Advertisement
opexxx

8258e89e2a7861c77c72982b3bb4b840.ioc

Dec 11th, 2015
177
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Bash 7.38 KB | None | 0 0
  1. <?xml version='1.0' encoding='us-ascii'?>
  2. <ioc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" id="6ff93f5a-fb3c-4e87-875a-89e1496685b2" last-modified="2015-12-12T00:15:43" xmlns="http://schemas.mandiant.com/2010/ioc">
  3.   <short_description>IOC stub by @iocbucket.</short_description>
  4.   <description>This is a stub of an IOC intended to be used as a base to make a more robust IOC.</description>
  5.   <authored_by>@iocbucket</authored_by>
  6.   <authored_date>2015-12-12T00:15:43</authored_date>
  7.   <definition>
  8.     <Indicator id="d3ab2069-0f45-4c59-9d79-2067e54120e4" operator="OR">
  9.       <IndicatorItem condition="is" id="c4114b12-0fa5-44c9-a138-2714074cf856">
  10.         <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
  11.         <Content type="md5">8258e89e2a7861c77c72982b3bb4b840</Content>
  12.       </IndicatorItem>
  13.       <IndicatorItem condition="is" id="eafa5688-21e4-49a7-b010-423cd5e9eaa8">
  14.         <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
  15.         <Content type="sha1">53cd357e7a3c7ca3281b237a5386d15fd83756f9</Content>
  16.       </IndicatorItem>
  17.       <IndicatorItem condition="is" id="5e47f5b4-f173-47a5-857f-0785c341e062">
  18.         <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
  19.         <Content type="sha256">1079f49a658c8b1e06762d2a49187befac3b105d3a91415ce4ac3d74c4ec51b0</Content>
  20.       </IndicatorItem>
  21.       <Indicator id="2990b620-d3e6-4ea1-822c-b4d3be17cf48" operator="AND">
  22.         <IndicatorItem condition="is" id="e8129090-6f6b-47eb-b332-d05f1276530f">
  23.           <Context document="FileItem" search="FileItem/FileName" type="mir"/>
  24.           <Content type="string">1079f49a658c8b1e06762d2a49187befac3b105d3a91415ce4ac3d74c4ec51b0.exe</Content>
  25.         </IndicatorItem>
  26.         <IndicatorItem condition="is" id="b1d0ab87-4577-4b5b-b708-f92211e94df2">
  27.           <Context document="FileItem" search="FileItem/SizeInBytes" type="mir"/>
  28.           <Content type="int">438272</Content>
  29.         </IndicatorItem>
  30.         <IndicatorItem condition="is" id="8a41b57f-1535-4a24-b117-683ca78c0fdc">
  31.           <Context document="FileItem" search="FileItem/PEInfo/PETimeStamp" type="mir"/>
  32.           <Content type="date">2007-07-04T10:50:49Z</Content>
  33.         </IndicatorItem>
  34.       </Indicator>
  35.       <Indicator id="e91cfba1-da27-4a6b-bd6f-40c9cdf557b7" operator="AND">
  36.         <IndicatorItem condition="is" id="66d42cc9-9526-456e-9a82-559c4337ed5b">
  37.           <Context document="FileItem" search="FileItem/FileName" type="mir"/>
  38.           <Content type="string">80.exe.bin</Content>
  39.         </IndicatorItem>
  40.         <IndicatorItem condition="is" id="7946ed04-1f6a-4f2f-b5d6-50de2117889f">
  41.           <Context document="FileItem" search="FileItem/SizeInBytes" type="mir"/>
  42.           <Content type="int">438272</Content>
  43.         </IndicatorItem>
  44.         <IndicatorItem condition="is" id="bb9288cf-8f54-4f0c-9c01-bd0c7f39e874">
  45.           <Context document="FileItem" search="FileItem/PEInfo/PETimeStamp" type="mir"/>
  46.           <Content type="date">2007-07-04T10:50:49Z</Content>
  47.         </IndicatorItem>
  48.       </Indicator>
  49.       <Indicator id="30032897-70d2-4eba-b7f4-3ce1cc2aa4a5" operator="AND">
  50.         <IndicatorItem condition="is" id="3cdde91a-158c-4c4a-af0f-931d2c66910c">
  51.           <Context document="FileItem" search="FileItem/FileName" type="mir"/>
  52.           <Content type="string">C:\Users\knoral\Downloads\dd\80.exe</Content>
  53.         </IndicatorItem>
  54.         <IndicatorItem condition="is" id="096f5120-739c-4dae-a0ba-50aee43504cf">
  55.           <Context document="FileItem" search="FileItem/SizeInBytes" type="mir"/>
  56.           <Content type="int">438272</Content>
  57.         </IndicatorItem>
  58.         <IndicatorItem condition="is" id="80e9a036-f930-4c93-b334-83bcc7c4ff73">
  59.           <Context document="FileItem" search="FileItem/PEInfo/PETimeStamp" type="mir"/>
  60.           <Content type="date">2007-07-04T10:50:49Z</Content>
  61.         </IndicatorItem>
  62.       </Indicator>
  63.       <Indicator id="ad3f42b1-cbb3-450a-9ef4-1b4115902c5e" operator="AND">
  64.         <IndicatorItem condition="is" id="ac855f17-af20-4c50-90bc-8968ec19a45b">
  65.           <Context document="FileItem" search="FileItem/FileName" type="mir"/>
  66.           <Content type="string">C:\Sandbox\KnorAl\DefaultBox\user\current\AppData\Roaming\rmcmlacroic.exe</Content>
  67.         </IndicatorItem>
  68.         <IndicatorItem condition="is" id="f4659211-9da5-46d2-91bc-9ab343ea1b28">
  69.           <Context document="FileItem" search="FileItem/SizeInBytes" type="mir"/>
  70.           <Content type="int">438272</Content>
  71.         </IndicatorItem>
  72.         <IndicatorItem condition="is" id="fa06fa3c-81fd-4fd3-9e0d-aed64027c2a7">
  73.           <Context document="FileItem" search="FileItem/PEInfo/PETimeStamp" type="mir"/>
  74.           <Content type="date">2007-07-04T10:50:49Z</Content>
  75.         </IndicatorItem>
  76.       </Indicator>
  77.       <Indicator id="921efe07-6cc6-41fc-8364-2f8216ddc30e" operator="AND">
  78.         <IndicatorItem condition="contains" id="85a6a00e-4753-4c7d-88dc-c591a178f224">
  79.           <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
  80.           <Content type="string">comdlg32.dll</Content>
  81.         </IndicatorItem>
  82.         <IndicatorItem condition="contains" id="de7101ae-6c57-4f6c-bb5b-467181a27fea">
  83.           <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
  84.           <Content type="string">GDI32.dll</Content>
  85.         </IndicatorItem>
  86.         <IndicatorItem condition="contains" id="06fe0726-9ef4-4d88-99a7-5c1bf49c76a4">
  87.           <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
  88.           <Content type="string">KERNEL32.dll</Content>
  89.         </IndicatorItem>
  90.         <IndicatorItem condition="contains" id="41de2f52-70a0-48be-a3f0-a07f8c9ef79a">
  91.           <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
  92.           <Content type="string">MSVCRT.dll</Content>
  93.         </IndicatorItem>
  94.         <IndicatorItem condition="contains" id="8ebb3bbc-e31c-4f93-811d-9aa46cad1799">
  95.           <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
  96.           <Content type="string">OLEAUT32.dll</Content>
  97.         </IndicatorItem>
  98.         <IndicatorItem condition="contains" id="23a4d128-e06d-4d62-bfd1-32924189a6ad">
  99.           <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
  100.           <Content type="string">ADVAPI32.dll</Content>
  101.         </IndicatorItem>
  102.         <IndicatorItem condition="contains" id="6af62364-889e-4f3b-a29c-e3e8ecf49d2a">
  103.           <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
  104.           <Content type="string">MFC42.DLL</Content>
  105.         </IndicatorItem>
  106.         <IndicatorItem condition="contains" id="71944969-1deb-4473-aa65-02279f10a652">
  107.           <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
  108.           <Content type="string">USER32.dll</Content>
  109.         </IndicatorItem>
  110.         <IndicatorItem condition="contains" id="7197822d-9522-4064-9e45-dab091030ede">
  111.           <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
  112.           <Content type="string">COMCTL32.dll</Content>
  113.         </IndicatorItem>
  114.       </Indicator>
  115.     </Indicator>
  116.   </definition>
  117. </ioc>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement