e1e-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-4ab0-4b27-9e1e-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsmail-google.cf</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-59304dd8-2f88-45ab-8a63-5d828e96ca05" timestamp="2017-06-01T13:24:40+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: webmail-dalailama.space (MISP Attribute #16067)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: webmail-dalailama.space (MISP Attribute #16067)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-59304dd8-2f88-45ab-8a63-5d828e96ca05">
<cybox:Object id=":DomainName-59304dd8-2f88-45ab-8a63-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">webmail-dalailama.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-06-01T13:24:40+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-8ac8-4e39-9241-07298e96ca05" timestamp="2018-01-16T16:34:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https-mail-google.gq (MISP Attribute #15556)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: https-mail-google.gq (MISP Attribute #15556)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-8ac8-4e39-9241-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-8ac8-4e39-9241-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">https-mail-google.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58e7b5c8-9a60-4396-b42c-53928e96ca05" timestamp="2017-04-07T11:52:40+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: cc-mail-secret.com (MISP Attribute #15812)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: cc-mail-secret.com (MISP Attribute #15812)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58e7b5c8-9a60-4396-b42c-53928e96ca05">
<cybox:Object id=":DomainName-58e7b5c8-9a60-4396-b42c-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">cc-mail-secret.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-07T11:52:40+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5935b5e6-6838-4e13-8e4a-53928e96ca05" timestamp="2017-06-05T15:49:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: xin-corp.space (MISP Attribute #16068)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: xin-corp.space (MISP Attribute #16068)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5935b5e6-6838-4e13-8e4a-53928e96ca05">
<cybox:Object id=":DomainName-5935b5e6-6838-4e13-8e4a-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">xin-corp.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-06-05T15:49:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-7160-4d05-b9dd-07298e96ca05" timestamp="2018-01-16T16:34:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: google-secure.gq (MISP Attribute #15557)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: google-secure.gq (MISP Attribute #15557)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-7160-4d05-b9dd-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-7160-4d05-b9dd-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">google-secure.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58e7b5c8-64c0-43cf-a8fd-53928e96ca05" timestamp="2017-04-07T11:52:40+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-goog1e.info (MISP Attribute #15813)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-goog1e.info (MISP Attribute #15813)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58e7b5c8-64c0-43cf-a8fd-53928e96ca05">
<cybox:Object id=":DomainName-58e7b5c8-64c0-43cf-a8fd-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-goog1e.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-07T11:52:40+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5935b5e6-e930-41fe-9c27-53928e96ca05" timestamp="2017-06-05T15:49:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-defend.space (MISP Attribute #16069)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-defend.space (MISP Attribute #16069)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5935b5e6-e930-41fe-9c27-53928e96ca05">
<cybox:Object id=":DomainName-5935b5e6-e930-41fe-9c27-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-defend.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-06-05T15:49:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58e7b5c8-f7f8-49f8-9246-53928e96ca05" timestamp="2017-04-07T11:52:40+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-mail.online (MISP Attribute #15814)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-mail.online (MISP Attribute #15814)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58e7b5c8-f7f8-49f8-9246-53928e96ca05">
<cybox:Object id=":DomainName-58e7b5c8-f7f8-49f8-9246-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-mail.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-07T11:52:40+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-59396b77-c09c-4765-aac8-53938e96ca05" timestamp="2017-06-08T11:21:27+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: appinstall-mail.space (MISP Attribute #16070)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: appinstall-mail.space (MISP Attribute #16070)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-59396b77-c09c-4765-aac8-53938e96ca05">
<cybox:Object id=":DomainName-59396b77-c09c-4765-aac8-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">appinstall-mail.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-06-08T11:21:27+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-3998-4684-961b-07298e96ca05" timestamp="2018-01-16T16:34:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: gmail-profile.com (MISP Attribute #15559)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: gmail-profile.com (MISP Attribute #15559)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-3998-4684-961b-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-3998-4684-961b-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">gmail-profile.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58eba748-88cc-4103-b1f4-53938e96ca05" timestamp="2017-04-10T11:39:52+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-gooog1e.space (MISP Attribute #15815)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-gooog1e.space (MISP Attribute #15815)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58eba748-88cc-4103-b1f4-53938e96ca05">
<cybox:Object id=":DomainName-58eba748-88cc-4103-b1f4-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-gooog1e.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-10T11:39:52+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-59396b77-2f9c-40dd-938c-53938e96ca05" timestamp="2017-06-08T11:21:27+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: edit-ymail.space (MISP Attribute #16071)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: edit-ymail.space (MISP Attribute #16071)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-59396b77-2f9c-40dd-938c-53938e96ca05">
<cybox:Object id=":DomainName-59396b77-2f9c-40dd-938c-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">edit-ymail.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-06-08T11:21:27+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58eba748-1028-4648-a69f-53938e96ca05" timestamp="2017-04-10T11:39:52+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: myaccounts-gooog1e.space (MISP Attribute #15816)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: myaccounts-gooog1e.space (MISP Attribute #15816)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58eba748-1028-4648-a69f-53938e96ca05">
<cybox:Object id=":DomainName-58eba748-1028-4648-a69f-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">myaccounts-gooog1e.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-10T11:39:52+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-cd40-40b2-aeea-07298e96ca05" timestamp="2018-01-16T16:34:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: hotmail-sign.com (MISP Attribute #15561)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: hotmail-sign.com (MISP Attribute #15561)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-cd40-40b2-aeea-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-cd40-40b2-aeea-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">hotmail-sign.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58eba748-0438-4514-bd1f-53938e96ca05" timestamp="2017-04-10T11:39:52+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: webmail-dalailama.com (MISP Attribute #15817)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: webmail-dalailama.com (MISP Attribute #15817)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58eba748-0438-4514-bd1f-53938e96ca05">
<cybox:Object id=":DomainName-58eba748-0438-4514-bd1f-53938e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">webmail-dalailama.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-10T11:39:52+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-e068-49d4-852b-07298e96ca05" timestamp="2018-01-16T16:34:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: yahoo-images.com (MISP Attribute #15562)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: yahoo-images.com (MISP Attribute #15562)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-e068-49d4-852b-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-e068-49d4-852b-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">yahoo-images.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-1a34-46ff-9a98-07298e96ca05" timestamp="2018-01-16T16:34:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: yahoo-safety.com (MISP Attribute #15563)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: yahoo-safety.com (MISP Attribute #15563)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-1a34-46ff-9a98-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-1a34-46ff-9a98-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">yahoo-safety.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-3c10-4fdc-98cb-07298e96ca05" timestamp="2018-01-16T16:34:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: google-post.com (MISP Attribute #15564)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: google-post.com (MISP Attribute #15564)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-3c10-4fdc-98cb-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-3c10-4fdc-98cb-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">google-post.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-8b3c-4300-a70b-07298e96ca05" timestamp="2018-01-16T16:34:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: yahoo-protect.com (MISP Attribute #15565)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: yahoo-protect.com (MISP Attribute #15565)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-8b3c-4300-a70b-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-8b3c-4300-a70b-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">yahoo-protect.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-ca80-495e-8d0c-07298e96ca05" timestamp="2018-01-16T16:34:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: gmail-safety.pw (MISP Attribute #15566)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: gmail-safety.pw (MISP Attribute #15566)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-ca80-495e-8d0c-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-ca80-495e-8d0c-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">gmail-safety.pw</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-b674-4ca5-9f07-07298e96ca05" timestamp="2018-01-16T16:34:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsdrive-google.pw (MISP Attribute #15567)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsdrive-google.pw (MISP Attribute #15567)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-b674-4ca5-9f07-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-b674-4ca5-9f07-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsdrive-google.pw</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-2abc-4a62-a220-07298e96ca05" timestamp="2018-01-16T16:34:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-doubt.com (MISP Attribute #15568)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-doubt.com (MISP Attribute #15568)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-2abc-4a62-a220-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-2abc-4a62-a220-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-doubt.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-a0f0-4f2a-9149-07298e96ca05" timestamp="2018-01-16T16:34:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: yahoomaintain.com (MISP Attribute #15569)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: yahoomaintain.com (MISP Attribute #15569)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-a0f0-4f2a-9149-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-a0f0-4f2a-9149-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">yahoomaintain.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-3dd8-4b9d-a1a9-07298e96ca05" timestamp="2018-01-16T16:34:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: t1bet.net (MISP Attribute #15570)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: t1bet.net (MISP Attribute #15570)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-3dd8-4b9d-a1a9-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-3dd8-4b9d-a1a9-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">t1bet.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58ee49a7-7740-4766-9547-5d828e96ca05" timestamp="2017-04-12T11:37:11+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-aol.space (MISP Attribute #15826)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-aol.space (MISP Attribute #15826)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58ee49a7-7740-4766-9547-5d828e96ca05">
<cybox:Object id=":DomainName-58ee49a7-7740-4766-9547-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-aol.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-12T11:37:11+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-be20-4fe3-92f4-07298e96ca05" timestamp="2018-01-16T16:34:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: google-secret.com (MISP Attribute #15571)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: google-secret.com (MISP Attribute #15571)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-be20-4fe3-92f4-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-be20-4fe3-92f4-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">google-secret.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58ee4d32-1f88-411b-bbe5-5d828e96ca05" timestamp="2017-04-12T11:52:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-epochtimes.space (MISP Attribute #15827)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-epochtimes.space (MISP Attribute #15827)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58ee4d32-1f88-411b-bbe5-5d828e96ca05">
<cybox:Object id=":DomainName-58ee4d32-1f88-411b-bbe5-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-epochtimes.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-12T11:52:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-9df0-4ca1-948f-07298e96ca05" timestamp="2018-01-16T16:34:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accountsgoog1e.info (MISP Attribute #15572)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accountsgoog1e.info (MISP Attribute #15572)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-9df0-4ca1-948f-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-9df0-4ca1-948f-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accountsgoog1e.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58ee553c-4c6c-4fa6-8c2f-5d828e96ca05" timestamp="2017-04-12T12:26:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-email.space (MISP Attribute #15828)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-email.space (MISP Attribute #15828)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58ee553c-4c6c-4fa6-8c2f-5d828e96ca05">
<cybox:Object id=":DomainName-58ee553c-4c6c-4fa6-8c2f-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-email.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-12T12:26:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-8128-4bd5-9dbc-07298e96ca05" timestamp="2018-01-16T16:34:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-google.info (MISP Attribute #15573)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-google.info (MISP Attribute #15573)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-8128-4bd5-9dbc-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-8128-4bd5-9dbc-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-google.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-7f20-46c1-9bd2-07298e96ca05" timestamp="2018-01-16T16:34:15+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: accounts-goog1e.com (MISP Attribute #15574)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: accounts-goog1e.com (MISP Attribute #15574)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-7f20-46c1-9bd2-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-7f20-46c1-9bd2-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">accounts-goog1e.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:15+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58efbb0f-19b4-4a87-8f27-5d828e96ca05" timestamp="2017-04-13T13:53:19+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: files-mail.space (MISP Attribute #15830)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: files-mail.space (MISP Attribute #15830)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58efbb0f-19b4-4a87-8f27-5d828e96ca05">
<cybox:Object id=":DomainName-58efbb0f-19b4-4a87-8f27-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">files-mail.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-13T13:53:19+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-8644-420d-b070-07298e96ca05" timestamp="2018-01-16T16:34:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: postmailsecret.com (MISP Attribute #15576)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: postmailsecret.com (MISP Attribute #15576)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-8644-420d-b070-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-8644-420d-b070-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">postmailsecret.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-5938-4cb4-9b4b-07298e96ca05" timestamp="2018-01-16T16:34:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsaccounts-google.pw (MISP Attribute #15577)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsaccounts-google.pw (MISP Attribute #15577)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-5938-4cb4-9b4b-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-5938-4cb4-9b4b-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsaccounts-google.pw</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-d4ec-4a9f-a9cb-07298e96ca05" timestamp="2018-01-16T16:34:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsaccounts-google.com (MISP Attribute #15578)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsaccounts-google.com (MISP Attribute #15578)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-d4ec-4a9f-a9cb-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-d4ec-4a9f-a9cb-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsaccounts-google.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-eb20-4b18-9740-07298e96ca05" timestamp="2018-01-16T16:34:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsdrive-google.site (MISP Attribute #15580)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsdrive-google.site (MISP Attribute #15580)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-eb20-4b18-9740-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-eb20-4b18-9740-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsdrive-google.site</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-be78-4001-bb08-07298e96ca05" timestamp="2018-01-16T16:34:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https-drive-google.com (MISP Attribute #15581)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: https-drive-google.com (MISP Attribute #15581)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-be78-4001-bb08-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-be78-4001-bb08-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">https-drive-google.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-2c48-4b14-915e-07298e96ca05" timestamp="2018-01-16T16:34:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsdrive-accounts-google.site (MISP Attribute #15582)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsdrive-accounts-google.site (MISP Attribute #15582)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-2c48-4b14-915e-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-2c48-4b14-915e-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsdrive-accounts-google.site</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-6b28-4688-9f8e-07298e96ca05" timestamp="2018-01-16T16:34:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsaccounts-google.site (MISP Attribute #15583)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsaccounts-google.site (MISP Attribute #15583)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-6b28-4688-9f8e-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-6b28-4688-9f8e-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsaccounts-google.site</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-cb00-4c50-9a6f-07298e96ca05" timestamp="2018-01-16T16:34:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsmyaccounts-google.space (MISP Attribute #15585)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsmyaccounts-google.space (MISP Attribute #15585)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-cb00-4c50-9a6f-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-cb00-4c50-9a6f-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsmyaccounts-google.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-0aa8-4976-9e0b-07298e96ca05" timestamp="2018-01-16T16:34:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsaccounts-google.info (MISP Attribute #15586)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsaccounts-google.info (MISP Attribute #15586)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-0aa8-4976-9e0b-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-0aa8-4976-9e0b-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsaccounts-google.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa321-4520-4b40-87c8-07298e96ca05" timestamp="2018-01-16T16:34:16+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mydrive-google.com (MISP Attribute #15587)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mydrive-google.com (MISP Attribute #15587)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa321-4520-4b40-87c8-07298e96ca05">
<cybox:Object id=":DomainName-587fa321-4520-4b40-87c8-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mydrive-google.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:16+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-7e2c-4594-aa21-07298e96ca05" timestamp="2018-01-16T16:34:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsmyaccount-google.info (MISP Attribute #15588)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsmyaccount-google.info (MISP Attribute #15588)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-7e2c-4594-aa21-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-7e2c-4594-aa21-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsmyaccount-google.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-ba50-47d9-82ba-07298e96ca05" timestamp="2018-01-16T16:34:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsdrive-google.net (MISP Attribute #15589)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsdrive-google.net (MISP Attribute #15589)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-ba50-47d9-82ba-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-ba50-47d9-82ba-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsdrive-google.net</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-0724-494e-bae1-07298e96ca05" timestamp="2018-01-16T16:34:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-accounts-google.com (MISP Attribute #15590)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-accounts-google.com (MISP Attribute #15590)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-0724-494e-bae1-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-0724-494e-bae1-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-accounts-google.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-a65c-4bd7-8c7d-07298e96ca05" timestamp="2018-01-16T16:34:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: myaccountsgoogle.info (MISP Attribute #15591)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: myaccountsgoogle.info (MISP Attribute #15591)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-a65c-4bd7-8c7d-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-a65c-4bd7-8c7d-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">myaccountsgoogle.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-b95c-42f0-ab69-07298e96ca05" timestamp="2018-01-16T16:34:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mg-mail-yahoo.us (MISP Attribute #15593)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mg-mail-yahoo.us (MISP Attribute #15593)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-b95c-42f0-ab69-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-b95c-42f0-ab69-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mg-mail-yahoo.us</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-dadc-4b51-963d-07298e96ca05" timestamp="2018-01-16T16:34:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: files-mail-qq.online (MISP Attribute #15594)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: files-mail-qq.online (MISP Attribute #15594)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-dadc-4b51-963d-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-dadc-4b51-963d-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">files-mail-qq.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-0718-42ca-a7e2-07298e96ca05" timestamp="2018-01-16T16:34:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mydrive-google.asia (MISP Attribute #15595)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mydrive-google.asia (MISP Attribute #15595)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-0718-42ca-a7e2-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-0718-42ca-a7e2-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mydrive-google.asia</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-4e2c-43dc-b683-07298e96ca05" timestamp="2018-01-16T16:34:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drivegoogle.biz (MISP Attribute #15596)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drivegoogle.biz (MISP Attribute #15596)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-4e2c-43dc-b683-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-4e2c-43dc-b683-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drivegoogle.biz</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-5284-467a-af2a-07298e96ca05" timestamp="2018-01-16T16:34:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: myaccounts-google.online (MISP Attribute #15597)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: myaccounts-google.online (MISP Attribute #15597)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-5284-467a-af2a-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-5284-467a-af2a-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">myaccounts-google.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58f90cf2-98f0-4a03-a482-53928e96ca05" timestamp="2017-04-20T15:33:06+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-gooog1e.info (MISP Attribute #15853)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-gooog1e.info (MISP Attribute #15853)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58f90cf2-98f0-4a03-a482-53928e96ca05">
<cybox:Object id=":DomainName-58f90cf2-98f0-4a03-a482-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-gooog1e.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-20T15:33:06+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-56a4-4e03-ad12-07298e96ca05" timestamp="2018-01-16T16:34:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-qq.online (MISP Attribute #15598)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-qq.online (MISP Attribute #15598)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-56a4-4e03-ad12-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-56a4-4e03-ad12-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-qq.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-90d4-4f92-a61e-07298e96ca05" timestamp="2018-01-16T16:34:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mydrive-google.online (MISP Attribute #15599)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mydrive-google.online (MISP Attribute #15599)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-90d4-4f92-a61e-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-90d4-4f92-a61e-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mydrive-google.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58f9103e-e3a0-419f-80b8-5d828e96ca05" timestamp="2017-04-20T15:47:10+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-protect.space (MISP Attribute #15855)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-protect.space (MISP Attribute #15855)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58f9103e-e3a0-419f-80b8-5d828e96ca05">
<cybox:Object id=":DomainName-58f9103e-e3a0-419f-80b8-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-protect.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-20T15:47:10+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-3fb4-4ae1-9474-07298e96ca05" timestamp="2018-01-16T16:34:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: myaccounts-google.info (MISP Attribute #15600)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: myaccounts-google.info (MISP Attribute #15600)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-3fb4-4ae1-9474-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-3fb4-4ae1-9474-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">myaccounts-google.info</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-ead0-4eae-891e-07298e96ca05" timestamp="2018-01-16T16:34:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-mail-google.cf (MISP Attribute #15601)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-mail-google.cf (MISP Attribute #15601)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-ead0-4eae-891e-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-ead0-4eae-891e-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-mail-google.cf</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-3504-44a3-9617-07298e96ca05" timestamp="2018-01-16T16:34:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-accounts-google.online (MISP Attribute #15602)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-accounts-google.online (MISP Attribute #15602)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-3504-44a3-9617-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-3504-44a3-9617-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-accounts-google.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-0730-4b97-aeba-07298e96ca05" timestamp="2018-01-16T16:34:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsdrive-google.space (MISP Attribute #15603)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsdrive-google.space (MISP Attribute #15603)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-0730-4b97-aeba-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-0730-4b97-aeba-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsdrive-google.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-8410-4810-ac33-07298e96ca05" timestamp="2018-01-16T16:34:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsmail-google.ml (MISP Attribute #15604)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsmail-google.ml (MISP Attribute #15604)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-8410-4810-ac33-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-8410-4810-ac33-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsmail-google.ml</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-c228-40b2-b26f-07298e96ca05" timestamp="2018-01-16T16:34:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-accounts-gooogle.com (MISP Attribute #15605)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-accounts-gooogle.com (MISP Attribute #15605)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-c228-40b2-b26f-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-c228-40b2-b26f-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-accounts-gooogle.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-db48-45a2-b841-07298e96ca05" timestamp="2018-01-16T16:34:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https-myaccounts-google.space (MISP Attribute #15606)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: https-myaccounts-google.space (MISP Attribute #15606)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-db48-45a2-b841-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-db48-45a2-b841-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">https-myaccounts-google.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-5f50-470e-b879-07298e96ca05" timestamp="2018-01-16T16:34:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-mail-google.com (MISP Attribute #15608)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-mail-google.com (MISP Attribute #15608)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-5f50-470e-b879-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-5f50-470e-b879-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-mail-google.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-b2a4-4870-8b10-07298e96ca05" timestamp="2018-01-16T16:34:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https-drive-google.gq (MISP Attribute #15609)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: https-drive-google.gq (MISP Attribute #15609)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-b2a4-4870-8b10-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-b2a4-4870-8b10-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">https-drive-google.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58fe51b3-ae50-45a7-ab7f-53928e96ca05" timestamp="2017-04-24T15:27:47+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: email-163.space (MISP Attribute #15865)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: email-163.space (MISP Attribute #15865)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58fe51b3-ae50-45a7-ab7f-53928e96ca05">
<cybox:Object id=":DomainName-58fe51b3-ae50-45a7-ab7f-53928e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">email-163.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-24T15:27:47+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58fe5290-6718-4a5b-9ec2-5d828e96ca05" timestamp="2017-04-24T15:31:28+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: drive-gooog1e.space (MISP Attribute #15866)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: drive-gooog1e.space (MISP Attribute #15866)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58fe5290-6718-4a5b-9ec2-5d828e96ca05">
<cybox:Object id=":DomainName-58fe5290-6718-4a5b-9ec2-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">drive-gooog1e.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-24T15:31:28+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-3948-484b-8f15-07298e96ca05" timestamp="2018-01-16T16:34:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsdrive-mail-google.gq (MISP Attribute #15612)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsdrive-mail-google.gq (MISP Attribute #15612)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-3948-484b-8f15-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-3948-484b-8f15-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsdrive-mail-google.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-58fe5c42-db88-4f68-a450-5d828e96ca05" timestamp="2017-04-24T16:12:50+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mail-attachment-usercontent.space (MISP Attribute #15868)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mail-attachment-usercontent.space (MISP Attribute #15868)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-58fe5c42-db88-4f68-a450-5d828e96ca05">
<cybox:Object id=":DomainName-58fe5c42-db88-4f68-a450-5d828e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mail-attachment-usercontent.space</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2017-04-24T16:12:50+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e58ea-2fe8-495b-89d6-06de8e96ca05" timestamp="2018-01-16T14:56:26+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: phpinfo.pw (MISP Attribute #17916)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: phpinfo.pw (MISP Attribute #17916)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e58ea-2fe8-495b-89d6-06de8e96ca05">
<cybox:Object id=":DomainName-5a5e58ea-2fe8-495b-89d6-06de8e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">phpinfo.pw</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T14:56:26+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-f124-4da4-b7dc-07298e96ca05" timestamp="2018-01-16T16:34:19+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: myaccounts-google.tk (MISP Attribute #15613)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: myaccounts-google.tk (MISP Attribute #15613)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-f124-4da4-b7dc-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-f124-4da4-b7dc-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">myaccounts-google.tk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:19+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-0d88-4d42-8935-07298e96ca05" timestamp="2018-01-16T16:34:19+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsaccounts-drive-google.gq (MISP Attribute #15614)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsaccounts-drive-google.gq (MISP Attribute #15614)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-0d88-4d42-8935-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-0d88-4d42-8935-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsaccounts-drive-google.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:19+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-587fa322-d888-4b55-bb55-07298e96ca05" timestamp="2018-01-16T16:34:19+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: httpsaccount-google.gq (MISP Attribute #15615)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: httpsaccount-google.gq (MISP Attribute #15615)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-587fa322-d888-4b55-bb55-07298e96ca05">
<cybox:Object id=":DomainName-587fa322-d888-4b55-bb55-07298e96ca05">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">httpsaccount-google.gq</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T16:34:19+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e59b5-fc40-4c1d-8e76-06de8e96ca05" timestamp="2018-01-16T14:59:48+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 104.207.132.165 (MISP Attribute #17917)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 104.207.132.165 (MISP Attribute #17917)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e59b5-fc40-4c1d-8e76-06de8e96ca05">
<cybox:Object id=":Address-5a5e59b5-fc40-4c1d-8e76-06de8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">104.207.132.165</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T14:59:48+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e59b5-adf0-4031-80bb-06de8e96ca05" timestamp="2018-01-16T14:59:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 45.63.0.49 (MISP Attribute #17918)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 45.63.0.49 (MISP Attribute #17918)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e59b5-adf0-4031-80bb-06de8e96ca05">
<cybox:Object id=":Address-5a5e59b5-adf0-4031-80bb-06de8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">45.63.0.49</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T14:59:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e59b5-c328-49e9-9334-06de8e96ca05" timestamp="2018-01-16T14:59:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 115.126.39.107 (MISP Attribute #17919)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 115.126.39.107 (MISP Attribute #17919)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e59b5-c328-49e9-9334-06de8e96ca05">
<cybox:Object id=":Address-5a5e59b5-c328-49e9-9334-06de8e96ca05">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">115.126.39.107</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T14:59:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e59f3-a7b8-403d-8836-06df8e96ca05" timestamp="2018-01-16T15:00:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 8e44755f02e9769c95dd9528ca1f462e (MISP Attribute #17920)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 8e44755f02e9769c95dd9528ca1f462e (MISP Attribute #17920)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e59f3-a7b8-403d-8836-06df8e96ca05">
<cybox:Object id=":File-5a5e59f3-a7b8-403d-8836-06df8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">MD5</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">8e44755f02e9769c95dd9528ca1f462e</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:00:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5a0d-d630-49f5-beab-06df8e96ca05" timestamp="2018-01-16T15:01:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 381f8f812a8609134eff661157d88d32da029af1 (MISP Attribute #17922)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 381f8f812a8609134eff661157d88d32da029af1 (MISP Attribute #17922)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e5a0d-d630-49f5-beab-06df8e96ca05">
<cybox:Object id=":File-5a5e5a0d-d630-49f5-beab-06df8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA1</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">381f8f812a8609134eff661157d88d32da029af1</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:01:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5a5e5a05-dfd4-4771-beff-06df8e96ca05" timestamp="2018-01-16T15:01:09+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 654e952324bddf09ca7b014bfdf79103c643d21d648182f911a65d7c907803b8 (MISP Attribute #17921)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 654e952324bddf09ca7b014bfdf79103c643d21d648182f911a65d7c907803b8 (MISP Attribute #17921)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5a5e5a05-dfd4-4771-beff-06df8e96ca05">
<cybox:Object id=":File-5a5e5a05-dfd4-4771-beff-06df8e96ca05">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">654e952324bddf09ca7b014bfdf79103c643d21d648182f911a65d7c907803b8</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-01-16T15:01:09+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:History>
</incident:History>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>