Skip to content

Instantly share code, notes, and snippets.

@sbarnum
Created October 2, 2018 20:33
Show Gist options
  • Save sbarnum/67049e9416875497200191e304bec637 to your computer and use it in GitHub Desktop.
Save sbarnum/67049e9416875497200191e304bec637 to your computer and use it in GitHub Desktop.
{
"type": "bundle",
"id": "bundle--3bac8691-327f-44cf-a3c4-85fd5ef6e1c4",
"objects": [
{
"type": "threat-actor",
"id": "threat-actor--426bd456-efe0-41a2-b557-b95f539b5810",
"spec_version": "2.1",
"created": "2012-01-06T20:03:48.000Z",
"modified": "2012-01-06T20:03:48.000Z",
"name": "APT472"
},
{
"type": "relationship",
"id": "relationship--b90ff7de-ae25-4008-a338-85aa85a06af6",
"spec_version": "2.1",
"created": "2015-04-06T21:00:50.000Z",
"modified": "2015-04-06T21:00:50.000Z",
"source_ref": "campaign--bab8ba60-db20-47cd-82fb-b9be7907bf3c",
"target_ref": "threat-actor--426bd456-efe0-41a2-b557-b95f539b5810",
"relationship_type": "attributed-to",
"start_time": "2015-06-01T00:00:00.000Z",
"stop_time": "2015-09-01T00:00:00.000Z"
},
{
"type": "campaign",
"id": "campaign--bab8ba60-db20-47cd-82fb-b9be7907bf3c",
"spec_version": "2.1",
"created": "2015-01-06T20:03:48.000Z",
"modified": "2015-01-06T20:03:48.000Z",
"name": "HarryGorilla",
"first_seen": "2015-06-01T00:00:00.000Z",
"last_seen": "2015-09-01T00:00:00.000Z"
},
{
"type": "relationship",
"id": "relationship--024f0413-fb6a-4f6d-9747-0cdaa7390bf5",
"spec_version": "2.1",
"created": "2015-04-06T21:00:50.000Z",
"modified": "2015-04-06T21:00:50.000Z",
"source_ref": "campaign--bab8ba60-db20-47cd-82fb-b9be7907bf3c",
"target_ref": "email-message--6bb97ad8-9001-48ec-a293-100d42240081",
"relationship_type": "uses",
"start_time": "2015-06-01T00:00:00.000Z",
"stop_time": "2015-07-01T00:00:00.000Z"
},
{
"type": "email-address",
"id": "email-address--febceeaa-adc1-46b3-a119-8d8cb4d6cd55",
"spec_version": "2.1",
"created": "2010-07-01T00:00:00.000Z",
"modified": "2010-07-01T00:00:00.000Z",
"value": "joe@example.com"
},
{
"type": "email-message",
"id": "email-message--6bb97ad8-9001-48ec-a293-100d42240081",
"spec_version": "2.1",
"created": "2015-07-01T00:00:00.000Z",
"modified": "2015-07-01T00:00:00.000Z",
"is_multipart": true,
"sender_ref": "email-address--febceeaa-adc1-46b3-a119-8d8cb4d6cd55",
"subject": "Windows Error Report",
"body_multipart": [
{
"content_type": "text/plain; charset=utf-8",
"content_disposition": "inline",
"body": "Windows User Alert - error report attached"
},
{
"content_type": "application/zip",
"content_disposition": "attachment; filename=\"Windows-Error-Report.zip\"",
"body_raw_ref": "file--c65cea3e-c75f-45b5-a14b-76777fae78d6"
}
]
},
{
"type": "file",
"id": "file--c65cea3e-c75f-45b5-a14b-76777fae78d6",
"spec_version": "2.1",
"created": "2010-07-01T00:00:00.000Z",
"modified": "2010-07-01T00:00:00.000Z",
"name": "Windows-Error-Report.zip",
"magic_number_hex": "504B0304",
"hashes": {
"SHA-256": "fe90a7e910cb3a4739bed9180e807e93fa70c90f25a8915476f5e4bfbac681db"
}
},
{
"type": "relationship",
"id": "relationship--d1bc57ba-c5f5-4943-8b9d-37689ed81b18",
"spec_version": "2.1",
"created": "2015-08-06T21:00:50.000Z",
"modified": "2015-08-06T21:00:50.000Z",
"source_ref": "campaign--bab8ba60-db20-47cd-82fb-b9be7907bf3c",
"target_ref": "email-message--895acde0-a6ed-467b-9e78-35397a9ce7c8",
"relationship_type": "uses",
"start_time": "2015-08-01T00:00:00.000Z",
"stop_time": "2015-09-01T00:00:00.000Z"
},
{
"type": "email-message",
"id": "email-message--895acde0-a6ed-467b-9e78-35397a9ce7c8",
"spec_version": "2.1",
"created": "2015-08-01T00:00:00.000Z",
"modified": "2015-08-01T00:00:00.000Z",
"is_multipart": true,
"sender_ref": "email-address--febceeaa-adc1-46b3-a119-8d8cb4d6cd55",
"subject": "Response Required",
"body_multipart": [
{
"content_type": "text/plain; charset=utf-8",
"content_disposition": "inline",
"body": "Expense report error - immediate response required for attached expense report or payment will be denied."
},
{
"content_type": "application/zip",
"content_disposition": "attachment; filename=\"Expense-Report.zip\"",
"body_raw_ref": "file--cf25d8c6-7f7c-4eef-967a-481d0be992fe"
}
]
},
{
"type": "file",
"id": "file--cf25d8c6-7f7c-4eef-967a-481d0be992fe",
"spec_version": "2.1",
"created": "2015-08-01T00:00:00.000Z",
"modified": "2015-08-01T00:00:00.000Z",
"name": "Expense-Report.zip",
"magic_number_hex": "504B0304",
"hashes": {
"SHA-256": "6E701C0F375CB752C9F1BE2EC6F07ED052CF740B72B0C7B7D8369589C8A579E6"
}
}
]
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment