Files
autarch/data/ioc/spyware/citizen_lab/201909_MissingLink/stix.xml

1624 lines
164 KiB
XML

<stix:STIX_Package
xmlns:cyboxCommon="http://cybox.mitre.org/common-2"
xmlns:cybox="http://cybox.mitre.org/cybox-2"
xmlns:cyboxVocabs="http://cybox.mitre.org/default_vocabularies-2"
xmlns:ASObj="http://cybox.mitre.org/objects#ASObject-1"
xmlns:AddressObj="http://cybox.mitre.org/objects#AddressObject-2"
xmlns:DomainNameObj="http://cybox.mitre.org/objects#DomainNameObject-1"
xmlns:EmailMessageObj="http://cybox.mitre.org/objects#EmailMessageObject-2"
xmlns:FileObj="http://cybox.mitre.org/objects#FileObject-2"
xmlns:HTTPSessionObj="http://cybox.mitre.org/objects#HTTPSessionObject-2"
xmlns:HostnameObj="http://cybox.mitre.org/objects#HostnameObject-1"
xmlns:MutexObj="http://cybox.mitre.org/objects#MutexObject-2"
xmlns:PipeObj="http://cybox.mitre.org/objects#PipeObject-2"
xmlns:URIObj="http://cybox.mitre.org/objects#URIObject-2"
xmlns:WinRegistryKeyObj="http://cybox.mitre.org/objects#WinRegistryKeyObject-2"
xmlns:marking="http://data-marking.mitre.org/Marking-1"
xmlns:tlpMarking="http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1"
xmlns:et="http://stix.mitre.org/ExploitTarget-1"
xmlns:incident="http://stix.mitre.org/Incident-1"
xmlns:indicator="http://stix.mitre.org/Indicator-2"
xmlns:ttp="http://stix.mitre.org/TTP-1"
xmlns:ta="http://stix.mitre.org/ThreatActor-1"
xmlns:stixCommon="http://stix.mitre.org/common-1"
xmlns:stixVocabs="http://stix.mitre.org/default_vocabularies-1"
xmlns:stix-ciqidentity="http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1"
xmlns:snortTM="http://stix.mitre.org/extensions/TestMechanism#Snort-1"
xmlns:stix="http://stix.mitre.org/stix-1"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xmlns:xal="urn:oasis:names:tc:ciq:xal:3"
xmlns:xnl="urn:oasis:names:tc:ciq:xnl:3"
xmlns:xpil="urn:oasis:names:tc:ciq:xpil:3"
xsi:schemaLocation="
http://cybox.mitre.org/common-2 http://cybox.mitre.org/XMLSchema/common/2.1/cybox_common.xsd
http://cybox.mitre.org/cybox-2 http://cybox.mitre.org/XMLSchema/core/2.1/cybox_core.xsd
http://cybox.mitre.org/default_vocabularies-2 http://cybox.mitre.org/XMLSchema/default_vocabularies/2.1/cybox_default_vocabularies.xsd
http://cybox.mitre.org/objects#ASObject-1 http://cybox.mitre.org/XMLSchema/objects/AS/1.0/AS_Object.xsd
http://cybox.mitre.org/objects#AddressObject-2 http://cybox.mitre.org/XMLSchema/objects/Address/2.1/Address_Object.xsd
http://cybox.mitre.org/objects#DomainNameObject-1 http://cybox.mitre.org/XMLSchema/objects/Domain_Name/1.0/Domain_Name_Object.xsd
http://cybox.mitre.org/objects#EmailMessageObject-2 http://cybox.mitre.org/XMLSchema/objects/Email_Message/2.1/Email_Message_Object.xsd
http://cybox.mitre.org/objects#FileObject-2 http://cybox.mitre.org/XMLSchema/objects/File/2.1/File_Object.xsd
http://cybox.mitre.org/objects#HTTPSessionObject-2 http://cybox.mitre.org/XMLSchema/objects/HTTP_Session/2.1/HTTP_Session_Object.xsd
http://cybox.mitre.org/objects#HostnameObject-1 http://cybox.mitre.org/XMLSchema/objects/Hostname/1.0/Hostname_Object.xsd
http://cybox.mitre.org/objects#MutexObject-2 http://cybox.mitre.org/XMLSchema/objects/Mutex/2.1/Mutex_Object.xsd
http://cybox.mitre.org/objects#PipeObject-2 http://cybox.mitre.org/XMLSchema/objects/Pipe/2.1/Pipe_Object.xsd
http://cybox.mitre.org/objects#URIObject-2 http://cybox.mitre.org/XMLSchema/objects/URI/2.1/URI_Object.xsd
http://cybox.mitre.org/objects#WinRegistryKeyObject-2 http://cybox.mitre.org/XMLSchema/objects/Win_Registry_Key/2.1/Win_Registry_Key_Object.xsd
http://data-marking.mitre.org/Marking-1 http://stix.mitre.org/XMLSchema/data_marking/1.1.1/data_marking.xsd
http://data-marking.mitre.org/extensions/MarkingStructure#TLP-1 http://stix.mitre.org/XMLSchema/extensions/marking/tlp/1.1.1/tlp_marking.xsd
http://stix.mitre.org/ExploitTarget-1 http://stix.mitre.org/XMLSchema/exploit_target/1.1.1/exploit_target.xsd
http://stix.mitre.org/Incident-1 http://stix.mitre.org/XMLSchema/incident/1.1.1/incident.xsd
http://stix.mitre.org/Indicator-2 http://stix.mitre.org/XMLSchema/indicator/2.1.1/indicator.xsd
http://stix.mitre.org/TTP-1 http://stix.mitre.org/XMLSchema/ttp/1.1.1/ttp.xsd
http://stix.mitre.org/ThreatActor-1 http://stix.mitre.org/XMLSchema/threat_actor/1.1.1/threat_actor.xsd
http://stix.mitre.org/common-1 http://stix.mitre.org/XMLSchema/common/1.1.1/stix_common.xsd
http://stix.mitre.org/default_vocabularies-1 http://stix.mitre.org/XMLSchema/default_vocabularies/1.1.1/stix_default_vocabularies.xsd
http://stix.mitre.org/extensions/Identity#CIQIdentity3.0-1 http://stix.mitre.org/XMLSchema/extensions/identity/ciq_3.0/1.1.1/ciq_3.0_identity.xsd
http://stix.mitre.org/extensions/TestMechanism#Snort-1 http://stix.mitre.org/XMLSchema/extensions/test_mechanism/snort/1.1.1/snort_test_mechanism.xsd
http://stix.mitre.org/stix-1 http://stix.mitre.org/XMLSchema/core/1.1.1/stix_core.xsd
urn:oasis:names:tc:ciq:xal:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xAL.xsd
urn:oasis:names:tc:ciq:xnl:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xNL.xsd
urn:oasis:names:tc:ciq:xpil:3 http://stix.mitre.org/XMLSchema/external/oasis_ciq_3.0/xPIL.xsd" id=":Package-99639f7e-a3dc-4663-9482-b63821367e3b" version="1.1.1" timestamp="2019-09-23T20:39:45.654572+00:00">
<stix:STIX_Header>
<stix:Title>Export from MISP</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Related_Packages>
<stix:Related_Package>
<stix:Package id=":STIXPackage-5bec8d43-b990-4129-a9f4-45d08064ab0b" version="1.1.1" timestamp="2019-09-23T16:38:32+00:00">
<stix:STIX_Header>
<stix:Title>MISSING LINK: Tibetan Groups Targeted with Mobile Exploits (MISP Event #140)</stix:Title>
<stix:Package_Intent xsi:type="stixVocabs:PackageIntentVocab-1.0">Threat Report</stix:Package_Intent>
</stix:STIX_Header>
<stix:Incidents>
<stix:Incident id=":incident-5bec8d43-b990-4129-a9f4-45d08064ab0b" timestamp="2019-09-23T16:39:10+00:00" xsi:type='incident:IncidentType'>
<incident:Title>MISSING LINK: Tibetan Groups Targeted with Mobile Exploits</incident:Title>
<incident:External_ID source="MISP Event">140</incident:External_ID>
<incident:Time>
<incident:Incident_Discovery precision="second">2019-09-24T00:00:00+00:00</incident:Incident_Discovery>
<incident:Incident_Reported precision="second">2019-09-23T16:39:10+00:00</incident:Incident_Reported>
</incident:Time>
<incident:Status xsi:type="stixVocabs:IncidentStatusVocab-1.0">Open</incident:Status>
<incident:Related_Indicators>
<incident:Related_Indicator>
<stixCommon:Relationship>Artifacts dropped</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76dfaf-574c-4253-b1f1-67578064ab0b" timestamp="2019-09-09T19:33:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Artifacts dropped: 0d2ee9ade24163613772fdda201af985d852ab506e3d3e7f07fb3fa8b0853560 (MISP Attribute #18567)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Artifacts dropped: 0d2ee9ade24163613772fdda201af985d852ab506e3d3e7f07fb3fa8b0853560 (MISP Attribute #18567)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76dfaf-574c-4253-b1f1-67578064ab0b">
<cybox:Object id=":File-5d76dfaf-574c-4253-b1f1-67578064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">0d2ee9ade24163613772fdda201af985d852ab506e3d3e7f07fb3fa8b0853560</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T19:33:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c9b2-8b24-4fb2-8ff3-61dc8064ab0b" timestamp="2019-09-09T17:52:50+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: dashenqu832@outlook.com (MISP Attribute #18558)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: dashenqu832@outlook.com (MISP Attribute #18558)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2019-09-09T17:52:50+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Attribution</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c9b2-5654-4b42-a28f-61dc8064ab0b" timestamp="2019-09-09T17:52:50+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Attribution: ornaments798@outlook.com (MISP Attribute #18559)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Attribution: ornaments798@outlook.com (MISP Attribute #18559)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Confidence timestamp="2019-09-09T17:52:50+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c70f-df94-4cd0-b977-4cea8064ab0b" timestamp="2019-09-09T19:33:59+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.energy-mail.org (MISP Attribute #18542)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.energy-mail.org (MISP Attribute #18542)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c70f-df94-4cd0-b977-4cea8064ab0b">
<cybox:Object id=":DomainName-5d76c70f-df94-4cd0-b977-4cea8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.energy-mail.org</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T19:33:59+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c98c-95a0-4186-9d08-61de8064ab0b" timestamp="2019-09-09T17:52:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: antmoving.online (MISP Attribute #18546)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: antmoving.online (MISP Attribute #18546)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c98c-95a0-4186-9d08-61de8064ab0b">
<cybox:Object id=":DomainName-5d76c98c-95a0-4186-9d08-61de8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">antmoving.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:52:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c98c-be94-4716-9cc3-61de8064ab0b" timestamp="2019-09-09T17:52:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: beemail.online (MISP Attribute #18547)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: beemail.online (MISP Attribute #18547)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c98c-be94-4716-9cc3-61de8064ab0b">
<cybox:Object id=":DomainName-5d76c98c-be94-4716-9cc3-61de8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">beemail.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:52:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c98c-0998-4c3d-94fa-61de8064ab0b" timestamp="2019-09-09T17:52:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: bf.mk (MISP Attribute #18548)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: bf.mk (MISP Attribute #18548)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c98c-0998-4c3d-94fa-61de8064ab0b">
<cybox:Object id=":DomainName-5d76c98c-0998-4c3d-94fa-61de8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">bf.mk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:52:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c98c-77cc-4a32-b989-61de8064ab0b" timestamp="2019-09-09T17:52:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: energy-mail.org (MISP Attribute #18549)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: energy-mail.org (MISP Attribute #18549)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c98c-77cc-4a32-b989-61de8064ab0b">
<cybox:Object id=":DomainName-5d76c98c-77cc-4a32-b989-61de8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">energy-mail.org</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:52:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c98c-a620-4e86-969b-61de8064ab0b" timestamp="2019-09-09T17:52:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: gmailapp.me (MISP Attribute #18550)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: gmailapp.me (MISP Attribute #18550)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c98c-a620-4e86-969b-61de8064ab0b">
<cybox:Object id=":DomainName-5d76c98c-a620-4e86-969b-61de8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">gmailapp.me</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:52:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c98c-8960-4e6c-be1c-61de8064ab0b" timestamp="2019-09-09T17:52:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: izelense.com (MISP Attribute #18551)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: izelense.com (MISP Attribute #18551)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c98c-8960-4e6c-be1c-61de8064ab0b">
<cybox:Object id=":DomainName-5d76c98c-8960-4e6c-be1c-61de8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">izelense.com</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:52:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c98c-52b4-4bb9-b61b-61de8064ab0b" timestamp="2019-09-09T17:52:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mailanalysis.services (MISP Attribute #18552)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mailanalysis.services (MISP Attribute #18552)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c98c-52b4-4bb9-b61b-61de8064ab0b">
<cybox:Object id=":DomainName-5d76c98c-52b4-4bb9-b61b-61de8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mailanalysis.services</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:52:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c98c-1b78-4933-98f8-61de8064ab0b" timestamp="2019-09-09T17:52:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mailcontactanalysis.online (MISP Attribute #18553)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mailcontactanalysis.online (MISP Attribute #18553)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c98c-1b78-4933-98f8-61de8064ab0b">
<cybox:Object id=":DomainName-5d76c98c-1b78-4933-98f8-61de8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mailcontactanalysis.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:52:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c98c-3358-4897-a52b-61de8064ab0b" timestamp="2019-09-09T17:52:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: mailnotes.online (MISP Attribute #18554)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: mailnotes.online (MISP Attribute #18554)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c98c-3358-4897-a52b-61de8064ab0b">
<cybox:Object id=":DomainName-5d76c98c-3358-4897-a52b-61de8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">mailnotes.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:52:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c98c-6be4-4b4a-9a37-61de8064ab0b" timestamp="2019-09-09T17:52:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: polarismail.services (MISP Attribute #18555)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: polarismail.services (MISP Attribute #18555)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c98c-6be4-4b4a-9a37-61de8064ab0b">
<cybox:Object id=":DomainName-5d76c98c-6be4-4b4a-9a37-61de8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">polarismail.services</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:52:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c98c-0cb4-4be5-b3d6-61de8064ab0b" timestamp="2019-09-09T17:52:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: rf.mk (MISP Attribute #18556)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: rf.mk (MISP Attribute #18556)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c98c-0cb4-4be5-b3d6-61de8064ab0b">
<cybox:Object id=":DomainName-5d76c98c-0cb4-4be5-b3d6-61de8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">rf.mk</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:52:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c98c-f230-436d-a69f-61de8064ab0b" timestamp="2019-09-09T17:52:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: walkingnote.online (MISP Attribute #18557)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: walkingnote.online (MISP Attribute #18557)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c98c-f230-436d-a69f-61de8064ab0b">
<cybox:Object id=":DomainName-5d76c98c-f230-436d-a69f-61de8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">walkingnote.online</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:52:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5bec8d6d-71e0-40b6-add8-171c8064ab0b" timestamp="2018-11-14T16:02:55+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: www.msap.services (MISP Attribute #18406)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: www.msap.services (MISP Attribute #18406)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5bec8d6d-71e0-40b6-add8-171c8064ab0b">
<cybox:Object id=":DomainName-5bec8d6d-71e0-40b6-add8-171c8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">www.msap.services</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-11-14T16:02:55+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5bec8d6d-6cc8-4aef-b8c9-171c8064ab0b" timestamp="2018-11-14T16:02:58+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: msap.services (MISP Attribute #18407)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Domain Watchlist</indicator:Type>
<indicator:Description>Network activity: msap.services (MISP Attribute #18407)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5bec8d6d-6cc8-4aef-b8c9-171c8064ab0b">
<cybox:Object id=":DomainName-5bec8d6d-6cc8-4aef-b8c9-171c8064ab0b">
<cybox:Properties xsi:type="DomainNameObj:DomainNameObjectType">
<DomainNameObj:Value condition="Equals">msap.services</DomainNameObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-11-14T16:02:58+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c7a0-2dac-4e65-a0ca-67208064ab0b" timestamp="2019-09-09T17:44:00+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 45.32.75.217 (MISP Attribute #18544)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 45.32.75.217 (MISP Attribute #18544)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c7a0-2dac-4e65-a0ca-67208064ab0b">
<cybox:Object id=":Address-5d76c7a0-2dac-4e65-a0ca-67208064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">45.32.75.217</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:44:00+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c7a0-3c28-4110-aa88-67208064ab0b" timestamp="2019-09-20T17:39:17+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 45.76.149.154 (MISP Attribute #18545)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 45.76.149.154 (MISP Attribute #18545)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c7a0-3c28-4110-aa88-67208064ab0b">
<cybox:Object id=":Address-5d76c7a0-3c28-4110-aa88-67208064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">45.76.149.154</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-20T17:39:17+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76cc33-7aac-4eb8-a1be-66c48064ab0b" timestamp="2019-09-09T19:34:08+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 45.78.79.100 (MISP Attribute #18560)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 45.78.79.100 (MISP Attribute #18560)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76cc33-7aac-4eb8-a1be-66c48064ab0b">
<cybox:Object id=":Address-5d76cc33-7aac-4eb8-a1be-66c48064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">45.78.79.100</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T19:34:08+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76cf56-94f8-4a16-84d5-67af8064ab0b" timestamp="2019-09-09T18:16:54+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 149.28.93.11 (MISP Attribute #18561)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 149.28.93.11 (MISP Attribute #18561)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76cf56-94f8-4a16-84d5-67af8064ab0b">
<cybox:Object id=":Address-5d76cf56-94f8-4a16-84d5-67af8064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">149.28.93.11</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T18:16:54+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76d19b-0704-42fa-95c5-61df8064ab0b" timestamp="2019-09-09T19:34:47+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 95.169.2.57 (MISP Attribute #18562)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 95.169.2.57 (MISP Attribute #18562)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76d19b-0704-42fa-95c5-61df8064ab0b">
<cybox:Object id=":Address-5d76d19b-0704-42fa-95c5-61df8064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">95.169.2.57</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T19:34:47+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76d6f2-f44c-4b21-ba2d-67578064ab0b" timestamp="2019-09-09T18:49:22+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 206.189.65.198 (MISP Attribute #18563)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 206.189.65.198 (MISP Attribute #18563)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76d6f2-f44c-4b21-ba2d-67578064ab0b">
<cybox:Object id=":Address-5d76d6f2-f44c-4b21-ba2d-67578064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">206.189.65.198</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T18:49:22+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76dae6-bdc4-4cca-8161-61de8064ab0b" timestamp="2019-09-09T19:06:14+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 140.82.17.222 (MISP Attribute #18564)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 140.82.17.222 (MISP Attribute #18564)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76dae6-bdc4-4cca-8161-61de8064ab0b">
<cybox:Object id=":Address-5d76dae6-bdc4-4cca-8161-61de8064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">140.82.17.222</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T19:06:14+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76dcf6-f094-47a0-8fd4-4cea8064ab0b" timestamp="2019-09-09T19:35:01+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 45.76.53.26 (MISP Attribute #18565)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 45.76.53.26 (MISP Attribute #18565)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76dcf6-f094-47a0-8fd4-4cea8064ab0b">
<cybox:Object id=":Address-5d76dcf6-f094-47a0-8fd4-4cea8064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">45.76.53.26</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T19:35:01+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76de15-2544-4f39-baed-61db8064ab0b" timestamp="2019-09-09T19:19:49+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 45.32.91.137 (MISP Attribute #18566)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 45.32.91.137 (MISP Attribute #18566)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76de15-2544-4f39-baed-61db8064ab0b">
<cybox:Object id=":Address-5d76de15-2544-4f39-baed-61db8064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">45.32.91.137</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T19:19:49+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5bec8d7b-b658-4050-8b3c-45cc8064ab0b" timestamp="2019-09-20T17:41:18+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 144.202.59.23 (MISP Attribute #18408)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 144.202.59.23 (MISP Attribute #18408)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5bec8d7b-b658-4050-8b3c-45cc8064ab0b">
<cybox:Object id=":Address-5bec8d7b-b658-4050-8b3c-45cc8064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">144.202.59.23</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-20T17:41:18+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5bed8343-d968-4c72-a106-2b328064ab0b" timestamp="2019-09-20T17:40:08+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 66.42.58.59 (MISP Attribute #18410)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 66.42.58.59 (MISP Attribute #18410)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5bed8343-d968-4c72-a106-2b328064ab0b">
<cybox:Object id=":Address-5bed8343-d968-4c72-a106-2b328064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">66.42.58.59</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-20T17:40:08+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5bed84bf-8710-4cba-b9eb-05688064ab0b" timestamp="2018-11-15T09:37:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: 43.251.16.87 (MISP Attribute #18411)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">IP Watchlist</indicator:Type>
<indicator:Description>Network activity: 43.251.16.87 (MISP Attribute #18411)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5bed84bf-8710-4cba-b9eb-05688064ab0b">
<cybox:Object id=":Address-5bed84bf-8710-4cba-b9eb-05688064ab0b">
<cybox:Properties xsi:type="AddressObj:AddressObjectType" category="ipv4-addr" is_source="false">
<AddressObj:Address_Value condition="Equals">43.251.16.87</AddressObj:Address_Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2018-11-15T09:37:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-b878-442a-b476-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://bit.ly/2z1WayM (MISP Attribute #18511)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://bit.ly/2z1WayM (MISP Attribute #18511)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-b878-442a-b476-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-b878-442a-b476-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://bit.ly/2z1WayM</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-b644-45e2-a9d7-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://www.msap.services/1R7mqD (MISP Attribute #18512)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://www.msap.services/1R7mqD (MISP Attribute #18512)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-b644-45e2-a9d7-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-b644-45e2-a9d7-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://www.msap.services/1R7mqD</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-14c4-4b77-85be-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://bit.ly/2AYy61a (MISP Attribute #18513)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://bit.ly/2AYy61a (MISP Attribute #18513)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-14c4-4b77-85be-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-14c4-4b77-85be-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://bit.ly/2AYy61a</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-f8f0-4399-a2ae-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http//www.msap.services/2bKr8Z (MISP Attribute #18514)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http//www.msap.services/2bKr8Z (MISP Attribute #18514)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-f8f0-4399-a2ae-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-f8f0-4399-a2ae-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http//www.msap.services/2bKr8Z</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-a174-4130-a62c-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://www.msap.services/6FeBOy (MISP Attribute #18515)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://www.msap.services/6FeBOy (MISP Attribute #18515)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-a174-4130-a62c-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-a174-4130-a62c-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://www.msap.services/6FeBOy</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-ce00-497f-9284-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://suo.im/5ot25j (MISP Attribute #18516)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://suo.im/5ot25j (MISP Attribute #18516)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-ce00-497f-9284-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-ce00-497f-9284-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://suo.im/5ot25j</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-1708-4847-8b18-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://news.cmitcsubs.tk:5000/web/info?org=aHR0cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MUlTakl2eFoxX1g5YkdJSnQtMlpKeDRDRWwzdVVhRmlv (MISP Attribute #18517)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://news.cmitcsubs.tk:5000/web/info?org=aHR0cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MUlTakl2eFoxX1g5YkdJSnQtMlpKeDRDRWwzdVVhRmlv (MISP Attribute #18517)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-1708-4847-8b18-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-1708-4847-8b18-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://news.cmitcsubs.tk:5000/web/info?org=aHR0cHM6Ly9kcml2ZS5nb29nbGUuY29tL29wZW4/aWQ9MUlTakl2eFoxX1g5YkdJSnQtMlpKeDRDRWwzdVVhRmlv</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-bb64-4b8d-b773-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://www.msap.services/yHJbS6 (MISP Attribute #18518)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://www.msap.services/yHJbS6 (MISP Attribute #18518)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-bb64-4b8d-b773-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-bb64-4b8d-b773-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://www.msap.services/yHJbS6</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-d218-49a3-96f3-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://bit.ly/2qHg3Xt (MISP Attribute #18519)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://bit.ly/2qHg3Xt (MISP Attribute #18519)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-d218-49a3-96f3-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-d218-49a3-96f3-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://bit.ly/2qHg3Xt</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-0658-494c-afb4-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://www.msap.services/S5gDoN (MISP Attribute #18520)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://www.msap.services/S5gDoN (MISP Attribute #18520)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-0658-494c-afb4-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-0658-494c-afb4-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://www.msap.services/S5gDoN</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-8624-44df-8338-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://bit.ly/2T2CoeX (MISP Attribute #18521)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://bit.ly/2T2CoeX (MISP Attribute #18521)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-8624-44df-8338-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-8624-44df-8338-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://bit.ly/2T2CoeX</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-1170-4f0e-ade3-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://www.msap.services/EzpOhU (MISP Attribute #18522)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://www.msap.services/EzpOhU (MISP Attribute #18522)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-1170-4f0e-ade3-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-1170-4f0e-ade3-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://www.msap.services/EzpOhU</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-578c-4a96-88fe-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://bit.ly/2PSvdau (MISP Attribute #18523)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://bit.ly/2PSvdau (MISP Attribute #18523)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-578c-4a96-88fe-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-578c-4a96-88fe-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://bit.ly/2PSvdau</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-7058-403d-a9b1-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://www.msap.services/GfHuRi (MISP Attribute #18524)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://www.msap.services/GfHuRi (MISP Attribute #18524)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-7058-403d-a9b1-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-7058-403d-a9b1-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://www.msap.services/GfHuRi</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-5824-4b00-8dda-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://suo.im/5okeFb (MISP Attribute #18525)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://suo.im/5okeFb (MISP Attribute #18525)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-5824-4b00-8dda-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-5824-4b00-8dda-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://suo.im/5okeFb</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-b8ec-438c-8161-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://news.cmitcsubs.tk:5000/web/info?org=aHR0cHM6Ly93d3cubnl0aW1lcy5jb20vMjAxOC8xMS8wMi9vYml0dWFyaWVzL2xvZGktZ3lhcmktZGVhZC5odG1s (MISP Attribute #18526)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://news.cmitcsubs.tk:5000/web/info?org=aHR0cHM6Ly93d3cubnl0aW1lcy5jb20vMjAxOC8xMS8wMi9vYml0dWFyaWVzL2xvZGktZ3lhcmktZGVhZC5odG1s (MISP Attribute #18526)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-b8ec-438c-8161-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-b8ec-438c-8161-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://news.cmitcsubs.tk:5000/web/info?org=aHR0cHM6Ly93d3cubnl0aW1lcy5jb20vMjAxOC8xMS8wMi9vYml0dWFyaWVzL2xvZGktZ3lhcmktZGVhZC5odG1s</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-a530-4671-8fab-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://bit.ly/2SVPqdY (MISP Attribute #18527)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://bit.ly/2SVPqdY (MISP Attribute #18527)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-a530-4671-8fab-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-a530-4671-8fab-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://bit.ly/2SVPqdY</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-bd08-4528-9fab-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://www.msap.services/F8XGNe (MISP Attribute #18528)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://www.msap.services/F8XGNe (MISP Attribute #18528)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-bd08-4528-9fab-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-bd08-4528-9fab-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://www.msap.services/F8XGNe</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-936c-411b-a0c9-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://bit.ly/2QroNMt (MISP Attribute #18529)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://bit.ly/2QroNMt (MISP Attribute #18529)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-936c-411b-a0c9-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-936c-411b-a0c9-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://bit.ly/2QroNMt</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-2f9c-40b2-8cd5-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://www.msap.services/70FtQX (MISP Attribute #18530)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://www.msap.services/70FtQX (MISP Attribute #18530)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-2f9c-40b2-8cd5-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-2f9c-40b2-8cd5-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://www.msap.services/70FtQX</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-2150-4f97-80c4-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://msap.services/yHJbS6 (MISP Attribute #18531)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://msap.services/yHJbS6 (MISP Attribute #18531)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-2150-4f97-80c4-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-2150-4f97-80c4-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://msap.services/yHJbS6</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-0d28-4b27-9ac6-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://bit.ly/2B4GwEf (MISP Attribute #18532)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://bit.ly/2B4GwEf (MISP Attribute #18532)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-0d28-4b27-9ac6-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-0d28-4b27-9ac6-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://bit.ly/2B4GwEf</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d3-8604-4125-b369-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://www.msap.services/XgL5A9 (MISP Attribute #18533)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://www.msap.services/XgL5A9 (MISP Attribute #18533)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d3-8604-4125-b369-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d3-8604-4125-b369-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://www.msap.services/XgL5A9</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d4-7398-45b0-b5e9-61de8064ab0b" timestamp="2019-09-09T17:40:35+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://bit.ly/2T6pCMf (MISP Attribute #18534)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://bit.ly/2T6pCMf (MISP Attribute #18534)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d4-7398-45b0-b5e9-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d4-7398-45b0-b5e9-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://bit.ly/2T6pCMf</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:35+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d4-0854-4d51-8fb7-61de8064ab0b" timestamp="2019-09-09T17:40:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://www.msap.services/ZpzstM (MISP Attribute #18535)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://www.msap.services/ZpzstM (MISP Attribute #18535)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d4-0854-4d51-8fb7-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d4-0854-4d51-8fb7-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://www.msap.services/ZpzstM</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d4-2fb8-46f2-a589-61de8064ab0b" timestamp="2019-09-09T17:40:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://bit.ly/2Drl90q (MISP Attribute #18536)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://bit.ly/2Drl90q (MISP Attribute #18536)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d4-2fb8-46f2-a589-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d4-2fb8-46f2-a589-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://bit.ly/2Drl90q</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d4-12f0-4f58-9a9b-61de8064ab0b" timestamp="2019-09-09T17:40:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://www.msap.services/ZQfqzs (MISP Attribute #18537)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://www.msap.services/ZQfqzs (MISP Attribute #18537)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d4-12f0-4f58-9a9b-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d4-12f0-4f58-9a9b-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://www.msap.services/ZQfqzs</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d4-c2a8-4ee3-bf3d-61de8064ab0b" timestamp="2019-09-09T17:40:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https://bit.ly/2MgSRwL (MISP Attribute #18538)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: https://bit.ly/2MgSRwL (MISP Attribute #18538)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d4-c2a8-4ee3-bf3d-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d4-c2a8-4ee3-bf3d-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://bit.ly/2MgSRwL</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d4-52b4-413f-bf04-61de8064ab0b" timestamp="2019-09-09T17:40:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https://www.energy-mail.org/B20V54 (MISP Attribute #18539)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: https://www.energy-mail.org/B20V54 (MISP Attribute #18539)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d4-52b4-413f-bf04-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d4-52b4-413f-bf04-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://www.energy-mail.org/B20V54</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d4-dde0-484e-ac13-61de8064ab0b" timestamp="2019-09-09T17:40:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: https://bit.ly/2XePmYt (MISP Attribute #18540)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: https://bit.ly/2XePmYt (MISP Attribute #18540)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d4-dde0-484e-ac13-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d4-dde0-484e-ac13-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">https://bit.ly/2XePmYt</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c6d4-3b64-4591-b0df-61de8064ab0b" timestamp="2019-09-09T17:40:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://45.76.149.154:5000/web/info?org=aHR0cDovL3d3dy5waGF5dWwuY29tL25ld3MvYXJ0aWNsZS5hc3B4P2lkPTQxNDc0JmZiY2xpZD1Jd0FSM1RadGdjanppUkhNZFJuOEdhZ1RMUV9iMHFrX0VBZWY2YldxRU5SanhaZkkzRFdPNFpsRExPcFdz (MISP Attribute #18541)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://45.76.149.154:5000/web/info?org=aHR0cDovL3d3dy5waGF5dWwuY29tL25ld3MvYXJ0aWNsZS5hc3B4P2lkPTQxNDc0JmZiY2xpZD1Jd0FSM1RadGdjanppUkhNZFJuOEdhZ1RMUV9iMHFrX0VBZWY2YldxRU5SanhaZkkzRFdPNFpsRExPcFdz (MISP Attribute #18541)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c6d4-3b64-4591-b0df-61de8064ab0b">
<cybox:Object id=":URI-5d76c6d4-3b64-4591-b0df-61de8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://45.76.149.154:5000/web/info?org=aHR0cDovL3d3dy5waGF5dWwuY29tL25ld3MvYXJ0aWNsZS5hc3B4P2lkPTQxNDc0JmZiY2xpZD1Jd0FSM1RadGdjanppUkhNZFJuOEdhZ1RMUV9iMHFrX0VBZWY2YldxRU5SanhaZkkzRFdPNFpsRExPcFdz</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:40:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76c730-b4c0-4746-af7e-61db8064ab0b" timestamp="2019-09-09T17:42:08+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: http://43.251.16.87:5000//dev/loader (MISP Attribute #18543)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">URL Watchlist</indicator:Type>
<indicator:Description>Network activity: http://43.251.16.87:5000//dev/loader (MISP Attribute #18543)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76c730-b4c0-4746-af7e-61db8064ab0b">
<cybox:Object id=":URI-5d76c730-b4c0-4746-af7e-61db8064ab0b">
<cybox:Properties xsi:type="URIObj:URIObjectType">
<URIObj:Value condition="Equals">http://43.251.16.87:5000//dev/loader</URIObj:Value>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T17:42:08+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Network activity</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d892cd4-fba0-4c21-90d9-0b328064ab0b" timestamp="2019-09-23T16:36:36+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Network activity: hots scot (MISP Attribute #18576)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Description>Network activity: hots scot (MISP Attribute #18576)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d892cd4-fba0-4c21-90d9-0b328064ab0b">
<cybox:Object id=":HTTPSession-5d892cd4-fba0-4c21-90d9-0b328064ab0b">
<cybox:Properties xsi:type="HTTPSessionObj:HTTPSessionObjectType">
<HTTPSessionObj:HTTP_Request_Response>
<HTTPSessionObj:HTTP_Client_Request>
<HTTPSessionObj:HTTP_Request_Header>
<HTTPSessionObj:Parsed_Header>
<HTTPSessionObj:User_Agent>hots scot</HTTPSessionObj:User_Agent>
</HTTPSessionObj:Parsed_Header>
</HTTPSessionObj:HTTP_Request_Header>
</HTTPSessionObj:HTTP_Client_Request>
</HTTPSessionObj:HTTP_Request_Response>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-23T16:36:36+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">High</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76e2eb-abe8-44bb-8dbf-67578064ab0b" timestamp="2019-09-09T19:40:27+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: antmoving.online@gmail.com (MISP Attribute #18568)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: antmoving.online@gmail.com (MISP Attribute #18568)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76e2eb-abe8-44bb-8dbf-67578064ab0b">
<cybox:Object id=":EmailMessage-5d76e2eb-abe8-44bb-8dbf-67578064ab0b">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">antmoving.online@gmail.com</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T19:40:27+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76e2eb-df2c-4913-b458-67578064ab0b" timestamp="2019-09-09T19:40:27+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: energymail.org@gmail.com (MISP Attribute #18569)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: energymail.org@gmail.com (MISP Attribute #18569)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76e2eb-df2c-4913-b458-67578064ab0b">
<cybox:Object id=":EmailMessage-5d76e2eb-df2c-4913-b458-67578064ab0b">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">energymail.org@gmail.com</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T19:40:27+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76e2eb-e004-41d8-bc9d-67578064ab0b" timestamp="2019-09-09T19:40:27+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: jameslewis199106@gmail.com (MISP Attribute #18570)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: jameslewis199106@gmail.com (MISP Attribute #18570)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76e2eb-e004-41d8-bc9d-67578064ab0b">
<cybox:Object id=":EmailMessage-5d76e2eb-e004-41d8-bc9d-67578064ab0b">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">jameslewis199106@gmail.com</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T19:40:27+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d76e2eb-37c8-4b75-b5d7-67578064ab0b" timestamp="2019-09-09T19:40:27+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: touchxun658@gmail.com (MISP Attribute #18571)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malicious E-mail</indicator:Type>
<indicator:Description>Payload delivery: touchxun658@gmail.com (MISP Attribute #18571)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d76e2eb-37c8-4b75-b5d7-67578064ab0b">
<cybox:Object id=":EmailMessage-5d76e2eb-37c8-4b75-b5d7-67578064ab0b">
<cybox:Properties xsi:type="EmailMessageObj:EmailMessageObjectType">
<EmailMessageObj:Header>
<EmailMessageObj:From xsi:type="AddressObj:AddressObjectType" category="e-mail">
<AddressObj:Address_Value condition="Equals">touchxun658@gmail.com</AddressObj:Address_Value>
</EmailMessageObj:From>
</EmailMessageObj:Header>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-09T19:40:27+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d8545bf-ec98-4d0c-a8a3-55038064ab0b" timestamp="2019-09-20T17:33:51+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 6977e6098815cd91016be9d76f194ed4622640d03c6cdd66b1032306a2190af7 (MISP Attribute #18572)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 6977e6098815cd91016be9d76f194ed4622640d03c6cdd66b1032306a2190af7 (MISP Attribute #18572)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d8545bf-ec98-4d0c-a8a3-55038064ab0b">
<cybox:Object id=":File-5d8545bf-ec98-4d0c-a8a3-55038064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">6977e6098815cd91016be9d76f194ed4622640d03c6cdd66b1032306a2190af7</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-20T17:33:51+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d8545d4-ee30-435b-827e-55078064ab0b" timestamp="2019-09-20T17:34:12+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: e510c361c8101384277dd95cc2c8e76715dd241f58553f592245b620422beaf3 (MISP Attribute #18573)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: e510c361c8101384277dd95cc2c8e76715dd241f58553f592245b620422beaf3 (MISP Attribute #18573)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d8545d4-ee30-435b-827e-55078064ab0b">
<cybox:Object id=":File-5d8545d4-ee30-435b-827e-55078064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">e510c361c8101384277dd95cc2c8e76715dd241f58553f592245b620422beaf3</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-20T17:34:12+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d8545e3-c264-43d8-9666-55068064ab0b" timestamp="2019-09-20T17:34:27+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: 0d13e403303b52edae6beb76a6fe7ed454f340aae1246b9a3f55ca728da2d6aa (MISP Attribute #18574)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: 0d13e403303b52edae6beb76a6fe7ed454f340aae1246b9a3f55ca728da2d6aa (MISP Attribute #18574)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d8545e3-c264-43d8-9666-55068064ab0b">
<cybox:Object id=":File-5d8545e3-c264-43d8-9666-55068064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">0d13e403303b52edae6beb76a6fe7ed454f340aae1246b9a3f55ca728da2d6aa</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-20T17:34:27+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
<incident:Related_Indicator>
<stixCommon:Relationship>Payload delivery</stixCommon:Relationship>
<stixCommon:Indicator id=":indicator-5d854603-8bf4-44fe-96ae-47ce8064ab0b" timestamp="2019-09-20T17:34:59+00:00" xsi:type='indicator:IndicatorType'>
<indicator:Title>Payload delivery: b85fe634f3c5b1022a1adbc21f3b85b58451ca2b89e9380fc5f22b9340a18b88 (MISP Attribute #18575)</indicator:Title>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">Malware Artifacts</indicator:Type>
<indicator:Type xsi:type="stixVocabs:IndicatorTypeVocab-1.1">File Hash Watchlist</indicator:Type>
<indicator:Description>Payload delivery: b85fe634f3c5b1022a1adbc21f3b85b58451ca2b89e9380fc5f22b9340a18b88 (MISP Attribute #18575)</indicator:Description>
<indicator:Valid_Time_Position/>
<indicator:Observable id=":observable-5d854603-8bf4-44fe-96ae-47ce8064ab0b">
<cybox:Object id=":File-5d854603-8bf4-44fe-96ae-47ce8064ab0b">
<cybox:Properties xsi:type="FileObj:FileObjectType">
<FileObj:Hashes>
<cyboxCommon:Hash>
<cyboxCommon:Type condition="Equals" xsi:type="cyboxVocabs:HashNameVocab-1.0">SHA256</cyboxCommon:Type>
<cyboxCommon:Simple_Hash_Value condition="Equals">b85fe634f3c5b1022a1adbc21f3b85b58451ca2b89e9380fc5f22b9340a18b88</cyboxCommon:Simple_Hash_Value>
</cyboxCommon:Hash>
</FileObj:Hashes>
</cybox:Properties>
</cybox:Object>
</indicator:Observable>
<indicator:Confidence timestamp="2019-09-20T17:34:59+00:00">
<stixCommon:Value xsi:type="stixVocabs:HighMediumLowVocab-1.0">None</stixCommon:Value>
<stixCommon:Description>Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none</stixCommon:Description>
</indicator:Confidence>
</stixCommon:Indicator>
</incident:Related_Indicator>
</incident:Related_Indicators>
<incident:Information_Source>
<stixCommon:Identity>
<stixCommon:Name>citizenlab</stixCommon:Name>
</stixCommon:Identity>
</incident:Information_Source>
<incident:Handling>
<marking:Marking>
<marking:Controlled_Structure>../../../descendant-or-self::node()</marking:Controlled_Structure>
<marking:Marking_Structure xsi:type='tlpMarking:TLPMarkingStructureType' color="GREEN"/>
</marking:Marking>
</incident:Handling>
</stix:Incident>
</stix:Incidents>
</stix:Package>
</stix:Related_Package>
</stix:Related_Packages>
</stix:STIX_Package>