Created
December 8, 2021 18:11
-
-
Save traut/ee9e0117cac06e5014ab7838776d4d9c to your computer and use it in GitHub Desktop.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
{ | |
"type": "bundle", | |
"id": "bundle--a6fb81b8-46c7-40de-85be-bee510f08d1b", | |
"objects": [ | |
{ | |
"type": "campaign", | |
"spec_version": "2.1", | |
"id": "campaign--12a111f0-b824-4baf-a224-83b80237a094", | |
"lang": "en", | |
"created": "2017-02-08T21:31:22.007Z", | |
"modified": "2017-02-08T21:31:22.007Z", | |
"name": "Bank Attack", | |
"description": "Some description about attack on the Bank", | |
"created_by_ref": "identity--e5f1b90a-d9b6-40ab-81a9-8a29df4b6b65", | |
"object_marking_refs": [ | |
"marking-definition--f88d31f6-486f-44da-b317-01333bde0b82", | |
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" | |
] | |
}, | |
{ | |
"type": "marking-definition", | |
"spec_version": "2.1", | |
"id": "marking-definition--f88d31f6-486f-44da-b317-01333bde0b82", | |
"created": "2016-08-01T00:00:00.000Z", | |
"definition_type": "tlp", | |
"name": "TLP:AMBER", | |
"definition": { | |
"tlp": "amber" | |
} | |
}, | |
{ | |
"type": "indicator", | |
"spec_version": "2.1", | |
"id": "indicator--8e2e2d2b-17d4-4cbf-938f-98ee46b3cd3f", | |
"created_by_ref": "identity--e5f1b90a-d9b6-40ab-81a9-8a29df4b6b65", | |
"created": "2016-04-06T20:03:48.000Z", | |
"modified": "2016-04-06T20:03:48.000Z", | |
"indicator_types": ["malicious-activity"], | |
"name": "Poison Ivy Malware", | |
"description": "This file is part of Poison Ivy", | |
"pattern": "[ file:hashes.'SHA-256' = '4bac27393bdd9777ce02453256c5577cd02275510b2227f473d03f533924f877' ]", | |
"pattern_type": "stix", | |
"valid_from": "2016-01-01T00:00:00Z", | |
"object_marking_refs": [ | |
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9" | |
] | |
}, | |
{ | |
"type": "relationship", | |
"spec_version": "2.1", | |
"id": "relationship--803fe1e3-56e8-46b7-a945-54f85fc55c2a", | |
"created_by_ref": "identity--f431f809-377b-45e0-aa1c-6a4751cae5ff", | |
"created": "2016-04-06T20:07:10.000Z", | |
"modified": "2016-04-06T20:07:10.000Z", | |
"relationship_type": "indicates", | |
"source_ref": "indicator--8e2e2d2b-17d4-4cbf-938f-98ee46b3cd3f", | |
"target_ref": "campaign--12a111f0-b824-4baf-a224-83b80237a094" | |
}, | |
{ | |
"type": "threat-actor", | |
"spec_version": "2.1", | |
"id": "threat-actor--8e2e2d2b-17d4-4cbf-938f-98ee46b3cd3f", | |
"created_by_ref": "identity--e5f1b90a-d9b6-40ab-81a9-8a29df4b6b65", | |
"created": "2016-04-06T20:03:48.000Z", | |
"modified": "2016-04-06T20:03:48.000Z", | |
"threat_actor_types": ["crime-syndicate"], | |
"name": "Evil Org", | |
"description": "The Evil Org threat actor group", | |
"aliases": ["Syndicate 1", "Evil Syndicate 99"], | |
"roles": ["director", "sponsor"], | |
"goals": ["Steal bank money", "Steal credit cards"], | |
"sophistication": "advanced", | |
"resource_level": "team", | |
"primary_motivation": "organizational-gain", | |
"object_marking_refs": [ | |
"marking-definition--5e57c739-391a-4eb3-b6be-7d15ca92d5ed" | |
] | |
}, | |
{ | |
"type": "relationship", | |
"spec_version": "2.1", | |
"id": "relationship--d21dd5f6-00f7-48ca-880d-1f699b267f90", | |
"created": "2016-05-09T08:17:27.000Z", | |
"modified": "2016-05-09T08:17:27.000Z", | |
"relationship_type": "uses", | |
"source_ref": "campaign--12a111f0-b824-4baf-a224-83b80237a094", | |
"target_ref": "tool--8e2e2d2b-17d4-4cbf-938f-98ee46b3cd3f" | |
}, | |
{ | |
"type": "relationship", | |
"spec_version": "2.1", | |
"id": "relationship--2b7c094b-dacc-40ee-8ffc-06b20bf5562b", | |
"created": "2016-05-09T08:17:27.000Z", | |
"modified": "2016-05-09T08:17:27.000Z", | |
"relationship_type": "uses", | |
"source_ref": "threat-actor--8e2e2d2b-17d4-4cbf-938f-98ee46b3cd3f", | |
"target_ref": "tool--8e2e2d2b-17d4-4cbf-938f-98ee46b3cd3f" | |
}, | |
{ | |
"type": "tool", | |
"spec_version": "2.1", | |
"id": "tool--8e2e2d2b-17d4-4cbf-938f-98ee46b3cd3f", | |
"created_by_ref": "identity--f431f809-377b-45e0-aa1c-6a4751cae5ff", | |
"created": "2016-04-06T20:03:48.000Z", | |
"modified": "2016-04-06T20:03:48.000Z", | |
"tool_types": ["remote-access"], | |
"name": "VNC", | |
"object_marking_refs": [ | |
"marking-definition--34098fce-860f-48ae-8e50-ebd3cc5e41da" | |
] | |
}, | |
{ | |
"type": "marking-definition", | |
"spec_version": "2.1", | |
"id": "marking-definition--34098fce-860f-48ae-8e50-ebd3cc5e41da", | |
"created": "2016-08-01T00:00:00.000Z", | |
"definition_type": "tlp", | |
"name": "TLP:GREEN", | |
"definition": { | |
"tlp": "green" | |
} | |
}, | |
{ | |
"type": "malware", | |
"spec_version": "2.1", | |
"id": "malware--31b940d4-6f7f-459a-80ea-9c1f17b5891b", | |
"created_by_ref": "identity--f431f809-377b-45e0-aa1c-6a4751cae5ff", | |
"created": "2016-04-06T20:07:09.000Z", | |
"modified": "2016-04-06T20:07:09.000Z", | |
"is_family": true, | |
"name": "Poison Ivy", | |
"malware_types": ["trojan"], | |
"object_marking_refs": [ | |
"marking-definition--f88d31f6-486f-44da-b317-01333bde0b82" | |
] | |
}, | |
{ | |
"type": "relationship", | |
"spec_version": "2.1", | |
"id": "relationship--afb36c5b-b1d6-4282-99b8-2cdc361faecc", | |
"created_by_ref": "identity--f431f809-377b-45e0-aa1c-6a4751cae5ff", | |
"created": "2016-04-06T20:06:37.000Z", | |
"modified": "2016-04-06T20:06:37.000Z", | |
"relationship_type": "authored-by", | |
"source_ref": "malware--31b940d4-6f7f-459a-80ea-9c1f17b5891b", | |
"target_ref": "threat-actor--8e2e2d2b-17d4-4cbf-938f-98ee46b3cd3f" | |
}, | |
{ | |
"type": "relationship", | |
"spec_version": "2.1", | |
"id": "relationship--d628a168-4b1c-45c8-9324-59f1bf1ce618", | |
"created_by_ref": "identity--f431f809-377b-45e0-aa1c-6a4751cae5ff", | |
"created": "2016-04-06T20:07:10.000Z", | |
"modified": "2016-04-06T20:07:10.000Z", | |
"relationship_type": "targets", | |
"source_ref": "malware--31b940d4-6f7f-459a-80ea-9c1f17b5891b", | |
"target_ref": "location--a6e9345f-5a15-4c29-8bb3-7dcc5d168d64" | |
}, | |
{ | |
"type": "location", | |
"spec_version": "2.1", | |
"id": "location--a6e9345f-5a15-4c29-8bb3-7dcc5d168d64", | |
"created_by_ref": "identity--e5f1b90a-d9b6-40ab-81a9-8a29df4b6b65", | |
"created": "2016-04-06T20:03:00.000Z", | |
"modified": "2016-04-06T20:03:00.000Z", | |
"region": "northern-america", | |
"object_marking_refs": [ | |
"marking-definition--34098fce-860f-48ae-8e50-ebd3cc5e41da" | |
] | |
}, | |
{ | |
"type": "relationship", | |
"spec_version": "2.1", | |
"id": "relationship--44298a74-ba52-4f0c-87a3-1824e67d7fad", | |
"created_by_ref": "identity--f431f809-377b-45e0-aa1c-6a4751cae5ff", | |
"created": "2016-04-06T20:06:37.000Z", | |
"modified": "2016-04-06T20:06:37.000Z", | |
"relationship_type": "indicates", | |
"source_ref": "indicator--8e2e2d2b-17d4-4cbf-938f-98ee46b3cd3f", | |
"target_ref": "malware--31b940d4-6f7f-459a-80ea-9c1f17b5891b" | |
} | |
] | |
} |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment