Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?xml version='1.0' encoding='us-ascii'?>
- <ioc xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:xsd="http://www.w3.org/2001/XMLSchema" id="6ff93f5a-fb3c-4e87-875a-89e1496685b2" last-modified="2015-12-12T00:15:43" xmlns="http://schemas.mandiant.com/2010/ioc">
- <short_description>IOC stub by @iocbucket.</short_description>
- <description>This is a stub of an IOC intended to be used as a base to make a more robust IOC.</description>
- <authored_by>@iocbucket</authored_by>
- <authored_date>2015-12-12T00:15:43</authored_date>
- <definition>
- <Indicator id="d3ab2069-0f45-4c59-9d79-2067e54120e4" operator="OR">
- <IndicatorItem condition="is" id="c4114b12-0fa5-44c9-a138-2714074cf856">
- <Context document="FileItem" search="FileItem/Md5sum" type="mir"/>
- <Content type="md5">8258e89e2a7861c77c72982b3bb4b840</Content>
- </IndicatorItem>
- <IndicatorItem condition="is" id="eafa5688-21e4-49a7-b010-423cd5e9eaa8">
- <Context document="FileItem" search="FileItem/Sha1sum" type="mir"/>
- <Content type="sha1">53cd357e7a3c7ca3281b237a5386d15fd83756f9</Content>
- </IndicatorItem>
- <IndicatorItem condition="is" id="5e47f5b4-f173-47a5-857f-0785c341e062">
- <Context document="FileItem" search="FileItem/Sha256sum" type="mir"/>
- <Content type="sha256">1079f49a658c8b1e06762d2a49187befac3b105d3a91415ce4ac3d74c4ec51b0</Content>
- </IndicatorItem>
- <Indicator id="2990b620-d3e6-4ea1-822c-b4d3be17cf48" operator="AND">
- <IndicatorItem condition="is" id="e8129090-6f6b-47eb-b332-d05f1276530f">
- <Context document="FileItem" search="FileItem/FileName" type="mir"/>
- <Content type="string">1079f49a658c8b1e06762d2a49187befac3b105d3a91415ce4ac3d74c4ec51b0.exe</Content>
- </IndicatorItem>
- <IndicatorItem condition="is" id="b1d0ab87-4577-4b5b-b708-f92211e94df2">
- <Context document="FileItem" search="FileItem/SizeInBytes" type="mir"/>
- <Content type="int">438272</Content>
- </IndicatorItem>
- <IndicatorItem condition="is" id="8a41b57f-1535-4a24-b117-683ca78c0fdc">
- <Context document="FileItem" search="FileItem/PEInfo/PETimeStamp" type="mir"/>
- <Content type="date">2007-07-04T10:50:49Z</Content>
- </IndicatorItem>
- </Indicator>
- <Indicator id="e91cfba1-da27-4a6b-bd6f-40c9cdf557b7" operator="AND">
- <IndicatorItem condition="is" id="66d42cc9-9526-456e-9a82-559c4337ed5b">
- <Context document="FileItem" search="FileItem/FileName" type="mir"/>
- <Content type="string">80.exe.bin</Content>
- </IndicatorItem>
- <IndicatorItem condition="is" id="7946ed04-1f6a-4f2f-b5d6-50de2117889f">
- <Context document="FileItem" search="FileItem/SizeInBytes" type="mir"/>
- <Content type="int">438272</Content>
- </IndicatorItem>
- <IndicatorItem condition="is" id="bb9288cf-8f54-4f0c-9c01-bd0c7f39e874">
- <Context document="FileItem" search="FileItem/PEInfo/PETimeStamp" type="mir"/>
- <Content type="date">2007-07-04T10:50:49Z</Content>
- </IndicatorItem>
- </Indicator>
- <Indicator id="30032897-70d2-4eba-b7f4-3ce1cc2aa4a5" operator="AND">
- <IndicatorItem condition="is" id="3cdde91a-158c-4c4a-af0f-931d2c66910c">
- <Context document="FileItem" search="FileItem/FileName" type="mir"/>
- <Content type="string">C:\Users\knoral\Downloads\dd\80.exe</Content>
- </IndicatorItem>
- <IndicatorItem condition="is" id="096f5120-739c-4dae-a0ba-50aee43504cf">
- <Context document="FileItem" search="FileItem/SizeInBytes" type="mir"/>
- <Content type="int">438272</Content>
- </IndicatorItem>
- <IndicatorItem condition="is" id="80e9a036-f930-4c93-b334-83bcc7c4ff73">
- <Context document="FileItem" search="FileItem/PEInfo/PETimeStamp" type="mir"/>
- <Content type="date">2007-07-04T10:50:49Z</Content>
- </IndicatorItem>
- </Indicator>
- <Indicator id="ad3f42b1-cbb3-450a-9ef4-1b4115902c5e" operator="AND">
- <IndicatorItem condition="is" id="ac855f17-af20-4c50-90bc-8968ec19a45b">
- <Context document="FileItem" search="FileItem/FileName" type="mir"/>
- <Content type="string">C:\Sandbox\KnorAl\DefaultBox\user\current\AppData\Roaming\rmcmlacroic.exe</Content>
- </IndicatorItem>
- <IndicatorItem condition="is" id="f4659211-9da5-46d2-91bc-9ab343ea1b28">
- <Context document="FileItem" search="FileItem/SizeInBytes" type="mir"/>
- <Content type="int">438272</Content>
- </IndicatorItem>
- <IndicatorItem condition="is" id="fa06fa3c-81fd-4fd3-9e0d-aed64027c2a7">
- <Context document="FileItem" search="FileItem/PEInfo/PETimeStamp" type="mir"/>
- <Content type="date">2007-07-04T10:50:49Z</Content>
- </IndicatorItem>
- </Indicator>
- <Indicator id="921efe07-6cc6-41fc-8364-2f8216ddc30e" operator="AND">
- <IndicatorItem condition="contains" id="85a6a00e-4753-4c7d-88dc-c591a178f224">
- <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
- <Content type="string">comdlg32.dll</Content>
- </IndicatorItem>
- <IndicatorItem condition="contains" id="de7101ae-6c57-4f6c-bb5b-467181a27fea">
- <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
- <Content type="string">GDI32.dll</Content>
- </IndicatorItem>
- <IndicatorItem condition="contains" id="06fe0726-9ef4-4d88-99a7-5c1bf49c76a4">
- <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
- <Content type="string">KERNEL32.dll</Content>
- </IndicatorItem>
- <IndicatorItem condition="contains" id="41de2f52-70a0-48be-a3f0-a07f8c9ef79a">
- <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
- <Content type="string">MSVCRT.dll</Content>
- </IndicatorItem>
- <IndicatorItem condition="contains" id="8ebb3bbc-e31c-4f93-811d-9aa46cad1799">
- <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
- <Content type="string">OLEAUT32.dll</Content>
- </IndicatorItem>
- <IndicatorItem condition="contains" id="23a4d128-e06d-4d62-bfd1-32924189a6ad">
- <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
- <Content type="string">ADVAPI32.dll</Content>
- </IndicatorItem>
- <IndicatorItem condition="contains" id="6af62364-889e-4f3b-a29c-e3e8ecf49d2a">
- <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
- <Content type="string">MFC42.DLL</Content>
- </IndicatorItem>
- <IndicatorItem condition="contains" id="71944969-1deb-4473-aa65-02279f10a652">
- <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
- <Content type="string">USER32.dll</Content>
- </IndicatorItem>
- <IndicatorItem condition="contains" id="7197822d-9522-4064-9e45-dab091030ede">
- <Context document="FileItem" search="FileItem/PEInfo/ImportedModules/Module/Name" type="mir"/>
- <Content type="string">COMCTL32.dll</Content>
- </IndicatorItem>
- </Indicator>
- </Indicator>
- </definition>
- </ioc>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement