diff --git a/yvisualization/attack-flow-builder/icedid/IcedID-032725.afb b/yvisualization/attack-flow-builder/icedid/IcedID-032725.afb
new file mode 100644
index 0000000..9e91633
--- /dev/null
+++ b/yvisualization/attack-flow-builder/icedid/IcedID-032725.afb
@@ -0,0 +1 @@
+{"version":"2.3.2","id":"49e4b0e6-5cc7-4757-81db-b1ae6788cd41","objects":[{"id":"49e4b0e6-5cc7-4757-81db-b1ae6788cd41","x":1572,"y":70,"attrs":0,"template":"flow","children":["ac0751dd-123e-488a-a093-6b5170f8e694","5ac84220-2268-4513-a117-dd38a5402739","268f83ee-d3de-4320-bdde-ec6a04c46280","4c9d6521-a65b-4982-8c61-f03fd1494615","eb5ca1e6-a396-4040-8318-436c3cce18e8","daf58001-205f-4454-a2df-b49bdda29205","11f4d871-cc16-4e49-b4b1-528b361d9415","f4c87cd1-9231-489e-8900-b0c1e6b77c31","df03a9d4-8a01-45b2-92eb-1038890c4163","1c8faaae-3d55-49ed-ba8d-e56f72d736bd","4d554511-0707-45f2-b2e6-f3c89792f3f2","bae7ae51-0d92-4bcd-b0a1-8176fe231f3c","cb9eccb5-8a52-4ef1-a93c-cbdbe9adda42","bce4df0c-1803-4c08-b8b6-394e266ff38d","c8955375-12ea-4fd6-abac-1f6e8d42fecd","7c98425a-58bf-4af5-86db-6a27b3c2f7d8","c15548fd-3f78-41c1-88ce-b9b7ef361170","eb109108-56ac-46e5-9d85-692afaa28a68","1e68a3cc-7581-4df0-8057-e95770fa9602","8814dbd7-b9c9-41a8-87f8-2a00c57d1d85","5e395ad7-7b62-4876-b26c-2de21d8db034","88bd84e5-e3b0-4dff-863e-5fedb8f4dc28","b9172571-156f-4389-9a09-e5d298fe77b6","01b76ff0-5e05-491d-b188-94e3ecea47f8","659602d1-d017-490b-8e31-68b567baa7ec","e91caa3d-6050-4df6-9428-dafc5415c8e4","e28bdaf7-eca6-439b-b14e-911193d0b45b","74fd5e7e-5861-46f1-a70f-da764935216f","9701c1ba-d1e1-4ed7-a7d8-e3b957a4b058","9ec1e943-a76c-49ec-8a3d-b706eed5238e","b910993b-d9ca-4f31-a058-ab7df512e665","a690f62f-30c3-4c78-a460-0779d8893282","e7ee4edf-9827-48b2-bef7-4912973ec1f9","49f52317-8552-4d5c-b4fa-85fd6d5c4243","39e09e78-6046-4979-abd3-4cc2e65d8246","451190ba-a29b-4426-9b99-3b098d0284ed","c0c55d0d-b281-4fdc-8af5-5aada501b724","d0f0dead-bbb7-459b-847d-7ca4d51bf67a","efbca724-bd9d-4244-97ea-c6a7187b5daf","6bf54f23-e1e3-49b6-9d31-d7df55e9dd69"],"properties":[["name","IcedID"],["description","Visual displaying IcedID malware behavior"],["author",[["name","Maddie Bright"],["identity_class",null],["contact_information",null]]],["scope","malware"],["external_references",[["d6d4a93aa4ffc3a488a080b3f728a776",[["source_name","THREAT ANALYSIS: From IcedID to Domain Compromise"],["description",null],["url","https://www.cybereason.com/blog/threat-analysis-from-icedid-to-domain-compromise"]]]]],["created","2025-02-21T15:58:38.809Z"]]},{"id":"ac0751dd-123e-488a-a093-6b5170f8e694","x":-160,"y":-360,"attrs":256,"template":"action","children":["87e72020-c676-4aae-a97b-8f6b15cca459","34491d09-a0d9-4384-bebc-027760ea64e4","5ada4652-ebdf-42df-9b57-9d03401ed333","693b43ce-100f-4942-9b05-161d2b3c894f","595a67fe-b87a-426f-b519-fa6924c09b62","3b01fd54-0c42-4f32-ba7f-c05bd72522a9","3fdb7ff7-fc87-4064-bc21-471d510273cb","5b0e36d6-af82-4e01-a4d0-c02fcb5385d4","a052e5a9-e198-426c-b839-49226c83721a","d129d574-eded-4454-9ab6-f6d954e0f7a4","d3bb1e25-9a94-46c1-9f51-7f620a9216bb","8a7a46fa-86cc-4ab7-9e27-979079c1d666"],"properties":[["name","Malicious File"],["tactic_id","TA0002"],["tactic_ref","x-mitre-tactic--4ca45d45-df4d-4613-8980-bac22d278fa5"],["technique_id","T1204.002"],["technique_ref","attack-pattern--232b7f21-adf9-4b42-b936-b9d6f7df856e"],["description","User executes a malicious archive"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"5ac84220-2268-4513-a117-dd38a5402739","x":-160,"y":10,"attrs":256,"template":"action","children":["2a5a62f9-650c-458d-b5c5-58b339c8dd46","69246ee1-4775-457a-b7aa-f993db68a05c","a9fc3fa5-0888-4992-b3ab-f8c623b0976e","b5e5dc9f-4460-411a-88e4-6c8f6de61590","77e14b5e-32ab-4632-b92b-791ca8f15b7b","a0bc8317-2d92-4c03-871b-3f0c4296807b","d2a9cc91-e7bf-4284-bbc4-0af662a3ef13","fffcaebc-ed26-4181-aac8-4f4fbc3aee09","fb381375-6f02-4826-b60e-a01b855b3982","d315fced-617f-470a-bbbf-e3d7185fd580","b79c4647-8788-4e55-ab9b-7f17209f6c94","ece71700-07f7-4142-9ff6-d9a98af4ebc0"],"properties":[["name","Hidden Files and Directories"],["tactic_id","TA0005"],["tactic_ref","x-mitre-tactic--78b23412-0651-46d7-a540-170a1ce8bd5a"],["technique_id","T1564.001"],["technique_ref","attack-pattern--ec8fc7e2-b356-455c-8db5-2e37be158e7d"],["description","Archive contains a hidden file which is a dependency called by the visible LNK file"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"268f83ee-d3de-4320-bdde-ec6a04c46280","x":1150,"y":10,"attrs":256,"template":"action","children":["484da459-3d56-467e-94ff-e87ce03af66f","a96d0bfc-1b0e-4292-8c41-32b6490ac636","7f3a6146-65cb-4a34-9cef-b2a64e84c26b","38e5c867-a5b8-4a29-9d25-b485d0c992d1","304f07d5-f080-49fb-8a53-72b893404702","23bad78d-15a1-42a2-adf1-5351776c47fe","1d203e8b-a87a-4206-bb96-0a68e7b9b541","daa7f16d-b296-4cf8-90fd-0cc99633cd29","f9bc0fe0-0a36-4f83-89f4-a3771514a9dc","6077de5f-ccac-47a0-a005-ddfba38722de","ad09b234-df7d-477f-9d60-0bba05c78e00","f2ca38d0-1372-496f-88bf-b763800dd63c"],"properties":[["name","Rundll32"],["tactic_id","TA0005"],["tactic_ref","x-mitre-tactic--78b23412-0651-46d7-a540-170a1ce8bd5a"],["technique_id","T1218.011"],["technique_ref","attack-pattern--045d0922-2310-4e60-b5e4-3302302cb3c5"],["description","Used for executing DLL files"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"4c9d6521-a65b-4982-8c61-f03fd1494615","x":1510,"y":330,"attrs":256,"template":"action","children":["a1d13510-fecb-480a-a2bb-96daf63513e3","377e4013-15f0-4870-9dba-e6ff838d0933","44a7f41f-de43-489c-936a-ef8cd3e738a6","d9f604de-ae2b-40e6-8827-30ee0c367d36","9599c994-2f1f-4929-8dc2-12bcd117cadd","b0cc849c-0808-46bc-a24a-890691e0e2ed","e15d8996-8b41-46ea-921f-882fde290ec0","19ec930f-9c59-42f9-b2de-9a526a6c1e0a","e2a3006b-7895-4068-9028-fdc1a217815d","f2559513-900e-4ad1-8d08-1694a8ca9ca8","d495a768-4538-4934-b4c4-a42c19252df6","9d63136a-c241-401a-a6ae-22caaa892b62"],"properties":[["name","Ingress Tool Transfer"],["tactic_id","OB0004"],["tactic_ref",null],["technique_id","E1105"],["technique_ref",null],["description",null],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"eb5ca1e6-a396-4040-8318-436c3cce18e8","x":190,"y":-280,"attrs":256,"template":"action","children":["783b9f5a-8e9f-4cea-8035-05e5cd10c7ef","094a356c-c57f-419e-b1c2-976d364bc90a","27250747-ab95-4723-a805-d3f2901bc013","44b72ec9-21df-4504-85c7-1dccfea1e39a","56c71c33-b6d8-4a20-aaf8-4cab78290555","e872bd92-662b-415c-805d-b43cbd41fec5","4e6af9ba-c936-4414-8884-7df09efb8b0e","d5731b34-9b7f-4df6-b7a9-90adf1592269","7c8fbba6-8264-41ba-a722-0d6fe8402a2a","077ba8da-a8b0-4a0b-8de5-fe1f7f70cd25","856840e8-f134-47c0-9e7a-3d07f500bf11","a01ac678-3287-4e60-bf1c-90a66e77c91a"],"properties":[["name","Executable Code Obfuscation"],["tactic_id","OB0002"],["tactic_ref",null],["technique_id","B0032"],["technique_ref",null],["description","File is obfuscated as demonstrated in the report"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"daf58001-205f-4454-a2df-b49bdda29205","x":-160,"y":-180,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["ac1aa249-fc6f-48ea-9b66-d2b73cec2899","b4420a5a-3b18-4358-9efc-52096005907f","dcbaf37a-cc65-4a1e-babc-669bc4594b21"],"properties":[]},{"id":"11f4d871-cc16-4e49-b4b1-528b361d9415","x":190,"y":10,"attrs":256,"template":"file","children":["7638849c-3389-4e79-ae6f-8a0b433865e3","6ae27ead-fb88-4349-8fce-1b3f5c5ab228","d535d46f-5cab-4e3c-90b7-345478be5bb5","527b30f1-5db0-48fb-979a-8441cb9d3de2","af859ab9-351d-4594-a134-b6e13d9558ca","22b26fc0-1288-476c-9ed4-29b8458c18cc","6876fb7f-f0a0-4662-922c-a544da72b91f","b1c4f6b0-41ca-4a0b-9881-17932006cdd8","3f05cd4e-9d1b-42b5-9bf7-d38dc8c85623","bd967aa2-16a4-4d39-9534-785f25038eeb","17cea2a6-d58f-4823-a0fb-e44d85f9d10e","c4ed9bb2-b0d7-4c6d-b8d0-868402920f3d"],"properties":[["name","Twelfth.bat"],["name_enc",null],["size",null],["hashes",[]],["magic_number_hex",null],["mime_type",null],["ctime",null],["mtime",null],["atime",null]]},{"id":"f4c87cd1-9231-489e-8900-b0c1e6b77c31","x":58,"y":10,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["7214ee1a-9d50-449f-8eaa-1f7932414cad","4e17922d-c65c-4df3-9175-c374cdd9061b","56a96f46-6a64-4593-98b7-d86e8ef7521d"],"properties":[]},{"id":"df03a9d4-8a01-45b2-92eb-1038890c4163","x":190,"y":-91,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["873aa7a0-5938-4760-983a-c3b20fda0ffe","0bf73c29-08b2-4eb3-82aa-2473779c7ea4","21159bc4-a773-47c1-a3b2-f2bb12cd1e82"],"properties":[]},{"id":"1c8faaae-3d55-49ed-ba8d-e56f72d736bd","x":540,"y":10,"attrs":256,"template":"action","children":["9ab339ad-1986-44e8-963f-130709312a33","3fe9baf9-d6e2-464c-821f-6766f2d7a282","c6c01fd6-ad71-4bd2-89f4-227e88f47999","67fdb6e0-d3fa-443b-9834-8713e915d3b9","a530482d-6f2a-4006-b7b3-0635ac221c68","685dd278-2c1c-48a0-bb01-7bd52d34a053","5effe57d-f818-49d1-af23-f89cdf530877","fb7c03de-727e-4faf-96c4-a72844a68f10","f4fb688d-466d-4268-97ee-58b9eb3cc168","7e068f33-46b5-4864-9659-7d36a91556d0","7e480d79-765a-4831-8c61-52b4e8ea6669","7b96282f-45b1-4cb4-aacb-a194d37a10e9"],"properties":[["name","Command and Scripting Interpreter"],["tactic_id","OB0009"],["tactic_ref",null],["technique_id","E1059"],["technique_ref",null],["description","bat file uses cmd.exe for executing further commands"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"4d554511-0707-45f2-b2e6-f3c89792f3f2","x":314,"y":10,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["41b96581-324e-4a04-9780-0a1d322c3984","e87e7feb-5a9b-45e7-8ecf-bce5bf83fae1","bcc949c2-08ea-49f2-9121-ef48aa1f9c10"],"properties":[]},{"id":"bae7ae51-0d92-4bcd-b0a1-8176fe231f3c","x":1150,"y":330,"attrs":256,"template":"action","children":["44da9834-70aa-4a69-b227-5bb206f2b33d","51bf591e-4d23-450c-bd96-1164f38cb3a4","90f438ff-0f12-4d66-b19d-86f81f99eadc","bd6e81f1-9398-4a68-9f40-d4b044ce4699","0a1ee9f5-dd9e-4077-a364-08e6dad2b9e0","7cbefbbe-eaee-4cba-852e-59fa10a8280d","adba6c5b-aabe-4d74-a67b-91581eccf4fa","c2f12ab6-bb13-4db1-bb5f-498b31ffdbf3","9a39f42b-6e94-43b9-b1be-8a300597eb34","d872a344-4230-4b17-9ce4-60378fde26cd","6ccf5b85-14a2-4fd0-bba1-8072c695246d","0fc45985-828e-40c3-8cca-f4657b151437"],"properties":[["name","Connect to Server"],["tactic_id","OC0006"],["tactic_ref",null],["technique_id","C0002.009"],["technique_ref",null],["description","connects to chronofire[.]info"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"cb9eccb5-8a52-4ef1-a93c-cbdbe9adda42","x":1332,"y":330,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["efd70d61-a05b-4dd2-a793-9110ccda9505","851132ea-c331-4c3c-bd99-3b1a4745d4df","43b758fb-a6df-4495-bd28-436afb0cfd97"],"properties":[]},{"id":"bce4df0c-1803-4c08-b8b6-394e266ff38d","x":850,"y":10,"attrs":256,"template":"action","children":["b206cab7-464b-48c7-b0bf-9f028f58f155","bee032c3-2cef-4fc2-89f8-bb87dde4b567","6a678413-79f0-4e95-a185-befab7f968d3","26bb6d28-36d0-4c73-83e5-02fe8bf005e9","af80750a-3724-46af-8b66-58863158777f","6e1099c0-480f-47bc-b0a5-eca32b80bc5a","555f94f5-df0f-4bf6-a52b-2ae04c4aeaf6","7540dedd-7774-49a9-bf90-08adbe31286d","834a53aa-8331-464e-970a-b920dc43257c","6eaacadc-8685-4ee6-a97f-4994eda5b8ca","53389c52-0d53-4eb8-a673-93412ab273f2","3e1c4ebc-277a-4c28-b289-f5fc56ee334c"],"properties":[["name","Copy File"],["tactic_id","OC0001"],["tactic_ref",null],["technique_id","C0045"],["technique_ref",null],["description","Uses xcopy.exe"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"c8955375-12ea-4fd6-abac-1f6e8d42fecd","x":745,"y":10,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["62e2d4e5-0e08-4589-a628-45f997d26a86","8caf49ab-2e63-4c79-b81d-7e38be288c6c","b00d57a7-1318-4671-b2b3-d72258b3395e"],"properties":[]},{"id":"7c98425a-58bf-4af5-86db-6a27b3c2f7d8","x":979,"y":10,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["88af77bd-c6f4-4aaf-a246-480879a388ea","dd8c2c90-cef4-421c-821f-8af83908d88e","240c66f7-4fd2-4570-9aa6-da1df0420afe"],"properties":[]},{"id":"c15548fd-3f78-41c1-88ce-b9b7ef361170","x":1730,"y":330,"attrs":256,"template":"action","children":["2e1fd942-c01f-4dcc-b795-fc0714887a1b","21545074-3048-4037-869e-524bdae1d8d0","91a12caf-eb40-442b-a107-c1c7b7fced09","8e682089-11f2-4c01-8c19-088511330453","aa0e37e5-5fac-4e77-b908-53d1eb2f34d3","a28a5750-5f7a-41cd-8466-ddc433d911fd","8c22a104-bbc5-40ee-9979-8897ffe63cf2","eb3bd9ba-2eb4-48f6-b620-473ba48762be","83b2b75d-4e61-458d-af84-5fe78c750f85","c9e00d76-5a41-4279-afcd-6a7d4436d2c6","8986c539-6583-4e80-ac89-634bb712a5cb","28df64f3-1bf2-4e7a-aeb1-fbafba7f60cb"],"properties":[["name","Rundll32"],["tactic_id","TA0005"],["tactic_ref","x-mitre-tactic--78b23412-0651-46d7-a540-170a1ce8bd5a"],["technique_id","T1218.011"],["technique_ref","attack-pattern--045d0922-2310-4e60-b5e4-3302302cb3c5"],["description",null],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"eb109108-56ac-46e5-9d85-692afaa28a68","x":2080,"y":500,"attrs":256,"template":"action","children":["5121adfd-1832-4761-8b53-fec8d1192088","1da567be-56d4-4138-b461-30e3c8b1c8b5","4d60e77b-8c66-4a48-b5b0-40bfebbe289a","63d33455-9cad-44e5-873f-bb8d1d8c489f","caa92854-bf6a-4c08-94ba-fed5c8490ffb","6f2f5d74-9b75-40dc-9f3a-cbf3bcb7c789","4dc86db1-2400-4263-ad0f-d2c8f8bd0347","9b6d65fa-bc98-4509-bac9-681ab9d2c31b","a831dcc1-29db-480f-9d61-87f4e57dbad7","b5b98f85-46b2-42d1-8630-7d1d4ec3a705","68e47794-fe37-4c5f-a106-cb628afddc4b","2874d8fa-db64-4b0e-8e65-08258fa8b03d"],"properties":[["name","Decrypt Data"],["tactic_id","OC0005"],["tactic_ref",null],["technique_id","C0031"],["technique_ref",null],["description","Decryption key is file provided in initial archive"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"1e68a3cc-7581-4df0-8057-e95770fa9602","x":1646,"y":330,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["f722c497-49b7-4e12-a482-7a23417904d9","c845ac89-d766-42d9-8aaf-aad76c1060a8","d87a57e0-46c3-4923-bad6-7eb163444853"],"properties":[]},{"id":"8814dbd7-b9c9-41a8-87f8-2a00c57d1d85","x":2080,"y":210,"attrs":256,"template":"action","children":["add8ad2d-93d4-4880-8a4d-93b4ff3ae627","b6ab5c88-7646-4d33-8e54-d88d8b47d1ae","bf9ec950-90f6-41ca-be84-fd59c9ba6882","7c56a4f1-b07c-413f-9cd1-4655e8827041","0ed74e9e-519d-4e3d-9517-739a0934b2fc","659fff72-eeeb-4fb2-a065-6f9af0c397c5","267bccda-1b8c-418e-b77c-2b92eb6e138c","0cf649fc-b4a0-4fe3-b851-942473304835","1e4881ad-8cbb-4172-a867-8c24ab4f3f2b","f4432c0f-047e-45ce-9552-f2fbd2953cdd","9b018fa8-a346-4925-a6c5-d0e3ddeea305","d05676a0-1547-463c-9644-9a924c474707"],"properties":[["name","Scheduled Task"],["tactic_id","TA0003"],["tactic_ref","x-mitre-tactic--5bc1d813-693e-4823-9961-abf9af4b0e92"],["technique_id","T1053.005"],["technique_ref","attack-pattern--005a06c6-14bf-4118-afa0-ebcd8aebb0c9"],["description","Executes xaeywn1.dll at every logon and every hour"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"5e395ad7-7b62-4876-b26c-2de21d8db034","x":2820,"y":210,"attrs":256,"template":"action","children":["883f65b9-cf1d-4c0f-9ea5-657993dab3ec","ebba230f-451f-47fa-a2ba-783a5fdd5162","fa256366-94d4-403d-b17d-d3844c0d1822","a6fdaeeb-c8a0-49c3-a399-dd8ec3ea4f68","87ec7161-23ba-49f2-b707-fa024947c77a","aa842de2-89f7-4369-8ca2-6618c059a0e1","de3a5a3d-74fc-4a51-bf2f-67b29b4ec9bc","17437ec2-59ff-4ebb-b12f-59040385bf5e","af350aa2-10b0-4ed6-a119-ee69a22bbf51","a27c8bef-0c72-4a88-94da-8d9f543355df","ca2f7211-e1d2-4b29-8f47-d9ea18421490","df9f939d-4213-4ecc-ab86-b8f35e93e409"],"properties":[["name","Connect to Server"],["tactic_id","OC0006"],["tactic_ref",null],["technique_id","C0002.009"],["technique_ref",null],["description","Domains observed were known to be connected to icedID"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"88bd84e5-e3b0-4dff-863e-5fedb8f4dc28","x":3280,"y":210,"attrs":256,"template":"action","children":["beb0bc0f-59fe-42ad-9ea7-aaa558c9be03","53731b44-d9e2-4073-a383-61e9408084c8","be65b92e-64f0-4c68-8de7-a73a3ac8baa2","1e4b5342-10b4-42c1-9373-5692f12f5c16","27c836d7-dd9f-49dc-8a4d-5c94d4e63fdb","63d9205a-853d-4b38-9b0d-3a039fce23ec","1d93968b-e6f9-491a-96c3-96967a51bf26","6bfb18c9-324d-4e97-95c2-cb218e6cf977","a99bba3f-c74f-4d42-9106-1eaed19f2081","d2983d92-fbe5-446a-9dfa-90fd0b2c8a69","8418c143-2010-4c50-943f-01fa6b836c60","80088a3a-e897-4cdb-8f86-50cb10e4339e"],"properties":[["name","Execute Shell Command"],["tactic_id","OB0004"],["tactic_ref",null],["technique_id","B0030.016"],["technique_ref",null],["description","Interactive remote shell session starts. Attacker uses this to manually control malware."],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"b9172571-156f-4389-9a09-e5d298fe77b6","x":3050,"y":210,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["9a30922a-3b2c-4a0c-992a-654a114c610f","0a02cbc8-0147-4daa-8700-67db787c0179","0940b535-1f7a-466e-946f-1584bc61fe90"],"properties":[]},{"id":"01b76ff0-5e05-491d-b188-94e3ecea47f8","x":850,"y":-230,"attrs":256,"template":"file","children":["373d058e-6d9d-4479-8b6d-4793576f8b8f","c500ab2c-ea28-4087-bcb6-6d023e43531f","8c954d7e-3ccd-4522-9e88-7475df55cd5a","0a9e00d1-160d-43f3-97a2-c03c19993d2f","d35c457a-8dad-4185-b305-100b55fedee5","610ac0e0-104b-4559-b7b5-4ef9d8c9bd61","267ed779-4ce7-4179-ad63-c18db15bb7e6","26f8e48d-2d9d-4bbb-a60a-655389f884c0","7a69e832-458e-41d4-bebb-1b085cdd6bfa","d6b6ee86-2365-44f7-a351-7be051d28446","368423d7-cd3d-4f7a-8d03-1f85ca61829d","ab1abd5b-87e8-4b06-9d30-9211e70c334c"],"properties":[["name","superstring.dll"],["name_enc",null],["size",null],["hashes",[]],["magic_number_hex",null],["mime_type",null],["ctime",null],["mtime",null],["atime",null]]},{"id":"659602d1-d017-490b-8e31-68b567baa7ec","x":1150,"y":-230,"attrs":256,"template":"file","children":["a2abe9d3-04e4-4d94-b9d4-9ee15c870077","56b29b6b-7024-4494-b5a9-3ffa618a0a23","76a536e8-8d0c-4cfd-99f0-61ea575ac216","979d8a2e-0034-455b-9e30-1c06413fada5","fe4bcf64-000d-4612-9544-b232fee2faa3","6e6773d5-533b-4204-9fd0-08b478c0ef63","9994acca-3cc1-4e54-b056-cf0447ebb445","bb1287ad-30aa-4611-bc2c-5960f8111896","7ad0b954-345b-4cc8-8be5-3f9843372351","b5f8ea39-9c3e-4989-a38a-1831185130b2","c47b4d74-2592-4877-9104-d481047e7e88","be67fe05-2ce2-487c-a52b-1b16a91e33c1"],"properties":[["name","%TEMP%\\homesteading.dll"],["name_enc",null],["size",null],["hashes",[]],["magic_number_hex",null],["mime_type",null],["ctime",null],["mtime",null],["atime",null]]},{"id":"e91caa3d-6050-4df6-9428-dafc5415c8e4","x":1620,"y":110,"attrs":256,"template":"file","children":["4f743274-bbcc-43bb-a7b7-6f704aebed9a","058525c5-c00f-414a-8791-4f943f543fd1","7357d55f-5fb1-44e8-b73c-f87193714aed","35ba6f19-907d-457e-815e-29849dbcc9a7","8bc31c6e-8e92-4eff-9bbd-5cd684f2c88c","a0f44fdc-56e6-47c2-9eeb-4c6345535d87","63bad3f5-7bda-4895-9d7a-f504c9c5ed3f","3f9ecb7f-708c-4ae2-a85f-5bfac3416f6d","f55ba817-651a-4c04-a0d3-62b82d00b970","6e2fd412-bbc1-47cb-9b8b-ca6b9bda8075","4e29da8d-3d77-4368-8183-0c56097d5d90","ea7165ce-ec45-4e35-a3ef-a8d7ed51b0be"],"properties":[["name","xaeywn1.dll"],["name_enc",null],["size",null],["hashes",[]],["magic_number_hex",null],["mime_type",null],["ctime",null],["mtime",null],["atime",null]]},{"id":"e28bdaf7-eca6-439b-b14e-911193d0b45b","x":973,"y":-230,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["a3dc20f1-5ffb-4ed5-aa2f-65e3042e94c9","ab4ffd40-1088-4e89-9430-15f41f8f934d","dee6608b-84b3-4b92-bb2d-11d35fb4fda9"],"properties":[]},{"id":"74fd5e7e-5861-46f1-a70f-da764935216f","x":1547,"y":189,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["6f8a5623-cb66-4aa0-9b55-a2fd84f3614d","e79a3e71-eb7b-45fb-8c70-556f639a7c20","542b920b-a40c-4419-82e1-68e128caaddc"],"properties":[]},{"id":"9701c1ba-d1e1-4ed7-a7d8-e3b957a4b058","x":1848,"y":270,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["7595c16b-bbae-4f52-8669-cb84748c8cb7","cfe15f9f-476f-4ee5-b826-543a6db37776","0b91d49f-92d4-488c-8331-7a092b5c6e9f"],"properties":[]},{"id":"9ec1e943-a76c-49ec-8a3d-b706eed5238e","x":2440,"y":500,"attrs":256,"template":"file","children":["d05fbbae-a25a-485d-a2fa-55d96e5f5fff","bed01324-1a1e-435e-9716-dcb2bc3f3dd1","f44f5fd4-e39d-4f1a-821e-9321526e3a30","28bbbba8-942b-449f-a713-17573c0522a8","4c43008b-21c3-4eeb-b020-764e937fc186","dbb0ddcb-46e9-4f8c-83ec-c712a298295b","1d20b45a-7673-490f-acef-f6a4a6c212a7","17a2c343-0d51-4a5d-83da-ec9b02af2d7a","8a5cc185-cb64-45ff-92ec-a7ed633a08a0","9f3cdedc-5b62-407c-9b3b-821dc8ad7050","4829b397-34cf-4a35-b0a1-90027f297e80","ff3b9aa2-9a6e-4e0b-b019-e15b26fdf662"],"properties":[["name","init_dll_64.dll"],["name_enc",null],["size",null],["hashes",[]],["magic_number_hex",null],["mime_type",null],["ctime",null],["mtime",null],["atime",null]]},{"id":"b910993b-d9ca-4f31-a058-ab7df512e665","x":2308,"y":500,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["0065a2f8-1695-4d6c-ae71-d9f36396fc85","941ec677-a015-4372-9c80-327c97b4b129","fae91b3e-a8c9-4b2d-89bd-6e4f2193a69a"],"properties":[]},{"id":"a690f62f-30c3-4c78-a460-0779d8893282","x":2440,"y":210,"attrs":256,"template":"action","children":["97314864-ae41-4a74-946f-98592a9bda9f","693b9900-ab28-43d8-98b9-7b5c649e4eb5","62d78c58-b18b-4508-afe0-1c456225bccd","6cb53cb3-a662-4c9d-b665-685fd462f572","c1f3eb59-dfc9-4411-976e-53fe9de8c874","8a97d6bc-569c-4bb6-b458-514d5010be03","b9c8bbb6-dcac-445e-bd86-adbcc45d71ca","64868270-251d-4fc5-857f-3ce3423cdd1b","81a35401-1c0b-4938-9a54-946692c28bee","16b3fafc-d65a-4c19-9ae8-1b200ac77d60","316ae5cd-b669-49fe-8198-6597657ee1ed","e48fe231-3d09-4c82-9712-e92d0644ebde"],"properties":[["name","Rundll32"],["tactic_id","TA0005"],["tactic_ref","x-mitre-tactic--78b23412-0651-46d7-a540-170a1ce8bd5a"],["technique_id","T1218.011"],["technique_ref","attack-pattern--045d0922-2310-4e60-b5e4-3302302cb3c5"],["description",null],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"e7ee4edf-9827-48b2-bef7-4912973ec1f9","x":2317,"y":210,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["8059c255-5733-4b97-b0c4-e1ccbe37b73a","75380a2b-5118-4890-b005-4de9f7d0493c","da01b0c3-b2b3-41a4-9e41-3e8855f3581a"],"properties":[]},{"id":"49f52317-8552-4d5c-b4fa-85fd6d5c4243","x":2569,"y":210,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["f8f9ce97-34cc-4f96-a5bc-64f17321f21e","36628238-7606-48e9-bb30-fa302b62042a","8c723b2e-ada7-4d74-8ef9-6f8461c90306"],"properties":[]},{"id":"39e09e78-6046-4979-abd3-4cc2e65d8246","x":1150,"y":170,"attrs":256,"template":"@__builtin__line_vertical_elbow","children":["44ed8728-2d47-4aef-b326-cdf28dd4fee5","81c63741-d718-42cd-9f34-a5c3a263ddbd","4112003f-3034-4393-b507-97c109427ed0"],"properties":[]},{"id":"451190ba-a29b-4426-9b99-3b098d0284ed","x":850,"y":-153,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["0164dfb2-da1e-4c22-b895-a93e624be99a","a847dada-8418-4406-94da-060334073172","4675480a-c60e-4ff6-9595-e185ae402d42"],"properties":[]},{"id":"c0c55d0d-b281-4fdc-8af5-5aada501b724","x":1150,"y":-153,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["b2c2aec1-0506-4a6f-8d38-17ab1679e95c","35640775-b987-478f-aae0-99d67c381579","a5ff4647-ef77-4150-9394-a908b2703d43"],"properties":[]},{"id":"d0f0dead-bbb7-459b-847d-7ca4d51bf67a","x":1692,"y":189,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["822c0981-85ce-42a7-a51a-7ae0a98b1bc1","adbaa7c0-f728-4de3-82ae-bf60d1b7bdb8","ccc404ac-ff76-4587-ae52-d37466f2071a"],"properties":[]},{"id":"efbca724-bd9d-4244-97ea-c6a7187b5daf","x":1848,"y":408,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["2c37e408-5a77-4c3f-b9de-c2910e78ccda","0809ad1e-e5f3-42a8-b00a-10b5125bd60f","5dc82c9e-454c-4ca1-986c-a3c05d47956e"],"properties":[]},{"id":"6bf54f23-e1e3-49b6-9d31-d7df55e9dd69","x":2440,"y":385,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["5b605dff-8f5b-47df-a599-556753aa8a2d","de519029-6101-4ec1-9ec4-416e9a97ef8e","c59a2cb2-1f99-4c34-b440-33e27a271961"],"properties":[]},{"id":"87e72020-c676-4aae-a97b-8f6b15cca459","x":-226.5,"y":-476,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"34491d09-a0d9-4384-bebc-027760ea64e4","x":-160,"y":-476,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"5ada4652-ebdf-42df-9b57-9d03401ed333","x":-93.5,"y":-476,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"693b43ce-100f-4942-9b05-161d2b3c894f","x":-27,"y":-418,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"595a67fe-b87a-426f-b519-fa6924c09b62","x":-27,"y":-360,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"3b01fd54-0c42-4f32-ba7f-c05bd72522a9","x":-27,"y":-302,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"3fdb7ff7-fc87-4064-bc21-471d510273cb","x":-93.5,"y":-243,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"5b0e36d6-af82-4e01-a4d0-c02fcb5385d4","x":-160,"y":-243,"attrs":0,"template":"@__builtin__anchor","children":["ac1aa249-fc6f-48ea-9b66-d2b73cec2899"],"properties":[],"angle":1},{"id":"a052e5a9-e198-426c-b839-49226c83721a","x":-226.5,"y":-243,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"d129d574-eded-4454-9ab6-f6d954e0f7a4","x":-293,"y":-302,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"d3bb1e25-9a94-46c1-9f51-7f620a9216bb","x":-293,"y":-360,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"8a7a46fa-86cc-4ab7-9e27-979079c1d666","x":-293,"y":-418,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"2a5a62f9-650c-458d-b5c5-58b339c8dd46","x":-238.5,"y":-117,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"69246ee1-4775-457a-b7aa-f993db68a05c","x":-160,"y":-117,"attrs":0,"template":"@__builtin__anchor","children":["dcbaf37a-cc65-4a1e-babc-669bc4594b21"],"properties":[],"angle":1},{"id":"a9fc3fa5-0888-4992-b3ab-f8c623b0976e","x":-81.5,"y":-117,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"b5e5dc9f-4460-411a-88e4-6c8f6de61590","x":-3,"y":-53.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"77e14b5e-32ab-4632-b92b-791ca8f15b7b","x":-3,"y":10,"attrs":0,"template":"@__builtin__anchor","children":["7214ee1a-9d50-449f-8eaa-1f7932414cad"],"properties":[],"angle":0},{"id":"a0bc8317-2d92-4c03-871b-3f0c4296807b","x":-3,"y":73.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"d2a9cc91-e7bf-4284-bbc4-0af662a3ef13","x":-81.5,"y":137,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"fffcaebc-ed26-4181-aac8-4f4fbc3aee09","x":-160,"y":137,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"fb381375-6f02-4826-b60e-a01b855b3982","x":-238.5,"y":137,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"d315fced-617f-470a-bbbf-e3d7185fd580","x":-317,"y":73.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"b79c4647-8788-4e55-ab9b-7f17209f6c94","x":-317,"y":10,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"ece71700-07f7-4142-9ff6-d9a98af4ebc0","x":-317,"y":-53.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"484da459-3d56-467e-94ff-e87ce03af66f","x":1093,"y":-106,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"a96d0bfc-1b0e-4292-8c41-32b6490ac636","x":1150,"y":-106,"attrs":0,"template":"@__builtin__anchor","children":["a5ff4647-ef77-4150-9394-a908b2703d43"],"properties":[],"angle":1},{"id":"7f3a6146-65cb-4a34-9cef-b2a64e84c26b","x":1207,"y":-106,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"38e5c867-a5b8-4a29-9d25-b485d0c992d1","x":1264,"y":-48,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"304f07d5-f080-49fb-8a53-72b893404702","x":1264,"y":10,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"23bad78d-15a1-42a2-adf1-5351776c47fe","x":1264,"y":68,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"1d203e8b-a87a-4206-bb96-0a68e7b9b541","x":1207,"y":127,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"daa7f16d-b296-4cf8-90fd-0cc99633cd29","x":1150,"y":127,"attrs":0,"template":"@__builtin__anchor","children":["44ed8728-2d47-4aef-b326-cdf28dd4fee5"],"properties":[],"angle":1},{"id":"f9bc0fe0-0a36-4f83-89f4-a3771514a9dc","x":1093,"y":127,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"6077de5f-ccac-47a0-a005-ddfba38722de","x":1036,"y":68,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"ad09b234-df7d-477f-9d60-0bba05c78e00","x":1036,"y":10,"attrs":0,"template":"@__builtin__anchor","children":["240c66f7-4fd2-4570-9aa6-da1df0420afe"],"properties":[],"angle":0},{"id":"f2ca38d0-1372-496f-88bf-b763800dd63c","x":1036,"y":-48,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a1d13510-fecb-480a-a2bb-96daf63513e3","x":1454.5,"y":240,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"377e4013-15f0-4870-9dba-e6ff838d0933","x":1510,"y":240,"attrs":0,"template":"@__builtin__anchor","children":["6f8a5623-cb66-4aa0-9b55-a2fd84f3614d"],"properties":[],"angle":1},{"id":"44a7f41f-de43-489c-936a-ef8cd3e738a6","x":1565.5,"y":240,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"d9f604de-ae2b-40e6-8827-30ee0c367d36","x":1622,"y":285,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"9599c994-2f1f-4929-8dc2-12bcd117cadd","x":1622,"y":330,"attrs":0,"template":"@__builtin__anchor","children":["f722c497-49b7-4e12-a482-7a23417904d9"],"properties":[],"angle":0},{"id":"b0cc849c-0808-46bc-a24a-890691e0e2ed","x":1622,"y":375,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"e15d8996-8b41-46ea-921f-882fde290ec0","x":1565.5,"y":421,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"19ec930f-9c59-42f9-b2de-9a526a6c1e0a","x":1510,"y":421,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"e2a3006b-7895-4068-9028-fdc1a217815d","x":1454.5,"y":421,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"f2559513-900e-4ad1-8d08-1694a8ca9ca8","x":1399,"y":375,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"d495a768-4538-4934-b4c4-a42c19252df6","x":1399,"y":330,"attrs":0,"template":"@__builtin__anchor","children":["43b758fb-a6df-4495-bd28-436afb0cfd97"],"properties":[],"angle":0},{"id":"9d63136a-c241-401a-a6ae-22caaa892b62","x":1399,"y":285,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"783b9f5a-8e9f-4cea-8035-05e5cd10c7ef","x":100,"y":-397,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"094a356c-c57f-419e-b1c2-976d364bc90a","x":190,"y":-397,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"27250747-ab95-4723-a805-d3f2901bc013","x":280,"y":-397,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"44b72ec9-21df-4504-85c7-1dccfea1e39a","x":370,"y":-338.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"56c71c33-b6d8-4a20-aaf8-4cab78290555","x":370,"y":-280,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"e872bd92-662b-415c-805d-b43cbd41fec5","x":370,"y":-221.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"4e6af9ba-c936-4414-8884-7df09efb8b0e","x":280,"y":-163,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"d5731b34-9b7f-4df6-b7a9-90adf1592269","x":190,"y":-163,"attrs":0,"template":"@__builtin__anchor","children":["873aa7a0-5938-4760-983a-c3b20fda0ffe"],"properties":[],"angle":1},{"id":"7c8fbba6-8264-41ba-a722-0d6fe8402a2a","x":100,"y":-163,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"077ba8da-a8b0-4a0b-8de5-fe1f7f70cd25","x":10,"y":-221.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"856840e8-f134-47c0-9e7a-3d07f500bf11","x":10,"y":-280,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a01ac678-3287-4e60-bf1c-90a66e77c91a","x":10,"y":-338.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"ac1aa249-fc6f-48ea-9b66-d2b73cec2899","x":-160,"y":-243,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"b4420a5a-3b18-4358-9efc-52096005907f","x":-160,"y":-180,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"dcbaf37a-cc65-4a1e-babc-669bc4594b21","x":-160,"y":-117,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"7638849c-3389-4e79-ae6f-8a0b433865e3","x":155,"y":-19,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"6ae27ead-fb88-4349-8fce-1b3f5c5ab228","x":190,"y":-19,"attrs":0,"template":"@__builtin__anchor","children":["21159bc4-a773-47c1-a3b2-f2bb12cd1e82"],"properties":[],"angle":1},{"id":"d535d46f-5cab-4e3c-90b7-345478be5bb5","x":225,"y":-19,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"527b30f1-5db0-48fb-979a-8441cb9d3de2","x":261,"y":-4.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"af859ab9-351d-4594-a134-b6e13d9558ca","x":261,"y":10,"attrs":0,"template":"@__builtin__anchor","children":["41b96581-324e-4a04-9780-0a1d322c3984"],"properties":[],"angle":0},{"id":"22b26fc0-1288-476c-9ed4-29b8458c18cc","x":261,"y":24.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"6876fb7f-f0a0-4662-922c-a544da72b91f","x":225,"y":40,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"b1c4f6b0-41ca-4a0b-9881-17932006cdd8","x":190,"y":40,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"3f05cd4e-9d1b-42b5-9bf7-d38dc8c85623","x":155,"y":40,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"bd967aa2-16a4-4d39-9534-785f25038eeb","x":120,"y":24.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"17cea2a6-d58f-4823-a0fb-e44d85f9d10e","x":120,"y":10,"attrs":0,"template":"@__builtin__anchor","children":["56a96f46-6a64-4593-98b7-d86e8ef7521d"],"properties":[],"angle":0},{"id":"c4ed9bb2-b0d7-4c6d-b8d0-868402920f3d","x":120,"y":-4.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"7214ee1a-9d50-449f-8eaa-1f7932414cad","x":-3,"y":10,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"4e17922d-c65c-4df3-9175-c374cdd9061b","x":58.5,"y":10,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"56a96f46-6a64-4593-98b7-d86e8ef7521d","x":120,"y":10,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"873aa7a0-5938-4760-983a-c3b20fda0ffe","x":190,"y":-163,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"0bf73c29-08b2-4eb3-82aa-2473779c7ea4","x":190,"y":-91,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"21159bc4-a773-47c1-a3b2-f2bb12cd1e82","x":190,"y":-19,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"9ab339ad-1986-44e8-963f-130709312a33","x":453.5,"y":-117,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"3fe9baf9-d6e2-464c-821f-6766f2d7a282","x":540,"y":-117,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c6c01fd6-ad71-4bd2-89f4-227e88f47999","x":626.5,"y":-117,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"67fdb6e0-d3fa-443b-9834-8713e915d3b9","x":713,"y":-53.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a530482d-6f2a-4006-b7b3-0635ac221c68","x":713,"y":10,"attrs":0,"template":"@__builtin__anchor","children":["62e2d4e5-0e08-4589-a628-45f997d26a86"],"properties":[],"angle":0},{"id":"685dd278-2c1c-48a0-bb01-7bd52d34a053","x":713,"y":73.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"5effe57d-f818-49d1-af23-f89cdf530877","x":626.5,"y":137,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"fb7c03de-727e-4faf-96c4-a72844a68f10","x":540,"y":137,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"f4fb688d-466d-4268-97ee-58b9eb3cc168","x":453.5,"y":137,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"7e068f33-46b5-4864-9659-7d36a91556d0","x":367,"y":73.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"7e480d79-765a-4831-8c61-52b4e8ea6669","x":367,"y":10,"attrs":0,"template":"@__builtin__anchor","children":["bcc949c2-08ea-49f2-9121-ef48aa1f9c10"],"properties":[],"angle":0},{"id":"7b96282f-45b1-4cb4-aacb-a194d37a10e9","x":367,"y":-53.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"41b96581-324e-4a04-9780-0a1d322c3984","x":261,"y":10,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"e87e7feb-5a9b-45e7-8ecf-bce5bf83fae1","x":314,"y":10,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"bcc949c2-08ea-49f2-9121-ef48aa1f9c10","x":367,"y":10,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"44da9834-70aa-4a69-b227-5bb206f2b33d","x":1092.5,"y":214,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"51bf591e-4d23-450c-bd96-1164f38cb3a4","x":1150,"y":214,"attrs":0,"template":"@__builtin__anchor","children":["4112003f-3034-4393-b507-97c109427ed0"],"properties":[],"angle":1},{"id":"90f438ff-0f12-4d66-b19d-86f81f99eadc","x":1207.5,"y":214,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"bd6e81f1-9398-4a68-9f40-d4b044ce4699","x":1265,"y":272,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"0a1ee9f5-dd9e-4077-a364-08e6dad2b9e0","x":1265,"y":330,"attrs":0,"template":"@__builtin__anchor","children":["efd70d61-a05b-4dd2-a793-9110ccda9505"],"properties":[],"angle":0},{"id":"7cbefbbe-eaee-4cba-852e-59fa10a8280d","x":1265,"y":388,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"adba6c5b-aabe-4d74-a67b-91581eccf4fa","x":1207.5,"y":447,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c2f12ab6-bb13-4db1-bb5f-498b31ffdbf3","x":1150,"y":447,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"9a39f42b-6e94-43b9-b1be-8a300597eb34","x":1092.5,"y":447,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"d872a344-4230-4b17-9ce4-60378fde26cd","x":1035,"y":388,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"6ccf5b85-14a2-4fd0-bba1-8072c695246d","x":1035,"y":330,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"0fc45985-828e-40c3-8cca-f4657b151437","x":1035,"y":272,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"efd70d61-a05b-4dd2-a793-9110ccda9505","x":1265,"y":330,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"851132ea-c331-4c3c-bd99-3b1a4745d4df","x":1332,"y":330,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"43b758fb-a6df-4495-bd28-436afb0cfd97","x":1399,"y":330,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"b206cab7-464b-48c7-b0bf-9f028f58f155","x":814,"y":-106,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"bee032c3-2cef-4fc2-89f8-bb87dde4b567","x":850,"y":-106,"attrs":0,"template":"@__builtin__anchor","children":["0164dfb2-da1e-4c22-b895-a93e624be99a"],"properties":[],"angle":1},{"id":"6a678413-79f0-4e95-a185-befab7f968d3","x":886,"y":-106,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"26bb6d28-36d0-4c73-83e5-02fe8bf005e9","x":923,"y":-48,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"af80750a-3724-46af-8b66-58863158777f","x":923,"y":10,"attrs":0,"template":"@__builtin__anchor","children":["88af77bd-c6f4-4aaf-a246-480879a388ea"],"properties":[],"angle":0},{"id":"6e1099c0-480f-47bc-b0a5-eca32b80bc5a","x":923,"y":68,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"555f94f5-df0f-4bf6-a52b-2ae04c4aeaf6","x":886,"y":127,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"7540dedd-7774-49a9-bf90-08adbe31286d","x":850,"y":127,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"834a53aa-8331-464e-970a-b920dc43257c","x":814,"y":127,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"6eaacadc-8685-4ee6-a97f-4994eda5b8ca","x":778,"y":68,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"53389c52-0d53-4eb8-a673-93412ab273f2","x":778,"y":10,"attrs":0,"template":"@__builtin__anchor","children":["b00d57a7-1318-4671-b2b3-d72258b3395e"],"properties":[],"angle":0},{"id":"3e1c4ebc-277a-4c28-b289-f5fc56ee334c","x":778,"y":-48,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"62e2d4e5-0e08-4589-a628-45f997d26a86","x":713,"y":10,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"8caf49ab-2e63-4c79-b81d-7e38be288c6c","x":745.5,"y":10,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"b00d57a7-1318-4671-b2b3-d72258b3395e","x":778,"y":10,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"88af77bd-c6f4-4aaf-a246-480879a388ea","x":923,"y":10,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"dd8c2c90-cef4-421c-821f-8af83908d88e","x":979.5,"y":10,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"240c66f7-4fd2-4570-9aa6-da1df0420afe","x":1036,"y":10,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"2e1fd942-c01f-4dcc-b795-fc0714887a1b","x":1700,"y":240,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"21545074-3048-4037-869e-524bdae1d8d0","x":1730,"y":240,"attrs":0,"template":"@__builtin__anchor","children":["ccc404ac-ff76-4587-ae52-d37466f2071a"],"properties":[],"angle":1},{"id":"91a12caf-eb40-442b-a107-c1c7b7fced09","x":1760,"y":240,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"8e682089-11f2-4c01-8c19-088511330453","x":1790,"y":285,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"aa0e37e5-5fac-4e77-b908-53d1eb2f34d3","x":1790,"y":330,"attrs":0,"template":"@__builtin__anchor","children":["7595c16b-bbae-4f52-8669-cb84748c8cb7"],"properties":[],"angle":0},{"id":"a28a5750-5f7a-41cd-8466-ddc433d911fd","x":1790,"y":375,"attrs":0,"template":"@__builtin__anchor","children":["2c37e408-5a77-4c3f-b9de-c2910e78ccda"],"properties":[],"angle":0},{"id":"8c22a104-bbc5-40ee-9979-8897ffe63cf2","x":1760,"y":420,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"eb3bd9ba-2eb4-48f6-b620-473ba48762be","x":1730,"y":420,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"83b2b75d-4e61-458d-af84-5fe78c750f85","x":1700,"y":420,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c9e00d76-5a41-4279-afcd-6a7d4436d2c6","x":1670,"y":375,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"8986c539-6583-4e80-ac89-634bb712a5cb","x":1670,"y":330,"attrs":0,"template":"@__builtin__anchor","children":["d87a57e0-46c3-4923-bad6-7eb163444853"],"properties":[],"angle":0},{"id":"28df64f3-1bf2-4e7a-aeb1-fbafba7f60cb","x":1670,"y":285,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"5121adfd-1832-4761-8b53-fec8d1192088","x":1993,"y":384,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"1da567be-56d4-4138-b461-30e3c8b1c8b5","x":2080,"y":384,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"4d60e77b-8c66-4a48-b5b0-40bfebbe289a","x":2167,"y":384,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"63d33455-9cad-44e5-873f-bb8d1d8c489f","x":2254,"y":442,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"caa92854-bf6a-4c08-94ba-fed5c8490ffb","x":2254,"y":500,"attrs":0,"template":"@__builtin__anchor","children":["0065a2f8-1695-4d6c-ae71-d9f36396fc85"],"properties":[],"angle":0},{"id":"6f2f5d74-9b75-40dc-9f3a-cbf3bcb7c789","x":2254,"y":558,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"4dc86db1-2400-4263-ad0f-d2c8f8bd0347","x":2167,"y":617,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"9b6d65fa-bc98-4509-bac9-681ab9d2c31b","x":2080,"y":617,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"a831dcc1-29db-480f-9d61-87f4e57dbad7","x":1993,"y":617,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"b5b98f85-46b2-42d1-8630-7d1d4ec3a705","x":1906,"y":558,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"68e47794-fe37-4c5f-a106-cb628afddc4b","x":1906,"y":500,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"2874d8fa-db64-4b0e-8e65-08258fa8b03d","x":1906,"y":442,"attrs":0,"template":"@__builtin__anchor","children":["5dc82c9e-454c-4ca1-986c-a3c05d47956e"],"properties":[],"angle":0},{"id":"f722c497-49b7-4e12-a482-7a23417904d9","x":1622,"y":330,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"c845ac89-d766-42d9-8aaf-aad76c1060a8","x":1646,"y":330,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"d87a57e0-46c3-4923-bad6-7eb163444853","x":1670,"y":330,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"add8ad2d-93d4-4880-8a4d-93b4ff3ae627","x":1993,"y":84,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"b6ab5c88-7646-4d33-8e54-d88d8b47d1ae","x":2080,"y":84,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"bf9ec950-90f6-41ca-be84-fd59c9ba6882","x":2167,"y":84,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"7c56a4f1-b07c-413f-9cd1-4655e8827041","x":2255,"y":147,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"0ed74e9e-519d-4e3d-9517-739a0934b2fc","x":2255,"y":210,"attrs":0,"template":"@__builtin__anchor","children":["8059c255-5733-4b97-b0c4-e1ccbe37b73a"],"properties":[],"angle":0},{"id":"659fff72-eeeb-4fb2-a065-6f9af0c397c5","x":2255,"y":273,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"267bccda-1b8c-418e-b77c-2b92eb6e138c","x":2167,"y":336,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"0cf649fc-b4a0-4fe3-b851-942473304835","x":2080,"y":336,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"1e4881ad-8cbb-4172-a867-8c24ab4f3f2b","x":1993,"y":336,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"f4432c0f-047e-45ce-9552-f2fbd2953cdd","x":1906,"y":273,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"9b018fa8-a346-4925-a6c5-d0e3ddeea305","x":1906,"y":210,"attrs":0,"template":"@__builtin__anchor","children":["0b91d49f-92d4-488c-8331-7a092b5c6e9f"],"properties":[],"angle":0},{"id":"d05676a0-1547-463c-9644-9a924c474707","x":1906,"y":147,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"883f65b9-cf1d-4c0f-9ea5-657993dab3ec","x":2729.5,"y":84,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"ebba230f-451f-47fa-a2ba-783a5fdd5162","x":2820,"y":84,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"fa256366-94d4-403d-b17d-d3844c0d1822","x":2910.5,"y":84,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"a6fdaeeb-c8a0-49c3-a399-dd8ec3ea4f68","x":3001,"y":147,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"87ec7161-23ba-49f2-b707-fa024947c77a","x":3001,"y":210,"attrs":0,"template":"@__builtin__anchor","children":["9a30922a-3b2c-4a0c-992a-654a114c610f"],"properties":[],"angle":0},{"id":"aa842de2-89f7-4369-8ca2-6618c059a0e1","x":3001,"y":273,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"de3a5a3d-74fc-4a51-bf2f-67b29b4ec9bc","x":2910.5,"y":337,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"17437ec2-59ff-4ebb-b12f-59040385bf5e","x":2820,"y":337,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"af350aa2-10b0-4ed6-a119-ee69a22bbf51","x":2729.5,"y":337,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"a27c8bef-0c72-4a88-94da-8d9f543355df","x":2639,"y":273,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"ca2f7211-e1d2-4b29-8f47-d9ea18421490","x":2639,"y":210,"attrs":0,"template":"@__builtin__anchor","children":["8c723b2e-ada7-4d74-8ef9-6f8461c90306"],"properties":[],"angle":0},{"id":"df9f939d-4213-4ecc-ab86-b8f35e93e409","x":2639,"y":147,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"beb0bc0f-59fe-42ad-9ea7-aaa558c9be03","x":3190,"y":84,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"53731b44-d9e2-4073-a383-61e9408084c8","x":3280,"y":84,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"be65b92e-64f0-4c68-8de7-a73a3ac8baa2","x":3370,"y":84,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"1e4b5342-10b4-42c1-9373-5692f12f5c16","x":3461,"y":147,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"27c836d7-dd9f-49dc-8a4d-5c94d4e63fdb","x":3461,"y":210,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"63d9205a-853d-4b38-9b0d-3a039fce23ec","x":3461,"y":273,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"1d93968b-e6f9-491a-96c3-96967a51bf26","x":3370,"y":337,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"6bfb18c9-324d-4e97-95c2-cb218e6cf977","x":3280,"y":337,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"a99bba3f-c74f-4d42-9106-1eaed19f2081","x":3190,"y":337,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"d2983d92-fbe5-446a-9dfa-90fd0b2c8a69","x":3100,"y":273,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"8418c143-2010-4c50-943f-01fa6b836c60","x":3100,"y":210,"attrs":0,"template":"@__builtin__anchor","children":["0940b535-1f7a-466e-946f-1584bc61fe90"],"properties":[],"angle":0},{"id":"80088a3a-e897-4cdb-8f86-50cb10e4339e","x":3100,"y":147,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"9a30922a-3b2c-4a0c-992a-654a114c610f","x":3001,"y":210,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"0a02cbc8-0147-4daa-8700-67db787c0179","x":3050.5,"y":210,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"0940b535-1f7a-466e-946f-1584bc61fe90","x":3100,"y":210,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"373d058e-6d9d-4479-8b6d-4793576f8b8f","x":808,"y":-259,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c500ab2c-ea28-4087-bcb6-6d023e43531f","x":850,"y":-259,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"8c954d7e-3ccd-4522-9e88-7475df55cd5a","x":892,"y":-259,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"0a9e00d1-160d-43f3-97a2-c03c19993d2f","x":935,"y":-244.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"d35c457a-8dad-4185-b305-100b55fedee5","x":935,"y":-230,"attrs":0,"template":"@__builtin__anchor","children":["a3dc20f1-5ffb-4ed5-aa2f-65e3042e94c9"],"properties":[],"angle":0},{"id":"610ac0e0-104b-4559-b7b5-4ef9d8c9bd61","x":935,"y":-215.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"267ed779-4ce7-4179-ad63-c18db15bb7e6","x":892,"y":-200,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"26f8e48d-2d9d-4bbb-a60a-655389f884c0","x":850,"y":-200,"attrs":0,"template":"@__builtin__anchor","children":["4675480a-c60e-4ff6-9595-e185ae402d42"],"properties":[],"angle":1},{"id":"7a69e832-458e-41d4-bebb-1b085cdd6bfa","x":808,"y":-200,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"d6b6ee86-2365-44f7-a351-7be051d28446","x":766,"y":-215.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"368423d7-cd3d-4f7a-8d03-1f85ca61829d","x":766,"y":-230,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"ab1abd5b-87e8-4b06-9d30-9211e70c334c","x":766,"y":-244.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a2abe9d3-04e4-4d94-b9d4-9ee15c870077","x":1080.5,"y":-259,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"56b29b6b-7024-4494-b5a9-3ffa618a0a23","x":1150,"y":-259,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"76a536e8-8d0c-4cfd-99f0-61ea575ac216","x":1219.5,"y":-259,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"979d8a2e-0034-455b-9e30-1c06413fada5","x":1290,"y":-244.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"fe4bcf64-000d-4612-9544-b232fee2faa3","x":1290,"y":-230,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"6e6773d5-533b-4204-9fd0-08b478c0ef63","x":1290,"y":-215.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"9994acca-3cc1-4e54-b056-cf0447ebb445","x":1219.5,"y":-200,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"bb1287ad-30aa-4611-bc2c-5960f8111896","x":1150,"y":-200,"attrs":0,"template":"@__builtin__anchor","children":["b2c2aec1-0506-4a6f-8d38-17ab1679e95c"],"properties":[],"angle":1},{"id":"7ad0b954-345b-4cc8-8be5-3f9843372351","x":1080.5,"y":-200,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"b5f8ea39-9c3e-4989-a38a-1831185130b2","x":1011,"y":-215.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"c47b4d74-2592-4877-9104-d481047e7e88","x":1011,"y":-230,"attrs":0,"template":"@__builtin__anchor","children":["dee6608b-84b3-4b92-bb2d-11d35fb4fda9"],"properties":[],"angle":0},{"id":"be67fe05-2ce2-487c-a52b-1b16a91e33c1","x":1011,"y":-244.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"4f743274-bbcc-43bb-a7b7-6f704aebed9a","x":1584.5,"y":81,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"058525c5-c00f-414a-8791-4f943f543fd1","x":1620,"y":81,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"7357d55f-5fb1-44e8-b73c-f87193714aed","x":1655.5,"y":81,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"35ba6f19-907d-457e-815e-29849dbcc9a7","x":1691,"y":95.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"8bc31c6e-8e92-4eff-9bbd-5cd684f2c88c","x":1691,"y":110,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a0f44fdc-56e6-47c2-9eeb-4c6345535d87","x":1691,"y":124.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"63bad3f5-7bda-4895-9d7a-f504c9c5ed3f","x":1655.5,"y":139,"attrs":0,"template":"@__builtin__anchor","children":["822c0981-85ce-42a7-a51a-7ae0a98b1bc1"],"properties":[],"angle":1},{"id":"3f9ecb7f-708c-4ae2-a85f-5bfac3416f6d","x":1620,"y":139,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"f55ba817-651a-4c04-a0d3-62b82d00b970","x":1584.5,"y":139,"attrs":0,"template":"@__builtin__anchor","children":["542b920b-a40c-4419-82e1-68e128caaddc"],"properties":[],"angle":1},{"id":"6e2fd412-bbc1-47cb-9b8b-ca6b9bda8075","x":1549,"y":124.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"4e29da8d-3d77-4368-8183-0c56097d5d90","x":1549,"y":110,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"ea7165ce-ec45-4e35-a3ef-a8d7ed51b0be","x":1549,"y":95.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a3dc20f1-5ffb-4ed5-aa2f-65e3042e94c9","x":935,"y":-230,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"ab4ffd40-1088-4e89-9430-15f41f8f934d","x":973,"y":-230,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"dee6608b-84b3-4b92-bb2d-11d35fb4fda9","x":1011,"y":-230,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"6f8a5623-cb66-4aa0-9b55-a2fd84f3614d","x":1510,"y":240,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"e79a3e71-eb7b-45fb-8c70-556f639a7c20","x":1547.25,"y":189.5,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"542b920b-a40c-4419-82e1-68e128caaddc","x":1584.5,"y":139,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"7595c16b-bbae-4f52-8669-cb84748c8cb7","x":1790,"y":330,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"cfe15f9f-476f-4ee5-b826-543a6db37776","x":1848,"y":270,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"0b91d49f-92d4-488c-8331-7a092b5c6e9f","x":1906,"y":210,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"d05fbbae-a25a-485d-a2fa-55d96e5f5fff","x":2401,"y":471,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"bed01324-1a1e-435e-9716-dcb2bc3f3dd1","x":2440,"y":471,"attrs":0,"template":"@__builtin__anchor","children":["5b605dff-8f5b-47df-a599-556753aa8a2d"],"properties":[],"angle":1},{"id":"f44f5fd4-e39d-4f1a-821e-9321526e3a30","x":2479,"y":471,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"28bbbba8-942b-449f-a713-17573c0522a8","x":2519,"y":485.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"4c43008b-21c3-4eeb-b020-764e937fc186","x":2519,"y":500,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"dbb0ddcb-46e9-4f8c-83ec-c712a298295b","x":2519,"y":514.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"1d20b45a-7673-490f-acef-f6a4a6c212a7","x":2479,"y":530,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"17a2c343-0d51-4a5d-83da-ec9b02af2d7a","x":2440,"y":530,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"8a5cc185-cb64-45ff-92ec-a7ed633a08a0","x":2401,"y":530,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"9f3cdedc-5b62-407c-9b3b-821dc8ad7050","x":2362,"y":514.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"4829b397-34cf-4a35-b0a1-90027f297e80","x":2362,"y":500,"attrs":0,"template":"@__builtin__anchor","children":["fae91b3e-a8c9-4b2d-89bd-6e4f2193a69a"],"properties":[],"angle":0},{"id":"ff3b9aa2-9a6e-4e0b-b019-e15b26fdf662","x":2362,"y":485.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"0065a2f8-1695-4d6c-ae71-d9f36396fc85","x":2254,"y":500,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"941ec677-a015-4372-9c80-327c97b4b129","x":2308,"y":500,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"fae91b3e-a8c9-4b2d-89bd-6e4f2193a69a","x":2362,"y":500,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"97314864-ae41-4a74-946f-98592a9bda9f","x":2410,"y":120,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"693b9900-ab28-43d8-98b9-7b5c649e4eb5","x":2440,"y":120,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"62d78c58-b18b-4508-afe0-1c456225bccd","x":2470,"y":120,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"6cb53cb3-a662-4c9d-b665-685fd462f572","x":2500,"y":165,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"c1f3eb59-dfc9-4411-976e-53fe9de8c874","x":2500,"y":210,"attrs":0,"template":"@__builtin__anchor","children":["f8f9ce97-34cc-4f96-a5bc-64f17321f21e"],"properties":[],"angle":0},{"id":"8a97d6bc-569c-4bb6-b458-514d5010be03","x":2500,"y":255,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"b9c8bbb6-dcac-445e-bd86-adbcc45d71ca","x":2470,"y":300,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"64868270-251d-4fc5-857f-3ce3423cdd1b","x":2440,"y":300,"attrs":0,"template":"@__builtin__anchor","children":["c59a2cb2-1f99-4c34-b440-33e27a271961"],"properties":[],"angle":1},{"id":"81a35401-1c0b-4938-9a54-946692c28bee","x":2410,"y":300,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"16b3fafc-d65a-4c19-9ae8-1b200ac77d60","x":2380,"y":255,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"316ae5cd-b669-49fe-8198-6597657ee1ed","x":2380,"y":210,"attrs":0,"template":"@__builtin__anchor","children":["da01b0c3-b2b3-41a4-9e41-3e8855f3581a"],"properties":[],"angle":0},{"id":"e48fe231-3d09-4c82-9712-e92d0644ebde","x":2380,"y":165,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"8059c255-5733-4b97-b0c4-e1ccbe37b73a","x":2255,"y":210,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"75380a2b-5118-4890-b005-4de9f7d0493c","x":2317.5,"y":210,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"da01b0c3-b2b3-41a4-9e41-3e8855f3581a","x":2380,"y":210,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"f8f9ce97-34cc-4f96-a5bc-64f17321f21e","x":2500,"y":210,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"36628238-7606-48e9-bb30-fa302b62042a","x":2569.5,"y":210,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"8c723b2e-ada7-4d74-8ef9-6f8461c90306","x":2639,"y":210,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"44ed8728-2d47-4aef-b326-cdf28dd4fee5","x":1150,"y":127,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"81c63741-d718-42cd-9f34-a5c3a263ddbd","x":1150,"y":170.5,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"4112003f-3034-4393-b507-97c109427ed0","x":1150,"y":214,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"0164dfb2-da1e-4c22-b895-a93e624be99a","x":850,"y":-106,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"a847dada-8418-4406-94da-060334073172","x":850,"y":-153,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"4675480a-c60e-4ff6-9595-e185ae402d42","x":850,"y":-200,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"b2c2aec1-0506-4a6f-8d38-17ab1679e95c","x":1150,"y":-200,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"35640775-b987-478f-aae0-99d67c381579","x":1150,"y":-153,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"a5ff4647-ef77-4150-9394-a908b2703d43","x":1150,"y":-106,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"822c0981-85ce-42a7-a51a-7ae0a98b1bc1","x":1655.5,"y":139,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"adbaa7c0-f728-4de3-82ae-bf60d1b7bdb8","x":1692.75,"y":189.5,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"ccc404ac-ff76-4587-ae52-d37466f2071a","x":1730,"y":240,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"2c37e408-5a77-4c3f-b9de-c2910e78ccda","x":1790,"y":375,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"0809ad1e-e5f3-42a8-b00a-10b5125bd60f","x":1848,"y":408.5,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"5dc82c9e-454c-4ca1-986c-a3c05d47956e","x":1906,"y":442,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"5b605dff-8f5b-47df-a599-556753aa8a2d","x":2440,"y":471,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"de519029-6101-4ec1-9ec4-416e9a97ef8e","x":2440,"y":385.5,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"c59a2cb2-1f99-4c34-b440-33e27a271961","x":2440,"y":300,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]}],"location":{"x":1812.0670241599867,"y":67.56851837437858,"k":0.30505611100813673}}
\ No newline at end of file
diff --git a/yvisualization/attack-flow-builder/icedid/IcedID-032725.json b/yvisualization/attack-flow-builder/icedid/IcedID-032725.json
new file mode 100644
index 0000000..1b3cefe
--- /dev/null
+++ b/yvisualization/attack-flow-builder/icedid/IcedID-032725.json
@@ -0,0 +1,484 @@
+{
+ "type": "bundle",
+ "id": "bundle--e6c7f586-0ad8-4a0e-b2f8-b2c8ff9b4f19",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "objects": [
+ {
+ "type": "extension-definition",
+ "id": "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4",
+ "spec_version": "2.1",
+ "created": "2022-08-02T19:34:35.143Z",
+ "modified": "2022-08-02T19:34:35.143Z",
+ "name": "Attack Flow",
+ "description": "Extends STIX 2.1 with features to create Attack Flows.",
+ "created_by_ref": "identity--fb9c968a-745b-4ade-9b25-c324172197f4",
+ "schema": "https://center-for-threat-informed-defense.github.io/attack-flow/stix/attack-flow-schema-2.0.0.json",
+ "version": "2.0.0",
+ "extension_types": [
+ "new-sdo"
+ ],
+ "external_references": [
+ {
+ "source_name": "Documentation",
+ "description": "Documentation for Attack Flow",
+ "url": "https://center-for-threat-informed-defense.github.io/attack-flow"
+ },
+ {
+ "source_name": "GitHub",
+ "description": "Source code repository for Attack Flow",
+ "url": "https://github.com/center-for-threat-informed-defense/attack-flow"
+ }
+ ]
+ },
+ {
+ "type": "identity",
+ "id": "identity--fb9c968a-745b-4ade-9b25-c324172197f4",
+ "spec_version": "2.1",
+ "created": "2022-08-02T19:34:35.143Z",
+ "modified": "2022-08-02T19:34:35.143Z",
+ "created_by_ref": "identity--fb9c968a-745b-4ade-9b25-c324172197f4",
+ "name": "MITRE Center for Threat-Informed Defense",
+ "identity_class": "organization"
+ },
+ {
+ "type": "attack-flow",
+ "id": "attack-flow--49e4b0e6-5cc7-4757-81db-b1ae6788cd41",
+ "spec_version": "2.1",
+ "created": "2025-02-21T15:58:38.809Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "created_by_ref": "identity--4458ed6f-138c-4356-924e-c6ae5bc9db18",
+ "start_refs": [
+ "attack-action--ac0751dd-123e-488a-a093-6b5170f8e694",
+ "attack-action--eb5ca1e6-a396-4040-8318-436c3cce18e8"
+ ],
+ "name": "IcedID",
+ "description": "Visual displaying IcedID malware behavior",
+ "scope": "malware",
+ "external_references": [
+ {
+ "source_name": "THREAT ANALYSIS: From IcedID to Domain Compromise",
+ "url": "https://www.cybereason.com/blog/threat-analysis-from-icedid-to-domain-compromise"
+ }
+ ]
+ },
+ {
+ "type": "identity",
+ "id": "identity--4458ed6f-138c-4356-924e-c6ae5bc9db18",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "name": "Maddie Bright"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--ac0751dd-123e-488a-a093-6b5170f8e694",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Malicious File",
+ "tactic_id": "TA0002",
+ "tactic_ref": "x-mitre-tactic--4ca45d45-df4d-4613-8980-bac22d278fa5",
+ "technique_id": "T1204.002",
+ "technique_ref": "attack-pattern--232b7f21-adf9-4b42-b936-b9d6f7df856e",
+ "description": "User executes a malicious archive",
+ "effect_refs": [
+ "attack-action--5ac84220-2268-4513-a117-dd38a5402739"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--5ac84220-2268-4513-a117-dd38a5402739",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Hidden Files and Directories",
+ "tactic_id": "TA0005",
+ "tactic_ref": "x-mitre-tactic--78b23412-0651-46d7-a540-170a1ce8bd5a",
+ "technique_id": "T1564.001",
+ "technique_ref": "attack-pattern--ec8fc7e2-b356-455c-8db5-2e37be158e7d",
+ "description": "Archive contains a hidden file which is a dependency called by the visible LNK file"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--268f83ee-d3de-4320-bdde-ec6a04c46280",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Rundll32",
+ "tactic_id": "TA0005",
+ "tactic_ref": "x-mitre-tactic--78b23412-0651-46d7-a540-170a1ce8bd5a",
+ "technique_id": "T1218.011",
+ "technique_ref": "attack-pattern--045d0922-2310-4e60-b5e4-3302302cb3c5",
+ "description": "Used for executing DLL files",
+ "effect_refs": [
+ "attack-action--bae7ae51-0d92-4bcd-b0a1-8176fe231f3c"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--4c9d6521-a65b-4982-8c61-f03fd1494615",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Ingress Tool Transfer",
+ "tactic_id": "OB0004",
+ "technique_id": "E1105",
+ "effect_refs": [
+ "attack-action--c15548fd-3f78-41c1-88ce-b9b7ef361170"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--eb5ca1e6-a396-4040-8318-436c3cce18e8",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Executable Code Obfuscation",
+ "tactic_id": "OB0002",
+ "technique_id": "B0032",
+ "description": "File is obfuscated as demonstrated in the report"
+ },
+ {
+ "type": "file",
+ "id": "file--11f4d871-cc16-4e49-b4b1-528b361d9415",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "name": "Twelfth.bat"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--1c8faaae-3d55-49ed-ba8d-e56f72d736bd",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Command and Scripting Interpreter",
+ "tactic_id": "OB0009",
+ "technique_id": "E1059",
+ "description": "bat file uses cmd.exe for executing further commands",
+ "effect_refs": [
+ "attack-action--bce4df0c-1803-4c08-b8b6-394e266ff38d"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--bae7ae51-0d92-4bcd-b0a1-8176fe231f3c",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Connect to Server",
+ "tactic_id": "OC0006",
+ "technique_id": "C0002.009",
+ "description": "connects to chronofire[.]info",
+ "effect_refs": [
+ "attack-action--4c9d6521-a65b-4982-8c61-f03fd1494615"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--bce4df0c-1803-4c08-b8b6-394e266ff38d",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Copy File",
+ "tactic_id": "OC0001",
+ "technique_id": "C0045",
+ "description": "Uses xcopy.exe",
+ "effect_refs": [
+ "attack-action--268f83ee-d3de-4320-bdde-ec6a04c46280"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--c15548fd-3f78-41c1-88ce-b9b7ef361170",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Rundll32",
+ "tactic_id": "TA0005",
+ "tactic_ref": "x-mitre-tactic--78b23412-0651-46d7-a540-170a1ce8bd5a",
+ "technique_id": "T1218.011",
+ "technique_ref": "attack-pattern--045d0922-2310-4e60-b5e4-3302302cb3c5",
+ "effect_refs": [
+ "attack-action--8814dbd7-b9c9-41a8-87f8-2a00c57d1d85",
+ "attack-action--eb109108-56ac-46e5-9d85-692afaa28a68"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--eb109108-56ac-46e5-9d85-692afaa28a68",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Decrypt Data",
+ "tactic_id": "OC0005",
+ "technique_id": "C0031",
+ "description": "Decryption key is file provided in initial archive"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--8814dbd7-b9c9-41a8-87f8-2a00c57d1d85",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Scheduled Task",
+ "tactic_id": "TA0003",
+ "tactic_ref": "x-mitre-tactic--5bc1d813-693e-4823-9961-abf9af4b0e92",
+ "technique_id": "T1053.005",
+ "technique_ref": "attack-pattern--005a06c6-14bf-4118-afa0-ebcd8aebb0c9",
+ "description": "Executes xaeywn1.dll at every logon and every hour",
+ "effect_refs": [
+ "attack-action--a690f62f-30c3-4c78-a460-0779d8893282"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--5e395ad7-7b62-4876-b26c-2de21d8db034",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Connect to Server",
+ "tactic_id": "OC0006",
+ "technique_id": "C0002.009",
+ "description": "Domains observed were known to be connected to icedID",
+ "effect_refs": [
+ "attack-action--88bd84e5-e3b0-4dff-863e-5fedb8f4dc28"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--88bd84e5-e3b0-4dff-863e-5fedb8f4dc28",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Execute Shell Command",
+ "tactic_id": "OB0004",
+ "technique_id": "B0030.016",
+ "description": "Interactive remote shell session starts. Attacker uses this to manually control malware."
+ },
+ {
+ "type": "file",
+ "id": "file--01b76ff0-5e05-491d-b188-94e3ecea47f8",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "name": "superstring.dll"
+ },
+ {
+ "type": "file",
+ "id": "file--659602d1-d017-490b-8e31-68b567baa7ec",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "name": "%TEMP%\\homesteading.dll"
+ },
+ {
+ "type": "file",
+ "id": "file--e91caa3d-6050-4df6-9428-dafc5415c8e4",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "name": "xaeywn1.dll"
+ },
+ {
+ "type": "file",
+ "id": "file--9ec1e943-a76c-49ec-8a3d-b706eed5238e",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "name": "init_dll_64.dll"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--a690f62f-30c3-4c78-a460-0779d8893282",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Rundll32",
+ "tactic_id": "TA0005",
+ "tactic_ref": "x-mitre-tactic--78b23412-0651-46d7-a540-170a1ce8bd5a",
+ "technique_id": "T1218.011",
+ "technique_ref": "attack-pattern--045d0922-2310-4e60-b5e4-3302302cb3c5",
+ "effect_refs": [
+ "attack-action--5e395ad7-7b62-4876-b26c-2de21d8db034"
+ ]
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--38d38edb-536e-45a8-8c93-59975d422ac3",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "relationship_type": "related-to",
+ "source_ref": "attack-action--5ac84220-2268-4513-a117-dd38a5402739",
+ "target_ref": "file--11f4d871-cc16-4e49-b4b1-528b361d9415"
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--58038769-6a95-44bb-ba87-c7cd82309002",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "relationship_type": "related-to",
+ "source_ref": "attack-action--4c9d6521-a65b-4982-8c61-f03fd1494615",
+ "target_ref": "file--e91caa3d-6050-4df6-9428-dafc5415c8e4"
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--e40259b3-205b-4263-a0fb-7937c8734bec",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "relationship_type": "related-to",
+ "source_ref": "attack-action--eb5ca1e6-a396-4040-8318-436c3cce18e8",
+ "target_ref": "file--11f4d871-cc16-4e49-b4b1-528b361d9415"
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--ee51df71-182c-4d5d-8a4d-6aeec4ebe661",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "relationship_type": "related-to",
+ "source_ref": "file--11f4d871-cc16-4e49-b4b1-528b361d9415",
+ "target_ref": "attack-action--1c8faaae-3d55-49ed-ba8d-e56f72d736bd"
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--77e05fad-4cc6-4973-8b04-d874022723f1",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "relationship_type": "related-to",
+ "source_ref": "attack-action--bce4df0c-1803-4c08-b8b6-394e266ff38d",
+ "target_ref": "file--01b76ff0-5e05-491d-b188-94e3ecea47f8"
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--f6621606-39b7-4b29-a867-1d79d57d8c64",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "relationship_type": "related-to",
+ "source_ref": "attack-action--eb109108-56ac-46e5-9d85-692afaa28a68",
+ "target_ref": "file--9ec1e943-a76c-49ec-8a3d-b706eed5238e"
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--2d2883dc-d4ae-4fa0-9f1a-b027bbebc91c",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "relationship_type": "related-to",
+ "source_ref": "file--01b76ff0-5e05-491d-b188-94e3ecea47f8",
+ "target_ref": "file--659602d1-d017-490b-8e31-68b567baa7ec"
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--9548d521-fb15-455b-8119-d519b08027b4",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "relationship_type": "related-to",
+ "source_ref": "file--659602d1-d017-490b-8e31-68b567baa7ec",
+ "target_ref": "attack-action--268f83ee-d3de-4320-bdde-ec6a04c46280"
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--39bfb8bc-a964-45cf-a615-a7eea3b2bfcc",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "relationship_type": "related-to",
+ "source_ref": "file--e91caa3d-6050-4df6-9428-dafc5415c8e4",
+ "target_ref": "attack-action--c15548fd-3f78-41c1-88ce-b9b7ef361170"
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--43118de5-c0bc-404f-87fe-f123ce2d10db",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:11:04.256Z",
+ "modified": "2025-03-31T13:11:04.256Z",
+ "relationship_type": "related-to",
+ "source_ref": "file--9ec1e943-a76c-49ec-8a3d-b706eed5238e",
+ "target_ref": "attack-action--a690f62f-30c3-4c78-a460-0779d8893282"
+ }
+ ]
+}
\ No newline at end of file
diff --git a/yvisualization/attack-flow-builder/icedid/IcedID-032725.png b/yvisualization/attack-flow-builder/icedid/IcedID-032725.png
new file mode 100644
index 0000000..26a6632
Binary files /dev/null and b/yvisualization/attack-flow-builder/icedid/IcedID-032725.png differ
diff --git a/yvisualization/attack-flow-builder/latrodectus/Latrodectus-032725.afb b/yvisualization/attack-flow-builder/latrodectus/Latrodectus-032725.afb
new file mode 100644
index 0000000..d1847ee
--- /dev/null
+++ b/yvisualization/attack-flow-builder/latrodectus/Latrodectus-032725.afb
@@ -0,0 +1 @@
+{"version":"2.3.2","id":"63e420c7-562f-4a0a-ac7d-7e59f6b904c3","objects":[{"id":"63e420c7-562f-4a0a-ac7d-7e59f6b904c3","x":1596,"y":1765,"attrs":0,"template":"flow","children":["257ffdd4-bb50-425b-9091-f82fc184eccc","7083e4bb-73a9-4982-b891-e65a17fd4cb3","c7f20500-3dab-4ffc-b3cb-545a1b901925","582fdf4c-da5a-45f9-ae83-b9dad0d8ccc5","0eea63f2-14c5-404e-840d-1bcf082fe164","e594ebea-5a98-4200-81ac-6a688e657831","218c1310-e244-493c-a8d5-76a71befb735","25137e20-5ce8-42f5-ba2e-ff1cbc5c32c5","6daf1e2b-0451-4233-9274-4e29c95e4204","f7a96d30-4e16-4955-94bc-64aa95732254","02f64672-ba05-4090-b1ef-066a28e7f0a5","c7b64762-30d9-42af-90f3-994fd35ae504","f0d4d59a-1f6a-4d51-8c6a-268be304f864","8fafaa85-739d-4c15-9038-f9f0cf20c92e","17382d39-8d97-457d-9a89-0f8d77dae0de","9bbbe9ff-b82f-40d9-840d-c6ad2439b7e6","f5c36be6-4afc-45bb-b98e-76f4f6a1e09b","1d85143a-059a-438c-a794-10012880f3e8","ed9ce25e-3124-46c3-9800-bf118b65c99c","e74ac193-4a84-408e-acaa-b19af464b93d","97de4877-44e3-4697-b262-a1123806db8a","961e50bf-5799-43f2-9277-df5d72d27de3","2ab9fa88-caf7-4fa0-9101-e5b91fef1d89","0f72ef7c-2379-44d9-9927-424fcfb6968c","ce3ca0c2-14b0-4348-baed-85069c8e149a","e119bf94-93b2-401f-a3c3-474ae7563c0a","2e8bc208-cd80-44ed-ad8f-cf71d00749d3","ed0736e8-f554-42b6-997d-fc18cd6aab41","c8cbe298-71ee-4ae3-92eb-dbd4e2e66a4f","4be22955-a841-4b3f-8414-3784d6143ede","3444fb5b-da4d-462f-88ce-3f7453e37f47","f286c4a1-20c8-402a-bf77-f64408250815","73fd998a-ea52-4cdb-a957-e08cbefef97d","08a24b37-fb16-4626-bef2-705b57e7782e","d0667ee0-ef70-49e0-a96a-b6777bda94ce","e88936bd-1cec-487a-89cd-7e494c5d9b59","cd7ef1a2-97a2-40a7-9134-629c6c105f54","78f23e8a-b4a6-47be-891f-1521e2272ab9","bc4c9f48-8244-494a-9241-7b062bd4620d","56d45603-8674-4651-8e68-b9aa9ffa8737","6ddee69f-4052-454b-a147-380da9a835aa","acba6cb6-d117-46a4-909c-d63f79e9c786","d30475f7-fcbe-4bea-8fe7-77d2880a8cb0","bd7f6922-bed0-4a88-a6fe-e2f1ed77046f","4091668b-3f98-4b05-95a9-521ec3d6703a","44965326-9631-4547-95cf-5550f5bb985b","ea43ca4b-a714-46fa-a2a7-6c0dce01d9e6","988738f3-3a58-4e60-90dd-4832918a46c8","aa621f2f-6695-4280-a648-12b7399d740b","be2065d6-b9b6-4c46-95ed-ff75f354abfc","4cb5012f-c68f-4a9b-99dc-02de70490b9a","2b4339ab-0b45-4cea-935f-9eda3205ab0a","8588d4db-63e3-47e9-9fda-35b8d7db3e5a","105cfc99-368e-48ad-8540-d10a89a56e55","62245105-a3d4-4419-8c62-d6e948492a91","95c87492-4e1f-4700-a123-ce3818ea20cd","049c3ed8-9a71-4974-b91b-4122df9593a7","29c279a7-55af-4e93-9bc6-68923570ac0f","e137813e-d96d-4dbc-aeec-d69654717b44","a0259e1b-b601-474e-bf36-884d9bc22c8e","232c50a2-3768-4fd3-8771-79dc4ec7c744","0e50092f-c41b-4c6d-a90b-906a8f40ee37","4c7c0a33-e47f-4904-90d0-5e1d3a1e6a77","cf70aa08-e577-49bb-b668-57358a4ac9dd","46738cb0-52ad-4c9f-852c-0e2fc468ce20","f2cc7510-ee8e-46b2-b110-56e51506d094","37b33226-2254-4cd6-9175-b3507f80b7a3","bbe2661f-8ab4-4fe6-9bf6-39305b1ec8bb","813bf6c6-89d0-41dc-a42a-ad190dbb3cf5","4d78d74a-eaf4-477d-ad24-fdbba67fa4cd","30e19a53-9009-48c3-a0fc-bbbc773358d4","2e0930f6-b4ef-4fdc-b394-94d1f85603eb","f2cfaa6c-5204-4708-8864-8f1d277c3170","a6aecd1a-a6c2-4f83-85ad-0cd55983c747","86b05982-622c-4ef2-81da-7dee944ddcd2","3ef34e8f-c083-4152-99c1-f68599457bee"],"properties":[["name","Latrodectus"],["description",null],["author",[["name","Maddie Bright"],["identity_class","individual"],["contact_information","mbright@mitre.org"]]],["scope","malware"],["external_references",[["f6e3de93150f9524731fb0c572d5b544",[["source_name","Latrodectus, are you coming back? | Bitsight"],["description",null],["url","https://www.bitsight.com/blog/latrodectus-are-you-coming-back"]]]]],["created","2025-02-04T14:50:20.511Z"]]},{"id":"257ffdd4-bb50-425b-9091-f82fc184eccc","x":910,"y":-40,"attrs":256,"template":"action","children":["a0b0c358-75dd-4746-a510-dbd0bff21c74","008566d0-68af-4cf9-972a-6d2066482cf5","315dcdbf-fbcb-46fa-a144-d7f978a78095","fdef2869-abb5-4d3b-bfba-21614fb74c89","9d233358-16f2-490a-90e4-38a9be7bf409","398d7882-44ee-4b04-99f4-c7f73b4fd443","8175879f-dc50-4cb8-a7de-68cdf2b5c107","da70ee67-6b25-4ce7-a98c-cdd4d5700d7d","7d086984-16e8-447b-a11b-651d827f7c77","846aff31-1694-46ad-8c90-d174759d2582","ecc0b9e2-86b4-47a1-9d3d-f97a48c24386","ce897802-396f-42e5-b2d1-ba167d0acb14"],"properties":[["name","Process Environment Block BeingDebugged"],["tactic_id","OB0001"],["tactic_ref",null],["technique_id","B0001.035"],["technique_ref",null],["description",null],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"7083e4bb-73a9-4982-b891-e65a17fd4cb3","x":1300,"y":-90,"attrs":256,"template":"action","children":["e8abdafe-6190-4a59-bda9-fc72c7b1c5f2","c8a93682-8ea0-45d6-abe1-5f3d17ff62d9","22ccafd3-f7cc-484c-a816-a00337837b31","1ed8cdb5-a814-410d-9927-58bc20e123c6","00477567-334c-48c4-8302-c1d8c81d60e8","d7dcbdde-3619-4e96-8f3c-17acd90ef48d","56b10b65-b7ff-4413-b7d4-978cdae6c7ec","02ba9256-14db-4daa-96a4-048861c71551","d6a58550-6084-4f9f-aa43-fb6ea71d2780","7d18c7cf-5954-466a-9082-c1caed1b5023","797c4501-50d8-404a-80e3-73d450fca63f","8168b36a-c86f-4fa6-897d-88cb7f143983"],"properties":[["name","Check Processes"],["tactic_id","OB0001"],["tactic_ref",null],["technique_id","B0009.004"],["technique_ref",null],["description","Assesses for > 75 running processes for Windows 10 and newer, > 50 for OS older than Windows 10"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"c7f20500-3dab-4ffc-b3cb-545a1b901925","x":1590,"y":250,"attrs":256,"template":"action","children":["4db4d636-238d-484b-97ef-99cfb8505112","b683e639-8061-42b5-9f50-5b1f3cd1536a","c64a2809-f51c-45d1-97b5-27425d667ce1","3f143250-b341-484f-a129-b29ba6348bec","a74d2f3d-7ef5-4a43-a51c-a6244cd6d012","dd8d2971-8905-4fa3-a4b1-7fe5382c9b64","1c1054d1-990d-4e02-9f0b-08a121e01e0b","a8fcfd3a-371e-4b8c-b27a-a60ba7580b85","68658dae-5a6e-4240-90b4-662e0444d139","886efed4-1802-4a03-aabb-b067c335dc57","2fa696df-a3b4-4f33-b081-a0243bb2d121","ab22bd0d-2d9e-4ede-9777-421c52ed0c02"],"properties":[["name","Modern Specs Check"],["tactic_id","OB0001"],["tactic_ref",null],["technique_id","B0009.013"],["technique_ref",null],["description","Checks for 64-bit host"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"582fdf4c-da5a-45f9-ae83-b9dad0d8ccc5","x":610,"y":250,"attrs":256,"template":"action","children":["f0ee6d6a-77c8-4fe0-8af7-a906fddf1584","c8429eb5-7e74-4e73-92ba-bad846a2577f","96afcd7c-a3d5-4b95-9b9d-0f3afec04955","8eac7286-d286-4431-b3d9-277ed2bc8dde","c215f802-898f-4470-bee6-b00c177015e0","657af429-9fdf-48a1-a0c6-acf44f75a224","6535d96f-7648-42b1-be92-96af6fd9d737","91ded85b-3ea0-4eb5-b3df-473ea1b539bd","7d86fc99-170f-425b-812b-9f55b9f5053b","86f9d220-4d33-4726-8435-73d10c145a6d","a9272ab7-ecaa-4313-9e8f-bef8564f216a","793ababd-f74f-4afe-b516-dc47ee572b07"],"properties":[["name","Unique Hardware/Firmware Check - MAC Address"],["tactic_id","OB0001"],["tactic_ref",null],["technique_id","B0009.028"],["technique_ref",null],["description","Ensures MAC addresses exist and are valid values"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"0eea63f2-14c5-404e-840d-1bcf082fe164","x":870,"y":530,"attrs":256,"template":"action","children":["3f1cfac8-efc0-4f34-bdce-266dd6f6a81c","c00d48a0-d0b1-44c1-9c46-54e8cc1ef2c0","c9a392ca-c447-4254-a025-7a7159f295f2","c23e7613-97b6-4a01-944f-55664512330a","5f6e3a11-7a51-41be-a1ce-912acc5829a9","0e89fc24-a890-463e-9a51-a2706d56371a","45535fc5-c7fe-4e31-a5c0-0a0fc45d7d70","68c19cf3-531a-40da-add7-d568472e1ce2","67ca96bd-3894-42cc-9bcd-210625115ff0","2475b468-8dae-48bf-8672-05ba630ad755","5740a894-efc5-4445-9c8c-59ae5e3a29e2","3ddb3968-9617-4d1a-ae77-a5181931cb79"],"properties":[["name","Check Mutex"],["tactic_id","OC0003"],["tactic_ref",null],["technique_id","C0043"],["technique_ref",null],["description","Looks for mutex named 'running'"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"e594ebea-5a98-4200-81ac-6a688e657831","x":1470,"y":770,"attrs":256,"template":"action","children":["d66b9f68-88ac-4624-b428-d63618b966f2","13366536-e3b3-4017-807b-bb6b9f25b9fa","ebd076aa-2dad-447f-af13-5298875a7a31","21e4f525-c22b-4dd2-a670-7141d70c5da0","3b54e5f2-0e97-447a-9c7f-d99353c40d65","4f6e0d0e-341c-4f10-878d-7f7b1ddc6088","a40c85c0-18fe-4b47-a470-7942d787ee48","e5250ba6-03b6-4c98-9b17-8d49dd1048ba","9b1827ec-3058-46c7-b867-efb073da1913","e1867595-2b46-49a8-9414-929e61ec8b48","97befd52-2a47-43cd-9036-70b3ad8e128d","7f097585-f6cb-462c-ab47-21c051795f18"],"properties":[["name","System Information Discovery"],["tactic_id","OB0007"],["tactic_ref",null],["technique_id","E1082"],["technique_ref",null],["description","GetVolumeInformationW is used to determine the serial number for computing the bot ID"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"218c1310-e244-493c-a8d5-76a71befb735","x":1490,"y":2110,"attrs":256,"template":"action","children":["5814dc5a-191c-4a3a-ab29-2f4419202420","b1119be6-9eb8-470e-98d2-6004efa1f118","9a107b86-bafc-42ea-ab06-f8e2ccdebc2b","61c10bc9-a021-47e1-b273-dfcec0683fef","d015cf79-2d64-4bad-b703-c3568e1bb9f4","b074f776-9d43-4b85-8524-e57b32eb855c","15a0ae72-3975-427b-8414-a49a37acbddd","808885d9-e59f-4146-8a95-5c95b3240b12","660c8fca-31eb-4a13-9908-02a8d5dd8ac4","c7c38678-3db5-405d-bf3a-943e158721dc","0792ac54-d4bd-4a81-9767-f0385a98e739","c4435b9b-962f-4b8b-90be-d4e7850b7062"],"properties":[["name","XOR"],["tactic_id","OC0004"],["tactic_ref",null],["technique_id","C0053.002"],["technique_ref",null],["description","Decodes XOR-encrypted file contents"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"25137e20-5ce8-42f5-ba2e-ff1cbc5c32c5","x":1490,"y":1800,"attrs":256,"template":"action","children":["94cc9caa-650d-47c8-8a81-4b9e4d657250","a3e0875f-1cb5-4c19-b6e3-b135e4e5ceed","a7e286b8-fdaf-42b2-b09c-a22050bdbcbd","88d15de7-fbff-4dec-8aef-091db9f08a02","3069d691-9760-4178-91c6-b02ba3124e07","73a81ae5-a291-483b-9933-c991c8d58362","0c3c4214-c3c3-4067-bd82-669b9fbb37a5","545d18b2-e55c-4eda-9001-71e1718b6439","49d5643b-da8a-427f-8e15-9f6215d3359e","2a465c09-515e-4c1d-b6e7-d6ff8a948dc0","b42945db-2ff9-4e34-928e-4350d05f9ae0","066fe4e1-47e4-481b-8fcc-ef6b7e9512b2"],"properties":[["name","Read File"],["tactic_id","OC0001"],["tactic_ref",null],["technique_id","C0051"],["technique_ref",null],["description","Fetches the C2 URLs"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"6daf1e2b-0451-4233-9274-4e29c95e4204","x":1910,"y":1950,"attrs":256,"template":"action","children":["d9df1d06-9384-42ac-bdae-72dc9e325ea6","7ae44945-110f-4e07-bfec-8a4aae0fbb4f","75e75c61-08dc-470b-80ae-55115eb97b59","2e5ceb27-efa8-4c97-acdd-935ab7ad4b2a","923a062c-5926-45e2-9633-9be3dde7e837","f04e3657-3feb-4080-aa85-be4340a4fde2","9227602c-b848-49d1-b652-0fd61511eb4a","0b65e886-180b-4a2c-b2b5-eb8905ad3d2f","ef3ad726-a3a4-44cf-8406-2de8f7295212","c01a9a1f-e5b4-4bde-84ff-efa299ea8d93","a8c828af-0317-49d2-a93e-89b3c4d08e2f","d11f7fb9-71e1-4345-8d68-09e522abc9c6"],"properties":[["name","Authentication"],["tactic_id","OB0004"],["tactic_ref",null],["technique_id","B0030.011"],["technique_ref",null],["description","sends MAC addresses, hostname, and host domain"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"f7a96d30-4e16-4955-94bc-64aa95732254","x":2250,"y":2410,"attrs":256,"template":"action","children":["8b5873c9-544b-4d39-84a8-f8cf9fcfe217","53bed4ad-0346-4e79-9480-8d6c4598efb7","fb000430-1dd8-47cc-b1ae-be19c4d22e8a","5ce4d4b1-2cea-446c-969f-c7cf11daa7b1","fd7b013f-c3d1-41ba-b510-359aea73a90b","529c4df3-4169-42c7-9af8-a959a12d95b6","29e8eb25-b561-4c32-801e-e8af85880493","75cff90a-a594-451e-b09b-61883fd03b59","b0dc8739-430e-45e9-9790-9fe87b2a6919","246c0a79-2d1e-4983-a13f-c7b703496212","337693a0-5fd4-4d80-9ffd-dc6048fa2392","aae98a29-2e36-409f-bd4a-85a02600454a"],"properties":[["name","RC4"],["tactic_id","OC0005"],["tactic_ref",null],["technique_id","C0027.009"],["technique_ref","attack-pattern--005a06c6-14bf-4118-afa0-ebcd8aebb0c9"],["description","Encypt the C2 beacon"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"02f64672-ba05-4090-b1ef-066a28e7f0a5","x":2550,"y":2410,"attrs":256,"template":"action","children":["cdb60fb7-23ea-4af1-806e-fd5280a4fb6b","896064ab-33dd-488e-85c3-9adf0ba260aa","4690c68a-4c3a-4f82-814f-f7d7ba76c33e","f133f600-3332-4d1b-863d-7c7d65e427fe","2756a55f-1564-4069-9aae-94f77b5b033f","90ca41b9-7508-4ebc-84ed-1fd5cfe2c40a","5ab7db1b-6205-428a-a60b-301689e3121f","9ad6250c-8d35-48a3-803b-c607a3629f7b","53488888-376a-4f66-ae28-8fd9040708d4","c8e5207e-46f1-4b53-b8c6-7005bcaa7269","5902aeb2-a6b2-4bd5-8b7a-742b77cfbe98","36439e26-538f-4f94-b785-dc26d1dd8e69"],"properties":[["name","Base64"],["tactic_id","OC0005"],["tactic_ref",null],["technique_id","C0026.001"],["technique_ref",null],["description","Encode the C2 beacon"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"c7b64762-30d9-42af-90f3-994fd35ae504","x":1630,"y":3310,"attrs":256,"template":"action","children":["586735d7-c8fd-416c-b564-f911e6410f4d","b8a93eeb-5ef8-441a-9a70-d2b73a2508cb","5b3ccabb-2f9b-486b-8581-aef5da7acfe6","747887d8-8824-4fd5-add0-f25600fa2999","dcd02fe7-1fc1-40d6-b421-a8751fb04143","0e426720-6a8d-47e7-86e9-3d710f7cfcb8","1137565d-7c12-49bd-805c-eab25d4a66e8","15eae059-1a20-43c4-b540-069d4277692d","e0d140ea-88b5-4c3f-9529-51e4386cea32","9a5af494-2cd3-4f85-9512-79065acc3d46","f743c005-d2e2-48fa-b526-3e89be924070","5552bca2-c64f-4eb3-a1e5-8969057ead57"],"properties":[["name","Directory Listing"],["tactic_id","OB0004"],["tactic_ref",null],["technique_id","B0030.012"],["technique_ref",null],["description","Collects file names from desktop"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"f0d4d59a-1f6a-4d51-8c6a-268be304f864","x":2220,"y":3320,"attrs":256,"template":"action","children":["96a88581-edd7-4bd4-816a-929b41f71f35","84ac336c-239f-4cea-bf4f-812998e23679","c503db39-57fe-48cc-8000-a8bdd4a6e8db","40c7d832-33cb-410d-8656-50add3622f15","e14610db-846f-444c-9fc4-5257ddde15da","68c4e56b-3f74-4285-9eaa-f88e4d8ec6f6","f6465f10-4753-4b25-8ceb-8586a0ff150f","18ed30ab-cf3c-41b6-b37f-be107c6a97e5","46a5541f-0b89-4deb-8be5-05ba76cc5b99","d609358d-2bd1-48cc-9b80-76f1171dd759","7432e73f-725b-4a13-b691-b44028bb6038","6429bc30-aaa8-473d-831b-36790ff0b71e"],"properties":[["name","Send System Information"],["tactic_id","OB0004"],["tactic_ref",null],["technique_id","B0030.006"],["technique_ref",null],["description","Runs pre-set group of WIndows recon commands"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"8fafaa85-739d-4c15-9038-f9f0cf20c92e","x":2390,"y":2800,"attrs":256,"template":"action","children":["af89ab21-ed68-4621-aa0c-903806bca997","5fa492e0-778a-4f1a-88cb-a93ee0786a20","f36a4708-deb3-4cf5-8976-100e60a368a9","40facf37-79a2-40ad-a39e-0e30ef7bf9e0","08b1a94e-8d23-4793-a0b1-b8923bde7ac8","3c1491ff-7baf-41e8-b50a-509d06ea72ee","1d8e0a07-657f-4b20-95d4-1a7f09863356","6e7a6b0b-2e0a-4c1f-8a74-67ebf4e00094","474ae488-d699-4909-9ded-25732cf588cc","33d8b002-d7e3-4393-ad62-2493137d633b","2f09c638-8764-4137-860f-15bee5484251","999e41de-3acc-4a62-be9c-9dc134f3afe4"],"properties":[["name","Process Discovery"],["tactic_id","TA0007"],["tactic_ref","x-mitre-tactic--c17c5845-175e-4421-9713-829d0573dbc9"],["technique_id","T1057"],["technique_ref","attack-pattern--8f4a33ec-8b1f-4b80-a2f6-642b2e479580"],["description","collects PIDs and names of running processes"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"17382d39-8d97-457d-9a89-0f8d77dae0de","x":1360,"y":2790,"attrs":256,"template":"action","children":["587bf7af-6ce3-44a0-a01c-e9c29493b2ad","b27b8380-0bbc-4a1c-8307-888e45e1940c","9ced5104-7cbd-4b69-bbc9-0721194aa771","921c60d9-4240-4d2d-a7e4-175c95b52829","0bcbca3c-ade6-43af-b30a-985cd7f38117","682297ee-7b1f-40c3-9792-732b2b8cd8a8","a672ef9c-304f-4dcd-830f-d0f0fa51558c","d12e1ecf-1ed2-480c-ad5a-393519cf94dc","8cff54dd-94a3-47ca-97b9-9a6f794408f1","3c154c18-2b0c-40aa-8d07-6d646b146707","33e3c8f5-b7bf-41c2-ae25-e2993db51c6d","069c7053-b0a0-4495-843d-66b65d1b5df7"],"properties":[["name","Server to Client File Transfer"],["tactic_id","OB0004"],["tactic_ref",null],["technique_id","B0030.003"],["technique_ref",null],["description","Downloads DLL or EXE files"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"9bbbe9ff-b82f-40d9-840d-c6ad2439b7e6","x":1880,"y":3630,"attrs":256,"template":"action","children":["322f3287-b2ce-4c46-92eb-530398486915","40729dae-6bc4-44f8-bcd1-48c2d11e1d73","b472dad6-3264-4ee7-bbba-b2927896f4df","f673543a-940b-4401-ac2b-66945fa287ad","675c7200-de29-42b4-8063-1ddd5c77cab1","c044155c-3dbe-4028-90ba-fccd4f64c871","e09df1db-70e7-484a-bd94-513988ae2a70","8b1285dd-ae36-4fdc-892a-1eacfef6e64c","0ff0396a-1566-4848-a01d-0efcb7772b10","8374b5c2-f2f4-4aa6-a8c1-67d8740046c9","f20e91b6-ebce-493f-bf1d-dc0e0a2d7f84","028944fc-e994-4ceb-9ae8-ee51219a4d74"],"properties":[["name","Execute File"],["tactic_id","OB0004"],["tactic_ref",null],["technique_id","B0030.013"],["technique_ref",null],["description","Uses rundll32 or cmd.exe to execute transferred files"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"f5c36be6-4afc-45bb-b98e-76f4f6a1e09b","x":2580,"y":3130,"attrs":256,"template":"action","children":["bfa17610-a018-4703-903a-a8c579472b4b","e3e1eb75-90cb-4591-be6f-aa5ba4e4c7c9","9cb8b3bc-455f-43e1-8192-45a0a136b10f","0876573a-c821-4ca6-83f0-24e55d6264c8","a20054aa-ac4e-4852-96cc-3c08db2f1459","8cf8fcf5-4f10-4275-8809-fc1cb57c9720","b7ae46f9-3228-4f7b-9fb8-c7bcd4eaa4e5","b29e1491-9003-405c-87dd-37715fe206cd","6d948b29-9086-47d9-8225-cacc5255be22","13dd7212-4d63-475f-891d-663fa6f3bc19","9659936c-633a-4e33-b434-e15c8c50ee90","dec7f193-fa5c-4ee6-a4f7-2f165de33ec2"],"properties":[["name","Ingress Tool Transfer"],["tactic_id","OB0004"],["tactic_ref",null],["technique_id","E1105"],["technique_ref",null],["description","Downloads a stealer module"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"1d85143a-059a-438c-a794-10012880f3e8","x":1150,"y":250,"attrs":256,"template":"grouping","children":["f96c80e1-5a66-453f-922e-bb29c362e304","1412d71d-2f38-485e-8bad-5a6e12431128","5b154456-953a-49d8-823c-1a3650b5f5ff","d527b6d2-4d38-40a8-a2e6-5755c6a9195f","af788d4f-4da0-4f5d-9032-44afab2d0ad3","f5417fae-5533-4925-94ca-1ccfd5d64386","4fea9507-5c53-47f5-9e79-5dc1e430ca32","b95baffc-6db1-44c1-8f77-b030f0730045","04df45fd-4ccb-4164-9dc1-24009ec3c58a","0b3e06ad-01b2-433a-b948-7585d5f23b22","cc092ee5-75f2-4662-ad55-07da983eea1b","724a3049-7e7f-43d5-b946-7e3246b98805"],"properties":[["name","Sandbox/VM Checks"],["description",null],["context","Malware checks to ensure it is not executing within an analysis environment"]]},{"id":"ed9ce25e-3124-46c3-9800-bf118b65c99c","x":1280,"y":510,"attrs":256,"template":"condition","children":["93668601-e35a-4062-ac43-0728d4e89185","a7bc63d6-706c-4577-925e-e42f7fc6a93c","61985b66-4a7c-4a9c-af70-2bd0955d0a95","0fb79972-831f-4587-8e03-f7b7091c194e","86ae7f9a-c508-4d07-9e40-599666dd6149","30a13a7e-8308-4fab-9bf7-c22ffee5f4e7","5d174e87-ee3e-4f13-b89a-3ac3cafdfa84","97dd95e0-1acc-45b7-b864-a4ef15617690","cd871faa-bccf-4e88-bf9b-e79d0474daea","606eab2e-e3df-46f0-a332-959ae6c9d5d7","412f69b8-a383-402d-a4c1-b6024b038dd5"],"properties":[["description","Discovers Indication of Execution in Sandbox?"],["pattern",null],["pattern_type",null],["pattern_version",null],["date",null]]},{"id":"e74ac193-4a84-408e-acaa-b19af464b93d","x":1257,"y":387,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["171fb351-bf8e-4088-be00-037a58fb2fd6","f259fcab-807e-470f-a369-045546ccb09c","f11e1e1d-369c-4d28-a24a-f22c1c3cbba9"],"properties":[]},{"id":"97de4877-44e3-4697-b262-a1123806db8a","x":1418,"y":606,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["ebcf9433-a38f-4728-83c3-edce789e8d8c","620fff19-649f-4475-b800-e6d1702a5625","5f7404cb-d7c5-4103-a284-c6449a15fb04"],"properties":[]},{"id":"961e50bf-5799-43f2-9277-df5d72d27de3","x":1470,"y":1080,"attrs":256,"template":"action","children":["ade4b00a-178c-4dec-9202-8bd1a4934a76","e7f5aef3-c5e7-4140-ab6d-267a28b27290","ac912536-c971-4f24-a5eb-4163f3cefab3","54e7f631-a8a7-4da7-98cf-5b9e0fbfa84f","968e2cfd-20c8-41cb-9394-aa3d80b8ef00","c218d56e-2686-4043-a7db-50648c5ebee4","d547288b-4a05-418b-84b4-0665028763de","7624e49c-4fed-4a15-8437-484e793ffbfc","2112a909-a230-401a-90f1-5bff3937365c","d90c3ed2-3539-4720-8b32-15dad27b1a27","f2211ae9-6c2c-4e9c-8743-c97c2cef8e77","b9ea9332-3024-4dbc-b987-5e10a871d7e5"],"properties":[["name","Non-cryptographic Hash: FNV Hash"],["tactic_id","OC0004"],["tactic_ref",null],["technique_id","C0030.005"],["technique_ref",null],["description","Used to calculate group ID"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"2ab9fa88-caf7-4fa0-9101-e5b91fef1d89","x":1470,"y":930,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["157e46a7-9a48-45a8-b3b5-4d156246d79d","ff3d50a4-7bde-47f1-9678-66627b13d081","e01be3d8-5927-4ae8-bcd7-2acd1b17c2e5"],"properties":[]},{"id":"0f72ef7c-2379-44d9-9927-424fcfb6968c","x":1730,"y":1550,"attrs":256,"template":"condition","children":["455f4a91-20d6-405e-a015-d3a5d4d75067","01637e4d-491e-42ba-b730-3a912cd1aafc","b20e7c8f-6caf-4b88-ae88-112b41a3d7d2","2cde27d0-f41e-4418-915f-d5eae3b1e0f7","754854cd-73e0-44d8-81e4-394444684bc8","10963a37-3edc-43cf-9917-78b1551f984c","e2be1cac-b738-4f82-b44a-eba7912e7185","67b0c66b-d6ff-4fd6-a6a5-88f1bb3dcf48","5ad54dd2-e992-4d94-beee-f0be33e3ae54","271d762f-4165-4253-857c-58f86c1f9cb6","70183590-5988-4c9b-8257-70014608b53e"],"properties":[["description","C2 File Exists?"],["pattern",null],["pattern_type",null],["pattern_version",null],["date",null]]},{"id":"ce3ca0c2-14b0-4348-baed-85069c8e149a","x":1586,"y":1641,"attrs":256,"template":"@__builtin__line_vertical_elbow","children":["f9710216-edda-44f1-b25a-0ae54fbc7d22","929ab254-1d9f-493b-99ee-ee35d0bfb7a5","b352e358-ec5e-48d3-889b-1101b67d70a3"],"properties":[]},{"id":"e119bf94-93b2-401f-a3c3-474ae7563c0a","x":1490,"y":1955,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["678b54da-f7ae-4b6d-831c-caa4d0862d46","fe0891a6-6743-4d4c-9c7e-b4048542b9ba","0d60f6f7-804e-4fb9-8697-34a459e23121"],"properties":[]},{"id":"2e8bc208-cd80-44ed-ad8f-cf71d00749d3","x":1840,"y":1080,"attrs":256,"template":"action","children":["11a3e078-1ad4-4077-965e-c21d461df45f","aa0f8c9d-ba6f-4eb6-b55d-2e89e5937e3d","805a9e36-a730-40eb-8e79-0b183275d614","d2c5ebb2-66b6-4630-9d6d-32fb862e0f92","dd9212be-7679-417e-a2ca-614f7cf8e6ad","fb813be2-3cf6-422f-a6bc-0a2311882bc7","5119793c-8888-44fb-8b13-c696f57106f8","4284a9b0-d8f5-4948-b803-109dfd265134","187a134b-705c-4c2d-b044-81b209b5d380","76882caa-4766-4bd3-a8f6-3fc44ced4f97","d82a016d-08b9-48f2-a52c-e111d7aacd22","29681192-5652-4d3e-bb76-bf7072f2f044"],"properties":[["name","Self-Discovery"],["tactic_id","OB0007"],["tactic_ref",null],["technique_id","B0038"],["technique_ref",null],["description","Check exe running from %appdata%"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"ed0736e8-f554-42b6-997d-fc18cd6aab41","x":1672,"y":1080,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["5919089d-0405-4b03-9fc2-ab22d6a96fe8","a8118633-433d-4c01-bcad-6bcb8ebfcef2","396a614a-5aae-4876-a7e7-c403f55d28b7"],"properties":[]},{"id":"c8cbe298-71ee-4ae3-92eb-dbd4e2e66a4f","x":2220,"y":1040,"attrs":256,"template":"condition","children":["a86dd764-006b-45ce-85ab-4442f7a58fea","63af241d-2d12-4ceb-83dd-3d6eea014584","1e4ae9aa-55f3-47ec-b826-59dbd5faee09","029a2a6e-b27b-45ed-88f7-9bb0a915b249","c7b251d1-9d0e-492a-ab1c-b8e6038e44c9","f564f00d-3c89-44be-ba7f-ce3203477a17","32c62353-141b-4716-917b-e7c080b28a12","7cc10ad2-f82d-44dd-939d-af9dde6a653b","c3494c62-be5f-46c2-8f6a-61bfb6c4c3ca","6460e2b9-aba3-4c50-9cbe-0438790ce73c","bff16312-8a4d-45c0-8853-e38952154b9d"],"properties":[["description","Executing from AppData?"],["pattern",null],["pattern_type",null],["pattern_version",null],["date",null]]},{"id":"4be22955-a841-4b3f-8414-3784d6143ede","x":2035,"y":1048,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["cac31540-41e7-4d9b-b3f0-07e9da669d90","391d37b2-cc1c-4bcd-8940-6dee130b6b51","70d0c801-3e3b-4d6f-a05d-a1c7513c9336"],"properties":[]},{"id":"3444fb5b-da4d-462f-88ce-3f7453e37f47","x":2490,"y":1270,"attrs":256,"template":"action","children":["452651e8-7dc5-4fb2-a421-83917453a56b","ab83ef46-8cbb-4fba-86c2-94cce8106f09","3f1e5c2e-05a2-4f0c-9ad2-e16e416fa560","fb70fedf-04f0-4fc9-a1e0-9acf3beda6fe","41e9bb99-cd3c-40c7-a1cf-f7ba73fa0ec1","79db4b88-f406-4156-8ec2-0a274111e447","4b05defb-7052-4a7a-be42-7501a17f574e","fe435c0a-81d0-4e59-accf-8a13af291ec3","316f29d0-be81-462d-8dba-97c70adf3423","0acc5b78-5b6e-4585-baac-9cedbca9a189","db55a4ba-ee2c-4890-87b2-f7e6f168b43e","8c2a8656-9fb1-4ccb-9a62-d203913a93e4"],"properties":[["name","Copy FIle"],["tactic_id","OC0001"],["tactic_ref",null],["technique_id","C0045"],["technique_ref",null],["description","Copies executable to %appdata%"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"f286c4a1-20c8-402a-bf77-f64408250815","x":2387,"y":1121,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["8d08efcc-1733-441f-b9d5-dea5bb196659","4a19bdba-2681-4d20-a90b-f8c932342a3d","33018f07-888b-466b-84ae-eb1f9b0afd00"],"properties":[]},{"id":"73fd998a-ea52-4cdb-a957-e08cbefef97d","x":2490,"y":1850,"attrs":256,"template":"action","children":["200342a3-b706-44b1-a8a6-0ab6e53a96a3","f3815ee5-6eb6-4017-8bdc-a15e2428ba11","243c5fe8-daf9-43cf-b940-54dbe6ddf9d7","206c79d9-798d-481e-b074-830607476393","012644f9-861f-455c-a7f6-ace4938f672a","7d597798-0fd8-4f5a-9584-7684a2886269","219676b3-8aa6-46c6-bb57-bfd1babf6961","33690bae-3d03-4b4e-a6ec-b133f50b6319","15fdce5c-001f-4218-90f3-dfbad021e0a1","448a0b2b-71a2-4d8e-a831-2d3c2d602611","dc0ee260-936e-4570-850e-656315a28f13","9cc44410-4f5c-4432-a76c-3bc57d1fdee6"],"properties":[["name","Delete FIle"],["tactic_id","OC0001"],["tactic_ref",null],["technique_id","C0047"],["technique_ref",null],["description","Deletes old executable after executing in appdata"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"08a24b37-fb16-4626-bef2-705b57e7782e","x":2490,"y":1436,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["169eb6b9-6688-41b5-8634-ed71ed040fc5","36cd005a-08be-49f8-9064-bdf12544e5b7","52384bd0-aae2-4ea9-a3e2-5d80d75c5674"],"properties":[]},{"id":"d0667ee0-ef70-49e0-a96a-b6777bda94ce","x":2070,"y":1550,"attrs":256,"template":"action","children":["3c78250f-eb99-427d-a747-611eb01453c3","21991030-a632-40c5-8c84-e6eef96d0d3a","a33183f3-3a6b-40b4-ac6d-02919545703d","6ca5db82-af4b-49ae-b524-6f9e5f3fb780","78177585-778e-448d-adc2-0736e4635c9c","0f7e4a78-8190-4b3d-963e-e890afaa5d9f","c7c982e3-7b7f-4096-beab-d8cf960ca35d","ec77308d-b722-4a4d-b1f2-c28e68c9672f","15f606bd-55ec-4733-a51a-da17a35137e0","e7569b3d-4f8f-4eb5-8a6f-e4faa101132a","882e3fd8-1ebc-43b4-8520-e751524d50c9","93c1ab7d-c846-4946-874d-fde4aaa17749"],"properties":[["name","Scheduled Task"],["tactic_id","TA0003"],["tactic_ref","x-mitre-tactic--5bc1d813-693e-4823-9961-abf9af4b0e92"],["technique_id","T1053.005"],["technique_ref","attack-pattern--005a06c6-14bf-4118-afa0-ebcd8aebb0c9"],["description","Creates task which runs at every logon"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"e88936bd-1cec-487a-89cd-7e494c5d9b59","x":2112,"y":1261,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["2072bb90-eecb-456c-a94e-aaeca9119f6f","c519af30-6b2e-4775-8ae3-2632e186a938","9293037f-aa96-4d04-8677-c0e42d90b4a6"],"properties":[]},{"id":"cd7ef1a2-97a2-40a7-9134-629c6c105f54","x":2268,"y":1550,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["2de3d811-f017-4ef2-9bd0-3c743895270b","79af9b1b-d931-4f72-b338-f3011d16d9b7","acb71bfd-ce1d-410b-b411-bb663a710e26"],"properties":[]},{"id":"78f23e8a-b4a6-47be-891f-1521e2272ab9","x":1872,"y":1550,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["30abd31f-a249-447d-ada4-6c4203c00d6e","68300c00-3b40-46aa-9042-eeba60a218ed","54b01be2-f312-46b1-9fa9-5cb3d4edbbeb"],"properties":[]},{"id":"bc4c9f48-8244-494a-9241-7b062bd4620d","x":1320,"y":2470,"attrs":256,"template":"action","children":["d0c1f493-e3cc-408a-8fe1-0c1db9e17925","70d0688b-8697-42b0-837f-484877defa9e","c4f88951-ac1d-45c0-888f-0f095b5d3971","21c1d051-a401-4fa1-a457-214727131263","39067643-7075-4cf8-b7c1-bdad83328daf","d95cc3df-056a-4a35-9225-b6a668306bc7","7a405274-5730-4ca0-b213-81ab05bc6600","8858555a-0b37-4bcb-b07c-56d996d2d39c","b10f5695-4faf-4985-99c4-a6c718477231","56478779-4bac-44c1-8429-6655f559251d","42e810fe-e25d-4c69-9ed8-dece23f8436d","338493df-bb61-4f36-9f2b-b2f85d3f4ebf"],"properties":[["name","Receive Data"],["tactic_id","OB0004"],["tactic_ref",null],["technique_id","B0030.002"],["technique_ref",null],["description","Receives commands from C2"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"56d45603-8674-4651-8e68-b9aa9ffa8737","x":1880,"y":2980,"attrs":256,"template":"grouping","children":["b5c2cd2a-b18e-4ec0-b356-2db1145d0934","5c357aaf-f36f-4035-be07-2eb14e3f10cb","7ad4cfb4-6670-4bdc-a747-cbe3d6cec178","4d2545a9-a966-40cd-a48d-011fc5d95393","c27f8cef-4f1a-492e-8016-f830865ca573","e809622d-fe3b-4c74-be3c-2c7f7715f620","0675b6c7-9c8d-430f-830d-a4b15357a280","43a6a1a5-66dd-4584-8603-0ebd5cf74ce9","ab6af750-a8eb-4ab8-8679-79e75fcf1dee","026abd86-199c-408b-97b7-3d054fdae981","808919e9-063b-4c73-baed-a6602816547c","c6dd0d22-9447-4284-8206-d0f9d5e0fd76"],"properties":[["name","C2 Commands"],["description",null],["context","Commands malware receives from C2 and sends data in response"]]},{"id":"6ddee69f-4052-454b-a147-380da9a835aa","x":1714,"y":3123,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["71e269a2-e64f-480b-8812-e46b609d3955","2a651847-3d13-4291-940e-b408a825b2ab","037cb1d4-7cb4-470f-929b-6b65f9288f52"],"properties":[]},{"id":"acba6cb6-d117-46a4-909c-d63f79e9c786","x":2090,"y":3123,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["337eb992-4b37-4432-8178-a7362c5b1856","913719f1-a680-4d83-aff6-ae301f1f8851","6bcc4543-252f-4a08-8756-85bc422b141a"],"properties":[]},{"id":"d30475f7-fcbe-4bea-8fe7-77d2880a8cb0","x":1880,"y":3278,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["e061d6d2-51b2-4901-9103-a6bd950b68d2","dac815c1-cbf1-4bfd-86f1-1a5f11c66927","375808d0-3924-48cc-b0ff-332b4104ac70"],"properties":[]},{"id":"bd7f6922-bed0-4a88-a6fe-e2f1ed77046f","x":2253,"y":3044,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["6021ad97-e007-42f4-9d51-5d5e36ea3163","beb76adc-6e1f-46a6-acf1-bddee35c5f1d","1c6e7fff-5c84-4a8f-81a5-edb98ee3094b"],"properties":[]},{"id":"4091668b-3f98-4b05-95a9-521ec3d6703a","x":480,"y":530,"attrs":256,"template":"condition","children":["bc5619bf-ffa7-498a-88bc-bb4efe3479dc","3773e065-f3fd-4059-820a-722875024d55","62d166f9-1010-4df2-9df9-dca5e0152442","b6633df0-0a70-4fcd-b571-f18ed883a863","d430b1bd-93cc-4e61-a5e6-245bc62f2f73","71b02c3c-ca24-4156-8055-ebd6a7c14476","0267053f-d862-4e35-bd76-222c9d8214e3","8da31f03-1fa1-4b4b-8a6f-82f81abcdebb","387a2cd8-c0e0-4ec7-9d99-ed57636952a6","38d29a15-26f2-48e8-83c4-56cc080949bc","be804939-f5b0-4021-8b48-da9ad34f5ddf"],"properties":[["description","Does the mutex already exist?"],["pattern",null],["pattern_type",null],["pattern_version",null],["date",null]]},{"id":"44965326-9631-4547-95cf-5550f5bb985b","x":686,"y":530,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["0b5ad376-58f1-4559-9780-2426f3c6ec63","49e3f8af-9aac-44ec-adf8-2ff1c46bea92","44154d41-d504-4db6-b206-77fb54c936c7"],"properties":[]},{"id":"ea43ca4b-a714-46fa-a2a7-6c0dce01d9e6","x":290,"y":830,"attrs":256,"template":"action","children":["5ed91cc0-d913-4aab-aa00-fcb12bfeda44","4ca96364-4c38-4b8b-bda4-683ca0f13375","e3374114-fb93-403e-af33-6511eb5e9287","1d253adf-07af-4354-8240-874971e91b15","95d03252-77a7-4ee4-93fe-841e77720c5d","1649f825-4501-49ff-a8eb-81a099d5483f","bbce4fb0-f168-4d0f-bb8b-b0254bb57822","649bfc8f-a9cc-48f6-9292-27a058f20aa8","e5dd5666-d83b-41cf-9dcd-2d7ab45e327e","4e0de801-4eef-4aea-8e2e-bb7705238a8d","55e9bd99-e8d1-4e45-990f-505217c6ba85","dc74ce3f-a6ae-423d-bac7-c34f476e9683"],"properties":[["name","Create Mutex"],["tactic_id","OC0003"],["tactic_ref",null],["technique_id","C0041"],["technique_ref",null],["description","Mutex ensures only one instance of malware is running"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"988738f3-3a58-4e60-90dd-4832918a46c8","x":347,"y":641,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["8c8edb68-dd77-45c4-bd4d-fb7450402c1d","b16d6e05-efea-45ca-8acf-aee554600a76","da83d08d-ae1e-4f39-b1a3-d36cdd1d8677"],"properties":[]},{"id":"aa621f2f-6695-4280-a648-12b7399d740b","x":1230,"y":3120,"attrs":256,"template":"action","children":["2276584a-78a7-4d25-8be9-f07eba696b2d","ec3e4a21-ebb0-4b23-aff9-d028e7aeee8b","3eeca1be-e201-4ab4-b38b-f6f54183138b","186ecbf7-fd68-4a4f-91b5-e5f4e7c4fa64","4f79fee8-092e-4f93-b0e9-2c6e0d5b8c94","022066e0-d141-4cc0-81e4-fae573a22ced","913fb1a8-bc81-4435-85a5-460e304c334f","81b9683d-8e0a-4068-9f26-f9327977090e","94ba69aa-98c5-4c3e-9083-e56e20bcca32","112d9c2d-e8cf-4dc7-a881-aa3e21058928","17f3dffe-5f36-46e8-875a-0f63c5350130","97340e33-383a-47f1-a738-88a1ec0b784d"],"properties":[["name","Write File"],["tactic_id","OC0001"],["tactic_ref",null],["technique_id","C0052"],["technique_ref",null],["description","Updates C2 URL file"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"be2065d6-b9b6-4c46-95ed-ff75f354abfc","x":1611,"y":2837,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["57df81f9-5b0b-4350-9277-7c593fcfb483","1d3806e3-a365-4ccb-a4ba-b522364a126f","f0d5373b-7885-40b4-ae79-f69ee9abdfd3"],"properties":[]},{"id":"4cb5012f-c68f-4a9b-99dc-02de70490b9a","x":1518,"y":3068,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["34cd69ee-aa26-4efa-a893-a3bb0bb9282b","101663c2-eea0-4e0f-95fe-91eb0c814cbf","8906d537-bf43-46b1-93c4-525281e03169"],"properties":[]},{"id":"2b4339ab-0b45-4cea-935f-9eda3205ab0a","x":1880,"y":2470,"attrs":256,"template":"grouping","children":["b7141a8d-b75c-4b29-86c0-014b68655420","4ceefda1-820b-4a13-9388-641579fe28d7","7a5ddb0e-16b2-4a02-ac1f-dbe32342c47e","74b3772a-09d1-4bab-affa-82e49e71afbe","fa40e8ca-bc86-4f43-b450-cf87ec99fb77","13edee41-b948-4839-bee8-db0d6e151eac","b389321d-3b55-4f41-b90c-056356de0539","a3ec78b9-fc19-4f4e-8456-fe0d5f013fe5","a78a03ff-afeb-47c9-8415-85ecf365997d","f87f30c2-28dc-459c-a464-32a2263952cb","8ef03e87-9159-4ecd-af3e-4756d3920c86","a1ea9d32-fc4b-4e8a-bd6d-5ec9ba64ee5a"],"properties":[["name","C2 Communications Loop"],["description",null],["context","After a C2 connection is established, the bot waits to receive commands and sends data back to the C2."]]},{"id":"8588d4db-63e3-47e9-9fda-35b8d7db3e5a","x":1643,"y":2307,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["cd1689f5-2c46-4778-96f9-db2037e2e51e","c6049d38-6f6e-4252-bf61-7f0040800127","b59a0415-2c7d-4aa3-87c1-1a2dbc429543"],"properties":[]},{"id":"105cfc99-368e-48ad-8540-d10a89a56e55","x":1843,"y":1711,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["43cf8559-4a36-4030-8163-e0ac8fbb59e8","ae97c620-d7a7-4843-85a8-7f0ba33b1025","c4c2597d-01c7-44d1-a73e-d739437a6b77"],"properties":[]},{"id":"62245105-a3d4-4419-8c62-d6e948492a91","x":1937,"y":2232,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["3ccef06e-3c32-4450-bbe9-7e87f43cf02a","554a36d5-dc7e-48b0-b39f-e3613c224cc0","d2b802ef-d1f2-4a4e-89c8-b04c160c6c68"],"properties":[]},{"id":"95c87492-4e1f-4700-a123-ce3818ea20cd","x":2102,"y":2440,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["31c9c8a8-a6ef-4df4-8f50-7d7a13e5aa4f","8488014c-43c3-4ae9-ba72-934dcb68e63b","f32fcd6e-5540-4525-9397-8912791d6d10"],"properties":[]},{"id":"049c3ed8-9a71-4974-b91b-4122df9593a7","x":2399,"y":2410,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["7f73aa27-617c-45bf-b1ac-d61ed565fd70","d46fdb2a-dfd1-4ede-ba88-6ef33a27fad0","eeeb36ee-462e-44a2-a8f9-5c16df6f0d56"],"properties":[]},{"id":"29c279a7-55af-4e93-9bc6-68923570ac0f","x":2900,"y":2410,"attrs":256,"template":"action","children":["2d40f138-f390-49f8-bb63-7364f9b1ca94","3bc91e50-2676-4361-983c-b820c47d84b1","91b16936-7f1f-479a-82ab-6874ab5cc8e9","ccbc7661-2634-4e36-8c1f-f7449f31a93c","34a07c72-0b9b-47bb-b4aa-3f13c5d3cfd4","b7661767-0ac8-4fd9-9c9c-d78d14edd4e4","a2457b5b-90e7-46e8-9c99-745b3061482f","59bbf8dc-2864-4e89-a492-5d83caa2fd59","7d441f06-8669-4efe-8f04-d34e0532fe58","13b12312-22fb-4f54-8479-c6a533b488e7","aa41bd75-ed32-4627-94be-efaae6a4dbd7","1d2d5e54-805b-4c60-93f5-9131b0f431a3"],"properties":[["name","Send Data"],["tactic_id","OB0004"],["tactic_ref",null],["technique_id","B0030.001"],["technique_ref",null],["description","Data collected by implant as per C2 commands is sent to C2 via HTTPS"],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"e137813e-d96d-4dbc-aeec-d69654717b44","x":2685,"y":2410,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["873c85cd-da8f-4c0e-ade2-1e331830362b","9a8e65f9-f639-41c4-a231-82ffe634cb77","81837c26-ce9e-489f-8637-532882b0b376"],"properties":[]},{"id":"a0259e1b-b601-474e-bf36-884d9bc22c8e","x":1880,"y":2730,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["9bb5646d-af04-45c5-b594-6fc8e028b94b","07d9c9d4-614e-4be5-b089-1a4c1578f33e","8911810b-122d-4011-8c44-931491a8f49d"],"properties":[]},{"id":"232c50a2-3768-4fd3-8771-79dc4ec7c744","x":1575,"y":2470,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["a918cc24-9554-471d-b879-f687ce82a2c4","acaeba8b-1633-40a5-b14c-32bcca6c1dd8","13c506ab-c1ca-4bf1-bc89-3edf9b64e893"],"properties":[]},{"id":"0e50092f-c41b-4c6d-a90b-906a8f40ee37","x":883,"y":250,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["fef5e417-4372-44c0-91b4-9880e4f52603","de6c7222-4a74-41cd-976f-6248e1af6670","7779f1fb-f1b8-4897-9aad-9e1d687408c2"],"properties":[]},{"id":"4c7c0a33-e47f-4904-90d0-5e1d3a1e6a77","x":988,"y":119,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["8aa841a6-2dda-4cdf-b3a7-f40e42bffd5f","d2ec3a56-dfcd-4808-8a6b-b9cfd34a1830","0fb8f2fd-af6f-40cf-aa7a-d18aee879ac2"],"properties":[]},{"id":"cf70aa08-e577-49bb-b668-57358a4ac9dd","x":1267,"y":112,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["df3ed19c-7e8d-4dca-bffd-b6767187ef0a","65f33e55-abb2-4080-8112-8968bc12a6df","05f9636e-3f74-4ac3-b6f8-62ebfa66ce65"],"properties":[]},{"id":"46738cb0-52ad-4c9f-852c-0e2fc468ce20","x":968,"y":369,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["d56c1abc-1141-4984-97e9-a71ec7e117e6","6e03ca80-c817-4073-a2ec-3b7eeaff3407","ea18277f-2474-4473-ad83-7801bb1c7f69"],"properties":[]},{"id":"f2cc7510-ee8e-46b2-b110-56e51506d094","x":890,"y":960,"attrs":256,"template":"action","children":["cc76b691-673a-4f7c-91fc-87fb9aa4221d","1e6a4cc7-3b9b-4f33-9897-80f3ccef0c2c","bf7dfebe-d649-4f0c-a2d2-fe19d081ce03","025b685f-3ce7-4440-9a7a-2ddc9652ddcf","16e8c866-7437-4bc9-86ed-234de9058a7c","9ce43f4a-be77-4449-9be7-624f3e2071c4","9565f4ea-2ca6-4e25-b7b7-ba40c388a1be","437bf8c7-1f12-4ab4-96fe-3445ca4c7b71","79c25f27-b47e-4ac3-af5d-f5effdf2db3f","0a8d764e-e973-4bc2-a46c-572bbd1c2969","a7a4ba79-92d9-44dc-9ca7-afd709c00b06","40229e8c-e017-4ad7-a968-2eb7cec330aa"],"properties":[["name","Suicide Exit"],["tactic_id","OB0009"],["tactic_ref",null],["technique_id","B0025.001"],["technique_ref",null],["description",null],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"37b33226-2254-4cd6-9175-b3507f80b7a3","x":704,"y":724,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["79eb6ba9-2e87-45de-9298-cd64b668fe2f","fcab581c-29a8-404e-9b2d-6f4ad1298576","bf6ee7de-2450-4779-90e6-e811bc8e82cf"],"properties":[]},{"id":"bbe2661f-8ab4-4fe6-9bf6-39305b1ec8bb","x":1059,"y":719,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["a5005bac-307f-4425-9283-efd9d6e286e9","a2793eaa-88ad-413f-b171-7d61e0af6fc5","214ace27-f975-4fda-9730-5d736a030bdf"],"properties":[]},{"id":"813bf6c6-89d0-41dc-a42a-ad190dbb3cf5","x":1398,"y":250,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["23ae5965-4d34-4258-b49d-2b4730b4acab","e9e7aea0-1b40-4c69-a6fc-f2ecb4e2915b","fdf99f45-2518-4856-874a-ea8d7be8891a"],"properties":[]},{"id":"4d78d74a-eaf4-477d-ad24-fdbba67fa4cd","x":2890,"y":1550,"attrs":256,"template":"file","children":["0d02f7c5-0d05-4435-9f15-45d67b5eddfc","7b8c62fe-8283-4c72-a356-6e91301a33db","c4089ab7-8fd7-4ecf-88f0-db7fe3b3c96f","4b4abd15-51f4-4d13-b595-9c8db2c42163","81d837e9-d360-4bd7-b076-7d1851528428","29114e05-07ef-40b6-8b36-ceb6538c28e6","5806658e-1d7c-4a02-b914-33658a05e84a","d41af8eb-be04-4a26-bbf0-93614d1de03e","674f6cf3-7d3e-4f6c-9ae8-d45f0e7459e4","58e3533e-6d2b-453d-b646-79afefeb8639","f55937bd-8fae-4ee6-9207-6b4c8a21b9d9","338c7bb6-f38b-4946-a369-c81ce7d03ae8"],"properties":[["name","Executable"],["name_enc",null],["size",null],["hashes",[]],["magic_number_hex",null],["mime_type",null],["ctime",null],["mtime",null],["atime",null]]},{"id":"30e19a53-9009-48c3-a0fc-bbbc773358d4","x":2721,"y":1402,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["3f797331-3db9-4909-b0be-0b72389e4aed","5197bfde-2c97-47b4-998b-509f58859de2","fb7fe74c-eef8-4e49-b8bd-f5d64f61661a"],"properties":[]},{"id":"2e0930f6-b4ef-4fdc-b394-94d1f85603eb","x":2733,"y":1675,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["605679fe-5246-4c16-b263-1c8bed0143cb","f9fda29a-ec4e-4665-a4a3-ad5fe13ffa9e","17266159-9d29-4d0e-97a2-7ea985028e17"],"properties":[]},{"id":"f2cfaa6c-5204-4708-8864-8f1d277c3170","x":2490,"y":1550,"attrs":256,"template":"action","children":["2f0b1705-4f26-4e44-b3f7-14a98940decc","054bc2bb-86b9-4641-9ed4-b980f2c3ab45","d9ae2b57-e148-4ab9-ab16-fbdd35a07570","5e90c165-522a-44e4-b85c-e04b28e695e5","40a39fb5-a65d-4f71-aaa6-9fda8712b553","16f0db08-2b48-41cf-ba35-d681e3601a78","a6123e62-b298-4f3a-a263-a58f718db8c8","3b54fd76-83be-42d9-b909-1ad4784fc267","90382f59-f3cc-48e2-8cc5-ef283775b207","699e4ec5-f730-45de-8434-d7fb30de3f3b","a665f873-8815-40b1-aef8-b3fb7130e36e","c98cbc6a-e331-44d2-a0f3-7961dc561200"],"properties":[["name","Command and Scripting Interpreter"],["tactic_id",null],["tactic_ref",null],["technique_id","T1059"],["technique_ref","attack-pattern--7385dfaf-6886-4229-9ecd-6fd678040830"],["description",null],["confidence",null],["execution_start",null],["execution_end",null]]},{"id":"a6aecd1a-a6c2-4f83-85ad-0cd55983c747","x":2490,"y":1669,"attrs":0,"template":"@__builtin__line_vertical_elbow","children":["89563b26-3d9e-4b9f-98c3-a599eaa4211a","f24679da-5850-4a88-8b74-e4b6de86ef2f","a9ec9b13-5481-4627-8140-f52aa26cdf67"],"properties":[]},{"id":"86b05982-622c-4ef2-81da-7dee944ddcd2","x":2742,"y":1550,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["4075bb0d-7a7a-4785-a1b8-61a115ec2782","125a0716-b030-4704-a719-d97ba995193d","ce44a654-5bdb-41f6-a296-c9a08ee24cfa"],"properties":[]},{"id":"3ef34e8f-c083-4152-99c1-f68599457bee","x":2129,"y":2871,"attrs":0,"template":"@__builtin__line_horizontal_elbow","children":["857e12c2-074f-4f83-9e36-38db3214711b","0e40842f-67b4-4dd3-819d-bd541448a5fc","c910579b-149a-4ed2-9ae1-db4aa846cf10"],"properties":[]},{"id":"a0b0c358-75dd-4746-a510-dbd0bff21c74","x":841,"y":-142,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"008566d0-68af-4cf9-972a-6d2066482cf5","x":910,"y":-142,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"315dcdbf-fbcb-46fa-a144-d7f978a78095","x":979,"y":-142,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"fdef2869-abb5-4d3b-bfba-21614fb74c89","x":1048,"y":-91,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"9d233358-16f2-490a-90e4-38a9be7bf409","x":1048,"y":-40,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"398d7882-44ee-4b04-99f4-c7f73b4fd443","x":1048,"y":11,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"8175879f-dc50-4cb8-a7de-68cdf2b5c107","x":979,"y":62,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"da70ee67-6b25-4ce7-a98c-cdd4d5700d7d","x":910,"y":62,"attrs":0,"template":"@__builtin__anchor","children":["0fb8f2fd-af6f-40cf-aa7a-d18aee879ac2"],"properties":[],"angle":1},{"id":"7d086984-16e8-447b-a11b-651d827f7c77","x":841,"y":62,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"846aff31-1694-46ad-8c90-d174759d2582","x":772,"y":11,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"ecc0b9e2-86b4-47a1-9d3d-f97a48c24386","x":772,"y":-40,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"ce897802-396f-42e5-b2d1-ba167d0acb14","x":772,"y":-91,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"e8abdafe-6190-4a59-bda9-fc72c7b1c5f2","x":1213,"y":-226,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c8a93682-8ea0-45d6-abe1-5f3d17ff62d9","x":1300,"y":-226,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"22ccafd3-f7cc-484c-a816-a00337837b31","x":1387,"y":-226,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"1ed8cdb5-a814-410d-9927-58bc20e123c6","x":1475,"y":-158,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"00477567-334c-48c4-8302-c1d8c81d60e8","x":1475,"y":-90,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"d7dcbdde-3619-4e96-8f3c-17acd90ef48d","x":1475,"y":-22,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"56b10b65-b7ff-4413-b7d4-978cdae6c7ec","x":1387,"y":47,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"02ba9256-14db-4daa-96a4-048861c71551","x":1300,"y":47,"attrs":0,"template":"@__builtin__anchor","children":["05f9636e-3f74-4ac3-b6f8-62ebfa66ce65"],"properties":[],"angle":1},{"id":"d6a58550-6084-4f9f-aa43-fb6ea71d2780","x":1213,"y":47,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"7d18c7cf-5954-466a-9082-c1caed1b5023","x":1126,"y":-22,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"797c4501-50d8-404a-80e3-73d450fca63f","x":1126,"y":-90,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"8168b36a-c86f-4fa6-897d-88cb7f143983","x":1126,"y":-158,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"4db4d636-238d-484b-97ef-99cfb8505112","x":1534,"y":134,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"b683e639-8061-42b5-9f50-5b1f3cd1536a","x":1590,"y":134,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c64a2809-f51c-45d1-97b5-27425d667ce1","x":1646,"y":134,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"3f143250-b341-484f-a129-b29ba6348bec","x":1703,"y":192,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a74d2f3d-7ef5-4a43-a51c-a6244cd6d012","x":1703,"y":250,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"dd8d2971-8905-4fa3-a4b1-7fe5382c9b64","x":1703,"y":308,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"1c1054d1-990d-4e02-9f0b-08a121e01e0b","x":1646,"y":367,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"a8fcfd3a-371e-4b8c-b27a-a60ba7580b85","x":1590,"y":367,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"68658dae-5a6e-4240-90b4-662e0444d139","x":1534,"y":367,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"886efed4-1802-4a03-aabb-b067c335dc57","x":1478,"y":308,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"2fa696df-a3b4-4f33-b081-a0243bb2d121","x":1478,"y":250,"attrs":0,"template":"@__builtin__anchor","children":["fdf99f45-2518-4856-874a-ea8d7be8891a"],"properties":[],"angle":0},{"id":"ab22bd0d-2d9e-4ede-9777-421c52ed0c02","x":1478,"y":192,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"f0ee6d6a-77c8-4fe0-8af7-a906fddf1584","x":523,"y":112,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c8429eb5-7e74-4e73-92ba-bad846a2577f","x":610,"y":112,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"96afcd7c-a3d5-4b95-9b9d-0f3afec04955","x":697,"y":112,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"8eac7286-d286-4431-b3d9-277ed2bc8dde","x":785,"y":181,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"c215f802-898f-4470-bee6-b00c177015e0","x":785,"y":250,"attrs":0,"template":"@__builtin__anchor","children":["7779f1fb-f1b8-4897-9aad-9e1d687408c2"],"properties":[],"angle":0},{"id":"657af429-9fdf-48a1-a0c6-acf44f75a224","x":785,"y":319,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"6535d96f-7648-42b1-be92-96af6fd9d737","x":697,"y":388,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"91ded85b-3ea0-4eb5-b3df-473ea1b539bd","x":610,"y":388,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"7d86fc99-170f-425b-812b-9f55b9f5053b","x":523,"y":388,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"86f9d220-4d33-4726-8435-73d10c145a6d","x":436,"y":319,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a9272ab7-ecaa-4313-9e8f-bef8564f216a","x":436,"y":250,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"793ababd-f74f-4afe-b516-dc47ee572b07","x":436,"y":181,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"3f1cfac8-efc0-4f34-bdce-266dd6f6a81c","x":806,"y":414,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c00d48a0-d0b1-44c1-9c46-54e8cc1ef2c0","x":870,"y":414,"attrs":0,"template":"@__builtin__anchor","children":["ea18277f-2474-4473-ad83-7801bb1c7f69"],"properties":[],"angle":1},{"id":"c9a392ca-c447-4254-a025-7a7159f295f2","x":934,"y":414,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c23e7613-97b6-4a01-944f-55664512330a","x":999,"y":472,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"5f6e3a11-7a51-41be-a1ce-912acc5829a9","x":999,"y":530,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"0e89fc24-a890-463e-9a51-a2706d56371a","x":999,"y":588,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"45535fc5-c7fe-4e31-a5c0-0a0fc45d7d70","x":934,"y":647,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"68c19cf3-531a-40da-add7-d568472e1ce2","x":870,"y":647,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"67ca96bd-3894-42cc-9bcd-210625115ff0","x":806,"y":647,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"2475b468-8dae-48bf-8672-05ba630ad755","x":742,"y":588,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"5740a894-efc5-4445-9c8c-59ae5e3a29e2","x":742,"y":530,"attrs":0,"template":"@__builtin__anchor","children":["0b5ad376-58f1-4559-9780-2426f3c6ec63"],"properties":[],"angle":0},{"id":"3ddb3968-9617-4d1a-ae77-a5181931cb79","x":742,"y":472,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"d66b9f68-88ac-4624-b428-d63618b966f2","x":1385,"y":643,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"13366536-e3b3-4017-807b-bb6b9f25b9fa","x":1470,"y":643,"attrs":0,"template":"@__builtin__anchor","children":["5f7404cb-d7c5-4103-a284-c6449a15fb04"],"properties":[],"angle":1},{"id":"ebd076aa-2dad-447f-af13-5298875a7a31","x":1555,"y":643,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"21e4f525-c22b-4dd2-a670-7141d70c5da0","x":1641,"y":706.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"3b54e5f2-0e97-447a-9c7f-d99353c40d65","x":1641,"y":770,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"4f6e0d0e-341c-4f10-878d-7f7b1ddc6088","x":1641,"y":833.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a40c85c0-18fe-4b47-a470-7942d787ee48","x":1555,"y":897,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"e5250ba6-03b6-4c98-9b17-8d49dd1048ba","x":1470,"y":897,"attrs":0,"template":"@__builtin__anchor","children":["157e46a7-9a48-45a8-b3b5-4d156246d79d"],"properties":[],"angle":1},{"id":"9b1827ec-3058-46c7-b867-efb073da1913","x":1385,"y":897,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"e1867595-2b46-49a8-9414-929e61ec8b48","x":1300,"y":833.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"97befd52-2a47-43cd-9036-70b3ad8e128d","x":1300,"y":770,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"7f097585-f6cb-462c-ab47-21c051795f18","x":1300,"y":706.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"5814dc5a-191c-4a3a-ab29-2f4419202420","x":1417,"y":1994,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"b1119be6-9eb8-470e-98d2-6004efa1f118","x":1490,"y":1994,"attrs":0,"template":"@__builtin__anchor","children":["0d60f6f7-804e-4fb9-8697-34a459e23121"],"properties":[],"angle":1},{"id":"9a107b86-bafc-42ea-ab06-f8e2ccdebc2b","x":1563,"y":1994,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"61c10bc9-a021-47e1-b273-dfcec0683fef","x":1637,"y":2052,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"d015cf79-2d64-4bad-b703-c3568e1bb9f4","x":1637,"y":2110,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"b074f776-9d43-4b85-8524-e57b32eb855c","x":1637,"y":2168,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"15a0ae72-3975-427b-8414-a49a37acbddd","x":1563,"y":2227,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"808885d9-e59f-4146-8a95-5c95b3240b12","x":1490,"y":2227,"attrs":0,"template":"@__builtin__anchor","children":["cd1689f5-2c46-4778-96f9-db2037e2e51e"],"properties":[],"angle":1},{"id":"660c8fca-31eb-4a13-9908-02a8d5dd8ac4","x":1417,"y":2227,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c7c38678-3db5-405d-bf3a-943e158721dc","x":1344,"y":2168,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"0792ac54-d4bd-4a81-9767-f0385a98e739","x":1344,"y":2110,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"c4435b9b-962f-4b8b-90be-d4e7850b7062","x":1344,"y":2052,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"94cc9caa-650d-47c8-8a81-4b9e4d657250","x":1445,"y":1684,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"a3e0875f-1cb5-4c19-b6e3-b135e4e5ceed","x":1490,"y":1684,"attrs":0,"template":"@__builtin__anchor","children":["b352e358-ec5e-48d3-889b-1101b67d70a3"],"properties":[],"angle":1},{"id":"a7e286b8-fdaf-42b2-b09c-a22050bdbcbd","x":1535,"y":1684,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"88d15de7-fbff-4dec-8aef-091db9f08a02","x":1581,"y":1742,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"3069d691-9760-4178-91c6-b02ba3124e07","x":1581,"y":1800,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"73a81ae5-a291-483b-9933-c991c8d58362","x":1581,"y":1858,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"0c3c4214-c3c3-4067-bd82-669b9fbb37a5","x":1535,"y":1917,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"545d18b2-e55c-4eda-9001-71e1718b6439","x":1490,"y":1917,"attrs":0,"template":"@__builtin__anchor","children":["678b54da-f7ae-4b6d-831c-caa4d0862d46"],"properties":[],"angle":1},{"id":"49d5643b-da8a-427f-8e15-9f6215d3359e","x":1445,"y":1917,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"2a465c09-515e-4c1d-b6e7-d6ff8a948dc0","x":1400,"y":1858,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"b42945db-2ff9-4e34-928e-4350d05f9ae0","x":1400,"y":1800,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"066fe4e1-47e4-481b-8fcc-ef6b7e9512b2","x":1400,"y":1742,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"d9df1d06-9384-42ac-bdae-72dc9e325ea6","x":1828,"y":1824,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"7ae44945-110f-4e07-bfec-8a4aae0fbb4f","x":1910,"y":1824,"attrs":0,"template":"@__builtin__anchor","children":["c4c2597d-01c7-44d1-a73e-d739437a6b77"],"properties":[],"angle":1},{"id":"75e75c61-08dc-470b-80ae-55115eb97b59","x":1992,"y":1824,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"2e5ceb27-efa8-4c97-acdd-935ab7ad4b2a","x":2075,"y":1887,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"923a062c-5926-45e2-9633-9be3dde7e837","x":2075,"y":1950,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"f04e3657-3feb-4080-aa85-be4340a4fde2","x":2075,"y":2013,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"9227602c-b848-49d1-b652-0fd61511eb4a","x":1992,"y":2077,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"0b65e886-180b-4a2c-b2b5-eb8905ad3d2f","x":1910,"y":2077,"attrs":0,"template":"@__builtin__anchor","children":["3ccef06e-3c32-4450-bbe9-7e87f43cf02a"],"properties":[],"angle":1},{"id":"ef3ad726-a3a4-44cf-8406-2de8f7295212","x":1828,"y":2077,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c01a9a1f-e5b4-4bde-84ff-efa299ea8d93","x":1746,"y":2013,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a8c828af-0317-49d2-a93e-89b3c4d08e2f","x":1746,"y":1950,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"d11f7fb9-71e1-4345-8d68-09e522abc9c6","x":1746,"y":1887,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"8b5873c9-544b-4d39-84a8-f8cf9fcfe217","x":2203,"y":2294,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"53bed4ad-0346-4e79-9480-8d6c4598efb7","x":2250,"y":2294,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"fb000430-1dd8-47cc-b1ae-be19c4d22e8a","x":2297,"y":2294,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"5ce4d4b1-2cea-446c-969f-c7cf11daa7b1","x":2345,"y":2352,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"fd7b013f-c3d1-41ba-b510-359aea73a90b","x":2345,"y":2410,"attrs":0,"template":"@__builtin__anchor","children":["7f73aa27-617c-45bf-b1ac-d61ed565fd70"],"properties":[],"angle":0},{"id":"529c4df3-4169-42c7-9af8-a959a12d95b6","x":2345,"y":2468,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"29e8eb25-b561-4c32-801e-e8af85880493","x":2297,"y":2527,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"75cff90a-a594-451e-b09b-61883fd03b59","x":2250,"y":2527,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"b0dc8739-430e-45e9-9790-9fe87b2a6919","x":2203,"y":2527,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"246c0a79-2d1e-4983-a13f-c7b703496212","x":2156,"y":2468,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"337693a0-5fd4-4d80-9ffd-dc6048fa2392","x":2156,"y":2410,"attrs":0,"template":"@__builtin__anchor","children":["f32fcd6e-5540-4525-9397-8912791d6d10"],"properties":[],"angle":0},{"id":"aae98a29-2e36-409f-bd4a-85a02600454a","x":2156,"y":2352,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"cdb60fb7-23ea-4af1-806e-fd5280a4fb6b","x":2502,"y":2294,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"896064ab-33dd-488e-85c3-9adf0ba260aa","x":2550,"y":2294,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"4690c68a-4c3a-4f82-814f-f7d7ba76c33e","x":2598,"y":2294,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"f133f600-3332-4d1b-863d-7c7d65e427fe","x":2647,"y":2352,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"2756a55f-1564-4069-9aae-94f77b5b033f","x":2647,"y":2410,"attrs":0,"template":"@__builtin__anchor","children":["873c85cd-da8f-4c0e-ade2-1e331830362b"],"properties":[],"angle":0},{"id":"90ca41b9-7508-4ebc-84ed-1fd5cfe2c40a","x":2647,"y":2468,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"5ab7db1b-6205-428a-a60b-301689e3121f","x":2598,"y":2527,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"9ad6250c-8d35-48a3-803b-c607a3629f7b","x":2550,"y":2527,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"53488888-376a-4f66-ae28-8fd9040708d4","x":2502,"y":2527,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c8e5207e-46f1-4b53-b8c6-7005bcaa7269","x":2454,"y":2468,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"5902aeb2-a6b2-4bd5-8b7a-742b77cfbe98","x":2454,"y":2410,"attrs":0,"template":"@__builtin__anchor","children":["eeeb36ee-462e-44a2-a8f9-5c16df6f0d56"],"properties":[],"angle":0},{"id":"36439e26-538f-4f94-b785-dc26d1dd8e69","x":2454,"y":2352,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"586735d7-c8fd-416c-b564-f911e6410f4d","x":1565.5,"y":3193,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"b8a93eeb-5ef8-441a-9a70-d2b73a2508cb","x":1630,"y":3193,"attrs":0,"template":"@__builtin__anchor","children":["037cb1d4-7cb4-470f-929b-6b65f9288f52"],"properties":[],"angle":1},{"id":"5b3ccabb-2f9b-486b-8581-aef5da7acfe6","x":1694.5,"y":3193,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"747887d8-8824-4fd5-add0-f25600fa2999","x":1760,"y":3251.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"dcd02fe7-1fc1-40d6-b421-a8751fb04143","x":1760,"y":3310,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"0e426720-6a8d-47e7-86e9-3d710f7cfcb8","x":1760,"y":3368.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"1137565d-7c12-49bd-805c-eab25d4a66e8","x":1694.5,"y":3427,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"15eae059-1a20-43c4-b540-069d4277692d","x":1630,"y":3427,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"e0d140ea-88b5-4c3f-9529-51e4386cea32","x":1565.5,"y":3427,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"9a5af494-2cd3-4f85-9512-79065acc3d46","x":1501,"y":3368.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"f743c005-d2e2-48fa-b526-3e89be924070","x":1501,"y":3310,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"5552bca2-c64f-4eb3-a1e5-8969057ead57","x":1501,"y":3251.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"96a88581-edd7-4bd4-816a-929b41f71f35","x":2147,"y":3193,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"84ac336c-239f-4cea-bf4f-812998e23679","x":2220,"y":3193,"attrs":0,"template":"@__builtin__anchor","children":["6bcc4543-252f-4a08-8756-85bc422b141a"],"properties":[],"angle":1},{"id":"c503db39-57fe-48cc-8000-a8bdd4a6e8db","x":2293,"y":3193,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"40c7d832-33cb-410d-8656-50add3622f15","x":2367,"y":3256.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"e14610db-846f-444c-9fc4-5257ddde15da","x":2367,"y":3320,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"68c4e56b-3f74-4285-9eaa-f88e4d8ec6f6","x":2367,"y":3383.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"f6465f10-4753-4b25-8ceb-8586a0ff150f","x":2293,"y":3447,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"18ed30ab-cf3c-41b6-b37f-be107c6a97e5","x":2220,"y":3447,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"46a5541f-0b89-4deb-8be5-05ba76cc5b99","x":2147,"y":3447,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"d609358d-2bd1-48cc-9b80-76f1171dd759","x":2074,"y":3383.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"7432e73f-725b-4a13-b691-b44028bb6038","x":2074,"y":3320,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"6429bc30-aaa8-473d-831b-36790ff0b71e","x":2074,"y":3256.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"af89ab21-ed68-4621-aa0c-903806bca997","x":2303.5,"y":2683,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"5fa492e0-778a-4f1a-88cb-a93ee0786a20","x":2390,"y":2683,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"f36a4708-deb3-4cf5-8976-100e60a368a9","x":2476.5,"y":2683,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"40facf37-79a2-40ad-a39e-0e30ef7bf9e0","x":2563,"y":2741.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"08b1a94e-8d23-4793-a0b1-b8923bde7ac8","x":2563,"y":2800,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"3c1491ff-7baf-41e8-b50a-509d06ea72ee","x":2563,"y":2858.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"1d8e0a07-657f-4b20-95d4-1a7f09863356","x":2476.5,"y":2917,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"6e7a6b0b-2e0a-4c1f-8a74-67ebf4e00094","x":2390,"y":2917,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"474ae488-d699-4909-9ded-25732cf588cc","x":2303.5,"y":2917,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"33d8b002-d7e3-4393-ad62-2493137d633b","x":2217,"y":2858.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"2f09c638-8764-4137-860f-15bee5484251","x":2217,"y":2800,"attrs":0,"template":"@__builtin__anchor","children":["c910579b-149a-4ed2-9ae1-db4aa846cf10"],"properties":[],"angle":0},{"id":"999e41de-3acc-4a62-be9c-9dc134f3afe4","x":2217,"y":2741.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"587bf7af-6ce3-44a0-a01c-e9c29493b2ad","x":1288.5,"y":2673,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"b27b8380-0bbc-4a1c-8307-888e45e1940c","x":1360,"y":2673,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"9ced5104-7cbd-4b69-bbc9-0721194aa771","x":1431.5,"y":2673,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"921c60d9-4240-4d2d-a7e4-175c95b52829","x":1503,"y":2731.5,"attrs":0,"template":"@__builtin__anchor","children":["f0d5373b-7885-40b4-ae79-f69ee9abdfd3"],"properties":[],"angle":0},{"id":"0bcbca3c-ade6-43af-b30a-985cd7f38117","x":1503,"y":2790,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"682297ee-7b1f-40c3-9792-732b2b8cd8a8","x":1503,"y":2848.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a672ef9c-304f-4dcd-830f-d0f0fa51558c","x":1431.5,"y":2907,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"d12e1ecf-1ed2-480c-ad5a-393519cf94dc","x":1360,"y":2907,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"8cff54dd-94a3-47ca-97b9-9a6f794408f1","x":1288.5,"y":2907,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"3c154c18-2b0c-40aa-8d07-6d646b146707","x":1217,"y":2848.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"33e3c8f5-b7bf-41c2-ae25-e2993db51c6d","x":1217,"y":2790,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"069c7053-b0a0-4495-843d-66b65d1b5df7","x":1217,"y":2731.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"322f3287-b2ce-4c46-92eb-530398486915","x":1789.5,"y":3503,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"40729dae-6bc4-44f8-bcd1-48c2d11e1d73","x":1880,"y":3503,"attrs":0,"template":"@__builtin__anchor","children":["375808d0-3924-48cc-b0ff-332b4104ac70"],"properties":[],"angle":1},{"id":"b472dad6-3264-4ee7-bbba-b2927896f4df","x":1970.5,"y":3503,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"f673543a-940b-4401-ac2b-66945fa287ad","x":2061,"y":3566.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"675c7200-de29-42b4-8063-1ddd5c77cab1","x":2061,"y":3630,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"c044155c-3dbe-4028-90ba-fccd4f64c871","x":2061,"y":3693.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"e09df1db-70e7-484a-bd94-513988ae2a70","x":1970.5,"y":3757,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"8b1285dd-ae36-4fdc-892a-1eacfef6e64c","x":1880,"y":3757,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"0ff0396a-1566-4848-a01d-0efcb7772b10","x":1789.5,"y":3757,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"8374b5c2-f2f4-4aa6-a8c1-67d8740046c9","x":1699,"y":3693.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"f20e91b6-ebce-493f-bf1d-dc0e0a2d7f84","x":1699,"y":3630,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"028944fc-e994-4ceb-9ae8-ee51219a4d74","x":1699,"y":3566.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"bfa17610-a018-4703-903a-a8c579472b4b","x":2523,"y":3014,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"e3e1eb75-90cb-4591-be6f-aa5ba4e4c7c9","x":2580,"y":3014,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"9cb8b3bc-455f-43e1-8192-45a0a136b10f","x":2637,"y":3014,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"0876573a-c821-4ca6-83f0-24e55d6264c8","x":2695,"y":3072,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a20054aa-ac4e-4852-96cc-3c08db2f1459","x":2695,"y":3130,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"8cf8fcf5-4f10-4275-8809-fc1cb57c9720","x":2695,"y":3188,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"b7ae46f9-3228-4f7b-9fb8-c7bcd4eaa4e5","x":2637,"y":3247,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"b29e1491-9003-405c-87dd-37715fe206cd","x":2580,"y":3247,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"6d948b29-9086-47d9-8225-cacc5255be22","x":2523,"y":3247,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"13dd7212-4d63-475f-891d-663fa6f3bc19","x":2466,"y":3188,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"9659936c-633a-4e33-b434-e15c8c50ee90","x":2466,"y":3130,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"dec7f193-fa5c-4ee6-a4f7-2f165de33ec2","x":2466,"y":3072,"attrs":0,"template":"@__builtin__anchor","children":["1c6e7fff-5c84-4a8f-81a5-edb98ee3094b"],"properties":[],"angle":0},{"id":"f96c80e1-5a66-453f-922e-bb29c362e304","x":1066,"y":177,"attrs":0,"template":"@__builtin__anchor","children":["8aa841a6-2dda-4cdf-b3a7-f40e42bffd5f"],"properties":[],"angle":1},{"id":"1412d71d-2f38-485e-8bad-5a6e12431128","x":1150,"y":177,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"5b154456-953a-49d8-823c-1a3650b5f5ff","x":1234,"y":177,"attrs":0,"template":"@__builtin__anchor","children":["df3ed19c-7e8d-4dca-bffd-b6767187ef0a"],"properties":[],"angle":1},{"id":"d527b6d2-4d38-40a8-a2e6-5755c6a9195f","x":1318,"y":213.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"af788d4f-4da0-4f5d-9032-44afab2d0ad3","x":1318,"y":250,"attrs":0,"template":"@__builtin__anchor","children":["23ae5965-4d34-4258-b49d-2b4730b4acab"],"properties":[],"angle":0},{"id":"f5417fae-5533-4925-94ca-1ccfd5d64386","x":1318,"y":286.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"4fea9507-5c53-47f5-9e79-5dc1e430ca32","x":1234,"y":324,"attrs":0,"template":"@__builtin__anchor","children":["171fb351-bf8e-4088-be00-037a58fb2fd6"],"properties":[],"angle":1},{"id":"b95baffc-6db1-44c1-8f77-b030f0730045","x":1150,"y":324,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"04df45fd-4ccb-4164-9dc1-24009ec3c58a","x":1066,"y":324,"attrs":0,"template":"@__builtin__anchor","children":["d56c1abc-1141-4984-97e9-a71ec7e117e6"],"properties":[],"angle":1},{"id":"0b3e06ad-01b2-433a-b948-7585d5f23b22","x":982,"y":286.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"cc092ee5-75f2-4662-ad55-07da983eea1b","x":982,"y":250,"attrs":0,"template":"@__builtin__anchor","children":["fef5e417-4372-44c0-91b4-9880e4f52603"],"properties":[],"angle":0},{"id":"724a3049-7e7f-43d5-b946-7e3246b98805","x":982,"y":213.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"93668601-e35a-4062-ac43-0728d4e89185","x":1106,"y":539.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a7bc63d6-706c-4577-925e-e42f7fc6a93c","x":1106,"y":510,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"61985b66-4a7c-4a9c-af70-2bd0955d0a95","x":1106,"y":480.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"0fb79972-831f-4587-8e03-f7b7091c194e","x":1193,"y":451,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"86ae7f9a-c508-4d07-9e40-599666dd6149","x":1280,"y":451,"attrs":0,"template":"@__builtin__anchor","children":["f11e1e1d-369c-4d28-a24a-f22c1c3cbba9"],"properties":[],"angle":1},{"id":"30a13a7e-8308-4fab-9bf7-c22ffee5f4e7","x":1367,"y":451,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"5d174e87-ee3e-4f13-b89a-3ac3cafdfa84","x":1454,"y":480.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"97dd95e0-1acc-45b7-b864-a4ef15617690","x":1454,"y":510,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"cd871faa-bccf-4e88-bf9b-e79d0474daea","x":1454,"y":539.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"606eab2e-e3df-46f0-a332-959ae6c9d5d7","x":1194,"y":569,"attrs":0,"template":"true_anchor","children":["a5005bac-307f-4425-9283-efd9d6e286e9"],"properties":[],"angle":1},{"id":"412f69b8-a383-402d-a4c1-b6024b038dd5","x":1367,"y":569,"attrs":0,"template":"false_anchor","children":["ebcf9433-a38f-4728-83c3-edce789e8d8c"],"properties":[],"angle":1},{"id":"171fb351-bf8e-4088-be00-037a58fb2fd6","x":1234,"y":324,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"f259fcab-807e-470f-a369-045546ccb09c","x":1257,"y":387.5,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"f11e1e1d-369c-4d28-a24a-f22c1c3cbba9","x":1280,"y":451,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"ebcf9433-a38f-4728-83c3-edce789e8d8c","x":1367,"y":569,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"620fff19-649f-4475-b800-e6d1702a5625","x":1418.5,"y":606,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"5f7404cb-d7c5-4103-a284-c6449a15fb04","x":1470,"y":643,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"ade4b00a-178c-4dec-9202-8bd1a4934a76","x":1383,"y":964,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"e7f5aef3-c5e7-4140-ab6d-267a28b27290","x":1470,"y":964,"attrs":0,"template":"@__builtin__anchor","children":["e01be3d8-5927-4ae8-bcd7-2acd1b17c2e5"],"properties":[],"angle":1},{"id":"ac912536-c971-4f24-a5eb-4163f3cefab3","x":1557,"y":964,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"54e7f631-a8a7-4da7-98cf-5b9e0fbfa84f","x":1644,"y":1022,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"968e2cfd-20c8-41cb-9394-aa3d80b8ef00","x":1644,"y":1080,"attrs":0,"template":"@__builtin__anchor","children":["5919089d-0405-4b03-9fc2-ab22d6a96fe8"],"properties":[],"angle":0},{"id":"c218d56e-2686-4043-a7db-50648c5ebee4","x":1644,"y":1138,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"d547288b-4a05-418b-84b4-0665028763de","x":1557,"y":1197,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"7624e49c-4fed-4a15-8437-484e793ffbfc","x":1470,"y":1197,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"2112a909-a230-401a-90f1-5bff3937365c","x":1383,"y":1197,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"d90c3ed2-3539-4720-8b32-15dad27b1a27","x":1296,"y":1138,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"f2211ae9-6c2c-4e9c-8743-c97c2cef8e77","x":1296,"y":1080,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"b9ea9332-3024-4dbc-b987-5e10a871d7e5","x":1296,"y":1022,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"157e46a7-9a48-45a8-b3b5-4d156246d79d","x":1470,"y":897,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"ff3d50a4-7bde-47f1-9678-66627b13d081","x":1470,"y":930.5,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"e01be3d8-5927-4ae8-bcd7-2acd1b17c2e5","x":1470,"y":964,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"455f4a91-20d6-405e-a015-d3a5d4d75067","x":1636,"y":1573.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"01637e4d-491e-42ba-b730-3a912cd1aafc","x":1636,"y":1550,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"b20e7c8f-6caf-4b88-ae88-112b41a3d7d2","x":1636,"y":1526.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"2cde27d0-f41e-4418-915f-d5eae3b1e0f7","x":1683,"y":1503,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"754854cd-73e0-44d8-81e4-394444684bc8","x":1730,"y":1503,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"10963a37-3edc-43cf-9917-78b1551f984c","x":1777,"y":1503,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"e2be1cac-b738-4f82-b44a-eba7912e7185","x":1824,"y":1526.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"67b0c66b-d6ff-4fd6-a6a5-88f1bb3dcf48","x":1824,"y":1550,"attrs":0,"template":"@__builtin__anchor","children":["54b01be2-f312-46b1-9fa9-5cb3d4edbbeb"],"properties":[],"angle":0},{"id":"5ad54dd2-e992-4d94-beee-f0be33e3ae54","x":1824,"y":1573.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"271d762f-4165-4253-857c-58f86c1f9cb6","x":1683,"y":1598,"attrs":0,"template":"true_anchor","children":["f9710216-edda-44f1-b25a-0ae54fbc7d22"],"properties":[],"angle":1},{"id":"70183590-5988-4c9b-8257-70014608b53e","x":1776,"y":1598,"attrs":0,"template":"false_anchor","children":["43cf8559-4a36-4030-8163-e0ac8fbb59e8"],"properties":[],"angle":1},{"id":"f9710216-edda-44f1-b25a-0ae54fbc7d22","x":1683,"y":1598,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"929ab254-1d9f-493b-99ee-ee35d0bfb7a5","x":1586.5,"y":1641,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"b352e358-ec5e-48d3-889b-1101b67d70a3","x":1490,"y":1684,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"678b54da-f7ae-4b6d-831c-caa4d0862d46","x":1490,"y":1917,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"fe0891a6-6743-4d4c-9c7e-b4048542b9ba","x":1490,"y":1955.5,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"0d60f6f7-804e-4fb9-8697-34a459e23121","x":1490,"y":1994,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"11a3e078-1ad4-4077-965e-c21d461df45f","x":1770,"y":963,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"aa0f8c9d-ba6f-4eb6-b55d-2e89e5937e3d","x":1840,"y":963,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"805a9e36-a730-40eb-8e79-0b183275d614","x":1910,"y":963,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"d2c5ebb2-66b6-4630-9d6d-32fb862e0f92","x":1981,"y":1021.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"dd9212be-7679-417e-a2ca-614f7cf8e6ad","x":1981,"y":1080,"attrs":0,"template":"@__builtin__anchor","children":["cac31540-41e7-4d9b-b3f0-07e9da669d90"],"properties":[],"angle":0},{"id":"fb813be2-3cf6-422f-a6bc-0a2311882bc7","x":1981,"y":1138.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"5119793c-8888-44fb-8b13-c696f57106f8","x":1910,"y":1197,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"4284a9b0-d8f5-4948-b803-109dfd265134","x":1840,"y":1197,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"187a134b-705c-4c2d-b044-81b209b5d380","x":1770,"y":1197,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"76882caa-4766-4bd3-a8f6-3fc44ced4f97","x":1700,"y":1138.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"d82a016d-08b9-48f2-a52c-e111d7aacd22","x":1700,"y":1080,"attrs":0,"template":"@__builtin__anchor","children":["396a614a-5aae-4876-a7e7-c403f55d28b7"],"properties":[],"angle":0},{"id":"29681192-5652-4d3e-bb76-bf7072f2f044","x":1700,"y":1021.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"5919089d-0405-4b03-9fc2-ab22d6a96fe8","x":1644,"y":1080,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"a8118633-433d-4c01-bcad-6bcb8ebfcef2","x":1672,"y":1080,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"396a614a-5aae-4876-a7e7-c403f55d28b7","x":1700,"y":1080,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"a86dd764-006b-45ce-85ab-4442f7a58fea","x":2089,"y":1063.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"63af241d-2d12-4ceb-83dd-3d6eea014584","x":2089,"y":1040,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"1e4ae9aa-55f3-47ec-b826-59dbd5faee09","x":2089,"y":1016.5,"attrs":0,"template":"@__builtin__anchor","children":["70d0c801-3e3b-4d6f-a05d-a1c7513c9336"],"properties":[],"angle":0},{"id":"029a2a6e-b27b-45ed-88f7-9bb0a915b249","x":2154.5,"y":993,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c7b251d1-9d0e-492a-ab1c-b8e6038e44c9","x":2220,"y":993,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"f564f00d-3c89-44be-ba7f-ce3203477a17","x":2285.5,"y":993,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"32c62353-141b-4716-917b-e7c080b28a12","x":2351,"y":1016.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"7cc10ad2-f82d-44dd-939d-af9dde6a653b","x":2351,"y":1040,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"c3494c62-be5f-46c2-8f6a-61bfb6c4c3ca","x":2351,"y":1063.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"6460e2b9-aba3-4c50-9cbe-0438790ce73c","x":2155,"y":1088,"attrs":0,"template":"true_anchor","children":["2072bb90-eecb-456c-a94e-aaeca9119f6f"],"properties":[],"angle":1},{"id":"bff16312-8a4d-45c0-8853-e38952154b9d","x":2285,"y":1088,"attrs":0,"template":"false_anchor","children":["8d08efcc-1733-441f-b9d5-dea5bb196659"],"properties":[],"angle":1},{"id":"cac31540-41e7-4d9b-b3f0-07e9da669d90","x":1981,"y":1080,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"391d37b2-cc1c-4bcd-8940-6dee130b6b51","x":2035,"y":1048.25,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"70d0c801-3e3b-4d6f-a05d-a1c7513c9336","x":2089,"y":1016.5,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"452651e8-7dc5-4fb2-a421-83917453a56b","x":2424.5,"y":1154,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"ab83ef46-8cbb-4fba-86c2-94cce8106f09","x":2490,"y":1154,"attrs":0,"template":"@__builtin__anchor","children":["33018f07-888b-466b-84ae-eb1f9b0afd00"],"properties":[],"angle":1},{"id":"3f1e5c2e-05a2-4f0c-9ad2-e16e416fa560","x":2555.5,"y":1154,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"fb70fedf-04f0-4fc9-a1e0-9acf3beda6fe","x":2622,"y":1212,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"41e9bb99-cd3c-40c7-a1cf-f7ba73fa0ec1","x":2622,"y":1270,"attrs":0,"template":"@__builtin__anchor","children":["3f797331-3db9-4909-b0be-0b72389e4aed"],"properties":[],"angle":0},{"id":"79db4b88-f406-4156-8ec2-0a274111e447","x":2622,"y":1328,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"4b05defb-7052-4a7a-be42-7501a17f574e","x":2555.5,"y":1387,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"fe435c0a-81d0-4e59-accf-8a13af291ec3","x":2490,"y":1387,"attrs":0,"template":"@__builtin__anchor","children":["169eb6b9-6688-41b5-8634-ed71ed040fc5"],"properties":[],"angle":1},{"id":"316f29d0-be81-462d-8dba-97c70adf3423","x":2424.5,"y":1387,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"0acc5b78-5b6e-4585-baac-9cedbca9a189","x":2359,"y":1328,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"db55a4ba-ee2c-4890-87b2-f7e6f168b43e","x":2359,"y":1270,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"8c2a8656-9fb1-4ccb-9a62-d203913a93e4","x":2359,"y":1212,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"8d08efcc-1733-441f-b9d5-dea5bb196659","x":2285,"y":1088,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"4a19bdba-2681-4d20-a90b-f8c932342a3d","x":2387.5,"y":1121,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"33018f07-888b-466b-84ae-eb1f9b0afd00","x":2490,"y":1154,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"200342a3-b706-44b1-a8a6-0ab6e53a96a3","x":2412,"y":1724,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"f3815ee5-6eb6-4017-8bdc-a15e2428ba11","x":2490,"y":1724,"attrs":0,"template":"@__builtin__anchor","children":["a9ec9b13-5481-4627-8140-f52aa26cdf67"],"properties":[],"angle":1},{"id":"243c5fe8-daf9-43cf-b940-54dbe6ddf9d7","x":2568,"y":1724,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"206c79d9-798d-481e-b074-830607476393","x":2646,"y":1787,"attrs":0,"template":"@__builtin__anchor","children":["17266159-9d29-4d0e-97a2-7ea985028e17"],"properties":[],"angle":0},{"id":"012644f9-861f-455c-a7f6-ace4938f672a","x":2646,"y":1850,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"7d597798-0fd8-4f5a-9584-7684a2886269","x":2646,"y":1913,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"219676b3-8aa6-46c6-bb57-bfd1babf6961","x":2568,"y":1977,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"33690bae-3d03-4b4e-a6ec-b133f50b6319","x":2490,"y":1977,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"15fdce5c-001f-4218-90f3-dfbad021e0a1","x":2412,"y":1977,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"448a0b2b-71a2-4d8e-a831-2d3c2d602611","x":2334,"y":1913,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"dc0ee260-936e-4570-850e-656315a28f13","x":2334,"y":1850,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"9cc44410-4f5c-4432-a76c-3bc57d1fdee6","x":2334,"y":1787,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"169eb6b9-6688-41b5-8634-ed71ed040fc5","x":2490,"y":1387,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"36cd005a-08be-49f8-9064-bdf12544e5b7","x":2490,"y":1436.5,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"52384bd0-aae2-4ea9-a3e2-5d80d75c5674","x":2490,"y":1486,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"3c78250f-eb99-427d-a747-611eb01453c3","x":1995,"y":1434,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"21991030-a632-40c5-8c84-e6eef96d0d3a","x":2070,"y":1434,"attrs":0,"template":"@__builtin__anchor","children":["9293037f-aa96-4d04-8677-c0e42d90b4a6"],"properties":[],"angle":1},{"id":"a33183f3-3a6b-40b4-ac6d-02919545703d","x":2145,"y":1434,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"6ca5db82-af4b-49ae-b524-6f9e5f3fb780","x":2220,"y":1492,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"78177585-778e-448d-adc2-0736e4635c9c","x":2220,"y":1550,"attrs":0,"template":"@__builtin__anchor","children":["acb71bfd-ce1d-410b-b411-bb663a710e26"],"properties":[],"angle":0},{"id":"0f7e4a78-8190-4b3d-963e-e890afaa5d9f","x":2220,"y":1608,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"c7c982e3-7b7f-4096-beab-d8cf960ca35d","x":2145,"y":1667,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"ec77308d-b722-4a4d-b1f2-c28e68c9672f","x":2070,"y":1667,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"15f606bd-55ec-4733-a51a-da17a35137e0","x":1995,"y":1667,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"e7569b3d-4f8f-4eb5-8a6f-e4faa101132a","x":1920,"y":1608,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"882e3fd8-1ebc-43b4-8520-e751524d50c9","x":1920,"y":1550,"attrs":0,"template":"@__builtin__anchor","children":["30abd31f-a249-447d-ada4-6c4203c00d6e"],"properties":[],"angle":0},{"id":"93c1ab7d-c846-4946-874d-fde4aaa17749","x":1920,"y":1492,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"2072bb90-eecb-456c-a94e-aaeca9119f6f","x":2155,"y":1088,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"c519af30-6b2e-4775-8ae3-2632e186a938","x":2112.5,"y":1261,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"9293037f-aa96-4d04-8677-c0e42d90b4a6","x":2070,"y":1434,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"2de3d811-f017-4ef2-9bd0-3c743895270b","x":2317,"y":1550,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"79af9b1b-d931-4f72-b338-f3011d16d9b7","x":2268.5,"y":1550,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"acb71bfd-ce1d-410b-b411-bb663a710e26","x":2220,"y":1550,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"30abd31f-a249-447d-ada4-6c4203c00d6e","x":1920,"y":1550,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"68300c00-3b40-46aa-9042-eeba60a218ed","x":1872,"y":1550,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"54b01be2-f312-46b1-9fa9-5cb3d4edbbeb","x":1824,"y":1550,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"d0c1f493-e3cc-408a-8fe1-0c1db9e17925","x":1261.5,"y":2353,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"70d0688b-8697-42b0-837f-484877defa9e","x":1320,"y":2353,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c4f88951-ac1d-45c0-888f-0f095b5d3971","x":1378.5,"y":2353,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"21c1d051-a401-4fa1-a457-214727131263","x":1438,"y":2411.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"39067643-7075-4cf8-b7c1-bdad83328daf","x":1438,"y":2470,"attrs":0,"template":"@__builtin__anchor","children":["13c506ab-c1ca-4bf1-bc89-3edf9b64e893"],"properties":[],"angle":0},{"id":"d95cc3df-056a-4a35-9225-b6a668306bc7","x":1438,"y":2528.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"7a405274-5730-4ca0-b213-81ab05bc6600","x":1378.5,"y":2587,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"8858555a-0b37-4bcb-b07c-56d996d2d39c","x":1320,"y":2587,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"b10f5695-4faf-4985-99c4-a6c718477231","x":1261.5,"y":2587,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"56478779-4bac-44c1-8429-6655f559251d","x":1203,"y":2528.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"42e810fe-e25d-4c69-9ed8-dece23f8436d","x":1203,"y":2470,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"338493df-bb61-4f36-9f2b-b2f85d3f4ebf","x":1203,"y":2411.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"b5c2cd2a-b18e-4ec0-b356-2db1145d0934","x":1799.5,"y":2907,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"5c357aaf-f36f-4035-be07-2eb14e3f10cb","x":1880,"y":2907,"attrs":0,"template":"@__builtin__anchor","children":["8911810b-122d-4011-8c44-931491a8f49d"],"properties":[],"angle":1},{"id":"7ad4cfb4-6670-4bdc-a747-cbe3d6cec178","x":1960.5,"y":2907,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"4d2545a9-a966-40cd-a48d-011fc5d95393","x":2041,"y":2943.5,"attrs":0,"template":"@__builtin__anchor","children":["857e12c2-074f-4f83-9e36-38db3214711b"],"properties":[],"angle":0},{"id":"c27f8cef-4f1a-492e-8016-f830865ca573","x":2041,"y":2980,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"e809622d-fe3b-4c74-be3c-2c7f7715f620","x":2041,"y":3016.5,"attrs":0,"template":"@__builtin__anchor","children":["6021ad97-e007-42f4-9d51-5d5e36ea3163"],"properties":[],"angle":0},{"id":"0675b6c7-9c8d-430f-830d-a4b15357a280","x":1960.5,"y":3053,"attrs":0,"template":"@__builtin__anchor","children":["337eb992-4b37-4432-8178-a7362c5b1856"],"properties":[],"angle":1},{"id":"43a6a1a5-66dd-4584-8603-0ebd5cf74ce9","x":1880,"y":3053,"attrs":0,"template":"@__builtin__anchor","children":["e061d6d2-51b2-4901-9103-a6bd950b68d2"],"properties":[],"angle":1},{"id":"ab6af750-a8eb-4ab8-8679-79e75fcf1dee","x":1799.5,"y":3053,"attrs":0,"template":"@__builtin__anchor","children":["71e269a2-e64f-480b-8812-e46b609d3955"],"properties":[],"angle":1},{"id":"026abd86-199c-408b-97b7-3d054fdae981","x":1719,"y":3016.5,"attrs":0,"template":"@__builtin__anchor","children":["34cd69ee-aa26-4efa-a893-a3bb0bb9282b"],"properties":[],"angle":0},{"id":"808919e9-063b-4c73-baed-a6602816547c","x":1719,"y":2980,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"c6dd0d22-9447-4284-8206-d0f9d5e0fd76","x":1719,"y":2943.5,"attrs":0,"template":"@__builtin__anchor","children":["57df81f9-5b0b-4350-9277-7c593fcfb483"],"properties":[],"angle":0},{"id":"71e269a2-e64f-480b-8812-e46b609d3955","x":1799.5,"y":3053,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"2a651847-3d13-4291-940e-b408a825b2ab","x":1714.75,"y":3123,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"037cb1d4-7cb4-470f-929b-6b65f9288f52","x":1630,"y":3193,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"337eb992-4b37-4432-8178-a7362c5b1856","x":1960.5,"y":3053,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"913719f1-a680-4d83-aff6-ae301f1f8851","x":2090.25,"y":3123,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"6bcc4543-252f-4a08-8756-85bc422b141a","x":2220,"y":3193,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"e061d6d2-51b2-4901-9103-a6bd950b68d2","x":1880,"y":3053,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"dac815c1-cbf1-4bfd-86f1-1a5f11c66927","x":1880,"y":3278,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"375808d0-3924-48cc-b0ff-332b4104ac70","x":1880,"y":3503,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"6021ad97-e007-42f4-9d51-5d5e36ea3163","x":2041,"y":3016.5,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"beb76adc-6e1f-46a6-acf1-bddee35c5f1d","x":2253.5,"y":3044.25,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"1c6e7fff-5c84-4a8f-81a5-edb98ee3094b","x":2466,"y":3072,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"bc5619bf-ffa7-498a-88bc-bb4efe3479dc","x":330,"y":553.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"3773e065-f3fd-4059-820a-722875024d55","x":330,"y":530,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"62d166f9-1010-4df2-9df9-dca5e0152442","x":330,"y":506.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"b6633df0-0a70-4fcd-b571-f18ed883a863","x":405,"y":483,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"d430b1bd-93cc-4e61-a5e6-245bc62f2f73","x":480,"y":483,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"71b02c3c-ca24-4156-8055-ebd6a7c14476","x":555,"y":483,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"0267053f-d862-4e35-bd76-222c9d8214e3","x":630,"y":506.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"8da31f03-1fa1-4b4b-8a6f-82f81abcdebb","x":630,"y":530,"attrs":0,"template":"@__builtin__anchor","children":["44154d41-d504-4db6-b206-77fb54c936c7"],"properties":[],"angle":0},{"id":"387a2cd8-c0e0-4ec7-9d99-ed57636952a6","x":630,"y":553.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"38d29a15-26f2-48e8-83c4-56cc080949bc","x":405,"y":578,"attrs":0,"template":"true_anchor","children":["8c8edb68-dd77-45c4-bd4d-fb7450402c1d"],"properties":[],"angle":1},{"id":"be804939-f5b0-4021-8b48-da9ad34f5ddf","x":554,"y":578,"attrs":0,"template":"false_anchor","children":["79eb6ba9-2e87-45de-9298-cd64b668fe2f"],"properties":[],"angle":1},{"id":"0b5ad376-58f1-4559-9780-2426f3c6ec63","x":742,"y":530,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"49e3f8af-9aac-44ec-adf8-2ff1c46bea92","x":686,"y":530,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"44154d41-d504-4db6-b206-77fb54c936c7","x":630,"y":530,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"5ed91cc0-d913-4aab-aa00-fcb12bfeda44","x":202.5,"y":704,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"4ca96364-4c38-4b8b-bda4-683ca0f13375","x":290,"y":704,"attrs":0,"template":"@__builtin__anchor","children":["da83d08d-ae1e-4f39-b1a3-d36cdd1d8677"],"properties":[],"angle":1},{"id":"e3374114-fb93-403e-af33-6511eb5e9287","x":377.5,"y":704,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"1d253adf-07af-4354-8240-874971e91b15","x":466,"y":767,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"95d03252-77a7-4ee4-93fe-841e77720c5d","x":466,"y":830,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"1649f825-4501-49ff-a8eb-81a099d5483f","x":466,"y":893,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"bbce4fb0-f168-4d0f-bb8b-b0254bb57822","x":377.5,"y":957,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"649bfc8f-a9cc-48f6-9292-27a058f20aa8","x":290,"y":957,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"e5dd5666-d83b-41cf-9dcd-2d7ab45e327e","x":202.5,"y":957,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"4e0de801-4eef-4aea-8e2e-bb7705238a8d","x":115,"y":893,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"55e9bd99-e8d1-4e45-990f-505217c6ba85","x":115,"y":830,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"dc74ce3f-a6ae-423d-bac7-c34f476e9683","x":115,"y":767,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"8c8edb68-dd77-45c4-bd4d-fb7450402c1d","x":405,"y":578,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"b16d6e05-efea-45ca-8acf-aee554600a76","x":347.5,"y":641,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"da83d08d-ae1e-4f39-b1a3-d36cdd1d8677","x":290,"y":704,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"2276584a-78a7-4d25-8be9-f07eba696b2d","x":1186.5,"y":3003,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"ec3e4a21-ebb0-4b23-aff9-d028e7aeee8b","x":1230,"y":3003,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"3eeca1be-e201-4ab4-b38b-f6f54183138b","x":1273.5,"y":3003,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"186ecbf7-fd68-4a4f-91b5-e5f4e7c4fa64","x":1318,"y":3061.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"4f79fee8-092e-4f93-b0e9-2c6e0d5b8c94","x":1318,"y":3120,"attrs":0,"template":"@__builtin__anchor","children":["8906d537-bf43-46b1-93c4-525281e03169"],"properties":[],"angle":0},{"id":"022066e0-d141-4cc0-81e4-fae573a22ced","x":1318,"y":3178.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"913fb1a8-bc81-4435-85a5-460e304c334f","x":1273.5,"y":3237,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"81b9683d-8e0a-4068-9f26-f9327977090e","x":1230,"y":3237,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"94ba69aa-98c5-4c3e-9083-e56e20bcca32","x":1186.5,"y":3237,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"112d9c2d-e8cf-4dc7-a881-aa3e21058928","x":1143,"y":3178.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"17f3dffe-5f36-46e8-875a-0f63c5350130","x":1143,"y":3120,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"97340e33-383a-47f1-a738-88a1ec0b784d","x":1143,"y":3061.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"57df81f9-5b0b-4350-9277-7c593fcfb483","x":1719,"y":2943.5,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"1d3806e3-a365-4ccb-a4ba-b522364a126f","x":1611,"y":2837.5,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"f0d5373b-7885-40b4-ae79-f69ee9abdfd3","x":1503,"y":2731.5,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"34cd69ee-aa26-4efa-a893-a3bb0bb9282b","x":1719,"y":3016.5,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"101663c2-eea0-4e0f-95fe-91eb0c814cbf","x":1518.5,"y":3068.25,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"8906d537-bf43-46b1-93c4-525281e03169","x":1318,"y":3120,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"b7141a8d-b75c-4b29-86c0-014b68655420","x":1796,"y":2387,"attrs":0,"template":"@__builtin__anchor","children":["b59a0415-2c7d-4aa3-87c1-1a2dbc429543"],"properties":[],"angle":1},{"id":"4ceefda1-820b-4a13-9388-641579fe28d7","x":1880,"y":2387,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"7a5ddb0e-16b2-4a02-ac1f-dbe32342c47e","x":1964,"y":2387,"attrs":0,"template":"@__builtin__anchor","children":["d2b802ef-d1f2-4a4e-89c8-b04c160c6c68"],"properties":[],"angle":1},{"id":"74b3772a-09d1-4bab-affa-82e49e71afbe","x":2049,"y":2428.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"fa40e8ca-bc86-4f43-b450-cf87ec99fb77","x":2049,"y":2470,"attrs":0,"template":"@__builtin__anchor","children":["31c9c8a8-a6ef-4df4-8f50-7d7a13e5aa4f"],"properties":[],"angle":0},{"id":"13edee41-b948-4839-bee8-db0d6e151eac","x":2049,"y":2511.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"b389321d-3b55-4f41-b90c-056356de0539","x":1964,"y":2554,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"a3ec78b9-fc19-4f4e-8456-fe0d5f013fe5","x":1880,"y":2554,"attrs":0,"template":"@__builtin__anchor","children":["9bb5646d-af04-45c5-b594-6fc8e028b94b"],"properties":[],"angle":1},{"id":"a78a03ff-afeb-47c9-8415-85ecf365997d","x":1796,"y":2554,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"f87f30c2-28dc-459c-a464-32a2263952cb","x":1712,"y":2511.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"8ef03e87-9159-4ecd-af3e-4756d3920c86","x":1712,"y":2470,"attrs":0,"template":"@__builtin__anchor","children":["a918cc24-9554-471d-b879-f687ce82a2c4"],"properties":[],"angle":0},{"id":"a1ea9d32-fc4b-4e8a-bd6d-5ec9ba64ee5a","x":1712,"y":2428.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"cd1689f5-2c46-4778-96f9-db2037e2e51e","x":1490,"y":2227,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"c6049d38-6f6e-4252-bf61-7f0040800127","x":1643,"y":2307,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"b59a0415-2c7d-4aa3-87c1-1a2dbc429543","x":1796,"y":2387,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"43cf8559-4a36-4030-8163-e0ac8fbb59e8","x":1776,"y":1598,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"ae97c620-d7a7-4843-85a8-7f0ba33b1025","x":1843,"y":1711,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"c4c2597d-01c7-44d1-a73e-d739437a6b77","x":1910,"y":1824,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"3ccef06e-3c32-4450-bbe9-7e87f43cf02a","x":1910,"y":2077,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"554a36d5-dc7e-48b0-b39f-e3613c224cc0","x":1937,"y":2232,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"d2b802ef-d1f2-4a4e-89c8-b04c160c6c68","x":1964,"y":2387,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"31c9c8a8-a6ef-4df4-8f50-7d7a13e5aa4f","x":2049,"y":2470,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"8488014c-43c3-4ae9-ba72-934dcb68e63b","x":2102.5,"y":2440,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"f32fcd6e-5540-4525-9397-8912791d6d10","x":2156,"y":2410,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"7f73aa27-617c-45bf-b1ac-d61ed565fd70","x":2345,"y":2410,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"d46fdb2a-dfd1-4ede-ba88-6ef33a27fad0","x":2399.5,"y":2410,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"eeeb36ee-462e-44a2-a8f9-5c16df6f0d56","x":2454,"y":2410,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"2d40f138-f390-49f8-bb63-7364f9b1ca94","x":2811.5,"y":2284,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"3bc91e50-2676-4361-983c-b820c47d84b1","x":2900,"y":2284,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"91b16936-7f1f-479a-82ab-6874ab5cc8e9","x":2988.5,"y":2284,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"ccbc7661-2634-4e36-8c1f-f7449f31a93c","x":3077,"y":2347,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"34a07c72-0b9b-47bb-b4aa-3f13c5d3cfd4","x":3077,"y":2410,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"b7661767-0ac8-4fd9-9c9c-d78d14edd4e4","x":3077,"y":2473,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a2457b5b-90e7-46e8-9c99-745b3061482f","x":2988.5,"y":2537,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"59bbf8dc-2864-4e89-a492-5d83caa2fd59","x":2900,"y":2537,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"7d441f06-8669-4efe-8f04-d34e0532fe58","x":2811.5,"y":2537,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"13b12312-22fb-4f54-8479-c6a533b488e7","x":2723,"y":2473,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"aa41bd75-ed32-4627-94be-efaae6a4dbd7","x":2723,"y":2410,"attrs":0,"template":"@__builtin__anchor","children":["81837c26-ce9e-489f-8637-532882b0b376"],"properties":[],"angle":0},{"id":"1d2d5e54-805b-4c60-93f5-9131b0f431a3","x":2723,"y":2347,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"873c85cd-da8f-4c0e-ade2-1e331830362b","x":2647,"y":2410,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"9a8e65f9-f639-41c4-a231-82ffe634cb77","x":2685,"y":2410,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"81837c26-ce9e-489f-8637-532882b0b376","x":2723,"y":2410,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"9bb5646d-af04-45c5-b594-6fc8e028b94b","x":1880,"y":2554,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"07d9c9d4-614e-4be5-b089-1a4c1578f33e","x":1880,"y":2730.5,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"8911810b-122d-4011-8c44-931491a8f49d","x":1880,"y":2907,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"a918cc24-9554-471d-b879-f687ce82a2c4","x":1712,"y":2470,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"acaeba8b-1633-40a5-b14c-32bcca6c1dd8","x":1575,"y":2470,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"13c506ab-c1ca-4bf1-bc89-3edf9b64e893","x":1438,"y":2470,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"fef5e417-4372-44c0-91b4-9880e4f52603","x":982,"y":250,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"de6c7222-4a74-41cd-976f-6248e1af6670","x":883.5,"y":250,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"7779f1fb-f1b8-4897-9aad-9e1d687408c2","x":785,"y":250,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"8aa841a6-2dda-4cdf-b3a7-f40e42bffd5f","x":1066,"y":177,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"d2ec3a56-dfcd-4808-8a6b-b9cfd34a1830","x":988,"y":119.5,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"0fb8f2fd-af6f-40cf-aa7a-d18aee879ac2","x":910,"y":62,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"df3ed19c-7e8d-4dca-bffd-b6767187ef0a","x":1234,"y":177,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"65f33e55-abb2-4080-8112-8968bc12a6df","x":1267,"y":112,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"05f9636e-3f74-4ac3-b6f8-62ebfa66ce65","x":1300,"y":47,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"d56c1abc-1141-4984-97e9-a71ec7e117e6","x":1066,"y":324,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"6e03ca80-c817-4073-a2ec-3b7eeaff3407","x":968,"y":369,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"ea18277f-2474-4473-ad83-7801bb1c7f69","x":870,"y":414,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"cc76b691-673a-4f7c-91fc-87fb9aa4221d","x":854.5,"y":870,"attrs":0,"template":"@__builtin__anchor","children":["bf6ee7de-2450-4779-90e6-e811bc8e82cf"],"properties":[],"angle":1},{"id":"1e6a4cc7-3b9b-4f33-9897-80f3ccef0c2c","x":890,"y":870,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"bf7dfebe-d649-4f0c-a2d2-fe19d081ce03","x":925.5,"y":870,"attrs":0,"template":"@__builtin__anchor","children":["214ace27-f975-4fda-9730-5d736a030bdf"],"properties":[],"angle":1},{"id":"025b685f-3ce7-4440-9a7a-2ddc9652ddcf","x":962,"y":915,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"16e8c866-7437-4bc9-86ed-234de9058a7c","x":962,"y":960,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"9ce43f4a-be77-4449-9be7-624f3e2071c4","x":962,"y":1005,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"9565f4ea-2ca6-4e25-b7b7-ba40c388a1be","x":925.5,"y":1051,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"437bf8c7-1f12-4ab4-96fe-3445ca4c7b71","x":890,"y":1051,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"79c25f27-b47e-4ac3-af5d-f5effdf2db3f","x":854.5,"y":1051,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"0a8d764e-e973-4bc2-a46c-572bbd1c2969","x":819,"y":1005,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a7a4ba79-92d9-44dc-9ca7-afd709c00b06","x":819,"y":960,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"40229e8c-e017-4ad7-a968-2eb7cec330aa","x":819,"y":915,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"79eb6ba9-2e87-45de-9298-cd64b668fe2f","x":554,"y":578,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"fcab581c-29a8-404e-9b2d-6f4ad1298576","x":704.25,"y":724,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"bf6ee7de-2450-4779-90e6-e811bc8e82cf","x":854.5,"y":870,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"a5005bac-307f-4425-9283-efd9d6e286e9","x":1194,"y":569,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"a2793eaa-88ad-413f-b171-7d61e0af6fc5","x":1059.75,"y":719.5,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"214ace27-f975-4fda-9730-5d736a030bdf","x":925.5,"y":870,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"23ae5965-4d34-4258-b49d-2b4730b4acab","x":1318,"y":250,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"e9e7aea0-1b40-4c69-a6fc-f2ecb4e2915b","x":1398,"y":250,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"fdf99f45-2518-4856-874a-ea8d7be8891a","x":1478,"y":250,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"0d02f7c5-0d05-4435-9f15-45d67b5eddfc","x":2855.5,"y":1521,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"7b8c62fe-8283-4c72-a356-6e91301a33db","x":2890,"y":1521,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"c4089ab7-8fd7-4ecf-88f0-db7fe3b3c96f","x":2924.5,"y":1521,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"4b4abd15-51f4-4d13-b595-9c8db2c42163","x":2959,"y":1535.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"81d837e9-d360-4bd7-b076-7d1851528428","x":2959,"y":1550,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"29114e05-07ef-40b6-8b36-ceb6538c28e6","x":2959,"y":1564.5,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"5806658e-1d7c-4a02-b914-33658a05e84a","x":2924.5,"y":1579,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"d41af8eb-be04-4a26-bbf0-93614d1de03e","x":2890,"y":1579,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"674f6cf3-7d3e-4f6c-9ae8-d45f0e7459e4","x":2855.5,"y":1579,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"58e3533e-6d2b-453d-b646-79afefeb8639","x":2821,"y":1564.5,"attrs":0,"template":"@__builtin__anchor","children":["605679fe-5246-4c16-b263-1c8bed0143cb"],"properties":[],"angle":0},{"id":"f55937bd-8fae-4ee6-9207-6b4c8a21b9d9","x":2821,"y":1550,"attrs":0,"template":"@__builtin__anchor","children":["4075bb0d-7a7a-4785-a1b8-61a115ec2782"],"properties":[],"angle":0},{"id":"338c7bb6-f38b-4946-a369-c81ce7d03ae8","x":2821,"y":1535.5,"attrs":0,"template":"@__builtin__anchor","children":["fb7fe74c-eef8-4e49-b8bd-f5d64f61661a"],"properties":[],"angle":0},{"id":"3f797331-3db9-4909-b0be-0b72389e4aed","x":2622,"y":1270,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"5197bfde-2c97-47b4-998b-509f58859de2","x":2721.5,"y":1402.75,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"fb7fe74c-eef8-4e49-b8bd-f5d64f61661a","x":2821,"y":1535.5,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"605679fe-5246-4c16-b263-1c8bed0143cb","x":2821,"y":1564.5,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"f9fda29a-ec4e-4665-a4a3-ad5fe13ffa9e","x":2733.5,"y":1675.75,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"17266159-9d29-4d0e-97a2-7ea985028e17","x":2646,"y":1787,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"2f0b1705-4f26-4e44-b3f7-14a98940decc","x":2403.5,"y":1486,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"054bc2bb-86b9-4641-9ed4-b980f2c3ab45","x":2490,"y":1486,"attrs":0,"template":"@__builtin__anchor","children":["52384bd0-aae2-4ea9-a3e2-5d80d75c5674"],"properties":[],"angle":1},{"id":"d9ae2b57-e148-4ab9-ab16-fbdd35a07570","x":2576.5,"y":1486,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"5e90c165-522a-44e4-b85c-e04b28e695e5","x":2663,"y":1518,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"40a39fb5-a65d-4f71-aaa6-9fda8712b553","x":2663,"y":1550,"attrs":0,"template":"@__builtin__anchor","children":["ce44a654-5bdb-41f6-a296-c9a08ee24cfa"],"properties":[],"angle":0},{"id":"16f0db08-2b48-41cf-ba35-d681e3601a78","x":2663,"y":1582,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a6123e62-b298-4f3a-a263-a58f718db8c8","x":2576.5,"y":1614,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"3b54fd76-83be-42d9-b909-1ad4784fc267","x":2490,"y":1614,"attrs":0,"template":"@__builtin__anchor","children":["89563b26-3d9e-4b9f-98c3-a599eaa4211a"],"properties":[],"angle":1},{"id":"90382f59-f3cc-48e2-8cc5-ef283775b207","x":2403.5,"y":1614,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":1},{"id":"699e4ec5-f730-45de-8434-d7fb30de3f3b","x":2317,"y":1582,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"a665f873-8815-40b1-aef8-b3fb7130e36e","x":2317,"y":1550,"attrs":0,"template":"@__builtin__anchor","children":["2de3d811-f017-4ef2-9bd0-3c743895270b"],"properties":[],"angle":0},{"id":"c98cbc6a-e331-44d2-a0f3-7961dc561200","x":2317,"y":1518,"attrs":0,"template":"@__builtin__anchor","children":[],"properties":[],"angle":0},{"id":"89563b26-3d9e-4b9f-98c3-a599eaa4211a","x":2490,"y":1614,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"f24679da-5850-4a88-8b74-e4b6de86ef2f","x":2490,"y":1669,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"a9ec9b13-5481-4627-8140-f52aa26cdf67","x":2490,"y":1724,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"4075bb0d-7a7a-4785-a1b8-61a115ec2782","x":2821,"y":1550,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"125a0716-b030-4704-a719-d97ba995193d","x":2742,"y":1550,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"ce44a654-5bdb-41f6-a296-c9a08ee24cfa","x":2663,"y":1550,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]},{"id":"857e12c2-074f-4f83-9e36-38db3214711b","x":2041,"y":2943.5,"attrs":0,"template":"@__builtin__line_source","children":[],"properties":[]},{"id":"0e40842f-67b4-4dd3-819d-bd541448a5fc","x":2129,"y":2871.75,"attrs":0,"template":"@__builtin__line_handle","children":[],"properties":[]},{"id":"c910579b-149a-4ed2-9ae1-db4aa846cf10","x":2217,"y":2800,"attrs":0,"template":"@__builtin__line_target","children":[],"properties":[]}],"location":{"x":1714.164590803276,"y":1135.407570026502,"k":0.3757495984220089}}
\ No newline at end of file
diff --git a/yvisualization/attack-flow-builder/latrodectus/Latrodectus-032725.json b/yvisualization/attack-flow-builder/latrodectus/Latrodectus-032725.json
new file mode 100644
index 0000000..62baa13
--- /dev/null
+++ b/yvisualization/attack-flow-builder/latrodectus/Latrodectus-032725.json
@@ -0,0 +1,749 @@
+{
+ "type": "bundle",
+ "id": "bundle--01ade9ab-1f53-4a2e-ad67-ec97110f0a16",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.852Z",
+ "modified": "2025-03-31T13:09:11.852Z",
+ "objects": [
+ {
+ "type": "extension-definition",
+ "id": "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4",
+ "spec_version": "2.1",
+ "created": "2022-08-02T19:34:35.143Z",
+ "modified": "2022-08-02T19:34:35.143Z",
+ "name": "Attack Flow",
+ "description": "Extends STIX 2.1 with features to create Attack Flows.",
+ "created_by_ref": "identity--fb9c968a-745b-4ade-9b25-c324172197f4",
+ "schema": "https://center-for-threat-informed-defense.github.io/attack-flow/stix/attack-flow-schema-2.0.0.json",
+ "version": "2.0.0",
+ "extension_types": [
+ "new-sdo"
+ ],
+ "external_references": [
+ {
+ "source_name": "Documentation",
+ "description": "Documentation for Attack Flow",
+ "url": "https://center-for-threat-informed-defense.github.io/attack-flow"
+ },
+ {
+ "source_name": "GitHub",
+ "description": "Source code repository for Attack Flow",
+ "url": "https://github.com/center-for-threat-informed-defense/attack-flow"
+ }
+ ]
+ },
+ {
+ "type": "identity",
+ "id": "identity--fb9c968a-745b-4ade-9b25-c324172197f4",
+ "spec_version": "2.1",
+ "created": "2022-08-02T19:34:35.143Z",
+ "modified": "2022-08-02T19:34:35.143Z",
+ "created_by_ref": "identity--fb9c968a-745b-4ade-9b25-c324172197f4",
+ "name": "MITRE Center for Threat-Informed Defense",
+ "identity_class": "organization"
+ },
+ {
+ "type": "attack-flow",
+ "id": "attack-flow--63e420c7-562f-4a0a-ac7d-7e59f6b904c3",
+ "spec_version": "2.1",
+ "created": "2025-02-04T14:50:20.511Z",
+ "modified": "2025-03-31T13:09:11.853Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "created_by_ref": "identity--98a5dd1b-9f86-4599-aa25-9ef0b78f3791",
+ "start_refs": [
+ "attack-action--257ffdd4-bb50-425b-9091-f82fc184eccc",
+ "attack-action--7083e4bb-73a9-4982-b891-e65a17fd4cb3",
+ "attack-action--c7f20500-3dab-4ffc-b3cb-545a1b901925",
+ "attack-action--582fdf4c-da5a-45f9-ae83-b9dad0d8ccc5",
+ "attack-action--0eea63f2-14c5-404e-840d-1bcf082fe164",
+ "attack-condition--ed9ce25e-3124-46c3-9800-bf118b65c99c"
+ ],
+ "name": "Latrodectus",
+ "scope": "malware",
+ "external_references": [
+ {
+ "source_name": "Latrodectus, are you coming back? | Bitsight",
+ "url": "https://www.bitsight.com/blog/latrodectus-are-you-coming-back"
+ }
+ ]
+ },
+ {
+ "type": "identity",
+ "id": "identity--98a5dd1b-9f86-4599-aa25-9ef0b78f3791",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.853Z",
+ "modified": "2025-03-31T13:09:11.853Z",
+ "name": "Maddie Bright",
+ "identity_class": "individual",
+ "contact_information": "mbright@mitre.org"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--257ffdd4-bb50-425b-9091-f82fc184eccc",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.853Z",
+ "modified": "2025-03-31T13:09:11.853Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Process Environment Block BeingDebugged",
+ "tactic_id": "OB0001",
+ "technique_id": "B0001.035"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--7083e4bb-73a9-4982-b891-e65a17fd4cb3",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.853Z",
+ "modified": "2025-03-31T13:09:11.853Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Check Processes",
+ "tactic_id": "OB0001",
+ "technique_id": "B0009.004",
+ "description": "Assesses for > 75 running processes for Windows 10 and newer, > 50 for OS older than Windows 10"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--c7f20500-3dab-4ffc-b3cb-545a1b901925",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Modern Specs Check",
+ "tactic_id": "OB0001",
+ "technique_id": "B0009.013",
+ "description": "Checks for 64-bit host"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--582fdf4c-da5a-45f9-ae83-b9dad0d8ccc5",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Unique Hardware/Firmware Check - MAC Address",
+ "tactic_id": "OB0001",
+ "technique_id": "B0009.028",
+ "description": "Ensures MAC addresses exist and are valid values"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--0eea63f2-14c5-404e-840d-1bcf082fe164",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Check Mutex",
+ "tactic_id": "OC0003",
+ "technique_id": "C0043",
+ "description": "Looks for mutex named 'running'",
+ "effect_refs": [
+ "attack-condition--4091668b-3f98-4b05-95a9-521ec3d6703a"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--e594ebea-5a98-4200-81ac-6a688e657831",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "System Information Discovery",
+ "tactic_id": "OB0007",
+ "technique_id": "E1082",
+ "description": "GetVolumeInformationW is used to determine the serial number for computing the bot ID",
+ "effect_refs": [
+ "attack-action--961e50bf-5799-43f2-9277-df5d72d27de3"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--218c1310-e244-493c-a8d5-76a71befb735",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "XOR",
+ "tactic_id": "OC0004",
+ "technique_id": "C0053.002",
+ "description": "Decodes XOR-encrypted file contents"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--25137e20-5ce8-42f5-ba2e-ff1cbc5c32c5",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Read File",
+ "tactic_id": "OC0001",
+ "technique_id": "C0051",
+ "description": "Fetches the C2 URLs",
+ "effect_refs": [
+ "attack-action--218c1310-e244-493c-a8d5-76a71befb735"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--6daf1e2b-0451-4233-9274-4e29c95e4204",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Authentication",
+ "tactic_id": "OB0004",
+ "technique_id": "B0030.011",
+ "description": "sends MAC addresses, hostname, and host domain"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--f7a96d30-4e16-4955-94bc-64aa95732254",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "RC4",
+ "tactic_id": "OC0005",
+ "technique_id": "C0027.009",
+ "technique_ref": "attack-pattern--005a06c6-14bf-4118-afa0-ebcd8aebb0c9",
+ "description": "Encypt the C2 beacon",
+ "effect_refs": [
+ "attack-action--02f64672-ba05-4090-b1ef-066a28e7f0a5"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--02f64672-ba05-4090-b1ef-066a28e7f0a5",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Base64",
+ "tactic_id": "OC0005",
+ "technique_id": "C0026.001",
+ "description": "Encode the C2 beacon",
+ "effect_refs": [
+ "attack-action--29c279a7-55af-4e93-9bc6-68923570ac0f"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--c7b64762-30d9-42af-90f3-994fd35ae504",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Directory Listing",
+ "tactic_id": "OB0004",
+ "technique_id": "B0030.012",
+ "description": "Collects file names from desktop"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--f0d4d59a-1f6a-4d51-8c6a-268be304f864",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Send System Information",
+ "tactic_id": "OB0004",
+ "technique_id": "B0030.006",
+ "description": "Runs pre-set group of WIndows recon commands"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--8fafaa85-739d-4c15-9038-f9f0cf20c92e",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Process Discovery",
+ "tactic_id": "TA0007",
+ "tactic_ref": "x-mitre-tactic--c17c5845-175e-4421-9713-829d0573dbc9",
+ "technique_id": "T1057",
+ "technique_ref": "attack-pattern--8f4a33ec-8b1f-4b80-a2f6-642b2e479580",
+ "description": "collects PIDs and names of running processes"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--17382d39-8d97-457d-9a89-0f8d77dae0de",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Server to Client File Transfer",
+ "tactic_id": "OB0004",
+ "technique_id": "B0030.003",
+ "description": "Downloads DLL or EXE files"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--9bbbe9ff-b82f-40d9-840d-c6ad2439b7e6",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Execute File",
+ "tactic_id": "OB0004",
+ "technique_id": "B0030.013",
+ "description": "Uses rundll32 or cmd.exe to execute transferred files"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--f5c36be6-4afc-45bb-b98e-76f4f6a1e09b",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Ingress Tool Transfer",
+ "tactic_id": "OB0004",
+ "technique_id": "E1105",
+ "description": "Downloads a stealer module"
+ },
+ {
+ "type": "grouping",
+ "id": "grouping--1d85143a-059a-438c-a794-10012880f3e8",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "name": "Sandbox/VM Checks",
+ "context": "Malware checks to ensure it is not executing within an analysis environment",
+ "object_refs": [
+ "attack-condition--ed9ce25e-3124-46c3-9800-bf118b65c99c",
+ "attack-action--582fdf4c-da5a-45f9-ae83-b9dad0d8ccc5",
+ "attack-action--257ffdd4-bb50-425b-9091-f82fc184eccc",
+ "attack-action--7083e4bb-73a9-4982-b891-e65a17fd4cb3",
+ "attack-action--0eea63f2-14c5-404e-840d-1bcf082fe164",
+ "attack-action--c7f20500-3dab-4ffc-b3cb-545a1b901925"
+ ]
+ },
+ {
+ "type": "attack-condition",
+ "id": "attack-condition--ed9ce25e-3124-46c3-9800-bf118b65c99c",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "description": "Discovers Indication of Execution in Sandbox?",
+ "on_false_refs": [
+ "attack-action--e594ebea-5a98-4200-81ac-6a688e657831"
+ ],
+ "on_true_refs": [
+ "attack-action--f2cc7510-ee8e-46b2-b110-56e51506d094"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--961e50bf-5799-43f2-9277-df5d72d27de3",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Non-cryptographic Hash: FNV Hash",
+ "tactic_id": "OC0004",
+ "technique_id": "C0030.005",
+ "description": "Used to calculate group ID",
+ "effect_refs": [
+ "attack-action--2e8bc208-cd80-44ed-ad8f-cf71d00749d3"
+ ]
+ },
+ {
+ "type": "attack-condition",
+ "id": "attack-condition--0f72ef7c-2379-44d9-9927-424fcfb6968c",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "description": "C2 File Exists?",
+ "on_true_refs": [
+ "attack-action--25137e20-5ce8-42f5-ba2e-ff1cbc5c32c5"
+ ],
+ "on_false_refs": [
+ "attack-action--6daf1e2b-0451-4233-9274-4e29c95e4204"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--2e8bc208-cd80-44ed-ad8f-cf71d00749d3",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Self-Discovery",
+ "tactic_id": "OB0007",
+ "technique_id": "B0038",
+ "description": "Check exe running from %appdata%",
+ "effect_refs": [
+ "attack-condition--c8cbe298-71ee-4ae3-92eb-dbd4e2e66a4f"
+ ]
+ },
+ {
+ "type": "attack-condition",
+ "id": "attack-condition--c8cbe298-71ee-4ae3-92eb-dbd4e2e66a4f",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "description": "Executing from AppData?",
+ "on_false_refs": [
+ "attack-action--3444fb5b-da4d-462f-88ce-3f7453e37f47"
+ ],
+ "on_true_refs": [
+ "attack-action--d0667ee0-ef70-49e0-a96a-b6777bda94ce"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--3444fb5b-da4d-462f-88ce-3f7453e37f47",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Copy FIle",
+ "tactic_id": "OC0001",
+ "technique_id": "C0045",
+ "description": "Copies executable to %appdata%",
+ "effect_refs": [
+ "attack-action--f2cfaa6c-5204-4708-8864-8f1d277c3170"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--73fd998a-ea52-4cdb-a957-e08cbefef97d",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Delete FIle",
+ "tactic_id": "OC0001",
+ "technique_id": "C0047",
+ "description": "Deletes old executable after executing in appdata"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--d0667ee0-ef70-49e0-a96a-b6777bda94ce",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Scheduled Task",
+ "tactic_id": "TA0003",
+ "tactic_ref": "x-mitre-tactic--5bc1d813-693e-4823-9961-abf9af4b0e92",
+ "technique_id": "T1053.005",
+ "technique_ref": "attack-pattern--005a06c6-14bf-4118-afa0-ebcd8aebb0c9",
+ "description": "Creates task which runs at every logon",
+ "effect_refs": [
+ "attack-condition--0f72ef7c-2379-44d9-9927-424fcfb6968c"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--bc4c9f48-8244-494a-9241-7b062bd4620d",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Receive Data",
+ "tactic_id": "OB0004",
+ "technique_id": "B0030.002",
+ "description": "Receives commands from C2"
+ },
+ {
+ "type": "grouping",
+ "id": "grouping--56d45603-8674-4651-8e68-b9aa9ffa8737",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "name": "C2 Commands",
+ "context": "Commands malware receives from C2 and sends data in response",
+ "object_refs": [
+ "attack-action--c7b64762-30d9-42af-90f3-994fd35ae504",
+ "attack-action--f0d4d59a-1f6a-4d51-8c6a-268be304f864",
+ "attack-action--9bbbe9ff-b82f-40d9-840d-c6ad2439b7e6",
+ "attack-action--f5c36be6-4afc-45bb-b98e-76f4f6a1e09b",
+ "attack-action--17382d39-8d97-457d-9a89-0f8d77dae0de",
+ "attack-action--aa621f2f-6695-4280-a648-12b7399d740b",
+ "attack-action--8fafaa85-739d-4c15-9038-f9f0cf20c92e"
+ ]
+ },
+ {
+ "type": "attack-condition",
+ "id": "attack-condition--4091668b-3f98-4b05-95a9-521ec3d6703a",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "description": "Does the mutex already exist?",
+ "on_true_refs": [
+ "attack-action--ea43ca4b-a714-46fa-a2a7-6c0dce01d9e6"
+ ],
+ "on_false_refs": [
+ "attack-action--f2cc7510-ee8e-46b2-b110-56e51506d094"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--ea43ca4b-a714-46fa-a2a7-6c0dce01d9e6",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Create Mutex",
+ "tactic_id": "OC0003",
+ "technique_id": "C0041",
+ "description": "Mutex ensures only one instance of malware is running"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--aa621f2f-6695-4280-a648-12b7399d740b",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Write File",
+ "tactic_id": "OC0001",
+ "technique_id": "C0052",
+ "description": "Updates C2 URL file"
+ },
+ {
+ "type": "grouping",
+ "id": "grouping--2b4339ab-0b45-4cea-935f-9eda3205ab0a",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "name": "C2 Communications Loop",
+ "context": "After a C2 connection is established, the bot waits to receive commands and sends data back to the C2.",
+ "object_refs": [
+ "attack-action--f7a96d30-4e16-4955-94bc-64aa95732254",
+ "grouping--56d45603-8674-4651-8e68-b9aa9ffa8737",
+ "attack-action--bc4c9f48-8244-494a-9241-7b062bd4620d"
+ ]
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--29c279a7-55af-4e93-9bc6-68923570ac0f",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Send Data",
+ "tactic_id": "OB0004",
+ "technique_id": "B0030.001",
+ "description": "Data collected by implant as per C2 commands is sent to C2 via HTTPS"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--f2cc7510-ee8e-46b2-b110-56e51506d094",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Suicide Exit",
+ "tactic_id": "OB0009",
+ "technique_id": "B0025.001"
+ },
+ {
+ "type": "file",
+ "id": "file--4d78d74a-eaf4-477d-ad24-fdbba67fa4cd",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "name": "Executable"
+ },
+ {
+ "type": "attack-action",
+ "id": "attack-action--f2cfaa6c-5204-4708-8864-8f1d277c3170",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.854Z",
+ "modified": "2025-03-31T13:09:11.854Z",
+ "extensions": {
+ "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "name": "Command and Scripting Interpreter",
+ "technique_id": "T1059",
+ "technique_ref": "attack-pattern--7385dfaf-6886-4229-9ecd-6fd678040830",
+ "effect_refs": [
+ "attack-action--d0667ee0-ef70-49e0-a96a-b6777bda94ce",
+ "attack-action--73fd998a-ea52-4cdb-a957-e08cbefef97d"
+ ]
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--6780f44b-8e45-4f5e-a711-4075fe133e2d",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.855Z",
+ "modified": "2025-03-31T13:09:11.855Z",
+ "relationship_type": "related-to",
+ "source_ref": "attack-action--218c1310-e244-493c-a8d5-76a71befb735",
+ "target_ref": "grouping--2b4339ab-0b45-4cea-935f-9eda3205ab0a"
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--c4f5f848-38e3-49df-84c4-19ee77a12f14",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.855Z",
+ "modified": "2025-03-31T13:09:11.855Z",
+ "relationship_type": "related-to",
+ "source_ref": "attack-action--6daf1e2b-0451-4233-9274-4e29c95e4204",
+ "target_ref": "grouping--2b4339ab-0b45-4cea-935f-9eda3205ab0a"
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--5558d034-8b62-420b-9b76-9de3fe217b4f",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.855Z",
+ "modified": "2025-03-31T13:09:11.855Z",
+ "relationship_type": "related-to",
+ "source_ref": "attack-action--3444fb5b-da4d-462f-88ce-3f7453e37f47",
+ "target_ref": "file--4d78d74a-eaf4-477d-ad24-fdbba67fa4cd"
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--22778212-ea2d-41bb-b207-248a2fd9e048",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.855Z",
+ "modified": "2025-03-31T13:09:11.855Z",
+ "relationship_type": "related-to",
+ "source_ref": "file--4d78d74a-eaf4-477d-ad24-fdbba67fa4cd",
+ "target_ref": "attack-action--73fd998a-ea52-4cdb-a957-e08cbefef97d"
+ },
+ {
+ "type": "relationship",
+ "id": "relationship--34d11c40-be04-48ca-9799-c1f134037a24",
+ "spec_version": "2.1",
+ "created": "2025-03-31T13:09:11.855Z",
+ "modified": "2025-03-31T13:09:11.855Z",
+ "relationship_type": "related-to",
+ "source_ref": "file--4d78d74a-eaf4-477d-ad24-fdbba67fa4cd",
+ "target_ref": "attack-action--f2cfaa6c-5204-4708-8864-8f1d277c3170"
+ }
+ ]
+}
\ No newline at end of file
diff --git a/yvisualization/attack-flow-builder/latrodectus/Latrodectus-032725.png b/yvisualization/attack-flow-builder/latrodectus/Latrodectus-032725.png
new file mode 100644
index 0000000..966c542
Binary files /dev/null and b/yvisualization/attack-flow-builder/latrodectus/Latrodectus-032725.png differ
diff --git a/yvisualization/stix-visualizer/icedid/icedid-stix.json b/yvisualization/stix-visualizer/icedid/icedid-stix.json
new file mode 100644
index 0000000..6286249
--- /dev/null
+++ b/yvisualization/stix-visualizer/icedid/icedid-stix.json
@@ -0,0 +1,2797 @@
+{
+ "type": "bundle",
+ "id": "bundle--9e30acee-86ce-419a-8424-7094bedf8239",
+ "objects": [
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--584dc938-3789-4e53-995e-f914dff31b71",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2022-08-02T00:00:00.000Z",
+ "modified": "2024-04-30T00:00:00.000Z",
+ "name": "System Information Discovery",
+ "obj_defn": {
+ "description": "Malware may attempt to get detailed information about the system. This can include details about the operating system, hardware configurations, installed software, system uptime, and other system-level details.\n\nSee ATT&CK: **System Information Discovery ([T1082](https://attack.mitre.org/techniques/T1082/))**.",
+ "external_id": "E1082",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/discovery/system-information-discovery.md"
+ },
+ "objective_refs": [
+ "malware-objective--f59acc38-c564-4181-93ef-3c4a5531cf4a"
+ ],
+ "detection_rules": [
+ {
+ "api_fncs": [
+ "kernel32.GetEnvironmentVariable",
+ "kernel32.GetEnvironmentStrings",
+ "kernel32.ExpandEnvironmentStrings",
+ "msvcr90.getenv",
+ "msvcrt.getenv",
+ "System.Environment::GetEnvironmentVariable",
+ "System.Environment::GetEnvironmentVariables",
+ "System.Environment::ExpandEnvironmentVariables"
+ ],
+ "rule_name": "query environment variable",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/environment-variable/query-environment-variable.yml"
+ },
+ {
+ "api_fncs": [
+ "kernel32.GetDriveType",
+ "kernel32.GetLogicalDrives",
+ "kernel32.GetVolumeInformation",
+ "kernel32.GetVolumeNameForVolumeMountPoint",
+ "kernel32.GetVolumePathNamesForVolumeName",
+ "kernel32.GetLogicalDriveStrings",
+ "kernel32.QueryDosDevice"
+ ],
+ "rule_name": "get disk information",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/hardware/storage/get-disk-information.yml"
+ },
+ {
+ "api_fncs": [
+ "kernel32.GetDiskFreeSpace",
+ "kernel32.GetDiskFreeSpaceEx"
+ ],
+ "rule_name": "get disk size",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/hardware/storage/get-disk-size.yml"
+ },
+ {
+ "rule_name": "check OS version",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/os/version/check-os-version.yml"
+ },
+ {
+ "api_fncs": [
+ "kernel32.GetComputerName",
+ "kernel32.GetComputerNameEx",
+ "GetComputerObjectName",
+ "ws2_32.gethostname",
+ "gethostname"
+ ],
+ "rule_name": "get hostname",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/os/hostname/get-hostname.yml"
+ },
+ {
+ "api_fncs": [
+ "DeviceIoControl",
+ "NtClose",
+ "NtCreateFile",
+ "NtDuplicateObject",
+ "NtOpenFile",
+ "NtDeviceIoControlFile"
+ ],
+ "rule_name": "antivm_generic_disk",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_disk.py"
+ },
+ {
+ "rule_name": "recon_systeminfo",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/recon_systeminfo.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "HttpOpenRequestA",
+ "HttpSendRequestA"
+ ],
+ "rule_name": "recon_beacon",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/recon_beacon.py"
+ },
+ {
+ "rule_name": "uses_adfind",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/uses_adfind.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "antivm_generic_cpu",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_cpu.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "accesses_mailslot",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/accesses_netlogon.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "accesses_netlogon_regkey",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/accesses_netlogon.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "antivm_generic_bios",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_bios.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "antivm_hyperv_keys",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_hyperv_keys.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "uses_windows_utilities_nltest",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/windows_utilities.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "RegOpenKeyExW",
+ "RegQueryValueExA",
+ "RegQueryValueExW",
+ "RegOpenKeyExA"
+ ],
+ "rule_name": "antivm_generic_scsi",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_scsi.py"
+ },
+ {
+ "rule_name": "antivm_parallels_keys",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_parallels_keys.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "antivm_generic_diskreg",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_diskreg.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "antivm_generic_system",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_system.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "system_account_discovery_cmd",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/collects_systeminfo_cmd.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "system_currently_loggedin_user_cmd",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/collects_systeminfo_cmd.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "system_info_discovery_cmd",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/collects_systeminfo_cmd.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "system_info_discovery_pwsh",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/collects_systeminfo_cmd.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "system_network_discovery_cmd",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/collects_systeminfo_cmd.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "system_network_discovery_pwsh",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/collects_systeminfo_cmd.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "system_user_discovery_cmd",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/collects_systeminfo_cmd.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "RegOpenKeyExW",
+ "RegEnumKeyExW",
+ "RegEnumKeyExA",
+ "RegOpenKeyExA"
+ ],
+ "rule_name": "antivm_generic_services",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_services.py"
+ },
+ {
+ "api_fncs": [
+ "SetupDiGetClassDevsA",
+ "SetupDiGetClassDevsW"
+ ],
+ "rule_name": "antivm_generic_disk_setupapi",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_generic_disk_setupapi.py"
+ },
+ {
+ "api_fncs": [
+ "rtcEnvironBstr"
+ ],
+ "rule_name": "antisandbox_check_userdomain",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_check_userdomain.py"
+ },
+ {
+ "api_fncs": [
+ "JsEval",
+ "COleScript_ParseScriptText",
+ "COleScript_Compile"
+ ],
+ "rule_name": "browser_scanbox",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/browser_scanbox.py"
+ },
+ {
+ "rule_name": "recon_fingerprint",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/recon_fingerprint.py",
+ "rule_type": "cape"
+ }
+ ],
+ "obj_version": "2.3",
+ "related_object_refs": [
+ "attack-pattern--354a7f88-63fb-41b5-a801-ce3b377b36f1"
+ ],
+ "external_references": [
+ {
+ "source_name": "trendmicro-ursnif",
+ "description": "\"PE_URSNIF.A2,\" Trend Micro, analysis report, Dec. 11, 2014 [Online].",
+ "url": "https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/PE_URSNIF.A2"
+ },
+ {
+ "source_name": "fsecure-quedagh",
+ "description": "\"BlackEnergy & Quedagh: The convergence of crimeware and APT attacks,\" F-Secure Labs [Online].",
+ "url": "https://blog-assets.f-secure.com/wp-content/uploads/2019/10/15163408/BlackEnergy_Quedagh.pdf"
+ },
+ {
+ "source_name": "kujawa",
+ "description": "A. Kujawa, \"You dirty RAT! Part 1: DarkComet,\" Malwarebytes Labs, blog, Jun. 9, 2012 [Online].",
+ "url": "https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/"
+ },
+ {
+ "source_name": "trendmicro-emotet",
+ "description": "\"Exploring Emotet's Activities,\" Trend Micro Research, 2019 [Online].",
+ "url": "https://documents.trendmicro.com/assets/white_papers/ExploringEmotetsActivities_Final.pdf"
+ },
+ {
+ "source_name": "falliere-stuxnet",
+ "description": "N. Falliere, L. Murchu, and E. Chien, \"W32.Stuxnet Dossier,\" Symantec Security Response, Feb. 2011 [Online].",
+ "url": "https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en"
+ },
+ {
+ "source_name": "fireeye-apt28",
+ "description": "\"APT28: A Window into Russia's Cyber Espionage Operations?\" FireEye, 2014 [Online].",
+ "url": "https://www2.fireeye.com/rs/fireye/images/rpt-apt28.pdf"
+ },
+ {
+ "source_name": "s2grupo",
+ "description": "\"Evolution of Trickbot,\" S2 Grupo, report, Jun. 2017 [Online].",
+ "url": "https://www.securityartwork.es/wp-content/uploads/2017/07/Trickbot-report-S2-Grupo.pdf"
+ },
+ {
+ "source_name": "mcafee-webcobra",
+ "description": "\"WebCobra Malware Uses Victims' Computers to Mine Cryptocurrency,\" McAfee, blog, Nov. 12, 2018 [Online].",
+ "url": "https://www.mcafee.com/blogs/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/"
+ },
+ {
+ "source_name": "capa analysis",
+ "description": "Analysis output, capa 4.0, analyzed at MITRE on Oct. 12, 2022.",
+ "url": "https://github.com/mandiant/capa-rules"
+ },
+ {
+ "source_name": "hromcov\u00e1",
+ "description": "Z. Hromcov\u00e1, \"Malicious campaign targets South Korean users with backdoor\u2011laced torrents,\" We Live Security, ESET, Jul. 8, 2019 [Online].",
+ "url": "https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--7ea1c41a-ed8b-4836-a4bc-48129c33c60b",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-12-04T00:00:00.000Z",
+ "modified": "2024-02-06T00:00:00.000Z",
+ "name": "Copy File",
+ "obj_defn": {
+ "description": "Malware copies a file.",
+ "external_id": "C0045",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/micro-behaviors/file-system/copy-file.md"
+ },
+ "objective_refs": [
+ "malware-objective--b535116e-3bd9-42f6-9615-68f24c7b42ed"
+ ],
+ "detection_rules": [
+ {
+ "api_fncs": [
+ "kernel32.CopyFile",
+ "kernel32.CopyFileEx",
+ "CopyFile2",
+ "CopyFileTransacted",
+ "LZCopy",
+ "System.IO.FileInfo::CopyTo",
+ "System.IO.File::Copy",
+ "kernel32.SHFileOperation"
+ ],
+ "rule_name": "copy file",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/file-system/copy/copy-file.yml"
+ },
+ {
+ "api_fncs": [
+ "NtCreateUserProcess",
+ "CreateProcessInternalW"
+ ],
+ "class": "InjectionExtension",
+ "rule_name": "injection_needextension",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/injection_needextension.py"
+ }
+ ],
+ "obj_version": "2.2",
+ "external_references": [
+ {
+ "source_name": "capa analysis",
+ "description": "Analysis output, capa 4.0, analyzed at MITRE on Oct. 12, 2022.",
+ "url": "https://github.com/mandiant/capa-rules"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--819ed2ae-7ed5-4caf-a057-485563efc26f",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2022-08-02T00:00:00.000Z",
+ "modified": "2024-04-30T00:00:00.000Z",
+ "name": "Command and Scripting Interpreter",
+ "obj_defn": {
+ "description": "Malware may abuse command and script interpreters to execute commands, scripts, or binaries. This is often done to carry out various malicious activities, such as exploring the system, escalating privileges, or exfiltrating data. Built-in command-line interpreters or scripting environments of the operating system, such as cmd.exe or Powershell on Windows, or Bash on Unix-like systems, are often used. Additionally, adversaries may use other scripting languages like Python, Perl, or Javascript. \n\nSee ATT&CK: **Command and Scripting Interpreter ([T1059](https://attack.mitre.org/techniques/T1059), [T1623](https://attack.mitre.org/techniques/T1623))**.",
+ "external_id": "E1059",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/execution/command-and-scripting-interpreter.md"
+ },
+ "objective_refs": [
+ "malware-objective--3336569b-d163-4a42-9b05-9eff0c7ac6d2"
+ ],
+ "detection_rules": [
+ {
+ "api_fncs": [
+ "GetCommandLine",
+ "CommandLineToArgv",
+ "System.Environment::GetCommandLineArgs"
+ ],
+ "rule_name": "accept command line arguments",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/cli/accept-command-line-arguments.yml"
+ },
+ {
+ "api_fncs": [
+ "System.Management.Automation.PowerShell::Create",
+ "System.Management.Automation.PowerShell::AddScript",
+ "System.Management.Automation.PowerShell::Invoke"
+ ],
+ "rule_name": "run PowerShell expression",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/load-code/powershell/run-powershell-expression.yml"
+ },
+ {
+ "api_fncs": [
+ "NtWriteFile"
+ ],
+ "rule_name": "office_postscript",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/office_exploit.py"
+ },
+ {
+ "api_fncs": [
+ "CDocument_write",
+ "JsEval",
+ "COleScript_ParseScriptText",
+ "COleScript_Compile"
+ ],
+ "rule_name": "js_suspicious_redirect",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/js_suspicious_redirect.py"
+ },
+ {
+ "rule_name": "odbcconf_bypass",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/bypass_applocker.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "LdrLoadDll"
+ ],
+ "rule_name": "regsvr32_squiblydoo_dll_load",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/bypass_applocker.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "squiblydoo_bypass",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/bypass_applocker.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "squiblytwo_bypass",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/bypass_applocker.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "JsEval"
+ ],
+ "rule_name": "exe_dropper_js",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/dropper_js.py"
+ },
+ {
+ "api_fncs": [
+ "RegSetValueExA",
+ "RegSetValueExW",
+ "NtSetValueKey"
+ ],
+ "rule_name": "persistence_registry_script",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/persistence_fileless.py"
+ },
+ {
+ "rule_name": "ie_martian_children",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/martians_ie.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "ShellExecuteExW",
+ "NtCreateUserProcess",
+ "CreateProcessInternalW"
+ ],
+ "rule_name": "bcdedit_command",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/bcdedit_command.py"
+ },
+ {
+ "rule_name": "office_martian_children",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/martians_office.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "JsEval",
+ "COleScript_ParseScriptText",
+ "COleScript_Compile"
+ ],
+ "rule_name": "js_phish",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/js_phish.py"
+ },
+ {
+ "rule_name": "disables_winfirewall",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/disables_winfirewall.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "script_tool_executed",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/windows_utilities.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "cmdline_obfuscation",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/cmdline_anomaly.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "cmdline_switches",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/cmdline_anomaly.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "cmdline_terminate",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/cmdline_anomaly.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "cmdline_forfiles_wildcard",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/cmdline_anomaly.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "cmdline_http_link",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/cmdline_anomaly.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "cmdline_long_string",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/cmdline_anomaly.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "cmdline_reversed_http_link",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/cmdline_anomaly.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "long_commandline",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/cmdline_anomaly.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "powershell_renamed_commandline",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/cmdline_anomaly.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "NtCreateUserProcess",
+ "CreateProcessInternalW"
+ ],
+ "rule_name": "wmi_script_process",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/wmi.py"
+ },
+ {
+ "api_fncs": [
+ "ShellExecuteExW",
+ "NtCreateUserProcess",
+ "CreateProcessInternalW"
+ ],
+ "rule_name": "disables_mappeddrives_autodisconnect",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/disables_drives_autodisconnect.py"
+ },
+ {
+ "rule_name": "system_account_discovery_cmd",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/collects_systeminfo_cmd.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "system_currently_loggedin_user_cmd",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/collects_systeminfo_cmd.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "system_info_discovery_cmd",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/collects_systeminfo_cmd.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "system_info_discovery_pwsh",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/collects_systeminfo_cmd.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "system_network_discovery_cmd",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/collects_systeminfo_cmd.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "system_network_discovery_pwsh",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/collects_systeminfo_cmd.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "system_user_discovery_cmd",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/collects_systeminfo_cmd.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "URLDownloadToFileW",
+ "HttpOpenRequestW",
+ "send",
+ "WSAConnect",
+ "InternetCrackUrlW",
+ "InternetCrackUrlA",
+ "InternetReadFile"
+ ],
+ "rule_name": "powershell_network_connection",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/powershell_command.py"
+ },
+ {
+ "rule_name": "powershell_scriptblock_logging",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/powershell_command.py"
+ },
+ {
+ "rule_name": "powershell_command_suspicious",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/powershell_command.py"
+ },
+ {
+ "rule_name": "powershell_renamed",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/powershell_command.py"
+ },
+ {
+ "rule_name": "powershell_reversed",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/powershell_command.py"
+ },
+ {
+ "rule_name": "powershell_variable_obfuscation",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/powershell_command.py"
+ },
+ {
+ "api_fncs": [
+ "LdrGetDllHandle",
+ "LdrLoadDll"
+ ],
+ "rule_name": "office_com_load",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/office_dll_loading.py"
+ },
+ {
+ "api_fncs": [
+ "LdrGetDllHandle",
+ "LdrLoadDll"
+ ],
+ "rule_name": "office_vb_load",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/office_dll_loading.py"
+ },
+ {
+ "api_fncs": [
+ "LdrGetDllHandle",
+ "LdrLoadDll"
+ ],
+ "rule_name": "office_wmi_load",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/office_dll_loading.py"
+ },
+ {
+ "api_fncs": [
+ "NtWriteFile"
+ ],
+ "rule_name": "document_script_exe_drop",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/document_exedrop.py"
+ },
+ {
+ "rule_name": "windows_defender_powershell",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/disables_windefender.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "NtCreateUserProcess",
+ "CreateProcessInternalW"
+ ],
+ "rule_name": "office_suspicious_processes",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/office_suspicious_process.py"
+ },
+ {
+ "api_fncs": [
+ "NtCreateUserProcess",
+ "CreateProcessInternalW"
+ ],
+ "rule_name": "script_created_process",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/script_downloader.py"
+ },
+ {
+ "api_fncs": [
+ "URLDownloadToFileW",
+ "HttpOpenRequestW",
+ "send",
+ "WSAConnect",
+ "InternetCrackUrlW",
+ "InternetCrackUrlA",
+ "SslEncryptPacket",
+ "InternetReadFile"
+ ],
+ "rule_name": "script_network_activity",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/script_downloader.py"
+ },
+ {
+ "api_fncs": [
+ "JsEval",
+ "COleScript_ParseScriptText"
+ ],
+ "rule_name": "suspicious_js_script",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/script_downloader.py"
+ }
+ ],
+ "obj_version": "2.2",
+ "related_object_refs": [
+ "attack-pattern--7385dfaf-6886-4229-9ecd-6fd678040830",
+ "attack-pattern--29f1f56c-7b7a-4c14-9e39-59577ea2743c"
+ ],
+ "external_references": [
+ {
+ "source_name": "njccic-poisonivy",
+ "description": "\"Poison Ivy,\" NJCCIC Threat Profile, Apr. 12, 2017 [Online].",
+ "url": "https://www.cyber.nj.gov/threat-center/threat-profiles/trojan-variants/poison-ivy"
+ },
+ {
+ "source_name": "hromcov\u00e1",
+ "description": "Z. Hromcov\u00e1, \"Malicious campaign targets South Korean users with backdoor\u2011laced torrents,\" We Live Security, ESET, Jul. 8, 2019 [Online].",
+ "url": "https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/"
+ },
+ {
+ "source_name": "bleeping-kovter",
+ "description": "\"How to remove the Kovter Trojan (Removal Guide),\" Bleeping Computer, Mar. 23, 2016 [Online].",
+ "url": "https://www.bleepingcomputer.com/virus-removal/remove-kovter-trojan"
+ },
+ {
+ "source_name": "palotay",
+ "description": "D. Palotay and P. Mackenzie, \"SamSam Ransomware Chooses Its Targets Carefully,\" Sophos Labs, Apr. 2018 [Online].",
+ "url": "https://www.sophos.com/en-us/medialibrary/PDFs/technical-papers/SamSam-ransomware-chooses-Its-targets-carefully-wpna.pdf"
+ },
+ {
+ "source_name": "mundo-shamoon",
+ "description": "A. Mundo, \"Shamoon Returns to Wipe Systems in Middle East, Europe,\" McAfee, blog, Dec. 14, 2018 [Online].",
+ "url": "https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-returns-to-wipe-systems-in-middle-east-europe/"
+ },
+ {
+ "source_name": "falliere-stuxnet",
+ "description": "N. Falliere, L. Murchu, and E. Chien, \"W32.Stuxnet Dossier,\" Symantec Security Response, Feb. 2011 [Online].",
+ "url": "https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en"
+ },
+ {
+ "source_name": "marschalek",
+ "description": "M. Marschalek, \"EvilBunny: Malware Instrumented by Lua,\" Cyphort Labs, blog, Dec. 16, 2014 [Online].",
+ "url": "https://web.archive.org/web/20150311013500/http://www.cyphort.com/evilbunny-malware-instrumented-lua/"
+ },
+ {
+ "source_name": "victor-netwalker",
+ "description": "K. Victor, \"Reflective Loading Runs Netwalker Fileless Ransomware,\" Trend Micro, May 18, 2020 [Online].",
+ "url": "https://www.trendmicro.com/en_us/research/20/e/netwalker-fileless-ransomware-injected-via-reflective-loading.html"
+ },
+ {
+ "source_name": "capa analysis",
+ "description": "Analysis output, capa 4.0, analyzed at MITRE on Oct. 12, 2022.",
+ "url": "https://github.com/mandiant/capa-rules"
+ },
+ {
+ "source_name": "reed-mac",
+ "description": "T. Reed, \"Mac malware intercepts encrypted web traffic for ad injection,\" Malwarebytes Labs, blog, Oct. 24, 2018 [Online].",
+ "url": "https://www.malwarebytes.com/blog/news/2018/10/mac-malware-intercepts-encrypted-web-traffic-for-ad-injection"
+ },
+ {
+ "source_name": "mcafee-webcobra",
+ "description": "\"WebCobra Malware Uses Victims' Computers to Mine Cryptocurrency,\" McAfee, blog, Nov. 12, 2018 [Online].",
+ "url": "https://www.mcafee.com/blogs/other-blogs/mcafee-labs/webcobra-malware-uses-victims-computers-to-mine-cryptocurrency/"
+ },
+ {
+ "source_name": "malwarebytes-kovter",
+ "description": "\"Untangling Kovter's persistence methods,\" Malwarebytes Labs, blog, Jul. 14, 2016 [Online].",
+ "url": "https://blog.malwarebytes.com/threat-analysis/2016/07/untangling-kovter/"
+ },
+ {
+ "source_name": "njccic-poisonivy",
+ "description": "\"Poison Ivy,\" NJCCIC Threat Profile, Apr. 12, 2017 [Online].",
+ "url": "https://www.cyber.nj.gov/threat-center/threat-profiles/trojan-variants/poison-ivy"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--201961ae-2a71-41f5-bbd0-8c22bbd748de",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2019-08-01T00:00:00.000Z",
+ "modified": "2024-04-28T00:00:00.000Z",
+ "name": "Ingress Tool Transfer",
+ "obj_defn": {
+ "description": "Malware may copy files from an external system to a system on a compromised network. \n\nNote that this behavior is separate from possible execution (installation) of the file, which is covered by the **Install Additional Program ([B0023](https://github.com/MBCProject/mbc-markdown/blob/main/execution/install-additional-program.md))** behavior. \n\nSee ATT&CK: **Ingress Tool Transfer ([T1105](https://attack.mitre.org/techniques/T1105/))**.",
+ "external_id": "E1105",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/command-and-control/ingress-tool-transfer.md"
+ },
+ "objective_refs": [
+ "malware-objective--6b7a98eb-cb9c-4cf1-aad6-714d64000dd3",
+ "malware-objective--91583649-6a8a-48d9-a42a-75a928d4b241",
+ "malware-objective--b0d7b24c-db02-461a-a9c9-bcf790572114"
+ ],
+ "detection_rules": [
+ {
+ "rule_name": "suspicious_mpcmdrun_use",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/windows_utilities.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "URLDownloadToFileW",
+ "HttpOpenRequestW",
+ "send",
+ "InternetCrackUrlW",
+ "InternetCrackUrlA",
+ "WSASend",
+ "URLDownloadToCacheFileW"
+ ],
+ "rule_name": "network_document_file",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/network_payload_download.py"
+ }
+ ],
+ "obj_version": "2.2",
+ "related_object_refs": [
+ "attack-pattern--e6919abc-99f9-4c6c-95a5-14761e7b2add"
+ ],
+ "external_references": [
+ {
+ "source_name": "kujawa",
+ "description": "A. Kujawa, \"You dirty RAT! Part 1: DarkComet,\" Malwarebytes Labs, blog, Jun. 9, 2012 [Online].",
+ "url": "https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/"
+ },
+ {
+ "source_name": "roccia-shamoon",
+ "description": "R. Roccia, \"Shamoon Attackers Employ New Tool Kit to Wipe Infected Systems,\" McAfee, blog, Dec. 19, 2018 [Online].",
+ "url": "https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-attackers-employ-new-tool-kit-to-wipe-infected-systems/"
+ },
+ {
+ "source_name": "levene-cozycar",
+ "description": "B. Levene, R. Falcone, and R. Wartell, \"Tracking MiniDionis: CozyCar's New Ride Is Related to Seaduke,\" Unit 42 by Palo Alto Networks, Jul 14, 2015 [Online].",
+ "url": "https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke"
+ },
+ {
+ "source_name": "kujawa",
+ "description": "A. Kujawa, \"You dirty RAT! Part 1: DarkComet,\" Malwarebytes Labs, blog, Jun. 9, 2012 [Online].",
+ "url": "https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/"
+ },
+ {
+ "source_name": "roccia-shamoon",
+ "description": "R. Roccia, \"Shamoon Attackers Employ New Tool Kit to Wipe Infected Systems,\" McAfee, blog, Dec. 19, 2018 [Online].",
+ "url": "https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-attackers-employ-new-tool-kit-to-wipe-infected-systems/"
+ },
+ {
+ "source_name": "levene-cozycar",
+ "description": "B. Levene, R. Falcone, and R. Wartell, \"Tracking MiniDionis: CozyCar's New Ride Is Related to Seaduke,\" Unit 42 by Palo Alto Networks, Jul 14, 2015 [Online].",
+ "url": "https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke"
+ },
+ {
+ "source_name": "sonicwall",
+ "description": "\"Revisiting Vobfus Worm,\" SonicWALL, Mar. 8, 2013 [Online].",
+ "url": "https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/"
+ },
+ {
+ "source_name": "cisa-ar21-039b",
+ "description": "\"MAR-10320115-1.v1 - TEARDROP,\" CISA, Cybersecurity Advisories, Alert Code AR21-039B, Apr. 15, 2021 [Online].",
+ "url": "https://www.cisa.gov/uscert/ncas/analysis-reports/ar21-039b"
+ },
+ {
+ "source_name": "dong-matanbuchus",
+ "description": "C. Dong, \"MATANBUCHUS: Another Loader as a Service Malware,\" Offset Training Solutions, blog, Feb. 15, 2022 [Online].",
+ "url": "https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/"
+ },
+ {
+ "source_name": "cohen-matabuchus",
+ "description": "B. Cohen, \"Inside Matanbuchus: A Quirky Loader,\" CyberArk, blog, Jul. 26, 2022 [Online].",
+ "url": "https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader"
+ },
+ {
+ "source_name": "hromcov\u00e1",
+ "description": "Z. Hromcov\u00e1, \"Malicious campaign targets South Korean users with backdoor\u2011laced torrents,\" We Live Security, ESET, Jul. 8, 2019 [Online].",
+ "url": "https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/"
+ },
+ {
+ "source_name": "mendrez",
+ "description": "R. Mendrez, \"Gamut Spambot Analysis,\" Trustwave, blog, Mar. 4, 2014 [Online].",
+ "url": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/"
+ },
+ {
+ "source_name": "citizen lab",
+ "description": "M. Brooks, J. Dalek, and M. Crete-Nishihata, \"Between Hong Kong and Burma: Tracking UP007 and SLServer Espionage Campaigns,\" The Citizen Lab, Apr. 18, 2016 [Online].",
+ "url": "https://docs.microsoft.com/en-us/windows/win32/winmsg/about-hooks?redirectedfrom=MSDN#hook-procedures"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--7cb5847c-f662-4260-bd44-857ffd4975da",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-08-14T00:00:00.000Z",
+ "modified": "2023-12-05T00:00:00.000Z",
+ "name": "Create File",
+ "obj_defn": {
+ "description": "Malware creates a file.",
+ "external_id": "C0016",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/micro-behaviors/file-system/create-file.md"
+ },
+ "objective_refs": [
+ "malware-objective--b535116e-3bd9-42f6-9615-68f24c7b42ed"
+ ],
+ "obj_version": "2.1",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--a28f7a00-c512-4a1e-88a9-9eeeca8a162a",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-08-14T00:00:00.000Z",
+ "modified": "2024-04-29T00:00:00.000Z",
+ "name": "DNS Communication",
+ "obj_defn": {
+ "description": "The DNS Communication micro-behavior focuses on DNS communication.",
+ "external_id": "C0011",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/micro-behaviors/communication/dns-communication.md"
+ },
+ "objective_refs": [
+ "malware-objective--5823a1fb-61cd-4484-abfc-adfa88cca816"
+ ],
+ "detection_rules": [
+ {
+ "detect_ref": "malware-method--8d2f6d63-16d3-4b1e-9a5c-2ea3cede8a96",
+ "rule_name": "reference DNS over HTTPS endpoints",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/dns/reference-dns-over-https-endpoints.yml"
+ },
+ {
+ "api_fncs": [
+ "ws2_32.gethostbyname",
+ "DnsQuery_A",
+ "DnsQuery_W",
+ "DnsQuery_UTF8",
+ "DnsQueryEx",
+ "GetAddrInfo",
+ "GetAddrInfoW",
+ "GetAddrInfoEx",
+ "gethostbyname",
+ "getaddrinfo",
+ "getnameinfo",
+ "gethostent",
+ "System.Net.Dns::GetHostAddresses"
+ ],
+ "detect_ref": "malware-method--40cb93ee-9bab-4239-a0de-0556ad4cd999",
+ "rule_type": "capa",
+ "rule_name": "resolve DNS",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/dns/resolve-dns.yml"
+ },
+ {
+ "class": "NetworkDNSBlockChain",
+ "rule_name": "network_dns_blockchain",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/network_dns_suspicious.py"
+ },
+ {
+ "api_fncs": [
+ "DnsQueryA"
+ ],
+ "rule_name": "network_dns_idn",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/network_dns_suspicious.py"
+ },
+ {
+ "rule_name": "network_dns_opennic",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/network_dns_suspicious.py"
+ },
+ {
+ "rule_name": "network_dns_reverse_proxy",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/network_dns_suspicious.py"
+ },
+ {
+ "api_fncs": [
+ "DnsQueryA"
+ ],
+ "rule_name": "network_dns_suspicious_querytype",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/network_dns_suspicious.py"
+ },
+ {
+ "api_fncs": [
+ "DnsQuery_A",
+ "DnsQuery_W"
+ ],
+ "rule_name": "network_dns_tunneling_request",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/network_dns_suspicious.py"
+ },
+ {
+ "rule_name": "network_dns_doh_tls",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/network_dns_suspicious.py"
+ },
+ {
+ "api_fncs": [
+ " --"
+ ],
+ "rule_name": "network_dga",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/network_dga.py"
+ }
+ ],
+ "obj_version": "2.2",
+ "external_references": [
+ {
+ "source_name": "capa analysis",
+ "description": "Analysis output, capa 4.0, analyzed at MITRE on Oct. 12, 2022.",
+ "url": "https://github.com/mandiant/capa-rules"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--c889b142-22b2-4e82-9412-cf5528523f56",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-08-14T00:00:00.000Z",
+ "modified": "2024-04-30T00:00:00.000Z",
+ "name": "HTTP Communication",
+ "obj_defn": {
+ "description": "This micro-behavior is related to HTTP communication. \n\nInstead of being listed alphabetically, methods have been grouped to better faciliate labeling and mapping.",
+ "external_id": "C0002",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/micro-behaviors/communication/http-communication.md"
+ },
+ "objective_refs": [
+ "malware-objective--5823a1fb-61cd-4484-abfc-adfa88cca816"
+ ],
+ "detection_rules": [
+ {
+ "api_fncs": [
+ "winhttp.WinHttpQueryHeaders"
+ ],
+ "detect_ref": "malware-method--f497cb57-7379-4ee2-a82d-72f6af86428a",
+ "rule_type": "capa",
+ "rule_name": "read HTTP header",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/read-http-header.yml"
+ },
+ {
+ "api_fncs": [
+ "winhttp.WinHttpOpen"
+ ],
+ "detect_ref": "malware-method--d7c2b07a-e9e6-462f-a3c0-fd7db1bb2e4c",
+ "rule_type": "capa",
+ "rule_name": "initialize WinHTTP library",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/initialize-winhttp-library.yml"
+ },
+ {
+ "api_fncs": [
+ "ole32.CoCreateInstance"
+ ],
+ "detect_ref": "malware-method--bf8e63c7-87a3-4653-a12e-5435d862ca09",
+ "rule_type": "capa",
+ "rule_name": "initialize IWebBrowser2",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/initialize-iwebbrowser2.yml"
+ },
+ {
+ "api_fncs": [
+ "wininet.HttpQueryInfo"
+ ],
+ "rule_name": "get HTTP content length",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/get-http-content-length.yml"
+ },
+ {
+ "api_fncs": [
+ "winhttp.WinHttpAddRequestHeaders",
+ "System.Net.WebHeaderCollection::Add"
+ ],
+ "detect_ref": "malware-method--b64291e4-c45a-4453-b913-65dba7268a1a",
+ "rule_type": "capa",
+ "rule_name": "set HTTP header",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/set-http-header.yml"
+ },
+ {
+ "api_fncs": [
+ "urlmon.ObtainUserAgentString"
+ ],
+ "rule_name": "reference HTTP User-Agent string",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/reference-http-user-agent-string.yml"
+ },
+ {
+ "api_fncs": [
+ "httpapi.HttpInitialize",
+ "httpapi.HttpTerminate",
+ "System.Net.HttpListener::Start"
+ ],
+ "detect_ref": "malware-method--1a300b38-c1ee-499b-9407-d5dbb6b34f8c",
+ "rule_type": "capa",
+ "rule_name": "start HTTP server",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/server/start-http-server.yml"
+ },
+ {
+ "api_fncs": [
+ "httpapi.HttpReceiveHttpRequest",
+ "httpapi.HttpReceiveRequestEntityBody"
+ ],
+ "detect_ref": "malware-method--350f8e7d-a2c1-435f-a0bd-03160cc222ff",
+ "rule_type": "capa",
+ "rule_name": "receive HTTP request",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/server/receive-http-request.yml"
+ },
+ {
+ "api_fncs": [
+ "httpapi.HttpSendHttpResponse",
+ "httpapi.HttpSendResponseEntityBody"
+ ],
+ "detect_ref": "malware-method--d64110a6-b465-472d-b0c7-fa3202c60a9d",
+ "rule_type": "capa",
+ "rule_name": "send HTTP response",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/server/send-http-response.yml"
+ },
+ {
+ "api_fncs": [
+ "System.Net.WebRequest::GetResponse",
+ "winhttp.WinHttpReceiveResponse",
+ "winhttp.WinHttpReadData",
+ "winhttp.WinHttpQueryDataAvailable"
+ ],
+ "detect_ref": "malware-method--f99e6728-13ac-4d81-9566-6d800737c68b",
+ "rule_type": "capa",
+ "rule_name": "receive HTTP response",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/receive-http-response.yml"
+ },
+ {
+ "api_fncs": [
+ "System.Net.WebRequest::GetResponse",
+ "System.Net.WebRequest::GetResponseAsync",
+ "wininet.HttpOpenRequest",
+ "wininet.InternetConnect",
+ "wininet.HttpSendRequest",
+ "wininet.HttpSendRequestEx",
+ "winhttp.WinHttpSendRequest",
+ "winhttp.WinHttpWriteData",
+ "winhttp.WinHttpOpenRequest",
+ "winhttp.WinHttpConnect"
+ ],
+ "detect_ref": "malware-method--c291cee5-5ea7-468a-8974-dc2624e7cbae",
+ "rule_type": "capa",
+ "rule_name": "send HTTP request",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/send-http-request.yml"
+ },
+ {
+ "api_fncs": [
+ "wininet.InternetReadFile",
+ "wininet.InternetReadFileEx",
+ "System.Net.WebClient::DownloadString",
+ "System.Net.WebClient::DownloadStringAsync",
+ "System.Net.WebClient::DownloadStringTaskAsync",
+ "System.Net.WebClient::DownloadData",
+ "System.Net.WebClient::DownloadDataAsync",
+ "System.Net.WebClient::DownloadDataTaskAsync"
+ ],
+ "detect_ref": "malware-method--f99e6728-13ac-4d81-9566-6d800737c68b",
+ "rule_type": "capa",
+ "rule_name": "read data from Internet",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/read-data-from-internet.yml"
+ },
+ {
+ "api_fncs": [
+ "oleaut32.SysAllocString",
+ "oleaut32.VariantInit"
+ ],
+ "detect_ref": "malware-method--f99e6728-13ac-4d81-9566-6d800737c68b",
+ "rule_type": "capa",
+ "rule_name": "get HTTP document via IWebBrowser2",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/get-http-document-via-iwebbrowser2.yml"
+ },
+ {
+ "api_fncs": [
+ "oleaut32.SysAllocString",
+ "oleaut32.VariantInit"
+ ],
+ "detect_ref": "malware-method--bf8e63c7-87a3-4653-a12e-5435d862ca09",
+ "rule_type": "capa",
+ "rule_name": "get HTTP document via IWebBrowser2",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/get-http-document-via-iwebbrowser2.yml"
+ },
+ {
+ "api_fncs": [
+ "urlmon.URLDownloadToFile",
+ "urlmon.URLDownloadToCacheFile",
+ "urlmon.URLOpenBlockingStream",
+ "urlmon.URLOpenPullStream",
+ "urlmon.URLOpenStream",
+ "System.Net.WebClient::DownloadFile",
+ "System.Net.WebClient::DownloadFileAsync",
+ "System.Net.WebClient::DownloadFileTaskAsync",
+ "Microsoft.VisualBasic.Devices.Network::DownloadFile"
+ ],
+ "detect_ref": "malware-method--addcbbea-4e82-4816-a138-0b19ddacd043",
+ "rule_type": "capa",
+ "rule_name": "download URL",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/download-url.yml"
+ },
+ {
+ "api_fncs": [
+ "winhttp.WinHttpOpenRequest"
+ ],
+ "detect_ref": "malware-method--d80c5d48-e802-4732-b48a-c71b84f4703a",
+ "rule_type": "capa",
+ "rule_name": "prepare HTTP request",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/prepare-http-request.yml"
+ },
+ {
+ "api_fncs": [
+ "wininet.InternetOpen",
+ "System.Net.WebRequest::Create",
+ "System.Net.WebRequest::CreateDefault",
+ "System.Net.WebRequest::CreateHttp",
+ "wininet.InternetCloseHandle"
+ ],
+ "detect_ref": "malware-method--d80c5d48-e802-4732-b48a-c71b84f4703a",
+ "rule_type": "capa",
+ "rule_name": "create HTTP request",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/create-http-request.yml"
+ },
+ {
+ "api_fncs": [
+ "wininet.InternetWriteFile"
+ ],
+ "detect_ref": "malware-method--9d13adf5-2774-4ea2-bbb1-ba8e8e3ca7ea",
+ "rule_type": "capa",
+ "rule_name": "send file via HTTP",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/send-file-via-http.yml"
+ },
+ {
+ "rule_name": "decompress HTTP response via IEncodingFilterFactory",
+ "detect_ref": "malware-method--f99e6728-13ac-4d81-9566-6d800737c68b",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/decompress-http-response-via-iencodingfilterfactory.yml"
+ },
+ {
+ "api_fncs": [
+ "atoi",
+ "wininet.HttpQueryInfo"
+ ],
+ "detect_ref": "malware-method--f497cb57-7379-4ee2-a82d-72f6af86428a",
+ "rule_type": "capa",
+ "rule_name": "check HTTP status code",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/check-http-status-code.yml"
+ },
+ {
+ "api_fncs": [
+ "wininet.HttpQueryInfo"
+ ],
+ "detect_ref": "malware-method--f99e6728-13ac-4d81-9566-6d800737c68b",
+ "rule_type": "capa",
+ "rule_name": "get HTTP response content encoding",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/get-http-response-content-encoding.yml"
+ },
+ {
+ "api_fncs": [
+ "wininet.InternetOpenUrl"
+ ],
+ "detect_ref": "malware-method--7d0ddef2-0802-48db-8a42-73b356ed083a",
+ "rule_type": "capa",
+ "rule_name": "connect to URL",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/connect-to-url.yml"
+ },
+ {
+ "api_fncs": [
+ "wininet.InternetConnect"
+ ],
+ "detect_ref": "malware-method--57c1f0f9-f551-4be2-857e-a9f168999eb1",
+ "rule_type": "capa",
+ "rule_name": "connect to HTTP server",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/connect-to-http-server.yml"
+ },
+ {
+ "detect_ref": "malware-method--7f1b234a-9409-4a3a-9f4c-03e21d04770a",
+ "rule_name": "extract HTTP body",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/communication/http/client/extract-http-body.yml"
+ },
+ {
+ "api_fncs": [
+ "HttpOpenRequestA",
+ "InternetConnectA",
+ "HttpOpenRequestW",
+ "InternetConnectW"
+ ],
+ "class": "Internet_Dropper",
+ "rule_name": "internet_dropper",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/internet_dropper.py"
+ },
+ {
+ "rule_name": "bot_madness",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/bot_madness.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "bot_madness",
+ "detect_ref": "malware-method--c291cee5-5ea7-468a-8974-dc2624e7cbae",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/bot_madness.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "bot_drive",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/bot_drive.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "bot_drive",
+ "detect_ref": "malware-method--9d13adf5-2774-4ea2-bbb1-ba8e8e3ca7ea",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/bot_drive.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "network_cnc_http",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/network_cnc_http.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "HttpOpenRequestA",
+ "HttpSendRequestA"
+ ],
+ "rule_name": "recon_beacon",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/recon_beacon.py"
+ },
+ {
+ "rule_name": "network_http",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/network_http.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "WinHttpConnect",
+ "WinHttpOpenRequest"
+ ],
+ "rule_name": "explorer_http",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/network_explorer.py"
+ },
+ {
+ "rule_name": "bot_drive2",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/bot_drive2.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "bot_drive2",
+ "detect_ref": "malware-method--9d13adf5-2774-4ea2-bbb1-ba8e8e3ca7ea",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/bot_drive2.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "bot_dirtjumper",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/bot_dirtjumper.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "bot_dirtjumper",
+ "detect_ref": "malware-method--9d13adf5-2774-4ea2-bbb1-ba8e8e3ca7ea",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/bot_dirtjumper.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "bot_athenahttp",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/bot_athenahttp.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "WinHttpOpenRequest",
+ "HttpOpenRequestW"
+ ],
+ "rule_name": "koadic_network_activity",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/exploitation_framework_koadic.py"
+ },
+ {
+ "api_fncs": [
+ "HttpOpenRequestA",
+ "HttpOpenRequestW",
+ "InternetConnectW",
+ "InternetOpenUrlA",
+ "InternetConnectA",
+ "InternetOpenUrlW",
+ "WinHttpGetProxyForUrl"
+ ],
+ "rule_name": "http_request",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/http_request.py"
+ },
+ {
+ "rule_name": "cmdline_http_link",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/cmdline_anomaly.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "cmdline_reversed_http_link",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/cmdline_anomaly.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "InternetCrackUrlW",
+ "InternetCrackUrlA",
+ "URLDownloadToFileW",
+ "HttpOpenRequestW",
+ "InternetReadFile",
+ "WSASend"
+ ],
+ "rule_name": "network_docfile_http",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/network_docfile_http.py"
+ },
+ {
+ "rule_name": "banker_zeus_url",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/all/banker_zeus_url.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "InternetOpenUrlA",
+ "WinHttpOpenRequest"
+ ],
+ "rule_name": "downloads_from_filehosting",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/filehostings.py"
+ },
+ {
+ "api_fncs": [
+ "InternetOpenW",
+ "HttpAddRequestHeadersA",
+ "HttpSendRequestW",
+ "HttpOpenRequestW"
+ ],
+ "rule_name": "purplewave_network_activity",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/infostealer_purplewave.py"
+ }
+ ],
+ "obj_version": "2.2",
+ "external_references": [
+ {
+ "source_name": "capa analysis",
+ "description": "Analysis output, capa 4.0, analyzed at MITRE on Oct. 12, 2022.",
+ "url": "https://github.com/mandiant/capa-rules"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--005a06c6-14bf-4118-afa0-ebcd8aebb0c9",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2019-11-27T14:58:00.429Z",
+ "modified": "2024-10-13T16:13:47.770Z",
+ "name": "Scheduled Task",
+ "description": "Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The [schtasks](https://attack.mitre.org/software/S0111) utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel.(Citation: Stack Overflow) In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.(Citation: Red Canary - Atomic Red Team)\n\nAn adversary may use Windows Task Scheduler to execute programs at system startup or on a scheduled basis for persistence. The Windows Task Scheduler can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM). Similar to [System Binary Proxy Execution](https://attack.mitre.org/techniques/T1218), adversaries have also abused the Windows Task Scheduler to potentially mask one-time execution under signed/trusted system processes.(Citation: ProofPoint Serpent)\n\nAdversaries may also create \"hidden\" scheduled tasks (i.e. [Hide Artifacts](https://attack.mitre.org/techniques/T1564)) that may not be visible to defender tools and manual queries used to enumerate tasks. Specifically, an adversary may hide a task from `schtasks /query` and the Task Scheduler by deleting the associated Security Descriptor (SD) registry value (where deletion of this value must be completed using SYSTEM permissions).(Citation: SigmaHQ)(Citation: Tarrask scheduled task) Adversaries may also employ alternate methods to hide tasks, such as altering the metadata (e.g., `Index` value) within associated registry keys.(Citation: Defending Against Scheduled Task Attacks in Windows Environments) ",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "execution"
+ },
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "persistence"
+ },
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "privilege-escalation"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1053/005",
+ "external_id": "T1053.005"
+ },
+ {
+ "source_name": "ProofPoint Serpent",
+ "description": "Campbell, B. et al. (2022, March 21). Serpent, No Swiping! New Backdoor Targets French Entities with Unique Attack Chain. Retrieved April 11, 2022.",
+ "url": "https://www.proofpoint.com/us/blog/threat-insight/serpent-no-swiping-new-backdoor-targets-french-entities-unique-attack-chain"
+ },
+ {
+ "source_name": "Defending Against Scheduled Task Attacks in Windows Environments",
+ "description": "Harshal Tupsamudre. (2022, June 20). Defending Against Scheduled Tasks. Retrieved July 5, 2022.",
+ "url": "https://blog.qualys.com/vulnerabilities-threat-research/2022/06/20/defending-against-scheduled-task-attacks-in-windows-environments"
+ },
+ {
+ "source_name": "Twitter Leoloobeek Scheduled Task",
+ "description": "Loobeek, L. (2017, December 8). leoloobeek Status. Retrieved September 12, 2024.",
+ "url": "https://x.com/leoloobeek/status/939248813465853953"
+ },
+ {
+ "source_name": "Tarrask scheduled task",
+ "description": "Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022.",
+ "url": "https://www.microsoft.com/security/blog/2022/04/12/tarrask-malware-uses-scheduled-tasks-for-defense-evasion/"
+ },
+ {
+ "source_name": "Microsoft Scheduled Task Events Win10",
+ "description": "Microsoft. (2017, May 28). Audit Other Object Access Events. Retrieved June 27, 2019.",
+ "url": "https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-other-object-access-events"
+ },
+ {
+ "source_name": "TechNet Scheduled Task Events",
+ "description": "Microsoft. (n.d.). General Task Registration. Retrieved December 12, 2017.",
+ "url": "https://technet.microsoft.com/library/dd315590.aspx"
+ },
+ {
+ "source_name": "Red Canary - Atomic Red Team",
+ "description": "Red Canary - Atomic Red Team. (n.d.). T1053.005 - Scheduled Task/Job: Scheduled Task. Retrieved June 19, 2024.",
+ "url": "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1053.005/T1053.005.md"
+ },
+ {
+ "source_name": "TechNet Autoruns",
+ "description": "Russinovich, M. (2016, January 4). Autoruns for Windows v13.51. Retrieved June 6, 2016.",
+ "url": "https://technet.microsoft.com/en-us/sysinternals/bb963902"
+ },
+ {
+ "source_name": "TechNet Forum Scheduled Task Operational Setting",
+ "description": "Satyajit321. (2015, November 3). Scheduled Tasks History Retention settings. Retrieved December 12, 2017.",
+ "url": "https://social.technet.microsoft.com/Forums/en-US/e5bca729-52e7-4fcb-ba12-3225c564674c/scheduled-tasks-history-retention-settings?forum=winserver8gen"
+ },
+ {
+ "source_name": "SigmaHQ",
+ "description": "Sittikorn S. (2022, April 15). Removal Of SD Value to Hide Schedule Task - Registry. Retrieved June 1, 2022.",
+ "url": "https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_delete/registry_delete_schtasks_hide_task_via_sd_value_removal.yml"
+ },
+ {
+ "source_name": "Stack Overflow",
+ "description": "Stack Overflow. (n.d.). How to find the location of the Scheduled Tasks folder. Retrieved June 19, 2024.",
+ "url": "https://stackoverflow.com/questions/2913816/how-to-find-the-location-of-the-scheduled-tasks-folder"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_attack_spec_version": "3.2.0",
+ "x_mitre_contributors": [
+ "Andrew Northern, @ex_raritas",
+ "Bryan Campbell, @bry_campbell",
+ "Zachary Abzug, @ZackDoesML",
+ "Selena Larson, @selenalarson",
+ "Sittikorn Sangrattanapitak"
+ ],
+ "x_mitre_data_sources": [
+ "Windows Registry: Windows Registry Key Creation",
+ "File: File Modification",
+ "File: File Creation",
+ "Process: Process Creation",
+ "Command: Command Execution",
+ "Network Traffic: Network Traffic Flow",
+ "Scheduled Job: Scheduled Job Creation"
+ ],
+ "x_mitre_deprecated": false,
+ "x_mitre_detection": "Monitor process execution from the svchost.exe in Windows 10 and the Windows Task Scheduler taskeng.exe for older versions of Windows. (Citation: Twitter Leoloobeek Scheduled Task) If scheduled tasks are not used for persistence, then the adversary is likely to remove the task when the action is complete. Monitor Windows Task Scheduler stores in %systemroot%\\System32\\Tasks for change entries related to scheduled tasks that do not correlate with known software, patch cycles, etc.\n\nConfigure event logging for scheduled task creation and changes by enabling the \"Microsoft-Windows-TaskScheduler/Operational\" setting within the event logging service. (Citation: TechNet Forum Scheduled Task Operational Setting) Several events will then be logged on scheduled task activity, including: (Citation: TechNet Scheduled Task Events)(Citation: Microsoft Scheduled Task Events Win10)\n\n* Event ID 106 on Windows 7, Server 2008 R2 - Scheduled task registered\n* Event ID 140 on Windows 7, Server 2008 R2 / 4702 on Windows 10, Server 2016 - Scheduled task updated\n* Event ID 141 on Windows 7, Server 2008 R2 / 4699 on Windows 10, Server 2016 - Scheduled task deleted\n* Event ID 4698 on Windows 10, Server 2016 - Scheduled task created\n* Event ID 4700 on Windows 10, Server 2016 - Scheduled task enabled\n* Event ID 4701 on Windows 10, Server 2016 - Scheduled task disabled\n\nTools such as Sysinternals Autoruns may also be used to detect system changes that could be attempts at persistence, including listing current scheduled tasks. (Citation: TechNet Autoruns)\n\nRemote access tools with built-in features may interact directly with the Windows API to perform these functions outside of typical system utilities. Tasks may also be created through Windows system management tools such as Windows Management Instrumentation and PowerShell, so additional logging may need to be configured to gather the appropriate data.",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": true,
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_permissions_required": [
+ "Administrator"
+ ],
+ "x_mitre_platforms": [
+ "Windows"
+ ],
+ "x_mitre_remote_support": true,
+ "x_mitre_version": "1.6"
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--01a5a209-b94c-450b-b7f9-946497d91055",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2017-05-31T21:30:44.329Z",
+ "modified": "2024-10-15T15:20:57.328Z",
+ "name": "Windows Management Instrumentation",
+ "description": "Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems.(Citation: WMI 1-3) WMI is an administration feature that provides a uniform environment to access Windows system components.\n\nThe WMI service enables both local and remote access, though the latter is facilitated by [Remote Services](https://attack.mitre.org/techniques/T1021) such as [Distributed Component Object Model](https://attack.mitre.org/techniques/T1021/003) and [Windows Remote Management](https://attack.mitre.org/techniques/T1021/006).(Citation: WMI 1-3) Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.(Citation: WMI 1-3) (Citation: Mandiant WMI)\n\nAn adversary can use WMI to interact with local and remote systems and use it as a means to execute various behaviors, such as gathering information for [Discovery](https://attack.mitre.org/tactics/TA0007) as well as [Execution](https://attack.mitre.org/tactics/TA0002) of commands and payloads.(Citation: Mandiant WMI) For example, `wmic.exe` can be abused by an adversary to delete shadow copies with the command `wmic.exe Shadowcopy Delete` (i.e., [Inhibit System Recovery](https://attack.mitre.org/techniques/T1490)).(Citation: WMI 6)\n\n**Note:** `wmic.exe` is deprecated as of January of 2024, with the WMIC feature being \u201cdisabled by default\u201d on Windows 11+. WMIC will be removed from subsequent Windows releases and replaced by [PowerShell](https://attack.mitre.org/techniques/T1059/001) as the primary WMI interface.(Citation: WMI 7,8) In addition to PowerShell and tools like `wbemtool.exe`, COM APIs can also be used to programmatically interact with WMI via C++, .NET, VBScript, etc.(Citation: WMI 7,8)",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "execution"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1047",
+ "external_id": "T1047"
+ },
+ {
+ "source_name": "FireEye WMI 2015",
+ "description": "Ballenthin, W., et al. (2015). Windows Management Instrumentation (WMI) Offense, Defense, and Forensics. Retrieved March 30, 2016.",
+ "url": "https://www.fireeye.com/content/dam/fireeye-www/global/en/current-threats/pdfs/wp-windows-management-instrumentation.pdf"
+ },
+ {
+ "source_name": "Mandiant WMI",
+ "description": "Mandiant. (n.d.). Retrieved February 13, 2024.",
+ "url": "https://www.mandiant.com/resources/reports"
+ },
+ {
+ "source_name": "WMI 6",
+ "description": "Microsoft. (2022, June 13). BlackCat. Retrieved February 13, 2024.",
+ "url": "https://www.microsoft.com/en-us/security/blog/2022/06/13/the-many-lives-of-blackcat-ransomware/"
+ },
+ {
+ "source_name": "WMI 1-3",
+ "description": "Microsoft. (2023, March 7). Retrieved February 13, 2024.",
+ "url": "https://learn.microsoft.com/en-us/windows/win32/wmisdk/wmi-start-page?redirectedfrom=MSDN"
+ },
+ {
+ "source_name": "WMI 7,8",
+ "description": "Microsoft. (2024, January 26). WMIC Deprecation. Retrieved February 13, 2024.",
+ "url": "https://techcommunity.microsoft.com/t5/windows-it-pro-blog/wmi-command-line-wmic-utility-deprecation-next-steps/ba-p/4039242"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_attack_spec_version": "3.2.0",
+ "x_mitre_contributors": [
+ "@ionstorm",
+ "Olaf Hartong, Falcon Force",
+ "Tristan Madani"
+ ],
+ "x_mitre_data_sources": [
+ "Network Traffic: Network Connection Creation",
+ "Process: Process Creation",
+ "WMI: WMI Creation",
+ "Command: Command Execution"
+ ],
+ "x_mitre_deprecated": false,
+ "x_mitre_detection": "Monitor network traffic for WMI connections; the use of WMI in environments that do not typically use WMI may be suspect. Perform process monitoring to capture command-line arguments of \"wmic\" and detect commands that are used to perform remote behavior. (Citation: FireEye WMI 2015)",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": false,
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_platforms": [
+ "Windows"
+ ],
+ "x_mitre_remote_support": true,
+ "x_mitre_version": "1.5"
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--045d0922-2310-4e60-b5e4-3302302cb3c5",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2020-01-23T18:03:46.248Z",
+ "modified": "2024-10-14T13:14:43.083Z",
+ "name": "Rundll32",
+ "description": "Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. [Shared Modules](https://attack.mitre.org/techniques/T1129)), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing DLL payloads (ex: rundll32.exe {DLLname, DLLfunction}).\n\nRundll32.exe can also be used to execute [Control Panel](https://attack.mitre.org/techniques/T1218/002) Item files (.cpl) through the undocumented shell32.dll functions Control_RunDLL and Control_RunDLLAsUser. Double-clicking a .cpl file also causes rundll32.exe to execute.(Citation: Trend Micro CPL) For example, [ClickOnce](https://attack.mitre.org/techniques/T1127/002) can be proxied through Rundll32.exe.\n\nRundll32 can also be used to execute scripts such as JavaScript. This can be done using a syntax similar to this: rundll32.exe javascript:\"\\..\\mshtml,RunHTMLApplication \";document.write();GetObject(\"script:https[:]//www[.]example[.]com/malicious.sct\")\" This behavior has been seen used by malware such as Poweliks. (Citation: This is Security Command Line Confusion)\n\nAdversaries may also attempt to obscure malicious code from analysis by abusing the manner in which rundll32.exe loads DLL function names. As part of Windows compatibility support for various character sets, rundll32.exe will first check for wide/Unicode then ANSI character-supported functions before loading the specified function (e.g., given the command rundll32.exe ExampleDLL.dll, ExampleFunction, rundll32.exe would first attempt to execute ExampleFunctionW, or failing that ExampleFunctionA, before loading ExampleFunction). Adversaries may therefore obscure malicious code by creating multiple identical exported function names and appending W and/or A to harmless ones.(Citation: Attackify Rundll32.exe Obscurity)(Citation: Github NoRunDll) DLL functions can also be exported and executed by an ordinal number (ex: rundll32.exe file.dll,#1).\n\nAdditionally, adversaries may use [Masquerading](https://attack.mitre.org/techniques/T1036) techniques (such as changing DLL file names, file extensions, or function names) to further conceal execution of a malicious payload.(Citation: rundll32.exe defense evasion) ",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "defense-evasion"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1218/011",
+ "external_id": "T1218.011"
+ },
+ {
+ "source_name": "rundll32.exe defense evasion",
+ "description": "Ariel silver. (2022, February 1). Defense Evasion Techniques. Retrieved April 8, 2022.",
+ "url": "https://www.cynet.com/attack-techniques-hands-on/defense-evasion-techniques/"
+ },
+ {
+ "source_name": "Attackify Rundll32.exe Obscurity",
+ "description": "Attackify. (n.d.). Rundll32.exe Obscurity. Retrieved August 23, 2021.",
+ "url": "https://www.attackify.com/blog/rundll32_execution_order/"
+ },
+ {
+ "source_name": "This is Security Command Line Confusion",
+ "description": "B. Ancel. (2014, August 20). Poweliks \u2013 Command Line Confusion. Retrieved March 5, 2018.",
+ "url": "https://www.stormshield.com/news/poweliks-command-line-confusion/"
+ },
+ {
+ "source_name": "Github NoRunDll",
+ "description": "gtworek. (2019, December 17). NoRunDll. Retrieved August 23, 2021.",
+ "url": "https://github.com/gtworek/PSBits/tree/master/NoRunDll"
+ },
+ {
+ "source_name": "Trend Micro CPL",
+ "description": "Merces, F. (2014). CPL Malware Malicious Control Panel Items. Retrieved November 1, 2017.",
+ "url": "https://www.trendmicro.de/cloud-content/us/pdfs/security-intelligence/white-papers/wp-cpl-malware.pdf"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_attack_spec_version": "3.2.0",
+ "x_mitre_contributors": [
+ "Gareth Phillips, Seek Ltd.",
+ "Casey Smith",
+ "Ricardo Dias",
+ "James_inthe_box, Me"
+ ],
+ "x_mitre_data_sources": [
+ "Process: Process Creation",
+ "Command: Command Execution",
+ "File: File Metadata",
+ "Module: Module Load"
+ ],
+ "x_mitre_defense_bypassed": [
+ "Digital Certificate Validation",
+ "Application control",
+ "Anti-virus"
+ ],
+ "x_mitre_deprecated": false,
+ "x_mitre_detection": "Use process monitoring to monitor the execution and arguments of rundll32.exe. Compare recent invocations of rundll32.exe with prior history of known good arguments and loaded DLLs to determine anomalous and potentially adversarial activity.\n\nCommand arguments used with the rundll32.exe invocation may also be useful in determining the origin and purpose of the DLL being loaded. Analyzing DLL exports and comparing to runtime arguments may be useful in uncovering obfuscated function calls.",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": true,
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_platforms": [
+ "Windows"
+ ],
+ "x_mitre_version": "2.3"
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--232b7f21-adf9-4b42-b936-b9d6f7df856e",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2020-03-11T14:49:36.954Z",
+ "modified": "2024-09-25T20:50:34.876Z",
+ "name": "Malicious File",
+ "description": "An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will lead to code execution. This user action will typically be observed as follow-on behavior from [Spearphishing Attachment](https://attack.mitre.org/techniques/T1566/001). Adversaries may use several types of files that require a user to execute them, including .doc, .pdf, .xls, .rtf, .scr, .exe, .lnk, .pif, .cpl, and .reg.\n\nAdversaries may employ various forms of [Masquerading](https://attack.mitre.org/techniques/T1036) and [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to increase the likelihood that a user will open and successfully execute a malicious file. These methods may include using a familiar naming convention and/or password protecting the file and supplying instructions to a user on how to open it.(Citation: Password Protected Word Docs) \n\nWhile [Malicious File](https://attack.mitre.org/techniques/T1204/002) frequently occurs shortly after Initial Access it may occur at other phases of an intrusion, such as when an adversary places a file in a shared directory or on a user's desktop hoping that a user will click on it. This activity may also be seen shortly after [Internal Spearphishing](https://attack.mitre.org/techniques/T1534).",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "execution"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1204/002",
+ "external_id": "T1204.002"
+ },
+ {
+ "source_name": "Password Protected Word Docs",
+ "description": "Lawrence Abrams. (2017, July 12). PSA: Don't Open SPAM Containing Password Protected Word Docs. Retrieved January 5, 2022.",
+ "url": "https://www.bleepingcomputer.com/news/security/psa-dont-open-spam-containing-password-protected-word-docs/"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_attack_spec_version": "3.2.0",
+ "x_mitre_contributors": [
+ "TruKno"
+ ],
+ "x_mitre_data_sources": [
+ "Process: Process Creation",
+ "File: File Creation"
+ ],
+ "x_mitre_deprecated": false,
+ "x_mitre_detection": "Monitor the execution of and command-line arguments for applications that may be used by an adversary to gain initial access that require user interaction. This includes compression applications, such as those for zip files, that can be used to [Deobfuscate/Decode Files or Information](https://attack.mitre.org/techniques/T1140) in payloads.\n\nAnti-virus can potentially detect malicious documents and files that are downloaded and executed on the user's computer. Endpoint sensing or network sensing can potentially detect malicious events once the file is opened (such as a Microsoft Word document or PDF reaching out to the internet or spawning powershell.exe).",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": true,
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_platforms": [
+ "Linux",
+ "macOS",
+ "Windows"
+ ],
+ "x_mitre_remote_support": false,
+ "x_mitre_version": "1.4"
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--62b8c999-dcc0-4755-bd69-09442d9359f5",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2017-05-31T21:31:06.045Z",
+ "modified": "2020-01-31T19:01:41.919Z",
+ "name": "Rundll32",
+ "description": "The rundll32.exe program can be called to execute an arbitrary binary. Adversaries may take advantage of this functionality to proxy execution of code to avoid triggering security tools that may not monitor execution of the rundll32.exe process because of whitelists or false positives from Windows using rundll32.exe for normal operations.\n\nRundll32.exe can be used to execute Control Panel Item files (.cpl) through the undocumented shell32.dll functions Control_RunDLL and Control_RunDLLAsUser. Double-clicking a .cpl file also causes rundll32.exe to execute. (Citation: Trend Micro CPL)\n\nRundll32 can also been used to execute scripts such as JavaScript. This can be done using a syntax similar to this: rundll32.exe javascript:\"\\..\\mshtml,RunHTMLApplication \";document.write();GetObject(\"script:https[:]//www[.]example[.]com/malicious.sct\")\" This behavior has been seen used by malware such as Poweliks. (Citation: This is Security Command Line Confusion)",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "defense-evasion"
+ },
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "execution"
+ }
+ ],
+ "revoked": true,
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1085",
+ "external_id": "T1085"
+ },
+ {
+ "source_name": "Trend Micro CPL",
+ "description": "Merces, F. (2014). CPL Malware Malicious Control Panel Items. Retrieved November 1, 2017.",
+ "url": "https://www.trendmicro.de/cloud-content/us/pdfs/security-intelligence/white-papers/wp-cpl-malware.pdf"
+ },
+ {
+ "source_name": "This is Security Command Line Confusion",
+ "description": "B. Ancel. (2014, August 20). Poweliks \u2013 Command Line Confusion. Retrieved March 5, 2018.",
+ "url": "https://thisissecurity.stormshield.com/2014/08/20/poweliks-command-line-confusion/"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_contributors": [
+ "Ricardo Dias",
+ "Casey Smith"
+ ],
+ "x_mitre_defense_bypassed": [
+ "Anti-virus",
+ "Application whitelisting",
+ "Digital Certificate Validation"
+ ],
+ "x_mitre_detection": "Use process monitoring to monitor the execution and arguments of rundll32.exe. Compare recent invocations of rundll32.exe with prior history of known good arguments and loaded DLLs to determine anomalous and potentially adversarial activity. Command arguments used with the rundll32.exe invocation may also be useful in determining the origin and purpose of the DLL being loaded.",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": false,
+ "x_mitre_permissions_required": [
+ "User"
+ ],
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_version": "1.1",
+ "x_mitre_platforms": [
+ "Windows"
+ ]
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--72b74d71-8169-42aa-92e0-e7b04b9f5a08",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2017-05-31T21:31:06.988Z",
+ "modified": "2024-10-15T15:35:28.784Z",
+ "name": "Account Discovery",
+ "description": "Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment. This information can help adversaries determine which accounts exist, which can aid in follow-on behavior such as brute-forcing, spear-phishing attacks, or account takeovers (e.g., [Valid Accounts](https://attack.mitre.org/techniques/T1078)).\n\nAdversaries may use several methods to enumerate accounts, including abuse of existing tools, built-in commands, and potential misconfigurations that leak account names and roles or permissions in the targeted environment.\n\nFor examples, cloud environments typically provide easily accessible interfaces to obtain user lists.(Citation: AWS List Users)(Citation: Google Cloud - IAM Servie Accounts List API) On hosts, adversaries can use default [PowerShell](https://attack.mitre.org/techniques/T1059/001) and other command line functionality to identify accounts. Information about email addresses and accounts may also be extracted by searching an infected system\u2019s files.",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "discovery"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1087",
+ "external_id": "T1087"
+ },
+ {
+ "source_name": "AWS List Users",
+ "description": "Amazon. (n.d.). List Users. Retrieved August 11, 2020.",
+ "url": "https://docs.aws.amazon.com/cli/latest/reference/iam/list-users.html"
+ },
+ {
+ "source_name": "Google Cloud - IAM Servie Accounts List API",
+ "description": "Google. (2020, June 23). gcloud iam service-accounts list. Retrieved August 4, 2020.",
+ "url": "https://cloud.google.com/sdk/gcloud/reference/iam/service-accounts/list"
+ },
+ {
+ "source_name": "Elastic - Koadiac Detection with EQL",
+ "description": "Stepanic, D.. (2020, January 13). Embracing offensive tooling: Building detections against Koadic using EQL. Retrieved November 30, 2020.",
+ "url": "https://www.elastic.co/blog/embracing-offensive-tooling-building-detections-against-koadic-using-eql"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_attack_spec_version": "3.2.0",
+ "x_mitre_contributors": [
+ "Daniel Stepanic, Elastic",
+ "Microsoft Threat Intelligence Center (MSTIC)",
+ "Travis Smith, Tripwire"
+ ],
+ "x_mitre_data_sources": [
+ "Process: Process Creation",
+ "Command: Command Execution",
+ "File: File Access"
+ ],
+ "x_mitre_deprecated": false,
+ "x_mitre_detection": "System and network discovery techniques normally occur throughout an operation as an adversary learns the environment. Data and events should not be viewed in isolation, but as part of a chain of behavior that could lead to other activities, such as Lateral Movement, based on the information obtained.\n\nMonitor processes and command-line arguments for actions that could be taken to gather system and network information. Remote access tools with built-in features may interact directly with the Windows API to gather information. Information may also be acquired through Windows system management tools such as [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) and [PowerShell](https://attack.mitre.org/techniques/T1059/001).\n\nMonitor for processes that can be used to enumerate user accounts, such as net.exe and net1.exe, especially when executed in quick succession.(Citation: Elastic - Koadiac Detection with EQL)",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": false,
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_platforms": [
+ "Windows",
+ "SaaS",
+ "IaaS",
+ "Linux",
+ "macOS",
+ "Office Suite",
+ "Identity Provider"
+ ],
+ "x_mitre_version": "2.5"
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--767dbf9e-df3f-45cb-8998-4903ab5f80c0",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2019-02-14T16:15:05.974Z",
+ "modified": "2022-06-16T19:18:22.305Z",
+ "name": "Domain Trust Discovery",
+ "description": "Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts provide a mechanism for a domain to allow access to resources based on the authentication procedures of another domain.(Citation: Microsoft Trusts) Domain trusts allow the users of the trusted domain to access resources in the trusting domain. The information discovered may help the adversary conduct [SID-History Injection](https://attack.mitre.org/techniques/T1134/005), [Pass the Ticket](https://attack.mitre.org/techniques/T1550/003), and [Kerberoasting](https://attack.mitre.org/techniques/T1558/003).(Citation: AdSecurity Forging Trust Tickets)(Citation: Harmj0y Domain Trusts) Domain trusts can be enumerated using the `DSEnumerateDomainTrusts()` Win32 API call, .NET methods, and LDAP.(Citation: Harmj0y Domain Trusts) The Windows utility [Nltest](https://attack.mitre.org/software/S0359) is known to be used by adversaries to enumerate domain trusts.(Citation: Microsoft Operation Wilysupply)",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "discovery"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1482",
+ "external_id": "T1482"
+ },
+ {
+ "source_name": "Microsoft Operation Wilysupply",
+ "description": "Florio, E.. (2017, May 4). Windows Defender ATP thwarts Operation WilySupply software supply chain cyberattack. Retrieved February 14, 2019.",
+ "url": "https://www.microsoft.com/security/blog/2017/05/04/windows-defender-atp-thwarts-operation-wilysupply-software-supply-chain-cyberattack/"
+ },
+ {
+ "source_name": "AdSecurity Forging Trust Tickets",
+ "description": "Metcalf, S. (2015, July 15). It\u2019s All About Trust \u2013 Forging Kerberos Trust Tickets to Spoof Access across Active Directory Trusts. Retrieved February 14, 2019.",
+ "url": "https://adsecurity.org/?p=1588"
+ },
+ {
+ "source_name": "Microsoft Trusts",
+ "description": "Microsoft. (2009, October 7). Trust Technologies. Retrieved February 14, 2019.",
+ "url": "https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2003/cc759554(v=ws.10)"
+ },
+ {
+ "source_name": "Microsoft GetAllTrustRelationships",
+ "description": "Microsoft. (n.d.). Domain.GetAllTrustRelationships Method. Retrieved February 14, 2019.",
+ "url": "https://docs.microsoft.com/en-us/dotnet/api/system.directoryservices.activedirectory.domain.getalltrustrelationships?redirectedfrom=MSDN&view=netframework-4.7.2#System_DirectoryServices_ActiveDirectory_Domain_GetAllTrustRelationships"
+ },
+ {
+ "source_name": "Harmj0y Domain Trusts",
+ "description": "Schroeder, W. (2017, October 30). A Guide to Attacking Domain Trusts. Retrieved February 14, 2019.",
+ "url": "https://posts.specterops.io/a-guide-to-attacking-domain-trusts-971e52cb2944"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_attack_spec_version": "2.1.0",
+ "x_mitre_contributors": [
+ "Dave Westgard",
+ "Elia Florio, Microsoft",
+ "Mnemonic",
+ "RedHuntLabs, @redhuntlabs",
+ "ExtraHop"
+ ],
+ "x_mitre_data_sources": [
+ "Process: Process Creation",
+ "Command: Command Execution",
+ "Script: Script Execution",
+ "Network Traffic: Network Traffic Content",
+ "Process: OS API Execution"
+ ],
+ "x_mitre_deprecated": false,
+ "x_mitre_detection": "System and network discovery techniques normally occur throughout an operation as an adversary learns the environment. Data and events should not be viewed in isolation but as part of a chain of behavior that could lead to other activities based on the information obtained.\n\nMonitor processes and command-line arguments for actions that could be taken to gather system and network information, such as `nltest /domain_trusts`. Remote access tools with built-in features may interact directly with the Windows API to gather information. Look for the `DSEnumerateDomainTrusts()` Win32 API call to spot activity associated with [Domain Trust Discovery](https://attack.mitre.org/techniques/T1482).(Citation: Harmj0y Domain Trusts) Information may also be acquired through Windows system management tools such as [PowerShell](https://attack.mitre.org/techniques/T1059/001). The .NET method `GetAllTrustRelationships()` can be an indicator of [Domain Trust Discovery](https://attack.mitre.org/techniques/T1482).(Citation: Microsoft GetAllTrustRelationships)\n",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": false,
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_platforms": [
+ "Windows"
+ ],
+ "x_mitre_version": "1.2"
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--8f4a33ec-8b1f-4b80-a2f6-642b2e479580",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2017-05-31T21:30:48.728Z",
+ "modified": "2024-04-16T12:43:55.369Z",
+ "name": "Process Discovery",
+ "description": "Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from [Process Discovery](https://attack.mitre.org/techniques/T1057) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nIn Windows environments, adversaries could obtain details on running processes using the [Tasklist](https://attack.mitre.org/software/S0057) utility via [cmd](https://attack.mitre.org/software/S0106) or Get-Process via [PowerShell](https://attack.mitre.org/techniques/T1059/001). Information about processes can also be extracted from the output of [Native API](https://attack.mitre.org/techniques/T1106) calls such as CreateToolhelp32Snapshot. In Mac and Linux, this is accomplished with the ps command. Adversaries may also opt to enumerate processes via `/proc`. \n\nOn network devices, [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands such as `show processes` can be used to display current running processes.(Citation: US-CERT-TA18-106A)(Citation: show_processes_cisco_cmd)",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "discovery"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1057",
+ "external_id": "T1057"
+ },
+ {
+ "source_name": "show_processes_cisco_cmd",
+ "description": "Cisco. (2022, August 16). show processes - . Retrieved July 13, 2022.",
+ "url": "https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/fundamentals/command/cf_command_ref/show_monitor_permit_list_through_show_process_memory.html#wp3599497760"
+ },
+ {
+ "source_name": "US-CERT-TA18-106A",
+ "description": "US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.",
+ "url": "https://www.us-cert.gov/ncas/alerts/TA18-106A"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_attack_spec_version": "3.2.0",
+ "x_mitre_contributors": [
+ "Austin Clark, @c2defense"
+ ],
+ "x_mitre_data_sources": [
+ "Process: Process Creation",
+ "Process: OS API Execution",
+ "Command: Command Execution"
+ ],
+ "x_mitre_deprecated": false,
+ "x_mitre_detection": "System and network discovery techniques normally occur throughout an operation as an adversary learns the environment. Data and events should not be viewed in isolation, but as part of a chain of behavior that could lead to other activities, such as Lateral Movement, based on the information obtained.\n\nNormal, benign system and network events that look like process discovery may be uncommon, depending on the environment and how they are used. Monitor processes and command-line arguments for actions that could be taken to gather system and network information. Remote access tools with built-in features may interact directly with the Windows API to gather information. Information may also be acquired through Windows system management tools such as [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) and [PowerShell](https://attack.mitre.org/techniques/T1059/001).\n\nFor network infrastructure devices, collect AAA logging to monitor for `show` commands being run by non-standard users from non-standard locations.",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": false,
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_platforms": [
+ "Linux",
+ "macOS",
+ "Windows",
+ "Network"
+ ],
+ "x_mitre_version": "1.5"
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--b97f1d35-4249-4486-a6b5-ee60ccf24fab",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2020-01-23T19:52:17.414Z",
+ "modified": "2023-04-21T12:24:56.148Z",
+ "name": "Regsvr32",
+ "description": "Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object linking and embedding controls, including dynamic link libraries (DLLs), on Windows systems. The Regsvr32.exe binary may also be signed by Microsoft. (Citation: Microsoft Regsvr32)\n\nMalicious usage of Regsvr32.exe may avoid triggering security tools that may not monitor execution of, and modules loaded by, the regsvr32.exe process because of allowlists or false positives from Windows using regsvr32.exe for normal operations. Regsvr32.exe can also be used to specifically bypass application control using functionality to load COM scriptlets to execute DLLs under user permissions. Since Regsvr32.exe is network and proxy aware, the scripts can be loaded by passing a uniform resource locator (URL) to file on an external Web server as an argument during invocation. This method makes no changes to the Registry as the COM object is not actually registered, only executed. (Citation: LOLBAS Regsvr32) This variation of the technique is often referred to as a \"Squiblydoo\" and has been used in campaigns targeting governments. (Citation: Carbon Black Squiblydoo Apr 2016) (Citation: FireEye Regsvr32 Targeting Mongolian Gov)\n\nRegsvr32.exe can also be leveraged to register a COM Object used to establish persistence via [Component Object Model Hijacking](https://attack.mitre.org/techniques/T1546/015). (Citation: Carbon Black Squiblydoo Apr 2016)",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "defense-evasion"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1218/010",
+ "external_id": "T1218.010"
+ },
+ {
+ "source_name": "FireEye Regsvr32 Targeting Mongolian Gov",
+ "description": "Anubhav, A., Kizhakkinan, D. (2017, February 22). Spear Phishing Techniques Used in Attacks Targeting the Mongolian Government. Retrieved February 24, 2017.",
+ "url": "https://www.fireeye.com/blog/threat-research/2017/02/spear_phishing_techn.html"
+ },
+ {
+ "source_name": "LOLBAS Regsvr32",
+ "description": "LOLBAS. (n.d.). Regsvr32.exe. Retrieved July 31, 2019.",
+ "url": "https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"
+ },
+ {
+ "source_name": "Microsoft Regsvr32",
+ "description": "Microsoft. (2015, August 14). How to use the Regsvr32 tool and troubleshoot Regsvr32 error messages. Retrieved June 22, 2016.",
+ "url": "https://support.microsoft.com/en-us/kb/249873"
+ },
+ {
+ "source_name": "Carbon Black Squiblydoo Apr 2016",
+ "description": "Nolen, R. et al.. (2016, April 28). Threat Advisory: \u201cSquiblydoo\u201d Continues Trend of Attackers Using Native OS Tools to \u201cLive off the Land\u201d. Retrieved April 9, 2018.",
+ "url": "https://www.carbonblack.com/2016/04/28/threat-advisory-squiblydoo-continues-trend-of-attackers-using-native-os-tools-to-live-off-the-land/"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_attack_spec_version": "3.1.0",
+ "x_mitre_contributors": [
+ "Casey Smith"
+ ],
+ "x_mitre_data_sources": [
+ "Module: Module Load",
+ "Command: Command Execution",
+ "Network Traffic: Network Connection Creation",
+ "Process: Process Creation"
+ ],
+ "x_mitre_defense_bypassed": [
+ "Digital Certificate Validation",
+ "Anti-virus",
+ "Application control"
+ ],
+ "x_mitre_deprecated": false,
+ "x_mitre_detection": "Use process monitoring to monitor the execution and arguments of regsvr32.exe. Compare recent invocations of regsvr32.exe with prior history of known good arguments and loaded files to determine anomalous and potentially adversarial activity. Command arguments used before and after the regsvr32.exe invocation may also be useful in determining the origin and purpose of the script or DLL being loaded. (Citation: Carbon Black Squiblydoo Apr 2016)",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": true,
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_platforms": [
+ "Windows"
+ ],
+ "x_mitre_version": "2.1"
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--bf1b6176-597c-4600-bfcd-ac989670f96b",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2020-03-09T15:04:32.767Z",
+ "modified": "2023-09-15T19:11:47.547Z",
+ "name": "Exfiltration to Cloud Storage",
+ "description": "Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for the storage, edit, and retrieval of data from a remote cloud storage server over the Internet.\n\nExamples of cloud storage services include Dropbox and Google Docs. Exfiltration to these cloud storage services can provide a significant amount of cover to the adversary if hosts within the network are already communicating with the service. ",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "exfiltration"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1567/002",
+ "external_id": "T1567.002"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_attack_spec_version": "3.1.0",
+ "x_mitre_data_sources": [
+ "Network Traffic: Network Traffic Content",
+ "Network Traffic: Network Connection Creation",
+ "Network Traffic: Network Traffic Flow",
+ "File: File Access",
+ "Command: Command Execution"
+ ],
+ "x_mitre_deprecated": false,
+ "x_mitre_detection": "Analyze network data for uncommon data flows (e.g., a client sending significantly more data than it receives from a server) to known cloud storage services. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious. User behavior monitoring may help to detect abnormal patterns of activity.",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": true,
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_platforms": [
+ "Linux",
+ "macOS",
+ "Windows"
+ ],
+ "x_mitre_version": "1.2"
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--e358d692-23c0-4a31-9eb6-ecc13a8d7735",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2017-05-31T21:30:28.187Z",
+ "modified": "2023-08-14T19:08:59.741Z",
+ "name": "Remote System Discovery",
+ "description": "Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system. Functionality could exist within remote access tools to enable this, but utilities available on the operating system could also be used such as [Ping](https://attack.mitre.org/software/S0097) or net view using [Net](https://attack.mitre.org/software/S0039).\n\nAdversaries may also analyze data from local host files (ex: C:\\Windows\\System32\\Drivers\\etc\\hosts or /etc/hosts) or other passive means (such as local [Arp](https://attack.mitre.org/software/S0099) cache entries) in order to discover the presence of remote systems in an environment.\n\nAdversaries may also target discovery of network infrastructure as well as leverage [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands on network devices to gather detailed information about systems within a network (e.g. show cdp neighbors, show arp).(Citation: US-CERT-TA18-106A)(Citation: CISA AR21-126A FIVEHANDS May 2021) \n",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "discovery"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1018",
+ "external_id": "T1018"
+ },
+ {
+ "source_name": "CISA AR21-126A FIVEHANDS May 2021",
+ "description": "CISA. (2021, May 6). Analysis Report (AR21-126A) FiveHands Ransomware. Retrieved June 7, 2021.",
+ "url": "https://us-cert.cisa.gov/ncas/analysis-reports/ar21-126a"
+ },
+ {
+ "source_name": "Elastic - Koadiac Detection with EQL",
+ "description": "Stepanic, D.. (2020, January 13). Embracing offensive tooling: Building detections against Koadic using EQL. Retrieved November 30, 2020.",
+ "url": "https://www.elastic.co/blog/embracing-offensive-tooling-building-detections-against-koadic-using-eql"
+ },
+ {
+ "source_name": "US-CERT-TA18-106A",
+ "description": "US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.",
+ "url": "https://www.us-cert.gov/ncas/alerts/TA18-106A"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_attack_spec_version": "3.1.0",
+ "x_mitre_contributors": [
+ "Daniel Stepanic, Elastic",
+ "RedHuntLabs, @redhuntlabs",
+ "Austin Clark, @c2defense"
+ ],
+ "x_mitre_data_sources": [
+ "Command: Command Execution",
+ "File: File Access",
+ "Network Traffic: Network Connection Creation",
+ "Process: Process Creation"
+ ],
+ "x_mitre_deprecated": false,
+ "x_mitre_detection": "System and network discovery techniques normally occur throughout an operation as an adversary learns the environment. Data and events should not be viewed in isolation, but as part of a chain of behavior that could lead to other activities, such as Lateral Movement, based on the information obtained.\n\nNormal, benign system and network events related to legitimate remote system discovery may be uncommon, depending on the environment and how they are used. Monitor processes and command-line arguments for actions that could be taken to gather system and network information. Remote access tools with built-in features may interact directly with the Windows API to gather information. Information may also be acquired through Windows system management tools such as [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) and [PowerShell](https://attack.mitre.org/techniques/T1059/001).\n\nMonitor for processes that can be used to discover remote systems, such as ping.exe and tracert.exe, especially when executed in quick succession.(Citation: Elastic - Koadiac Detection with EQL)",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": false,
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_platforms": [
+ "Linux",
+ "macOS",
+ "Windows",
+ "Network"
+ ],
+ "x_mitre_version": "3.5"
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--ec8fc7e2-b356-455c-8db5-2e37be158e7d",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2020-02-26T17:46:13.128Z",
+ "modified": "2020-03-29T22:32:25.985Z",
+ "name": "Hidden Files and Directories",
+ "description": "Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system, most operating systems have the concept of a \u2018hidden\u2019 file. These files don\u2019t show up when a user browses the file system with a GUI or when using normal commands on the command line. Users must explicitly ask to show the hidden files either via a series of Graphical User Interface (GUI) prompts or with command line switches (dir /a for Windows and ls \u2013a for Linux and macOS).\n\nOn Linux and Mac, users can mark specific files as hidden simply by putting a \u201c.\u201d as the first character in the file or folder name (Citation: Sofacy Komplex Trojan) (Citation: Antiquated Mac Malware). Files and folders that start with a period, \u2018.\u2019, are by default hidden from being viewed in the Finder application and standard command-line utilities like \u201cls\u201d. Users must specifically change settings to have these files viewable.\n\nFiles on macOS can also be marked with the UF_HIDDEN flag which prevents them from being seen in Finder.app, but still allows them to be seen in Terminal.app (Citation: WireLurker). On Windows, users can mark specific files as hidden by using the attrib.exe binary. Many applications create these hidden files and folders to store information so that it doesn\u2019t clutter up the user\u2019s workspace. For example, SSH utilities create a .ssh folder that\u2019s hidden and contains the user\u2019s known hosts and keys.\n\nAdversaries can use this to their advantage to hide files and folders anywhere on the system and evading a typical user or system analysis that does not incorporate investigation of hidden files.",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "defense-evasion"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1564/001",
+ "external_id": "T1564.001"
+ },
+ {
+ "source_name": "Sofacy Komplex Trojan",
+ "description": "Dani Creus, Tyler Halfpop, Robert Falcone. (2016, September 26). Sofacy's 'Komplex' OS X Trojan. Retrieved July 8, 2017.",
+ "url": "https://researchcenter.paloaltonetworks.com/2016/09/unit42-sofacys-komplex-os-x-trojan/"
+ },
+ {
+ "source_name": "Antiquated Mac Malware",
+ "description": "Thomas Reed. (2017, January 18). New Mac backdoor using antiquated code. Retrieved July 5, 2017.",
+ "url": "https://blog.malwarebytes.com/threat-analysis/2017/01/new-mac-backdoor-using-antiquated-code/"
+ },
+ {
+ "source_name": "WireLurker",
+ "description": "Claud Xiao. (n.d.). WireLurker: A New Era in iOS and OS X Malware. Retrieved July 10, 2017.",
+ "url": "https://www.paloaltonetworks.com/content/dam/pan/en_US/assets/pdf/reports/Unit_42/unit42-wirelurker.pdf"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_data_sources": [
+ "Process: Process Creation",
+ "File: File Creation",
+ "File: File Metadata",
+ "Command: Command Execution"
+ ],
+ "x_mitre_defense_bypassed": [
+ "Host forensic analysis"
+ ],
+ "x_mitre_detection": "Monitor the file system and shell commands for files being created with a leading \".\" and the Windows command-line use of attrib.exe to add the hidden attribute.",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": true,
+ "x_mitre_permissions_required": [
+ "User"
+ ],
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_platforms": [
+ "Windows",
+ "macOS",
+ "Linux"
+ ],
+ "x_mitre_version": "1.0"
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--f2877f7f-9a4c-4251-879f-1224e3006bee",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2020-02-11T18:43:38.588Z",
+ "modified": "2024-09-23T22:20:10.994Z",
+ "name": "Kerberoasting",
+ "description": "Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to [Brute Force](https://attack.mitre.org/techniques/T1110).(Citation: Empire InvokeKerberoast Oct 2016)(Citation: AdSecurity Cracking Kerberos Dec 2015) \n\nService principal names (SPNs) are used to uniquely identify each instance of a Windows service. To enable authentication, Kerberos requires that SPNs be associated with at least one service logon account (an account specifically tasked with running a service(Citation: Microsoft Detecting Kerberoasting Feb 2018)).(Citation: Microsoft SPN)(Citation: Microsoft SetSPN)(Citation: SANS Attacking Kerberos Nov 2014)(Citation: Harmj0y Kerberoast Nov 2016)\n\nAdversaries possessing a valid Kerberos ticket-granting ticket (TGT) may request one or more Kerberos ticket-granting service (TGS) service tickets for any SPN from a domain controller (DC).(Citation: Empire InvokeKerberoast Oct 2016)(Citation: AdSecurity Cracking Kerberos Dec 2015) Portions of these tickets may be encrypted with the RC4 algorithm, meaning the Kerberos 5 TGS-REP etype 23 hash of the service account associated with the SPN is used as the private key and is thus vulnerable to offline [Brute Force](https://attack.mitre.org/techniques/T1110) attacks that may expose plaintext credentials.(Citation: AdSecurity Cracking Kerberos Dec 2015)(Citation: Empire InvokeKerberoast Oct 2016) (Citation: Harmj0y Kerberoast Nov 2016)\n\nThis same behavior could be executed using service tickets captured from network traffic.(Citation: AdSecurity Cracking Kerberos Dec 2015)\n\nCracked hashes may enable [Persistence](https://attack.mitre.org/tactics/TA0003), [Privilege Escalation](https://attack.mitre.org/tactics/TA0004), and [Lateral Movement](https://attack.mitre.org/tactics/TA0008) via access to [Valid Accounts](https://attack.mitre.org/techniques/T1078).(Citation: SANS Attacking Kerberos Nov 2014)",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "credential-access"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1558/003",
+ "external_id": "T1558.003"
+ },
+ {
+ "source_name": "Microsoft Detecting Kerberoasting Feb 2018",
+ "description": "Bani, M. (2018, February 23). Detecting Kerberoasting activity using Azure Security Center. Retrieved March 23, 2018.",
+ "url": "https://blogs.technet.microsoft.com/motiba/2018/02/23/detecting-kerberoasting-activity-using-azure-security-center/"
+ },
+ {
+ "source_name": "Empire InvokeKerberoast Oct 2016",
+ "description": "EmpireProject. (2016, October 31). Invoke-Kerberoast.ps1. Retrieved March 22, 2018.",
+ "url": "https://github.com/EmpireProject/Empire/blob/master/data/module_source/credentials/Invoke-Kerberoast.ps1"
+ },
+ {
+ "source_name": "SANS Attacking Kerberos Nov 2014",
+ "description": "Medin, T. (2014, November). Attacking Kerberos - Kicking the Guard Dog of Hades. Retrieved March 22, 2018.",
+ "url": "https://redsiege.com/kerberoast-slides"
+ },
+ {
+ "source_name": "AdSecurity Cracking Kerberos Dec 2015",
+ "description": "Metcalf, S. (2015, December 31). Cracking Kerberos TGS Tickets Using Kerberoast \u2013 Exploiting Kerberos to Compromise the Active Directory Domain. Retrieved March 22, 2018.",
+ "url": "https://adsecurity.org/?p=2293"
+ },
+ {
+ "source_name": "Microsoft SetSPN",
+ "description": "Microsoft. (2010, April 13). Service Principal Names (SPNs) SetSPN Syntax (Setspn.exe). Retrieved March 22, 2018.",
+ "url": "https://social.technet.microsoft.com/wiki/contents/articles/717.service-principal-names-spns-setspn-syntax-setspn-exe.aspx"
+ },
+ {
+ "source_name": "Microsoft SPN",
+ "description": "Microsoft. (n.d.). Service Principal Names. Retrieved March 22, 2018.",
+ "url": "https://msdn.microsoft.com/library/ms677949.aspx"
+ },
+ {
+ "source_name": "Harmj0y Kerberoast Nov 2016",
+ "description": "Schroeder, W. (2016, November 1). Kerberoasting Without Mimikatz. Retrieved September 23, 2024.",
+ "url": "https://blog.harmj0y.net/powershell/kerberoasting-without-mimikatz/"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_attack_spec_version": "3.2.0",
+ "x_mitre_contributors": [
+ "Praetorian"
+ ],
+ "x_mitre_data_sources": [
+ "Active Directory: Active Directory Credential Request"
+ ],
+ "x_mitre_deprecated": false,
+ "x_mitre_detection": "Enable Audit Kerberos Service Ticket Operations to log Kerberos TGS service ticket requests. Particularly investigate irregular patterns of activity (ex: accounts making numerous requests, Event ID 4769, within a small time frame, especially if they also request RC4 encryption [Type 0x17]).(Citation: Microsoft Detecting Kerberoasting Feb 2018)(Citation: AdSecurity Cracking Kerberos Dec 2015)",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": true,
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_platforms": [
+ "Windows"
+ ],
+ "x_mitre_system_requirements": [
+ "Valid domain account or the ability to sniff traffic within a domain"
+ ],
+ "x_mitre_version": "1.2"
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--f303a39a-6255-4b89-aecc-18c4d8ca7163",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2020-02-11T18:45:34.293Z",
+ "modified": "2024-10-15T15:54:08.312Z",
+ "name": "DCSync",
+ "description": "Adversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API)(Citation: Microsoft DRSR Dec 2017) (Citation: Microsoft GetNCCChanges) (Citation: Samba DRSUAPI) (Citation: Wine API samlib.dll) to simulate the replication process from a remote domain controller using a technique called DCSync.\n\nMembers of the Administrators, Domain Admins, and Enterprise Admin groups or computer accounts on the domain controller are able to run DCSync to pull password data(Citation: ADSecurity Mimikatz DCSync) from Active Directory, which may include current and historical hashes of potentially useful accounts such as KRBTGT and Administrators. The hashes can then in turn be used to create a [Golden Ticket](https://attack.mitre.org/techniques/T1558/001) for use in [Pass the Ticket](https://attack.mitre.org/techniques/T1550/003)(Citation: Harmj0y Mimikatz and DCSync) or change an account's password as noted in [Account Manipulation](https://attack.mitre.org/techniques/T1098).(Citation: InsiderThreat ChangeNTLM July 2017)\n\nDCSync functionality has been included in the \"lsadump\" module in [Mimikatz](https://attack.mitre.org/software/S0002).(Citation: GitHub Mimikatz lsadump Module) Lsadump also includes NetSync, which performs DCSync over a legacy replication protocol.(Citation: Microsoft NRPC Dec 2017)",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "credential-access"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1003/006",
+ "external_id": "T1003.006"
+ },
+ {
+ "source_name": "GitHub Mimikatz lsadump Module",
+ "description": "Deply, B., Le Toux, V. (2016, June 5). module ~ lsadump. Retrieved August 7, 2017.",
+ "url": "https://github.com/gentilkiwi/mimikatz/wiki/module-~-lsadump"
+ },
+ {
+ "source_name": "ADSecurity Mimikatz DCSync",
+ "description": "Metcalf, S. (2015, September 25). Mimikatz DCSync Usage, Exploitation, and Detection. Retrieved August 7, 2017.",
+ "url": "https://adsecurity.org/?p=1729"
+ },
+ {
+ "source_name": "AdSecurity DCSync Sept 2015",
+ "description": "Metcalf, S. (2015, September 25). Mimikatz DCSync Usage, Exploitation, and Detection. Retrieved December 4, 2017.",
+ "url": "https://adsecurity.org/?p=1729"
+ },
+ {
+ "source_name": "Microsoft DRSR Dec 2017",
+ "description": "Microsoft. (2017, December 1). MS-DRSR Directory Replication Service (DRS) Remote Protocol. Retrieved December 4, 2017.",
+ "url": "https://msdn.microsoft.com/library/cc228086.aspx"
+ },
+ {
+ "source_name": "Microsoft NRPC Dec 2017",
+ "description": "Microsoft. (2017, December 1). MS-NRPC - Netlogon Remote Protocol. Retrieved December 6, 2017.",
+ "url": "https://msdn.microsoft.com/library/cc237008.aspx"
+ },
+ {
+ "source_name": "Microsoft GetNCCChanges",
+ "description": "Microsoft. (n.d.). IDL_DRSGetNCChanges (Opnum 3). Retrieved December 4, 2017.",
+ "url": "https://msdn.microsoft.com/library/dd207691.aspx"
+ },
+ {
+ "source_name": "Microsoft SAMR",
+ "description": "Microsoft. (n.d.). MS-SAMR Security Account Manager (SAM) Remote Protocol (Client-to-Server) - Transport. Retrieved December 4, 2017.",
+ "url": "https://msdn.microsoft.com/library/cc245496.aspx"
+ },
+ {
+ "source_name": "Samba DRSUAPI",
+ "description": "SambaWiki. (n.d.). DRSUAPI. Retrieved December 4, 2017.",
+ "url": "https://wiki.samba.org/index.php/DRSUAPI"
+ },
+ {
+ "source_name": "Harmj0y DCSync Sept 2015",
+ "description": "Schroeder, W. (2015, September 22). Mimikatz and DCSync and ExtraSids, Oh My. Retrieved December 4, 2017.",
+ "url": "http://www.harmj0y.net/blog/redteaming/mimikatz-and-dcsync-and-extrasids-oh-my/"
+ },
+ {
+ "source_name": "Harmj0y Mimikatz and DCSync",
+ "description": "Schroeder, W. (2015, September 22). Mimikatz and DCSync and ExtraSids, Oh My. Retrieved September 23, 2024.",
+ "url": "https://blog.harmj0y.net/redteaming/mimikatz-and-dcsync-and-extrasids-oh-my/"
+ },
+ {
+ "source_name": "InsiderThreat ChangeNTLM July 2017",
+ "description": "Warren, J. (2017, July 11). Manipulating User Passwords with Mimikatz. Retrieved December 4, 2017.",
+ "url": "https://blog.stealthbits.com/manipulating-user-passwords-with-mimikatz-SetNTLM-ChangeNTLM"
+ },
+ {
+ "source_name": "Wine API samlib.dll",
+ "description": "Wine API. (n.d.). samlib.dll. Retrieved December 4, 2017.",
+ "url": "https://source.winehq.org/WineAPI/samlib.html"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_attack_spec_version": "3.2.0",
+ "x_mitre_contributors": [
+ "ExtraHop",
+ "Vincent Le Toux"
+ ],
+ "x_mitre_data_sources": [
+ "Active Directory: Active Directory Object Access",
+ "Network Traffic: Network Traffic Content",
+ "Network Traffic: Network Traffic Flow"
+ ],
+ "x_mitre_deprecated": false,
+ "x_mitre_detection": "Monitor domain controller logs for replication requests and other unscheduled activity possibly associated with DCSync.(Citation: Microsoft DRSR Dec 2017) (Citation: Microsoft GetNCCChanges) (Citation: Samba DRSUAPI) Also monitor for network protocols(Citation: Microsoft DRSR Dec 2017) (Citation: Microsoft NRPC Dec 2017) and other replication requests(Citation: Microsoft SAMR) from IPs not associated with known domain controllers.(Citation: AdSecurity DCSync Sept 2015)\n\nNote: Domain controllers may not log replication requests originating from the default domain controller account.(Citation: Harmj0y DCSync Sept 2015)",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": true,
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_version": "1.1",
+ "x_mitre_platforms": [
+ "Windows"
+ ]
+ },
+ {
+ "type": "malware",
+ "spec_version": "2.1",
+ "id": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "created": "2025-02-21T13:06:12.771358Z",
+ "modified": "2025-02-21T13:06:12.771358Z",
+ "name": "IcedID",
+ "malware_types": [
+ "backdoor",
+ "downloader"
+ ],
+ "is_family": true,
+ "capabilities": [
+ "accesses-remote-machines",
+ "exfiltrates-data",
+ "escalates_privileges",
+ "exfiltrates_data",
+ "installs-other-components",
+ "steals-authentication-credentials"
+ ]
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--0284880d-ad4f-44db-8298-128c202cf7c7",
+ "created": "2025-02-21T13:06:12.776734Z",
+ "modified": "2025-02-21T13:06:12.776734Z",
+ "relationship_type": "related-to",
+ "source_ref": "threat-actor--132a4b4b-80cd-49fa-be94-15a44e422e22",
+ "target_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--724268a3-d272-4849-8cce-223bd6fbf6a2",
+ "created": "2025-02-21T13:06:12.772882Z",
+ "modified": "2025-02-21T13:06:12.772882Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "attack-pattern--005a06c6-14bf-4118-afa0-ebcd8aebb0c9"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--1fc86411-bbd4-4ab6-8cc8-9bd0ac3aab93",
+ "created": "2025-02-21T13:06:12.773289Z",
+ "modified": "2025-02-21T13:06:12.773289Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "attack-pattern--01a5a209-b94c-450b-b7f9-946497d91055"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--fd87ac97-569f-45fd-9d03-533aa5aae657",
+ "created": "2025-02-21T13:06:12.773498Z",
+ "modified": "2025-02-21T13:06:12.773498Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "attack-pattern--045d0922-2310-4e60-b5e4-3302302cb3c5"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--8027764f-d0e3-4e7e-9f36-e3bbd29b12ae",
+ "created": "2025-02-21T13:06:12.773645Z",
+ "modified": "2025-02-21T13:06:12.773645Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "attack-pattern--232b7f21-adf9-4b42-b936-b9d6f7df856e"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--1725ce04-9e16-4891-9e25-86e7f9c9b10d",
+ "created": "2025-02-21T13:06:12.773782Z",
+ "modified": "2025-02-21T13:06:12.773782Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "attack-pattern--62b8c999-dcc0-4755-bd69-09442d9359f5"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--fc969b0d-b8a3-4210-bf39-8101bf881477",
+ "created": "2025-02-21T13:06:12.773918Z",
+ "modified": "2025-02-21T13:06:12.773918Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "attack-pattern--72b74d71-8169-42aa-92e0-e7b04b9f5a08"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--7e6623eb-5dc4-4141-86e3-11514526de16",
+ "created": "2025-02-21T13:06:12.774051Z",
+ "modified": "2025-02-21T13:06:12.774051Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "attack-pattern--767dbf9e-df3f-45cb-8998-4903ab5f80c0"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--d6922d74-7bcc-4df6-8ba4-3826381484e6",
+ "created": "2025-02-21T13:06:12.774183Z",
+ "modified": "2025-02-21T13:06:12.774183Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "attack-pattern--8f4a33ec-8b1f-4b80-a2f6-642b2e479580"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--4eeed28c-4b15-4da6-b342-758a5e443b16",
+ "created": "2025-02-21T13:06:12.774316Z",
+ "modified": "2025-02-21T13:06:12.774316Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "attack-pattern--b97f1d35-4249-4486-a6b5-ee60ccf24fab"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--b5cb0af5-b551-4547-941b-60ec5bed1289",
+ "created": "2025-02-21T13:06:12.774444Z",
+ "modified": "2025-02-21T13:06:12.774444Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "attack-pattern--bf1b6176-597c-4600-bfcd-ac989670f96b"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--6b1ae64f-b1b2-4d13-b9be-702b0d2c77a3",
+ "created": "2025-02-21T13:06:12.77467Z",
+ "modified": "2025-02-21T13:06:12.77467Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "attack-pattern--e358d692-23c0-4a31-9eb6-ecc13a8d7735"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--d422a4ba-48e9-4381-8a73-8a51aaa24ede",
+ "created": "2025-02-21T13:06:12.774807Z",
+ "modified": "2025-02-21T13:06:12.774807Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "attack-pattern--ec8fc7e2-b356-455c-8db5-2e37be158e7d"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--530ac4c8-58b1-4f65-acce-5532bdd54279",
+ "created": "2025-02-21T13:06:12.774988Z",
+ "modified": "2025-02-21T13:06:12.774988Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "attack-pattern--f2877f7f-9a4c-4251-879f-1224e3006bee"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--f62cd356-9c86-4a18-80bb-35303308f785",
+ "created": "2025-02-21T13:06:12.775124Z",
+ "modified": "2025-02-21T13:06:12.775124Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "attack-pattern--f303a39a-6255-4b89-aecc-18c4d8ca7163"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--208cd85c-4b52-4223-ba8b-ce82bc24e309",
+ "created": "2025-02-21T13:06:12.775258Z",
+ "modified": "2025-02-21T13:06:12.775258Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "malware-behavior--584dc938-3789-4e53-995e-f914dff31b71"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--50819a1e-977a-408b-a453-b0cd2e33ae7c",
+ "created": "2025-02-21T13:06:12.775391Z",
+ "modified": "2025-02-21T13:06:12.775391Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "malware-behavior--7ea1c41a-ed8b-4836-a4bc-48129c33c60b"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--bda4d586-e0c3-4993-ae81-b6fb38899bf0",
+ "created": "2025-02-21T13:06:12.775521Z",
+ "modified": "2025-02-21T13:06:12.775521Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "malware-behavior--819ed2ae-7ed5-4caf-a057-485563efc26f"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--7b72b81a-8569-4352-8539-82c037312954",
+ "created": "2025-02-21T13:06:12.775656Z",
+ "modified": "2025-02-21T13:06:12.775656Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "malware-behavior--201961ae-2a71-41f5-bbd0-8c22bbd748de"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--2a6eecf5-eab5-497a-8a22-f815f5696cab",
+ "created": "2025-02-21T13:06:12.775787Z",
+ "modified": "2025-02-21T13:06:12.775787Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "malware-behavior--7cb5847c-f662-4260-bd44-857ffd4975da"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--853d09d6-1a39-438a-945d-268035981844",
+ "created": "2025-02-21T13:06:12.775922Z",
+ "modified": "2025-02-21T13:06:12.775922Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "malware-behavior--a28f7a00-c512-4a1e-88a9-9eeeca8a162a"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--b7ac27d2-2b05-42e2-9c4a-0ea807e0b433",
+ "created": "2025-02-21T13:06:12.77606Z",
+ "modified": "2025-02-21T13:06:12.77606Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--7ff26fc5-d53d-4eb0-a469-eb72cd617bf0",
+ "target_ref": "malware-behavior--c889b142-22b2-4e82-9412-cf5528523f56"
+ }
+ ]
+}
diff --git a/yvisualization/stix-visualizer/icedid/icedid-viz.png b/yvisualization/stix-visualizer/icedid/icedid-viz.png
new file mode 100644
index 0000000..b8f8351
Binary files /dev/null and b/yvisualization/stix-visualizer/icedid/icedid-viz.png differ
diff --git a/yvisualization/stix-visualizer/latrodectus/latrodectus-viz.png b/yvisualization/stix-visualizer/latrodectus/latrodectus-viz.png
new file mode 100644
index 0000000..097b77f
Binary files /dev/null and b/yvisualization/stix-visualizer/latrodectus/latrodectus-viz.png differ
diff --git a/yvisualization/stix-visualizer/latrodectus/latrodectus.json b/yvisualization/stix-visualizer/latrodectus/latrodectus.json
new file mode 100644
index 0000000..055a022
--- /dev/null
+++ b/yvisualization/stix-visualizer/latrodectus/latrodectus.json
@@ -0,0 +1,2142 @@
+{
+ "type": "bundle",
+ "id": "bundle--a39ee1fe-60c8-43a6-a09b-663382214b1e",
+ "objects": [
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--5e658b0e-6fdc-40cd-8d65-b5f44d8637dd",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2019-08-01T00:00:00.000Z",
+ "modified": "2024-04-28T00:00:00.000Z",
+ "name": "Send System Information",
+ "obj_defn": {
+ "description": "Implant sends system information.",
+ "external_id": "B0030.006",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--22eb2825-fe0c-4ef1-a156-f967a0ffcfb7",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--73a87642-8eeb-4309-82a8-8f4e88cf104a",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2019-08-01T00:00:00.000Z",
+ "modified": "2024-04-28T00:00:00.000Z",
+ "name": "Server to Client File Transfer",
+ "obj_defn": {
+ "description": "File is transferred from controller to implant.",
+ "external_id": "B0030.003",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--22eb2825-fe0c-4ef1-a156-f967a0ffcfb7",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--53f5c51c-ad5d-48b4-862d-bd251f918010",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2019-08-01T00:00:00.000Z",
+ "modified": "2024-04-27T00:00:00.000Z",
+ "name": "Process Environment Block BeingDebugged",
+ "obj_defn": {
+ "description": "The BeingDebugged field is tested to determine whether the process is being debugged.",
+ "external_id": "B0001.035",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--f69ed861-f8ce-4ada-abfc-b5b82cc2cdda",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--4b1f3c4b-2197-4a81-90c5-93057e47c4a6",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2019-08-01T00:00:00.000Z",
+ "modified": "2024-04-28T00:00:00.000Z",
+ "name": "Directory Listing",
+ "obj_defn": {
+ "description": "Controller requests a directory listing from the implant, optionally from a given path, optionally recursive.",
+ "external_id": "B0030.012",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--22eb2825-fe0c-4ef1-a156-f967a0ffcfb7",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--47a66a67-6cc7-492f-90ae-0e4f198a9d11",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2019-08-01T00:00:00.000Z",
+ "modified": "2024-04-28T00:00:00.000Z",
+ "name": "Receive Data",
+ "obj_defn": {
+ "description": "Receive data or command from a controller.",
+ "external_id": "B0030.002",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--22eb2825-fe0c-4ef1-a156-f967a0ffcfb7",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--6fcef7e8-e79b-4771-891f-d8d08dbd489e",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2019-08-01T00:00:00.000Z",
+ "modified": "2024-04-27T00:00:00.000Z",
+ "name": "Modern Specs Check",
+ "obj_defn": {
+ "description": "Different aspects of the hardware are inspected to determine whether the machine has modern characteristics. A machine with substandard specifications indicates a virtual environment.",
+ "external_id": "B0009.013",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--8d21a9e4-bf53-43aa-81fd-c3f72c12f7b3",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--52b5f972-e1ca-4da3-b29e-379ac9311e02",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-12-29T00:00:00.000Z",
+ "modified": "2023-03-01T00:00:00.000Z",
+ "name": "Base64",
+ "obj_defn": {
+ "description": "Malware may decode data using base64.",
+ "external_id": "C0053.001",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--f1f2e3d3-7d01-41bb-a3f0-6f2f3c856c1a",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--58d1341b-5804-4d75-b74b-ebc1a109f628",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-10-13T00:00:00.000Z",
+ "modified": "2024-04-30T00:00:00.000Z",
+ "name": "FNV",
+ "obj_defn": {
+ "description": "Malware uses the FNV hash function.",
+ "external_id": "C0030.005",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--f9d8c51b-9600-40af-ad7f-6972030e0444",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--a271c92f-de0b-4f10-a5ea-ebea24b0e07b",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2019-08-01T00:00:00.000Z",
+ "modified": "2024-04-28T00:00:00.000Z",
+ "name": "Execute Shell Command",
+ "obj_defn": {
+ "description": "Execute/run the given command using a built-in program (e.g. cmd.exe, PowerShell, bash). This differs from Start Interactive Shell because the shell process is started only for the received command or set of commands and then exits. There is no loop looking for additional commands while the shell process is still running.",
+ "external_id": "B0030.014",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--22eb2825-fe0c-4ef1-a156-f967a0ffcfb7",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--50cb3a45-bb76-4483-a134-6f6312d44c92",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-12-29T00:00:00.000Z",
+ "modified": "2023-03-01T00:00:00.000Z",
+ "name": "XOR",
+ "obj_defn": {
+ "description": "Malware may use XOR to decode data.",
+ "external_id": "C0053.002",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--f1f2e3d3-7d01-41bb-a3f0-6f2f3c856c1a",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--9d13adf5-2774-4ea2-bbb1-ba8e8e3ca7ea",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-08-14T00:00:00.000Z",
+ "modified": "2024-04-30T00:00:00.000Z",
+ "name": "Send Data",
+ "obj_defn": {
+ "description": "HTTP clients sends data to a server (POST/PUT).",
+ "external_id": "C0002.005",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--c889b142-22b2-4e82-9412-cf5528523f56",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--9d13adf5-2774-4ea2-bbb1-ba8e8e3ca7ea",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-08-14T00:00:00.000Z",
+ "modified": "2024-04-30T00:00:00.000Z",
+ "name": "Send Data",
+ "obj_defn": {
+ "description": "HTTP clients sends data to a server (POST/PUT).",
+ "external_id": "C0002.005",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--c889b142-22b2-4e82-9412-cf5528523f56",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--f52bfd6d-ddfa-4552-b99b-8558d5eac711",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2019-08-01T00:00:00.000Z",
+ "modified": "2024-04-28T00:00:00.000Z",
+ "name": "Send Data",
+ "obj_defn": {
+ "description": "Send data to a controller.",
+ "external_id": "B0030.001",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--22eb2825-fe0c-4ef1-a156-f967a0ffcfb7",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--f52bfd6d-ddfa-4552-b99b-8558d5eac711",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2019-08-01T00:00:00.000Z",
+ "modified": "2024-04-28T00:00:00.000Z",
+ "name": "Send Data",
+ "obj_defn": {
+ "description": "Send data to a controller.",
+ "external_id": "B0030.001",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--22eb2825-fe0c-4ef1-a156-f967a0ffcfb7",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--c2ab7efa-d323-4f91-8d48-acf9d35461db",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-10-13T00:00:00.000Z",
+ "modified": "2023-12-05T00:00:00.000Z",
+ "name": "Base64",
+ "obj_defn": {
+ "description": "Malware may encode data using Base64.",
+ "external_id": "C0026.001",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--72985da4-70ca-46f6-b143-bc9a46aa173b",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--714905f5-038c-4b03-82f7-3e290ab84743",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-09-25T00:00:00.000Z",
+ "modified": "2024-04-30T00:00:00.000Z",
+ "name": "Send Data",
+ "obj_defn": {
+ "description": "Send data on socket.",
+ "external_id": "C0001.007",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--3b52f0b3-2898-47ec-87b7-f1b90999cc7a",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--3a879212-7127-4f91-84ef-7aa65e971ef3",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-10-13T00:00:00.000Z",
+ "modified": "2024-02-06T00:00:00.000Z",
+ "name": "RC4",
+ "obj_defn": {
+ "description": "Malware encrypts with the RC4 algorithm.",
+ "external_id": "C0027.009",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--121d1e3e-9fec-4518-aefb-46b63c26fbba",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--af6960c9-b141-4bd0-b4f0-288e52c82645",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2019-08-01T00:00:00.000Z",
+ "modified": "2024-04-28T00:00:00.000Z",
+ "name": "Execute File",
+ "obj_defn": {
+ "description": "Execute/run/open the file using default operating system functionality, optionally with provided command-and-scripting-interpreter arguments. The file may or may not already exist on the victim.",
+ "external_id": "B0030.013",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--22eb2825-fe0c-4ef1-a156-f967a0ffcfb7",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--610e10e9-530f-4871-9f31-2548e10d2d01",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2019-08-01T00:00:00.000Z",
+ "modified": "2023-09-13T00:00:00.000Z",
+ "name": "Unique Hardware/Firmware Check - MAC Address",
+ "obj_defn": {
+ "description": "Malware may check for hardware characteristics unique to being virtualized, allowing the malware to detect the virtual environment. VMware uses specific virtual MAC address that can be detected. The usual MAC address used started with the following numbers: \"00:0C:29\", \"00:1C:14\", \"00:50:56\", \"00:05:69\". Virtualbox uses specific virtual MAC address that can be detected by Malware. The usual MAC address used started with the following numbers: 08:00:27. [2] This method is related to Unprotect technique U1335.",
+ "external_id": "B0009.028",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--8d21a9e4-bf53-43aa-81fd-c3f72c12f7b3",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--ce830efe-16ec-41a4-9fff-41255449d077",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-10-13T00:00:00.000Z",
+ "modified": "2023-12-05T00:00:00.000Z",
+ "name": "RC4",
+ "obj_defn": {
+ "description": "Malware decrypts data encrypted with the RC4 algorithm.",
+ "external_id": "C0031.008",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--7778eae9-e41c-4112-bdb6-448557481846",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-method",
+ "spec_version": "2.1",
+ "id": "malware-method--15a3f947-455e-4b57-b950-b0e52b3ac2c2",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2019-08-01T00:00:00.000Z",
+ "modified": "2024-04-28T00:00:00.000Z",
+ "name": "Authenticate",
+ "obj_defn": {
+ "description": "Implant may authenticate itself to the controller, controller may authenticate itself to implant, or both. This is often at or near the start of communication. Examples include but are not limited to a simple shared secret (e.g. password), challenge-response with symmetric encryption, or challenge-response with asymmetric encryption.",
+ "external_id": "B0030.011",
+ "source_name": "mitre-mbc"
+ },
+ "behavior_ref": "malware-behavior--22eb2825-fe0c-4ef1-a156-f967a0ffcfb7",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--19bbde8e-2a08-4ecd-a1e0-44240ed97113",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-08-14T00:00:00.000Z",
+ "modified": "2024-04-30T00:00:00.000Z",
+ "name": "Generate Pseudo-random Sequence",
+ "obj_defn": {
+ "description": "The Generate Pseudo-random Sequence micro-behavior can be used for a number of purposes. The methods below include specific functions, as well as pseudo-random number generators (PRNG).",
+ "external_id": "C0021",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/micro-behaviors/cryptography/generate-pseudorandom-sequence.md"
+ },
+ "objective_refs": [
+ "malware-objective--aa176dc6-7969-4333-8b7b-677c92341818"
+ ],
+ "detection_rules": [
+ {
+ "detect_ref": "malware-method--f762e3c0-d54d-44fb-8bdb-d58818cf9a8d",
+ "rule_name": "encrypt data using RC4 PRGA",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/data-manipulation/encryption/rc4/encrypt-data-using-rc4-prga.yml"
+ },
+ {
+ "api_fncs": [
+ "BCryptGenRandom",
+ "CryptGenRandom",
+ "BCryptOpenAlgorithmProvider",
+ "BCryptCloseAlgorithmProvider",
+ "CryptAquireContext"
+ ],
+ "detect_ref": "malware-method--1de80818-0c49-4de7-a85e-5ef660bafd17",
+ "rule_type": "capa",
+ "rule_name": "generate random numbers via WinAPI",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/data-manipulation/prng/generate-random-numbers-via-winapi.yml"
+ },
+ {
+ "api_fncs": [
+ "SystemFunction036"
+ ],
+ "detect_ref": "malware-method--1de80818-0c49-4de7-a85e-5ef660bafd17",
+ "rule_type": "capa",
+ "rule_name": "generate random numbers via RtlGenRandom",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/data-manipulation/prng/generate-random-numbers-via-rtlgenrandom.yml"
+ },
+ {
+ "rule_name": "generate random numbers using a Mersenne Twister",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/data-manipulation/prng/mersenne/generate-random-numbers-using-a-mersenne-twister.yml"
+ }
+ ],
+ "obj_version": "2.1",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "external_references": [
+ {
+ "source_name": "capa analysis",
+ "description": "Analysis output, capa 4.0, analyzed at MITRE on Oct. 12, 2022.",
+ "url": "https://github.com/mandiant/capa-rules"
+ }
+ ]
+ },
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--3b0f15b6-e989-4cb3-8743-15601847efa1",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-12-04T00:00:00.000Z",
+ "modified": "2024-04-30T00:00:00.000Z",
+ "name": "Check Mutex",
+ "obj_defn": {
+ "description": "Malware checks a mutex.",
+ "external_id": "C0043",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/micro-behaviors/process/check-mutex.md"
+ },
+ "objective_refs": [
+ "malware-objective--340ce208-c849-44e7-bb4d-47b90fe19e7c"
+ ],
+ "detection_rules": [
+ {
+ "api_fncs": [
+ "kernel32.OpenMutex",
+ "System.Threading.Mutex::OpenExisting",
+ "System.Threading.Mutex::TryOpenExisting",
+ "kernel32.GetLastError"
+ ],
+ "rule_name": "check mutex",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/mutex/check-mutex.yml"
+ },
+ {
+ "api_fncs": [
+ "ExitProcess",
+ "exit",
+ "_Exit",
+ "_exit",
+ "WaitForSingleObject",
+ "GetLastError"
+ ],
+ "rule_name": "check mutex and exit",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/mutex/check-mutex-and-exit.yml"
+ },
+ {
+ "class": "VPCDetectMutex",
+ "rule_name": "antivm_vpc_mutex",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vpc_mutex.py"
+ },
+ {
+ "rule_name": "antisandbox_sboxie_mutex",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_sboxie_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "antivm_vmware_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antivm_vmware_mutexes.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "purplewave_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/infostealer_purplewave.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "antisandbox_sboxie_mutex",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antisandbox_sboxie_mutex.py",
+ "rule_type": "cape"
+ }
+ ],
+ "obj_version": "2.2",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "external_references": [
+ {
+ "source_name": "zhang-poisonivy",
+ "description": "X. Zhang, \"Deep Analysis of New Poison Ivy Variant,\" Fortiguard Labs Threat Research, Aug. 23, 2017 [Online].",
+ "url": "https://www.fortinet.com/blog/threat-research/deep-analysis-of-new-poison-ivy-variant"
+ },
+ {
+ "source_name": "dong-matanbuchus",
+ "description": "C. Dong, \"MATANBUCHUS: Another Loader as a Service Malware,\" Offset Training Solutions, blog, Feb. 15, 2022 [Online].",
+ "url": "https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/"
+ },
+ {
+ "source_name": "cohen-matabuchus",
+ "description": "B. Cohen, \"Inside Matanbuchus: A Quirky Loader,\" CyberArk, blog, Jul. 26, 2022 [Online].",
+ "url": "https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader"
+ }
+ ]
+ },
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--f710327b-7f89-4b45-9a84-2f5d23b23378",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-12-04T00:00:00.000Z",
+ "modified": "2024-09-16T00:00:00.000Z",
+ "name": "Create Mutex",
+ "obj_defn": {
+ "description": "Malware creates a mutex. Mutexes may be created for synchronization purposes (two or more processes/threads to share a resource).",
+ "external_id": "C0042",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/micro-behaviors/process/create-mutex.md"
+ },
+ "objective_refs": [
+ "malware-objective--340ce208-c849-44e7-bb4d-47b90fe19e7c"
+ ],
+ "detection_rules": [
+ {
+ "api_fncs": [
+ "kernel32.CreateMutex",
+ "kernel32.CreateMutexEx",
+ "System.Threading.Mutex::ctor"
+ ],
+ "rule_name": "create mutex",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/mutex/create-mutex.yml"
+ },
+ {
+ "api_fncs": [
+ "fcntl"
+ ],
+ "rule_name": "lock file",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/mutex/lock-file.yml"
+ },
+ {
+ "class": "AllapleMutexes",
+ "rule_name": "allaple_mutexes",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/worm_allaple_mutex.py"
+ },
+ {
+ "rule_name": "andromut_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/downloader_andromut_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "asyncrat_mutex_raccoon",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/infostealer_raccoon.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "asyncrat_mutex",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/asyncrat_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "azorult_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/infostealer_azorult_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "banker_cridex",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/banker_cridex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "banker_spyeye_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/banker_spyeye_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "banker_zeus_mutex",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/banker_zeus_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "banker_zeus_p2p",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/all/banker_zeus_p2p.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "blackrat_mutexes",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_blackremote.py"
+ },
+ {
+ "rule_name": "bot_russkill",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/bot_russkill.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "carberp_mutex",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/carberp_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "crat_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_crat.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "cryptomix_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_cryptomix.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "cypherit_mutex",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/cypherit_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "dcrat_mutexes",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_dcrat.py"
+ },
+ {
+ "rule_name": "deepfreeze_mutex",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/deepfreeze_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "dharma_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_dharma.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "fleercivet_mutex",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/trojan_fleercivet_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "fonix_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_fonix_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "gandcrab_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_gandcrab.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "geodo_banking_trojan",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/banker_geodo.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "germanwiper_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_germanwiper.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "limerat_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_limerat.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "lokibot_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/trojan_lokibot_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "medusalocker_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_medusalocker.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "nemty_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_nemty.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "neshta_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/virus_neshta.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "obliquerat_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_oblique.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "okrum_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/backdoor_okrum_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "packer_armadillo_mutex",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/packer_armadillo_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "parallax_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_parallax_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "phorpiex_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/downloader_phorpiex_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "powerpool_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/powerpool_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "protonbot_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/downloader_protonbot_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "pysa_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_pysa_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "qulab_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/infostealer_qulab.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "ransomware_radamant",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_radamant.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "rat_beebus_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_beebus_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "rat_fynloski_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_fynloski_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ " CryptHashData",
+ "NtCreateMutant"
+ ],
+ "rule_name": "rat_luminosity",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_luminosity.py"
+ },
+ {
+ "rule_name": "rat_nanocore",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_nanocore.py"
+ },
+ {
+ "rule_name": "rat_pcclient",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_pcclient.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "rat_plugx_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_plugx_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "rat_poisonivy_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_poisonivy.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "rat_quasar_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_quasar.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "rat_spynet",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_spynet.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "rat_xtreme_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_xtreme_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "ratsnif_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_ratsnif_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "remcos_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/remcos.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "renamer_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/virus_renamer_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "revil_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_revil_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "satan_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_satan_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "snake_ransom_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_snake_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "stop_ransom_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_stop.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "targeted_flame",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/targeted_flame.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "trickbot_mutex",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/trickbot_mutex.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "ursnif_behavior",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/trojan_ursnif.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "venomrat_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_venom.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "xpertrat_mutexes",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/rat_xpert.py",
+ "rule_type": "cape"
+ }
+ ],
+ "obj_version": "2.2",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "external_references": [
+ {
+ "source_name": "zhang-poisonivy",
+ "description": "X. Zhang, \"Deep Analysis of New Poison Ivy Variant,\" Fortiguard Labs Threat Research, Aug. 23, 2017 [Online].",
+ "url": "https://www.fortinet.com/blog/threat-research/deep-analysis-of-new-poison-ivy-variant"
+ },
+ {
+ "source_name": "falliere-stuxnet",
+ "description": "N. Falliere, L. Murchu, and E. Chien, \"W32.Stuxnet Dossier,\" Symantec Security Response, Feb. 2011 [Online].",
+ "url": "https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en"
+ },
+ {
+ "source_name": "capa analysis",
+ "description": "Analysis output, capa 4.0, analyzed at MITRE on Oct. 12, 2022.",
+ "url": "https://github.com/mandiant/capa-rules"
+ }
+ ]
+ },
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--201961ae-2a71-41f5-bbd0-8c22bbd748de",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2019-08-01T00:00:00.000Z",
+ "modified": "2024-04-28T00:00:00.000Z",
+ "name": "Ingress Tool Transfer",
+ "obj_defn": {
+ "description": "Malware may copy files from an external system to a system on a compromised network. \n\nNote that this behavior is separate from possible execution (installation) of the file, which is covered by the **Install Additional Program ([B0023](https://github.com/MBCProject/mbc-markdown/blob/main/execution/install-additional-program.md))** behavior. \n\nSee ATT&CK: **Ingress Tool Transfer ([T1105](https://attack.mitre.org/techniques/T1105/))**.",
+ "external_id": "E1105",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/command-and-control/ingress-tool-transfer.md"
+ },
+ "objective_refs": [
+ "malware-objective--6b7a98eb-cb9c-4cf1-aad6-714d64000dd3",
+ "malware-objective--91583649-6a8a-48d9-a42a-75a928d4b241",
+ "malware-objective--b0d7b24c-db02-461a-a9c9-bcf790572114"
+ ],
+ "detection_rules": [
+ {
+ "rule_name": "suspicious_mpcmdrun_use",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/windows_utilities.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "URLDownloadToFileW",
+ "HttpOpenRequestW",
+ "send",
+ "InternetCrackUrlW",
+ "InternetCrackUrlA",
+ "WSASend",
+ "URLDownloadToCacheFileW"
+ ],
+ "rule_name": "network_document_file",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/network_payload_download.py"
+ }
+ ],
+ "obj_version": "2.2",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "related_object_refs": [
+ "attack-pattern--e6919abc-99f9-4c6c-95a5-14761e7b2add"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "external_references": [
+ {
+ "source_name": "kujawa",
+ "description": "A. Kujawa, \"You dirty RAT! Part 1: DarkComet,\" Malwarebytes Labs, blog, Jun. 9, 2012 [Online].",
+ "url": "https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/"
+ },
+ {
+ "source_name": "roccia-shamoon",
+ "description": "R. Roccia, \"Shamoon Attackers Employ New Tool Kit to Wipe Infected Systems,\" McAfee, blog, Dec. 19, 2018 [Online].",
+ "url": "https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-attackers-employ-new-tool-kit-to-wipe-infected-systems/"
+ },
+ {
+ "source_name": "levene-cozycar",
+ "description": "B. Levene, R. Falcone, and R. Wartell, \"Tracking MiniDionis: CozyCar's New Ride Is Related to Seaduke,\" Unit 42 by Palo Alto Networks, Jul 14, 2015 [Online].",
+ "url": "https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke"
+ },
+ {
+ "source_name": "kujawa",
+ "description": "A. Kujawa, \"You dirty RAT! Part 1: DarkComet,\" Malwarebytes Labs, blog, Jun. 9, 2012 [Online].",
+ "url": "https://blog.malwarebytes.com/threat-analysis/2012/06/you-dirty-rat-part-1-darkcomet/"
+ },
+ {
+ "source_name": "roccia-shamoon",
+ "description": "R. Roccia, \"Shamoon Attackers Employ New Tool Kit to Wipe Infected Systems,\" McAfee, blog, Dec. 19, 2018 [Online].",
+ "url": "https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-attackers-employ-new-tool-kit-to-wipe-infected-systems/"
+ },
+ {
+ "source_name": "levene-cozycar",
+ "description": "B. Levene, R. Falcone, and R. Wartell, \"Tracking MiniDionis: CozyCar's New Ride Is Related to Seaduke,\" Unit 42 by Palo Alto Networks, Jul 14, 2015 [Online].",
+ "url": "https://unit42.paloaltonetworks.com/tracking-minidionis-cozycars-new-ride-is-related-to-seaduke"
+ },
+ {
+ "source_name": "sonicwall",
+ "description": "\"Revisiting Vobfus Worm,\" SonicWALL, Mar. 8, 2013 [Online].",
+ "url": "https://securitynews.sonicwall.com/xmlpost/revisiting-vobfus-worm-mar-8-2013/"
+ },
+ {
+ "source_name": "cisa-ar21-039b",
+ "description": "\"MAR-10320115-1.v1 - TEARDROP,\" CISA, Cybersecurity Advisories, Alert Code AR21-039B, Apr. 15, 2021 [Online].",
+ "url": "https://www.cisa.gov/uscert/ncas/analysis-reports/ar21-039b"
+ },
+ {
+ "source_name": "dong-matanbuchus",
+ "description": "C. Dong, \"MATANBUCHUS: Another Loader as a Service Malware,\" Offset Training Solutions, blog, Feb. 15, 2022 [Online].",
+ "url": "https://www.0ffset.net/reverse-engineering/matanbuchus-loader-analysis/"
+ },
+ {
+ "source_name": "cohen-matabuchus",
+ "description": "B. Cohen, \"Inside Matanbuchus: A Quirky Loader,\" CyberArk, blog, Jul. 26, 2022 [Online].",
+ "url": "https://www.cyberark.com/resources/threat-research-blog/inside-matanbuchus-a-quirky-loader"
+ },
+ {
+ "source_name": "hromcov\u00e1",
+ "description": "Z. Hromcov\u00e1, \"Malicious campaign targets South Korean users with backdoor\u2011laced torrents,\" We Live Security, ESET, Jul. 8, 2019 [Online].",
+ "url": "https://www.welivesecurity.com/2019/07/08/south-korean-users-backdoor-torrents/"
+ },
+ {
+ "source_name": "mendrez",
+ "description": "R. Mendrez, \"Gamut Spambot Analysis,\" Trustwave, blog, Mar. 4, 2014 [Online].",
+ "url": "https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/gamut-spambot-analysis/"
+ },
+ {
+ "source_name": "citizen lab",
+ "description": "M. Brooks, J. Dalek, and M. Crete-Nishihata, \"Between Hong Kong and Burma: Tracking UP007 and SLServer Espionage Campaigns,\" The Citizen Lab, Apr. 18, 2016 [Online].",
+ "url": "https://docs.microsoft.com/en-us/windows/win32/winmsg/about-hooks?redirectedfrom=MSDN#hook-procedures"
+ }
+ ]
+ },
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--7cb5847c-f662-4260-bd44-857ffd4975da",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-08-14T00:00:00.000Z",
+ "modified": "2023-12-05T00:00:00.000Z",
+ "name": "Create File",
+ "obj_defn": {
+ "description": "Malware creates a file.",
+ "external_id": "C0016",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/micro-behaviors/file-system/create-file.md"
+ },
+ "objective_refs": [
+ "malware-objective--b535116e-3bd9-42f6-9615-68f24c7b42ed"
+ ],
+ "obj_version": "2.1",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ }
+ },
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--6b99bf51-1fcb-4284-9ae0-d780e46b7825",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-12-04T00:00:00.000Z",
+ "modified": "2024-04-30T00:00:00.000Z",
+ "name": "Read File",
+ "obj_defn": {
+ "description": "Malware reads a file.",
+ "external_id": "C0051",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/micro-behaviors/file-system/read-file.md"
+ },
+ "objective_refs": [
+ "malware-objective--b535116e-3bd9-42f6-9615-68f24c7b42ed"
+ ],
+ "detection_rules": [
+ {
+ "api_fncs": [
+ "kernel32.ReadFile",
+ "ReadFileEx",
+ "NtReadFile",
+ "ZwReadFile",
+ "LZRead",
+ "_read",
+ "fread",
+ "System.IO.File::ReadAllBytes",
+ "System.IO.File::ReadAllBytesAsync",
+ "System.IO.File::ReadAllLines",
+ "System.IO.File::ReadAllLinesAsync",
+ "System.IO.File::ReadAllText",
+ "System.IO.File::ReadAllTextAsync",
+ "System.IO.File::ReadLines"
+ ],
+ "rule_name": "read file on Windows",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/file-system/read/read-file-on-windows.yml"
+ },
+ {
+ "api_fncs": [
+ "kernel32.MapViewOfFile",
+ "kernel32.UnmapViewOfFile",
+ "kernel32.CreateFileMapping"
+ ],
+ "rule_name": "read file via mapping",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/file-system/read/read-file-via-mapping.yml"
+ },
+ {
+ "api_fncs": [
+ "fgetc",
+ "fgets",
+ "getc",
+ "getchar",
+ "read",
+ "getline",
+ "getdelim",
+ "fgetwc",
+ "getwc",
+ "fscanf",
+ "vfscanf",
+ "fread"
+ ],
+ "rule_name": "read file on Linux",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/file-system/read/read-file-on-linux.yml"
+ },
+ {
+ "api_fncs": [
+ "GetPrivateProfileInt",
+ "GetPrivateProfileString",
+ "GetPrivateProfileStruct",
+ "GetPrivateProfileSection",
+ "GetPrivateProfileSectionNames",
+ "GetFullPathName"
+ ],
+ "rule_name": "read .ini file",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/file-system/read/read-ini-file.yml"
+ },
+ {
+ "api_fncs": [
+ "NtReadFile",
+ "NtSetInformationFile",
+ "NtClose",
+ "NtCreateFile",
+ "NtOpenFile"
+ ],
+ "class": "ReadsSelf",
+ "rule_name": "reads_self",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/reads_self.py"
+ },
+ {
+ "rule_name": "accesses_sysvol",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/accesses_sysvol.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "antidebug_devices",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antidebug_devices.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "antiav_detectfile",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antiav_detectfile.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "NtReadFile",
+ "CopyFileA",
+ "CopyFileExW",
+ "CopyFileW"
+ ],
+ "rule_name": "infostealer_browser",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/infostealer_browser.py"
+ },
+ {
+ "rule_name": "antianalysis_detectfile",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/antianalysis_detectfile.py",
+ "rule_type": "cape"
+ }
+ ],
+ "obj_version": "2.3",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "external_references": [
+ {
+ "source_name": "capa analysis",
+ "description": "Analysis output, capa 4.0, analyzed at MITRE on Oct. 12, 2022.",
+ "url": "https://github.com/mandiant/capa-rules"
+ }
+ ]
+ },
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--7cc1a672-d56d-4b3d-915f-e3845b24ef97",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-12-04T00:00:00.000Z",
+ "modified": "2024-04-30T00:00:00.000Z",
+ "name": "Writes File",
+ "obj_defn": {
+ "description": "Malware writes to a file.",
+ "external_id": "C0052",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/micro-behaviors/file-system/writes-file.md"
+ },
+ "objective_refs": [
+ "malware-objective--b535116e-3bd9-42f6-9615-68f24c7b42ed"
+ ],
+ "detection_rules": [
+ {
+ "api_fncs": [
+ "fputc",
+ "fputs",
+ "putc",
+ "write",
+ "fputwc",
+ "putwc",
+ "fputws",
+ "fwrite",
+ "putwchar",
+ "dprintf",
+ "vdprnitf",
+ "fprintf",
+ "vfprintf"
+ ],
+ "rule_name": "write file on Linux",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/file-system/write/write-file-on-linux.yml"
+ },
+ {
+ "api_fncs": [
+ "kernel32.WriteFile",
+ "kernel32.WriteFileEx",
+ "NtWriteFile",
+ "ZwWriteFile",
+ "_fwrite",
+ "fwrite",
+ "System.IO.File::WriteAllBytes",
+ "System.IO.File::WriteAllBytesAsync",
+ "System.IO.File::WriteAllLines",
+ "System.IO.File::WriteAllLinesAsync",
+ "System.IO.File::WriteAllText",
+ "System.IO.File::WriteAllTextAsync",
+ "System.IO.File::AppendAllLines",
+ "System.IO.File::AppendAllLinesAsync",
+ "System.IO.File::AppendAllText",
+ "System.IO.File::AppendAllTextAsync",
+ "System.IO.File::AppendText",
+ "System.IO.FileInfo::AppendText"
+ ],
+ "rule_name": "write file on Windows",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/file-system/write/write-file-on-windows.yml"
+ },
+ {
+ "api_fncs": [
+ "dbghelp.MiniDumpWriteDump"
+ ],
+ "rule_name": "create process memory minidump",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/process/dump/create-process-memory-minidump.yml"
+ },
+ {
+ "class": "UpatreFiles",
+ "rule_name": "upatre_files",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/upatre_files.py"
+ },
+ {
+ "api_fncs": [
+ "NtWriteFile"
+ ],
+ "rule_name": "wiper_zeroedbytes",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/wiper.py"
+ },
+ {
+ "rule_name": "modify_hostsfile",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/modifies_hostsfile.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "writes_sysvol",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/accesses_sysvol.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "ursnif_behavior",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/trojan_ursnif.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "poullight_files",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/infostealer_poullight.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "echelon_files",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/infostealer_echelon.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "apocalypse_stealer_file_behavior",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/infostealer_apocalypse.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "NtWriteFile"
+ ],
+ "rule_name": "masslogger_version",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/infostealer_masslogger.py"
+ },
+ {
+ "api_fncs": [
+ "FindFirstFileExW",
+ "CryptDecrypt"
+ ],
+ "rule_name": "masslogger_artifacts",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/infostealer_masslogger.py"
+ }
+ ],
+ "obj_version": "2.3",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "external_references": [
+ {
+ "source_name": "capa analysis",
+ "description": "Analysis output, capa 4.0, analyzed at MITRE on Oct. 12, 2022.",
+ "url": "https://github.com/mandiant/capa-rules"
+ }
+ ]
+ },
+ {
+ "type": "malware-behavior",
+ "spec_version": "2.1",
+ "id": "malware-behavior--bb415897-9886-4d23-8e61-b421808d6931",
+ "created_by_ref": "identity--b73c59c1-8560-449a-b8d0-c2ce0533c5bf",
+ "created": "2020-12-04T00:00:00.000Z",
+ "modified": "2024-04-30T00:00:00.000Z",
+ "name": "Delete File",
+ "obj_defn": {
+ "description": "Malware deletes a file.",
+ "external_id": "C0047",
+ "source_name": "mitre-mbc",
+ "url": "https://github.com/MBCProject/mbc-markdown/blob/main/micro-behaviors/file-system/delete-file.md"
+ },
+ "objective_refs": [
+ "malware-objective--b535116e-3bd9-42f6-9615-68f24c7b42ed"
+ ],
+ "detection_rules": [
+ {
+ "api_fncs": [
+ "kernel32.DeleteFile",
+ "DeleteFileTransacted",
+ "NtDeleteFile",
+ "ZwDeleteFile",
+ "remove",
+ "_wremove",
+ "System.IO.File::Delete",
+ "System.IO.FileSystemInfo::Delete",
+ "kernel32.SHFileOperation",
+ "MoveFileEx"
+ ],
+ "rule_name": "delete file",
+ "rule_type": "capa",
+ "url": "https://github.com/mandiant/capa-rules/blob/master/host-interaction/file-system/delete/delete-file.yml"
+ },
+ {
+ "class": "ClearsLogs",
+ "rule_name": "clears_logs",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/clears_logs.py"
+ },
+ {
+ "api_fncs": [
+ "DeleteFileW"
+ ],
+ "rule_name": "trickbot_task_delete",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/trickbot_files.py"
+ },
+ {
+ "api_fncs": [
+ "DeleteFileA"
+ ],
+ "rule_name": "upatre_behavior",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/deprecated/upatre_apis.py"
+ },
+ {
+ "api_fncs": [
+ "MoveFileWithProgressW",
+ "MoveFileWithProgressTransactedW",
+ "NtCreateFile",
+ "NtWriteFile"
+ ],
+ "rule_name": "ransomware_file_modifications",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/windows/ransomware_filemodifications.py"
+ },
+ {
+ "api_fncs": [
+ "NtDeleteFile",
+ "DeleteFileW",
+ "DeleteFileA"
+ ],
+ "rule_name": "anomalous_deletefile",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/anomalous_deletefile.py"
+ },
+ {
+ "api_fncs": [
+ "NtDeleteFile",
+ "DeleteFileW",
+ "DeleteFileA",
+ "MoveFileWithProgressW",
+ "MoveFileWithProgressTransactedW"
+ ],
+ "rule_name": "deletes_self",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/deletes_self.py"
+ },
+ {
+ "rule_name": "deletes_files",
+ "url": "https://github.com/CAPESandbox/community/blob/master/modules/signatures/linux/deletes_files.py",
+ "rule_type": "cape"
+ },
+ {
+ "rule_name": "ransomware_recyclebin",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/ransomware_recyclebin.py",
+ "rule_type": "cape"
+ },
+ {
+ "api_fncs": [
+ "DeleteFileW",
+ "DeleteFileA"
+ ],
+ "rule_name": "removes_zoneid_ads",
+ "rule_type": "cape",
+ "url": "https://github.com/CAPESandbox/community/tree/master/modules/signatures/windows/removes_zoneid_ads.py"
+ }
+ ],
+ "obj_version": "2.3",
+ "object_marking_refs": [
+ "marking-definition--093b6375-cd45-4aa3-8f91-6a03ddd7a3d3"
+ ],
+ "extensions": {
+ "extension-definition--d57b7c9c-7fa6-436b-b82c-8e6f69cdc3d0": {
+ "extension_type": "new-sdo"
+ }
+ },
+ "external_references": [
+ {
+ "source_name": "capa analysis",
+ "description": "Analysis output, capa 4.0, analyzed at MITRE on Oct. 12, 2022.",
+ "url": "https://github.com/mandiant/capa-rules"
+ }
+ ]
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--005a06c6-14bf-4118-afa0-ebcd8aebb0c9",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2019-11-27T14:58:00.429Z",
+ "modified": "2024-10-13T16:13:47.770Z",
+ "name": "Scheduled Task",
+ "description": "Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The [schtasks](https://attack.mitre.org/software/S0111) utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel.(Citation: Stack Overflow) In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.(Citation: Red Canary - Atomic Red Team)\n\nAn adversary may use Windows Task Scheduler to execute programs at system startup or on a scheduled basis for persistence. The Windows Task Scheduler can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM). Similar to [System Binary Proxy Execution](https://attack.mitre.org/techniques/T1218), adversaries have also abused the Windows Task Scheduler to potentially mask one-time execution under signed/trusted system processes.(Citation: ProofPoint Serpent)\n\nAdversaries may also create \"hidden\" scheduled tasks (i.e. [Hide Artifacts](https://attack.mitre.org/techniques/T1564)) that may not be visible to defender tools and manual queries used to enumerate tasks. Specifically, an adversary may hide a task from `schtasks /query` and the Task Scheduler by deleting the associated Security Descriptor (SD) registry value (where deletion of this value must be completed using SYSTEM permissions).(Citation: SigmaHQ)(Citation: Tarrask scheduled task) Adversaries may also employ alternate methods to hide tasks, such as altering the metadata (e.g., `Index` value) within associated registry keys.(Citation: Defending Against Scheduled Task Attacks in Windows Environments) ",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "execution"
+ },
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "persistence"
+ },
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "privilege-escalation"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1053/005",
+ "external_id": "T1053.005"
+ },
+ {
+ "source_name": "ProofPoint Serpent",
+ "description": "Campbell, B. et al. (2022, March 21). Serpent, No Swiping! New Backdoor Targets French Entities with Unique Attack Chain. Retrieved April 11, 2022.",
+ "url": "https://www.proofpoint.com/us/blog/threat-insight/serpent-no-swiping-new-backdoor-targets-french-entities-unique-attack-chain"
+ },
+ {
+ "source_name": "Defending Against Scheduled Task Attacks in Windows Environments",
+ "description": "Harshal Tupsamudre. (2022, June 20). Defending Against Scheduled Tasks. Retrieved July 5, 2022.",
+ "url": "https://blog.qualys.com/vulnerabilities-threat-research/2022/06/20/defending-against-scheduled-task-attacks-in-windows-environments"
+ },
+ {
+ "source_name": "Twitter Leoloobeek Scheduled Task",
+ "description": "Loobeek, L. (2017, December 8). leoloobeek Status. Retrieved September 12, 2024.",
+ "url": "https://x.com/leoloobeek/status/939248813465853953"
+ },
+ {
+ "source_name": "Tarrask scheduled task",
+ "description": "Microsoft Threat Intelligence Team & Detection and Response Team . (2022, April 12). Tarrask malware uses scheduled tasks for defense evasion. Retrieved June 1, 2022.",
+ "url": "https://www.microsoft.com/security/blog/2022/04/12/tarrask-malware-uses-scheduled-tasks-for-defense-evasion/"
+ },
+ {
+ "source_name": "Microsoft Scheduled Task Events Win10",
+ "description": "Microsoft. (2017, May 28). Audit Other Object Access Events. Retrieved June 27, 2019.",
+ "url": "https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/audit-other-object-access-events"
+ },
+ {
+ "source_name": "TechNet Scheduled Task Events",
+ "description": "Microsoft. (n.d.). General Task Registration. Retrieved December 12, 2017.",
+ "url": "https://technet.microsoft.com/library/dd315590.aspx"
+ },
+ {
+ "source_name": "Red Canary - Atomic Red Team",
+ "description": "Red Canary - Atomic Red Team. (n.d.). T1053.005 - Scheduled Task/Job: Scheduled Task. Retrieved June 19, 2024.",
+ "url": "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1053.005/T1053.005.md"
+ },
+ {
+ "source_name": "TechNet Autoruns",
+ "description": "Russinovich, M. (2016, January 4). Autoruns for Windows v13.51. Retrieved June 6, 2016.",
+ "url": "https://technet.microsoft.com/en-us/sysinternals/bb963902"
+ },
+ {
+ "source_name": "TechNet Forum Scheduled Task Operational Setting",
+ "description": "Satyajit321. (2015, November 3). Scheduled Tasks History Retention settings. Retrieved December 12, 2017.",
+ "url": "https://social.technet.microsoft.com/Forums/en-US/e5bca729-52e7-4fcb-ba12-3225c564674c/scheduled-tasks-history-retention-settings?forum=winserver8gen"
+ },
+ {
+ "source_name": "SigmaHQ",
+ "description": "Sittikorn S. (2022, April 15). Removal Of SD Value to Hide Schedule Task - Registry. Retrieved June 1, 2022.",
+ "url": "https://github.com/SigmaHQ/sigma/blob/master/rules/windows/registry/registry_delete/registry_delete_schtasks_hide_task_via_sd_value_removal.yml"
+ },
+ {
+ "source_name": "Stack Overflow",
+ "description": "Stack Overflow. (n.d.). How to find the location of the Scheduled Tasks folder. Retrieved June 19, 2024.",
+ "url": "https://stackoverflow.com/questions/2913816/how-to-find-the-location-of-the-scheduled-tasks-folder"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_attack_spec_version": "3.2.0",
+ "x_mitre_contributors": [
+ "Andrew Northern, @ex_raritas",
+ "Bryan Campbell, @bry_campbell",
+ "Zachary Abzug, @ZackDoesML",
+ "Selena Larson, @selenalarson",
+ "Sittikorn Sangrattanapitak"
+ ],
+ "x_mitre_data_sources": [
+ "Windows Registry: Windows Registry Key Creation",
+ "File: File Modification",
+ "File: File Creation",
+ "Process: Process Creation",
+ "Command: Command Execution",
+ "Network Traffic: Network Traffic Flow",
+ "Scheduled Job: Scheduled Job Creation"
+ ],
+ "x_mitre_deprecated": false,
+ "x_mitre_detection": "Monitor process execution from the svchost.exe in Windows 10 and the Windows Task Scheduler taskeng.exe for older versions of Windows. (Citation: Twitter Leoloobeek Scheduled Task) If scheduled tasks are not used for persistence, then the adversary is likely to remove the task when the action is complete. Monitor Windows Task Scheduler stores in %systemroot%\\System32\\Tasks for change entries related to scheduled tasks that do not correlate with known software, patch cycles, etc.\n\nConfigure event logging for scheduled task creation and changes by enabling the \"Microsoft-Windows-TaskScheduler/Operational\" setting within the event logging service. (Citation: TechNet Forum Scheduled Task Operational Setting) Several events will then be logged on scheduled task activity, including: (Citation: TechNet Scheduled Task Events)(Citation: Microsoft Scheduled Task Events Win10)\n\n* Event ID 106 on Windows 7, Server 2008 R2 - Scheduled task registered\n* Event ID 140 on Windows 7, Server 2008 R2 / 4702 on Windows 10, Server 2016 - Scheduled task updated\n* Event ID 141 on Windows 7, Server 2008 R2 / 4699 on Windows 10, Server 2016 - Scheduled task deleted\n* Event ID 4698 on Windows 10, Server 2016 - Scheduled task created\n* Event ID 4700 on Windows 10, Server 2016 - Scheduled task enabled\n* Event ID 4701 on Windows 10, Server 2016 - Scheduled task disabled\n\nTools such as Sysinternals Autoruns may also be used to detect system changes that could be attempts at persistence, including listing current scheduled tasks. (Citation: TechNet Autoruns)\n\nRemote access tools with built-in features may interact directly with the Windows API to perform these functions outside of typical system utilities. Tasks may also be created through Windows system management tools such as Windows Management Instrumentation and PowerShell, so additional logging may need to be configured to gather the appropriate data.",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": true,
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_permissions_required": [
+ "Administrator"
+ ],
+ "x_mitre_platforms": [
+ "Windows"
+ ],
+ "x_mitre_remote_support": true,
+ "x_mitre_version": "1.6"
+ },
+ {
+ "type": "attack-pattern",
+ "spec_version": "2.1",
+ "id": "attack-pattern--8f4a33ec-8b1f-4b80-a2f6-642b2e479580",
+ "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "created": "2017-05-31T21:30:48.728Z",
+ "modified": "2024-04-16T12:43:55.369Z",
+ "name": "Process Discovery",
+ "description": "Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from [Process Discovery](https://attack.mitre.org/techniques/T1057) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nIn Windows environments, adversaries could obtain details on running processes using the [Tasklist](https://attack.mitre.org/software/S0057) utility via [cmd](https://attack.mitre.org/software/S0106) or Get-Process via [PowerShell](https://attack.mitre.org/techniques/T1059/001). Information about processes can also be extracted from the output of [Native API](https://attack.mitre.org/techniques/T1106) calls such as CreateToolhelp32Snapshot. In Mac and Linux, this is accomplished with the ps command. Adversaries may also opt to enumerate processes via `/proc`. \n\nOn network devices, [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands such as `show processes` can be used to display current running processes.(Citation: US-CERT-TA18-106A)(Citation: show_processes_cisco_cmd)",
+ "kill_chain_phases": [
+ {
+ "kill_chain_name": "mitre-attack",
+ "phase_name": "discovery"
+ }
+ ],
+ "external_references": [
+ {
+ "source_name": "mitre-attack",
+ "url": "https://attack.mitre.org/techniques/T1057",
+ "external_id": "T1057"
+ },
+ {
+ "source_name": "show_processes_cisco_cmd",
+ "description": "Cisco. (2022, August 16). show processes - . Retrieved July 13, 2022.",
+ "url": "https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/fundamentals/command/cf_command_ref/show_monitor_permit_list_through_show_process_memory.html#wp3599497760"
+ },
+ {
+ "source_name": "US-CERT-TA18-106A",
+ "description": "US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.",
+ "url": "https://www.us-cert.gov/ncas/alerts/TA18-106A"
+ }
+ ],
+ "object_marking_refs": [
+ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
+ ],
+ "x_mitre_attack_spec_version": "3.2.0",
+ "x_mitre_contributors": [
+ "Austin Clark, @c2defense"
+ ],
+ "x_mitre_data_sources": [
+ "Process: Process Creation",
+ "Process: OS API Execution",
+ "Command: Command Execution"
+ ],
+ "x_mitre_deprecated": false,
+ "x_mitre_detection": "System and network discovery techniques normally occur throughout an operation as an adversary learns the environment. Data and events should not be viewed in isolation, but as part of a chain of behavior that could lead to other activities, such as Lateral Movement, based on the information obtained.\n\nNormal, benign system and network events that look like process discovery may be uncommon, depending on the environment and how they are used. Monitor processes and command-line arguments for actions that could be taken to gather system and network information. Remote access tools with built-in features may interact directly with the Windows API to gather information. Information may also be acquired through Windows system management tools such as [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) and [PowerShell](https://attack.mitre.org/techniques/T1059/001).\n\nFor network infrastructure devices, collect AAA logging to monitor for `show` commands being run by non-standard users from non-standard locations.",
+ "x_mitre_domains": [
+ "enterprise-attack"
+ ],
+ "x_mitre_is_subtechnique": false,
+ "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
+ "x_mitre_platforms": [
+ "Linux",
+ "macOS",
+ "Windows",
+ "Network"
+ ],
+ "x_mitre_version": "1.5"
+ },
+ {
+ "type": "malware",
+ "spec_version": "2.1",
+ "id": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "created": "2025-02-12T15:52:19.753115Z",
+ "modified": "2025-02-12T15:52:19.753115Z",
+ "name": "Latrodectus",
+ "malware_types": [
+ "backdoor"
+ ],
+ "is_family": true,
+ "capabilities": [
+ "anti-debugging",
+ "anti-emulation",
+ "anti-sandbox",
+ "anti-vm",
+ "communicates-with-c2",
+ "determines-c2-server",
+ "exfiltrates-data",
+ "installs-other-components",
+ "self-modifies"
+ ]
+ },
+ {
+ "type": "malware",
+ "spec_version": "2.1",
+ "id": "malware--2c759cf6-3737-4a3e-ae41-9c7f61ac22f4",
+ "created": "2025-02-12T15:52:19.753212Z",
+ "modified": "2025-02-12T15:52:19.753212Z",
+ "name": "IcedID",
+ "is_family": true
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--55820d01-27cc-4216-9174-7028e4f60f8f",
+ "created": "2025-02-12T15:52:19.75629Z",
+ "modified": "2025-02-12T15:52:19.75629Z",
+ "relationship_type": "delivers",
+ "source_ref": "malware-behavior--201961ae-2a71-41f5-bbd0-8c22bbd748de",
+ "target_ref": "malware--2c759cf6-3737-4a3e-ae41-9c7f61ac22f4"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--b96e6e31-a6f2-487f-bb52-14ac8c0f5245",
+ "created": "2025-02-12T15:52:19.756359Z",
+ "modified": "2025-02-12T15:52:19.756359Z",
+ "relationship_type": "related-to",
+ "source_ref": "threat-actor--9bc47404-3f5e-4555-a36d-a303a2b86457",
+ "target_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--9d085d86-d988-48b5-8dfb-f8c2ee6fc3f7",
+ "created": "2025-02-12T15:52:19.756425Z",
+ "modified": "2025-02-12T15:52:19.756425Z",
+ "relationship_type": "related-to",
+ "source_ref": "threat-actor--42b48d39-7f79-4485-8153-e3008073a138",
+ "target_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--19e11644-1c56-4886-9129-49dba33debf0",
+ "created": "2025-02-12T15:52:19.753667Z",
+ "modified": "2025-02-12T15:52:19.753667Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "attack-pattern--005a06c6-14bf-4118-afa0-ebcd8aebb0c9"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--24c6822b-6ac8-4e20-ba72-c83b73de5b44",
+ "created": "2025-02-12T15:52:19.754249Z",
+ "modified": "2025-02-12T15:52:19.754249Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "attack-pattern--8f4a33ec-8b1f-4b80-a2f6-642b2e479580"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--e7283925-a8e1-4975-9388-77455f9bfd73",
+ "created": "2025-02-12T15:52:19.754341Z",
+ "modified": "2025-02-12T15:52:19.754341Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--5e658b0e-6fdc-40cd-8d65-b5f44d8637dd"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--b066dc55-b755-4aaf-8110-e080ca7c2335",
+ "created": "2025-02-12T15:52:19.754416Z",
+ "modified": "2025-02-12T15:52:19.754416Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--73a87642-8eeb-4309-82a8-8f4e88cf104a"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--269465a7-65e8-4b35-806e-44a7580a7560",
+ "created": "2025-02-12T15:52:19.754485Z",
+ "modified": "2025-02-12T15:52:19.754485Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--53f5c51c-ad5d-48b4-862d-bd251f918010"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--f4e916ee-9d95-4093-9c9d-bd4e97f25b03",
+ "created": "2025-02-12T15:52:19.754558Z",
+ "modified": "2025-02-12T15:52:19.754558Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--4b1f3c4b-2197-4a81-90c5-93057e47c4a6"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--e4799b4f-b675-4b8b-a098-e1ef425b8ed9",
+ "created": "2025-02-12T15:52:19.754626Z",
+ "modified": "2025-02-12T15:52:19.754626Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--47a66a67-6cc7-492f-90ae-0e4f198a9d11"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--8f07135d-cbc7-40e6-8777-4e83ba0fc3da",
+ "created": "2025-02-12T15:52:19.754695Z",
+ "modified": "2025-02-12T15:52:19.754695Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--6fcef7e8-e79b-4771-891f-d8d08dbd489e"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--8a27dc9a-8d80-4c3f-bc91-803a4fe530a1",
+ "created": "2025-02-12T15:52:19.754762Z",
+ "modified": "2025-02-12T15:52:19.754762Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--52b5f972-e1ca-4da3-b29e-379ac9311e02"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--a476f52d-1121-46dd-b601-44a352502e8f",
+ "created": "2025-02-12T15:52:19.754827Z",
+ "modified": "2025-02-12T15:52:19.754827Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--58d1341b-5804-4d75-b74b-ebc1a109f628"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--4cab8dc5-3ee3-4da0-b018-6caba430be7b",
+ "created": "2025-02-12T15:52:19.754901Z",
+ "modified": "2025-02-12T15:52:19.754901Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--a271c92f-de0b-4f10-a5ea-ebea24b0e07b"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--2a0f47a9-4cd9-4012-8c33-e6d91640aa04",
+ "created": "2025-02-12T15:52:19.754967Z",
+ "modified": "2025-02-12T15:52:19.754967Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--50cb3a45-bb76-4483-a134-6f6312d44c92"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--e6eef865-31b4-4dc9-9bf4-ec3a5ba364b6",
+ "created": "2025-02-12T15:52:19.755036Z",
+ "modified": "2025-02-12T15:52:19.755036Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--9d13adf5-2774-4ea2-bbb1-ba8e8e3ca7ea"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--cdf21cbf-996a-44de-8215-13abaffd3773",
+ "created": "2025-02-12T15:52:19.755102Z",
+ "modified": "2025-02-12T15:52:19.755102Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--9d13adf5-2774-4ea2-bbb1-ba8e8e3ca7ea"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--5e23a867-2d1c-413b-807d-6247ea361579",
+ "created": "2025-02-12T15:52:19.755168Z",
+ "modified": "2025-02-12T15:52:19.755168Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--f52bfd6d-ddfa-4552-b99b-8558d5eac711"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--b20d500d-16eb-45a5-9cbc-14f25b5c7273",
+ "created": "2025-02-12T15:52:19.755235Z",
+ "modified": "2025-02-12T15:52:19.755235Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--f52bfd6d-ddfa-4552-b99b-8558d5eac711"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--8f733df7-3b4a-473e-aed1-b21bcd1a8b5e",
+ "created": "2025-02-12T15:52:19.755301Z",
+ "modified": "2025-02-12T15:52:19.755301Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--c2ab7efa-d323-4f91-8d48-acf9d35461db"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--984e12bb-f0c4-4620-a907-26f74a7b113f",
+ "created": "2025-02-12T15:52:19.755366Z",
+ "modified": "2025-02-12T15:52:19.755366Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--714905f5-038c-4b03-82f7-3e290ab84743"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--0451887d-d88c-4abc-9051-e240fea88b5c",
+ "created": "2025-02-12T15:52:19.755431Z",
+ "modified": "2025-02-12T15:52:19.755431Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--3a879212-7127-4f91-84ef-7aa65e971ef3"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--8befe6fc-62e0-4129-90ed-aa5a58e6dfd1",
+ "created": "2025-02-12T15:52:19.755497Z",
+ "modified": "2025-02-12T15:52:19.755497Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--af6960c9-b141-4bd0-b4f0-288e52c82645"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--62fcdbcd-a822-4781-963f-ed2324ad7023",
+ "created": "2025-02-12T15:52:19.755562Z",
+ "modified": "2025-02-12T15:52:19.755562Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--610e10e9-530f-4871-9f31-2548e10d2d01"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--a8eab650-e278-4c56-ba7b-3cc9e2840663",
+ "created": "2025-02-12T15:52:19.755626Z",
+ "modified": "2025-02-12T15:52:19.755626Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--ce830efe-16ec-41a4-9fff-41255449d077"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--a87264fe-ce5b-4353-b31c-3ff8792bb70f",
+ "created": "2025-02-12T15:52:19.755691Z",
+ "modified": "2025-02-12T15:52:19.755691Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-method--15a3f947-455e-4b57-b950-b0e52b3ac2c2"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--3af91abd-8630-4df3-96c2-d037219a2190",
+ "created": "2025-02-12T15:52:19.755756Z",
+ "modified": "2025-02-12T15:52:19.755756Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-behavior--19bbde8e-2a08-4ecd-a1e0-44240ed97113"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--2e6b2f98-2c08-41a2-9ad8-142d7fc1f4ff",
+ "created": "2025-02-12T15:52:19.755823Z",
+ "modified": "2025-02-12T15:52:19.755823Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-behavior--3b0f15b6-e989-4cb3-8743-15601847efa1"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--fc666103-edbc-4bac-a5de-f7cc362b58c8",
+ "created": "2025-02-12T15:52:19.755887Z",
+ "modified": "2025-02-12T15:52:19.755887Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-behavior--f710327b-7f89-4b45-9a84-2f5d23b23378"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--1fd3c319-f2ae-4270-b204-91ac2b8995c2",
+ "created": "2025-02-12T15:52:19.755951Z",
+ "modified": "2025-02-12T15:52:19.755951Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-behavior--201961ae-2a71-41f5-bbd0-8c22bbd748de"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--b39ccc66-2cba-4871-b84a-e8b5d1403235",
+ "created": "2025-02-12T15:52:19.756016Z",
+ "modified": "2025-02-12T15:52:19.756016Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-behavior--7cb5847c-f662-4260-bd44-857ffd4975da"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--cf7c5bcf-c35f-4e72-8ca3-2c4978cb7187",
+ "created": "2025-02-12T15:52:19.756081Z",
+ "modified": "2025-02-12T15:52:19.756081Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-behavior--6b99bf51-1fcb-4284-9ae0-d780e46b7825"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--18b35b4e-d3c8-4aa2-8efc-d6b214389c8d",
+ "created": "2025-02-12T15:52:19.756146Z",
+ "modified": "2025-02-12T15:52:19.756146Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-behavior--7cc1a672-d56d-4b3d-915f-e3845b24ef97"
+ },
+ {
+ "type": "relationship",
+ "spec_version": "2.1",
+ "id": "relationship--bcf43629-2624-4fa0-a134-7b9891ed984e",
+ "created": "2025-02-12T15:52:19.756211Z",
+ "modified": "2025-02-12T15:52:19.756211Z",
+ "relationship_type": "uses",
+ "source_ref": "malware--c7e6c857-6891-4c09-953e-16ac17d6a867",
+ "target_ref": "malware-behavior--bb415897-9886-4d23-8e61-b421808d6931"
+ }
+ ]
+}
diff --git a/yvisualization/stix-visualizer/mbc-icons/stix2_malware_behavior_icon_tiny_round_v1.png b/yvisualization/stix-visualizer/mbc-icons/stix2_malware_behavior_icon_tiny_round_v1.png
new file mode 100644
index 0000000..8756a30
Binary files /dev/null and b/yvisualization/stix-visualizer/mbc-icons/stix2_malware_behavior_icon_tiny_round_v1.png differ
diff --git a/yvisualization/stix-visualizer/mbc-icons/stix2_malware_method_icon_tiny_round_v1.png b/yvisualization/stix-visualizer/mbc-icons/stix2_malware_method_icon_tiny_round_v1.png
new file mode 100644
index 0000000..842bb4b
Binary files /dev/null and b/yvisualization/stix-visualizer/mbc-icons/stix2_malware_method_icon_tiny_round_v1.png differ
diff --git a/yvisualization/stix-visualizer/mbc-icons/stix2_malware_objective_icon_tiny_round_v1.png b/yvisualization/stix-visualizer/mbc-icons/stix2_malware_objective_icon_tiny_round_v1.png
new file mode 100644
index 0000000..3e91adb
Binary files /dev/null and b/yvisualization/stix-visualizer/mbc-icons/stix2_malware_objective_icon_tiny_round_v1.png differ
diff --git a/yvisualization/stix-visualizer/stix2viz.js b/yvisualization/stix-visualizer/stix2viz.js
new file mode 100644
index 0000000..fb8e1ca
--- /dev/null
+++ b/yvisualization/stix-visualizer/stix2viz.js
@@ -0,0 +1,1881 @@
+"use strict";
+
+/*
+Configure how embedded relationships (ref properties) are mapped to graph
+edges. This map maps a STIX type to a list of triples, where each triple
+describes an embedded relationship. Each triple consists of (1) a
+property path, (2) an edge label, and (3) a boolean which determines the
+directionality of the edge: true to point to the referent, or false to point
+to the referring object.
+
+The null key maps to embedded relationships which should be checked on all
+object types. This is appropriate for common properties many objects can have.
+
+A property path is a string formatted as a sequence of property names
+separated by dots. See getValuesAtPath().
+*/
+let embeddedRelationships = new Map([
+ [null, [
+ ["created_by_ref", "created-by", true],
+ ["object_marking_refs", "applies-to", false]
+ ]],
+ ["directory", [
+ ["contains_refs", "contains", true]
+ ]],
+ ["domain-name", [
+ ["resolves_to_refs", "resolves-to", true]
+ ]],
+ ["email-addr", [
+ ["belongs_to_ref", "belongs-to", true]
+ ]],
+ ["email-message", [
+ ["from_ref", "from", true],
+ ["sender_ref", "sent-by", true],
+ ["to_refs", "to", true],
+ ["cc_refs", "cc", true],
+ ["bcc_refs", "bcc", true],
+ ["raw_email_ref", "raw-binary-of", false]
+ ]],
+ ["file", [
+ ["contains_refs", "contains", true],
+ ["content_ref", "contents-of", false],
+ ["parent_directory_ref", "parent-of", false]
+ ]],
+ ["grouping", [
+ ["object_refs", "refers-to", true]
+ ]],
+ ["ipv4-addr", [
+ ["resolves_to_refs", "resolves-to", true]
+ ]],
+ ["ipv6-addr", [
+ ["resolves_to_refs", "resolves-to", true]
+ ]],
+ ["language-content", [
+ ["object_ref", "applies-to", true]
+ ]],
+ ["malware", [
+ ["sample_refs", "sample-of", false]
+ ]],
+ ["malware-behavior", [
+ ["extensions.extension-definition--8e9e338f-c9ee-4d4f-8cac-85b4dcfdf3c1.related_object_refs", "related-to", false]
+ // ["contributor_refs", "contributed-by", false]
+ ]],
+ ["malware-method", [
+ ["extensions.extension-definition--8e9e338f-c9ee-4d4f-8cac-85b4dcfdf3c1.behavior_ref", "demonstrates", false]
+ ]],
+ ["malware-objective", [
+ ["extensions.extension-definition--8e9e338f-c9ee-4d4f-8cac-85b4dcfdf3c1.created_by_ref", "created-by", false],
+ ["extensions.extension-definition--8e9e338f-c9ee-4d4f-8cac-85b4dcfdf3c1.object_marking_refs", "applies-to", false]
+ ]],
+ ["malware-analysis", [
+ ["analysis_sco_refs", "captured-by", false]
+ ]],
+ ["network-traffic", [
+ ["src_ref", "source-of", false],
+ ["dst_ref", "destination-of", false],
+ ["src_payload_ref", "source-payload-of", false],
+ ["dst_payload_ref", "destination-payload-of", false],
+ ["encapsulates_refs", "encapsulated-by", false],
+ ["encapsulated_by_ref", "encapsulated-by", true]
+ ]],
+ ["note", [
+ ["object_refs", "refers-to", true]
+ ]],
+ ["observed-data", [
+ ["object_refs", "refers-to", true]
+ ]],
+ ["opinion", [
+ ["object_refs", "refers-to", true]
+ ]],
+ ["process", [
+ ["opened_connection_refs", "opened-by", false],
+ ["creator_user_ref", "created-by", true],
+ ["image_ref", "image-of", false],
+ ["parent_ref", "parent-of", false]
+ ]],
+ ["report", [
+ ["object_refs", "refers-to", true]
+ ]],
+ ["sighting", [
+ ["sighting_of_ref", "sighting-of", true],
+ ["observed_data_refs", "observed", true],
+ ["where_sighted_refs", "saw", false]
+ ]],
+ ["windows-registry-key", [
+ ["creator_user_ref", "created-by", true]
+ ]],
+ ["attack-pattern", [
+ ["created_by_ref", "created-by", false]
+ ]]
+]);
+
+
+// Defines operator support for the mongo-ish match algorithm.
+let valueOps = new Map([
+ ["$eq", (a, b) => a === b],
+ ["$gt", (a, b) => a > b],
+ ["$gte", (a, b) => a >= b],
+ ["$in", (val, arr) => arr.includes(val)],
+ ["$lt", (a, b) => a < b],
+ ["$lte", (a, b) => a <= b],
+ ["$ne", (a, b) => a !== b],
+ ["$nin", (val, arr) => !arr.includes(val)]
+]);
+
+
+/**
+ * Instances represent general invalid STIX content passed into the visualizer.
+ */
+class STIXContentError extends Error
+{
+ constructor(message=null, opts=null)
+ {
+ // Use a default generic message.
+ if (!message)
+ message = "Invalid STIX content: expected a non-empty mapping"
+ + " (object or Map) which is a single STIX object or bundle with"
+ + " at least one object, or a non-empty array of objects.";
+
+ super(message, opts);
+ }
+}
+
+
+/**
+ * Instances represent a particular invalid STIX object.
+ */
+class InvalidSTIXObjectError extends STIXContentError
+{
+ constructor(stixObject, opts=null)
+ {
+ let message = "Invalid STIX object: requires at least type and id"
+ + " properties";
+
+ // May as well give some extra info if we know it. It may seem
+ // silly to say we require an id property... and them give the value
+ // of the id property! I think users will get the idea.
+ let stixId = stixObject.get("id");
+ if (stixId)
+ message += ": " + stixId;
+
+ super(message, opts);
+
+ this.stixObject = stixObject;
+ }
+}
+
+
+/**
+ * Instances represent an invalid configuration value.
+ */
+class InvalidConfigError extends Error
+{
+ constructor(message=null, opts=null)
+ {
+ if (!message)
+ message = "Invalid configuration value: must be a JSON or"
+ + " Javascript object.";
+
+ super(message, opts);
+ }
+}
+
+
+/**
+ * Instances represent an invalid operator in match criteria for STIX objects.
+ */
+class InvalidMatchOperator extends Error
+{
+ constructor(op=null, opts=null)
+ {
+ let message = "In match criteria, invalid operator: " + op;
+
+ super(message, opts);
+ }
+}
+
+
+/**
+ * Determine whether the given value is a plain javascript object. E.g. one
+ * which was given as an object literal.
+ */
+function isPlainObject(value)
+{
+ let result = false;
+
+ // null/undefined would cause errors in Object.getPrototypeOf(), and
+ // {} and [] are actually truthy in javascript! I don't think anything
+ // falsey could be a plain object.
+ if (value)
+ // https://stackoverflow.com/questions/52001739/what-is-considered-a-plain-object
+ result = Object.getPrototypeOf(value) === Object.prototype;
+
+ return result;
+}
+
+
+/**
+ * A JSON.parse() "reviver" function which may be used to cause JSON.parse()
+ * to produce a Map instead of a plain javascript object (from a JSON object).
+ */
+function mapReviver(key, value)
+{
+ if (isPlainObject(value))
+ return new Map(Object.entries(value));
+ else
+ return value;
+}
+
+
+/**
+ * Recursively search through the given value and convert all plain objects
+ * found into Map's.
+ */
+function recursiveObjectToMap(obj)
+{
+ let newValue;
+
+ if (isPlainObject(obj))
+ {
+ let map = new Map();
+ for (let [key, value] of Object.entries(obj))
+ map.set(key, recursiveObjectToMap(value));
+
+ newValue = map;
+ }
+ else if (Array.isArray(obj))
+ newValue = obj.map(recursiveObjectToMap);
+ else
+ newValue = obj;
+
+ return newValue;
+}
+
+
+/**
+ * Convert the given content to a data structure which uses Maps. E.g. for
+ * strings, do the same thing as normal JSON.parse(), but translate JSON
+ * objects into Javascript Maps instead of plain objects. For plain objects,
+ * convert them and their sub-objects to Maps. That way we can use more sane
+ * container types.
+ *
+ * @param jsonContent A JSON string, plain object, or array
+ * @return The converted content
+ */
+function parseToMap(jsonContent)
+{
+ let newValue;
+
+ if (typeof jsonContent === "string" || jsonContent instanceof String)
+ newValue = JSON.parse(jsonContent, mapReviver);
+ else
+ newValue = recursiveObjectToMap(jsonContent);
+
+ return newValue;
+}
+
+/**
+ * Check value(s) for a match against some criteria. This is inspired by
+ * Mongo queries, but isn't the same. It is Mongo-ish. The value(s) to be
+ * checked are inside the given object, identified by the given property path.
+ *
+ * This function differs from mongoishMatchObject() in that it operates on
+ * potentially multiple values instead of just one (due to the propPath
+ * selector), and it supports the "$exists" operator at the top level to check
+ * existence.
+ *
+ * The "$exists" key must be mapped to a boolean value. If the mapped
+ * value is true, the check evaluates to true iff any values are selected by
+ * propPath. If the mapped value is false, the check evaluates to true iff no
+ * value is selected by propPath.
+ *
+ * Otherwise, it behaves analogously to the aforementioned function. See its
+ * documentation for more details.
+ *
+ * @param object A Map instance
+ * @param propPath A property path which selects some values within object
+ * @param criteria Some match criteria
+ * @return true if any of the selected values match; false otherwise
+ */
+function mongoishMatchProperty(object, propPath, criteria)
+{
+ // Separate various types of criteria.
+ let logicalCriteria = new Map();
+ let valueCriteria = new Map();
+ let presenceCriteria = new Map();
+
+ if (criteria instanceof Map)
+ {
+ for (let [critPropName, critPropValue] of criteria)
+ {
+ if (["$and", "$or", "$not"].includes(critPropName))
+ logicalCriteria.set(critPropName, critPropValue);
+ else if (valueOps.has(critPropName))
+ valueCriteria.set(critPropName, critPropValue);
+ else if (critPropName === "$exists")
+ presenceCriteria.set(critPropName, critPropValue);
+ else if (critPropName.startsWith("$"))
+ throw new InvalidMatchOperator(critPropName);
+ else
+ // Another property path style check
+ valueCriteria.set(critPropName, critPropValue);
+ }
+ }
+ else
+ // Non-map: treat the same as a plain equality check.
+ valueCriteria.set("$eq", criteria);
+
+ let result = true;
+
+ // Check logical criteria
+ for (let [logicalOp, subCriteria] of logicalCriteria)
+ {
+ if (logicalOp === "$or")
+ {
+ let orResult = false;
+ for (let subCriterion of subCriteria)
+ if (mongoishMatchProperty(object, propPath, subCriterion))
+ {
+ orResult = true;
+ break;
+ }
+
+ result &&= orResult;
+ }
+ else if (logicalOp === "$and")
+ {
+ let andResult = true;
+ for (let subCriterion of subCriteria)
+ if (!mongoishMatchProperty(object, propPath, subCriterion))
+ {
+ andResult = false;
+ break;
+ }
+
+ result &&= andResult;
+ }
+ else // logicalOp === "$not"
+ result &&= !mongoishMatchProperty(
+ object, propPath, subCriteria
+ );
+
+ if (!result)
+ break;
+ }
+
+ let anyValuesFound = false;
+ if (result)
+ {
+ // Check value criteria. If there aren't any, this check trivially
+ // passes. But we still need to go as far as ascertaining whether any
+ // values exist which match the propPath selector. That is necessary
+ // for any subsequent presence checking.
+ //
+ // If there are any value criteria, the implied per-value checks here
+ // are implicitly OR'd.
+ if (valueCriteria.size > 0)
+ result = false;
+
+ for (let propValue of getValuesAtPath(object, propPath))
+ {
+ anyValuesFound = true;
+
+ // If already trivially passed (see above), this loop really just
+ // acts to tell whether the property path refers to any values.
+ // There is no need to test any values against criteria. If we are
+ // in this loop body, we found a referent value.
+ if (result)
+ break;
+
+ result = mongoishMatchObject(propValue, valueCriteria);
+
+ if (result)
+ break;
+ }
+ }
+
+ // Check presence criteria.
+ if (result)
+ {
+ // Hard-code handling of the only presence criterion we support.
+ if (presenceCriteria.has("$exists"))
+ {
+ let exists = presenceCriteria.get("$exists"); // true or false
+ result &&= (exists === anyValuesFound);
+ }
+ }
+
+ return result;
+}
+
+
+/**
+ * Check a value for a match against some criteria. This is inspired by
+ * Mongo queries, but isn't the same. It is Mongo-ish.
+ *
+ * The value and criteria can be anything. It is most interesting though, if
+ * both are Map instances. If neither is a Map, this acts as an equality check
+ * (using "===", with the weirdness that entails). If the value is a Map and
+ * criteria is not, it's an automatic non-match. If value is not a Map but
+ * criteria is, one can obtain simple comparisons using some Mongo-style
+ * operators, e.g. "$lt".
+ *
+ * Criteria as a Map is a conjunction of a few types of checks (i.e. all checks
+ * are implicitly AND'd): logical, value, and property. The last is applicable
+ * only to Map values since others don't have any properties. Each key/value
+ * pair constitutes one of these types of checks, as follows:
+ *
+ * If the key is "$and", "$or", or "$not", then it is a logical check. The
+ * key must map to an array of checks in the first two cases, and any check in
+ * the latter case. For "$not", the mapped check is performed and the result
+ * is simply inverted. It does *not* invert nested operators.
+ *
+ * If the key is "$eq", "$gt", "$gte" "$in", "$lt", "$lte" "$ne", "$nin",
+ * then it is a "value" check, i.e. a check of the value as a whole, not any
+ * of its properties (if applicable). The "$in" and "$nin" operators must be
+ * mapped to arrays (they mean "in" and "not in" the given array).
+ *
+ * A string property name which does not begin with a "$" is treated as a
+ * property path, i.e. a type of "selector" of values within a Map. The
+ * property path maps to some check. The result is a disjunction over checks
+ * of all selected values, i.e. it is implicitly OR'd. See getValuesAtPath()
+ * for property path syntax and semantics. Property path checks support an
+ * additional "$exists" operator to check whether any values are selected (the
+ * values themselves are irrelevant). This amounts to a type of existence
+ * check. See mongoishMatchProperty() for for details on "$exists".
+ *
+ * For example, given:
+ *
+ * {
+ * "foo": [
+ * {"bar": 1}
+ * {"bar": 2}
+ * ]
+ * }
+ *
+ * Criteria:
+ *
+ * {"foo.bar": 1} results in a match
+ * {"foo.bar": {"$or": [2, 3]}} results in a match
+ * {"foo.bar": {"$in": [2, 3]}} results in a match
+ * {"foo.bar": {"$nin": [2, 3]}} results in a match
+ * {"foo.bar": {"$not": {"$in": [2, 3]}}} results in no match
+ *
+ * Firstly, the "foo.bar" path selects both 1 and 2 from the mapping.
+ *
+ * 1 results in a match because the check (as with all of the criteria) is
+ * implicitly OR'd across all selected values. Also, non-Map value/criteria is
+ * treated as a simple equality check. So this is equivalent to
+ * (1 === 1 || 2 === 1).
+ *
+ * $or and $in wound up being the same, but $or's mapped value is treated as an
+ * array of arbitrary sub-criteria, whereas $in uses the array literally
+ * (Array.includes() is used), so it is only suited to simple values. $in may
+ * also be more efficient, where applicable.
+ *
+ * $in and $nin both result in a match because the first looks for a value in
+ * [2, 3] and the second looks for a value not in [2, 3], and a satisfying
+ * value exists in both cases. The $not $in case results in no match because
+ * $not inverts result of the $in check. As noted, the $in check results in
+ * true, so the inverse is false. This shows that using $not and inverting an
+ * operator don't necessarily result in the same behavior.
+ *
+ * @param value Some value to check
+ * @param criteria Some criteria to check for
+ * @return true if value matches the criteria; false if not
+ */
+function mongoishMatchObject(value, criteria)
+{
+ let result = true;
+
+ // Separate various types of criteria.
+ let logicalCriteria = new Map();
+ let valueCriteria = new Map();
+ let propValueCriteria = new Map();
+
+ if (criteria instanceof Map)
+ {
+ // Map criteria can check properties of a map value, and can also check
+ // non-map values (in the latter case, the criteria keys must be
+ // operators, e.g. "$lt").
+ for (let [critKey, critValue] of criteria)
+ {
+ if (["$and", "$or", "$not"].includes(critKey))
+ logicalCriteria.set(critKey, critValue);
+ else if (valueOps.has(critKey))
+ valueCriteria.set(critKey, critValue);
+ else if (critKey.startsWith("$"))
+ throw new InvalidMatchOperator(critKey);
+ else
+ // Key is a property path.
+ propValueCriteria.set(critKey, critValue);
+ }
+ }
+ else if (value instanceof Map)
+ // Non-map criteria is not applicable to a map value. Not sure what
+ // the semantics would be... e.g. comparing a Map to 4. What would
+ // that mean? Just treat as a non-match.
+ result = false;
+ else
+ // A non-map criteria can be a check on a non-map value. Just treat as
+ // an equality check.
+ valueCriteria.set("$eq", criteria);
+
+ // Check logical criteria
+ if (result)
+ {
+ for (let [logicalOp, subCriteria] of logicalCriteria)
+ {
+ if (logicalOp === "$or")
+ {
+ let orResult = false;
+ for (let subCriterion of subCriteria)
+ if (mongoishMatchObject(value, subCriterion))
+ {
+ orResult = true;
+ break;
+ }
+
+ result &&= orResult;
+ }
+ else if (logicalOp === "$and")
+ {
+ let andResult = true;
+ for (let subCriterion of subCriteria)
+ if (!mongoishMatchObject(value, subCriterion))
+ {
+ andResult = false;
+ break;
+ }
+
+ result &&= andResult;
+ }
+ else // logicalOp === "$not"
+ result &&= !mongoishMatchObject(value, subCriteria);
+
+ if (!result)
+ break;
+ }
+ }
+
+ // Check value criteria
+ if (result)
+ {
+ for (let [op, operand] of valueCriteria)
+ {
+ let opFunc = valueOps.get(op);
+ result &&= opFunc(value, operand);
+
+ if (!result)
+ break;
+ }
+ }
+
+ // Check property value criteria
+ if (result)
+ {
+ for (let [propPath, criteria] of propValueCriteria)
+ {
+ if (value instanceof Map)
+ result &&= mongoishMatchProperty(value, propPath, criteria);
+ else
+ // Kind of an n/a situation. Criteria is given as if it was to
+ // be used with a map (including property paths), but this
+ // value is not a map! Well it can't match, so just eval to
+ // false.
+ result = false;
+
+ if (!result)
+ break;
+ }
+ }
+
+ return result;
+}
+
+
+/**
+ * Perform a simple sanity check on a STIX object to determine whether it's
+ * valid.
+ *
+ * @param stixObject The STIX object
+ * @return true if the object is valid; false if not
+ */
+function isValidStixObject(stixObject)
+{
+ // assume we've gone through the normalization process such that we
+ // can assume we have a Map object. This is more about whether an object
+ // has what we need, than whether we have an object in the first place.
+ return stixObject.has("id") && stixObject.has("type");
+}
+
+
+/**
+ * Sometimes we want to restrict attention to STIX types which are usable as
+ * nodes in our graph. (relationships are notably invalid for this.)
+ *
+ * @param stixType A STIX type
+ * @return true if the type is usable as a node, false if not
+ */
+function isStixTypeValidForNode(stixType)
+{
+ return stixType !== "relationship";
+}
+
+
+/**
+ * Sometimes we want to restrict attention to STIX types which are usable as
+ * nodes in our graph. (relationships are notably invalid for this.)
+ * This function is useful for object references, which are STIX IDs.
+ *
+ * @param stixId A STIX ID
+ * @return true if the type embedded within the ID is usable as a node, false
+ * if not
+ */
+function isStixIdValidForNode(stixId)
+{
+ // length of UUIDs is 36 chars, plus 2 for the "--"
+ let typeLength = stixId.length - 38;
+ let stixType = stixId.substring(0, typeLength);
+
+ return isStixTypeValidForNode(stixType);
+}
+
+
+/**
+ * Given a name, modify it to make it unique: add a "(n)" suffix depending
+ * on the content of nameCounts. nameCounts contains the number of times the
+ * name was previously seen. nameCounts is updated as necessary.
+ *
+ * @param baseName A computed name, which may not be unique
+ * @param nameCounts Bookkeeping to support uniquefication, mapping previously
+ * seen base names to counts
+ * @return A uniquefied name
+ */
+function uniquefyName(baseName, nameCounts)
+{
+ let uniqueName;
+ let nameCount = nameCounts.get(baseName) || 0;
+
+ ++nameCount;
+ nameCounts.set(baseName, nameCount);
+
+ if (nameCount === 1)
+ uniqueName = baseName;
+ else
+ uniqueName = baseName + "(" + nameCount.toString() + ")";
+
+ return uniqueName;
+}
+
+
+/**
+ * Find a name for the given STIX object. This will be the label users see
+ * in the graph. If a name has already been computed for the object, it is
+ * returned. Otherwise, a new name is computed and data structures updated
+ * (stixIdToName and nameCounts).
+ *
+ * @param stixObject a STIX object
+ * @param stixIdToName A mapping from IDs of STIX objects to previously
+ * computed names.
+ * @param nameCounts A mapping from names to counts, used to uniquefy new names.
+ * @param config A config object containing preferences for naming objects;
+ * null to use defaults
+ * @return A name
+ */
+function nameForStixObject(stixObject, stixIdToName, nameCounts, config=null)
+{
+ let stixId = stixObject.get("id");
+ let stixType = stixObject.get("type");
+
+ let name = stixIdToName.get(stixId);
+ if (!name)
+ {
+ let baseName;
+ let userLabels;
+
+ // Look for an ID-specific label; if that fails, look for a
+ // type-specific label; if that fails, use some hard-coded fallbacks,
+ // which eventually just default to using the STIX type.
+ if (config)
+ {
+ userLabels = config.get("userLabels");
+ if (userLabels)
+ baseName = userLabels.get(stixId);
+
+ if (!baseName)
+ {
+ let typeConfig = config.get(stixType);
+ if (typeConfig)
+ {
+ let labelPropName = typeConfig.get("displayProperty");
+ if (labelPropName)
+ baseName = stixObject.get(labelPropName);
+ }
+ }
+ }
+
+ // Copied from old visualizer, fall back to some hard-coded properties
+ if (!baseName)
+ baseName = stixObject.get("name");
+ if (!baseName)
+ baseName = stixObject.get("value");
+ if (!baseName)
+ baseName = stixObject.get("path");
+ if (!baseName)
+ baseName = stixType;
+
+ // Copied from old visualizer: ensure the name isn't too long.
+ if (baseName.length > 40)
+ baseName = baseName.substr(0,40) + '...';
+
+ name = uniquefyName(baseName, nameCounts);
+ stixIdToName.set(stixId, name);
+ }
+
+ return name;
+}
+
+
+/**
+ * Create a URL to an icon file for the given STIX type. This does not check
+ * whether the icon file actually exists.
+ *
+ * @param stixType the STIX type to get a URL for
+ * @param iconPath A path to prepend to an icon filename. The path is
+ * prepended as /, i.e. it is separated from the filename
+ * with a forward slash. If null/undefined, don't prepend a path.
+ * @param iconFileName An icon file name. If falsey, a default is constructed
+ * from the given STIX type.
+ * @return A URL of an icon for the given STIX type
+ */
+function stixTypeToIconURL(stixType, iconPath, iconFileName)
+{
+ let iconUrl;
+
+ if (!iconFileName)
+ iconFileName = "stix2_"
+ + stixType.replaceAll("-", "_")
+ + "_icon_tiny_round_v1.png";
+
+ if (iconPath === null || iconPath === undefined)
+ iconUrl = iconFileName;
+ else
+ iconUrl = iconPath + "/" + iconFileName;
+
+ return iconUrl;
+}
+
+
+/**
+ * Create an object representing a visjs network edge. Any changes to edge
+ * config settings can be made here.
+ *
+ * @param sourceRef STIX ID of the source object
+ * @param targetRef STIX ID of the dest object
+ * @param label A label to be associated with the edge
+ * @param stixId If this edge represents a relationship SRO, the STIX ID of
+ * the SRO. If it represents another type of relationship (e.g. an
+ * embedded relationship), this can be null.
+ * @return An edge object
+ */
+function makeEdgeObject(sourceRef, targetRef, label, stixId=null)
+{
+ let edge = {
+ from: sourceRef,
+ to: targetRef,
+ label: label
+ };
+
+ if (stixId)
+ edge.id = stixId;
+
+ return edge;
+}
+
+
+/**
+ * Create an object representing an visjs network node. Any changes to node
+ * config settings can be made here.
+ *
+ * @param name A node name; will be used to label the node in the graph
+ * @param stixObject The STIX object. Provided in case any info from it is
+ * needed for configuring the node
+ * @return A node object
+ */
+function makeNodeObject(name, stixObject)
+{
+ let node = {
+ id: stixObject.get("id"),
+ label: name
+ };
+
+ return node;
+}
+
+
+/**
+ * Create a fallback icon URL to use any time the usual STIX type based
+ * icon file is not found. (Implied: this default is the same, regardless of
+ * STIX type.) Of course, this fallback *should* be known to always exist!
+ *
+ * @param iconPath The user-configured setting for the icon directory, in case
+ * it is relevant for the fallback; null if one was not configured.
+ * @return A URL to an icon
+ */
+function getDefaultIconURL(iconPath=null)
+{
+ let defaultURL = stixTypeToIconURL('custom_object', iconPath, null);
+ defaultURL = defaultURL.replace('.png', '.svg');
+
+ return defaultURL;
+}
+
+
+/**
+ * Make a data structure which is suitable for an external entity to create a
+ * legend.
+ *
+ * @param stixIdToObject A mapping from STIX IDs to Map instances containing
+ * all STIX objects
+ * @param config Config data used for finding icons for legend entries; null
+ * to use default settings (a Map instance)
+ * @return A [iconURLs, defaultIconURL] 2-tuple, where iconURLs is a Map
+ * instance which maps STIX type to a URL, and defaultIconURL is a
+ * fallback URL in case the URL in the mapping does not resolve.
+ */
+function makeLegendData(stixIdToObject, config=null)
+{
+ let iconPath = null;
+ if (config)
+ iconPath = config.get("iconDir");
+
+ let defaultIconURL = getDefaultIconURL(iconPath);
+
+ let stixTypes = new Set();
+
+ // collect our types
+ for (let object of stixIdToObject.values())
+ {
+ let stixType = object.get("type");
+ if (isStixTypeValidForNode(stixType))
+ stixTypes.add(stixType);
+ }
+
+ let iconURLs = new Map();
+ for (let type of stixTypes)
+ {
+ // Choose an icon file according to config settings
+ let iconFileName;
+
+ if (config)
+ {
+ let typeConfig = config.get(type);
+ if (typeConfig)
+ iconFileName = typeConfig.get("displayIcon");
+ }
+
+ let iconURL = stixTypeToIconURL(type, iconPath, iconFileName);
+
+ iconURLs.set(type, iconURL);
+ }
+
+ return [iconURLs, defaultIconURL];
+}
+
+
+/**
+ * Config can be given as JSON or an object. Normalize whatever we are given
+ * to a Map.
+ *
+ * @param config configuration as given to this module
+ * @return A configuration Map
+ * @throw InvalidConfigError if the given config value is invalid
+ */
+function normalizeConfig(config)
+{
+ try
+ {
+ config = parseToMap(config)
+ }
+ catch(err)
+ {
+ throw new InvalidConfigError(null, {cause: err});
+ }
+
+ if (!(config instanceof Map))
+ throw new InvalidConfigError();
+
+ return config;
+}
+
+
+/**
+ * STIX content input can take different forms. This function normalizes it to
+ * an array of objects, so subsequent code only deals with a single form. Each
+ * object is itself normalized to a Map instance (as are all sub-objects).
+ *
+ * This function also does some simple sanity checks on the input to try to
+ * ensure it is valid.
+ *
+ * @param stixContent STIX content consisting of a single STIX object, array of
+ * objects, or bundle of objects, as a plain javascript object, array,
+ * Map instance, or JSON string.
+ * @return An array of objects
+ * @throw STIXContentError if any errors are found in the input
+ */
+function normalizeContent(stixContent)
+{
+ let stixObjects;
+
+ try
+ {
+ stixContent = parseToMap(stixContent);
+ }
+ catch (err)
+ {
+ throw new STIXContentError(null, {cause: err});
+ }
+
+ if (stixContent instanceof Map && stixContent.size > 0)
+ {
+ if (stixContent.get("type") === "bundle")
+ stixObjects = stixContent.get("objects") || [];
+ else
+ // Assume we were given a single object
+ stixObjects = [stixContent];
+ }
+ else if (Array.isArray(stixContent))
+ stixObjects = stixContent;
+ else
+ throw new STIXContentError();
+
+ if (!Array.isArray(stixObjects) || stixObjects.length <= 0)
+ throw new STIXContentError();
+
+ // Do a simple validity check on our individual STIX objects.
+ for (let stixObject of stixObjects)
+ if (!isValidStixObject(stixObject))
+ throw new InvalidSTIXObjectError(stixObject);
+
+ return stixObjects;
+}
+
+
+/**
+ * Abstract base class for views of STIX-derived graph data.
+ */
+class STIXContentView
+{
+ #legendData;
+
+ constructor(stixIdToObject, config=null)
+ {
+ this.#legendData = makeLegendData(stixIdToObject, config);
+ }
+
+ /**
+ * Get a data structure which is suitable for an external entity to create
+ * a legend.
+ *
+ * @return A [iconURLs, defaultIconURL] 2-tuple, where iconURLs is a Map
+ * instance which maps STIX type to a URL, and defaultIconURL is a
+ * fallback URL in case the URL in the mapping does not resolve.
+ */
+ get legendData()
+ {
+ return this.#legendData;
+ }
+
+ /**
+ * Add an event listener to the view. Events/semantics depends on the
+ * view.
+ */
+ on(...args)
+ {
+ }
+
+ /**
+ * Dispose of the view to free up resources.
+ */
+ destroy()
+ {
+ }
+
+ /**
+ * Toggle display of view elements of a particular STIX type.
+ *
+ * @param stixType the STIX type whose nodes should be toggled
+ */
+ toggleStixType(stixType)
+ {
+ }
+
+ /**
+ * Set the selection to the view element corresponding to the given STIX
+ * ID.
+ *
+ * @param stixId the STIX ID of the node to select
+ */
+ selectNode(stixId)
+ {
+ }
+}
+
+
+/**
+ * A view of STIX-derived graph data which is a simple textual list.
+ */
+class ListView extends STIXContentView
+{
+ #containerRoot;
+ #contentRoot;
+ #stixIdToObject;
+ #selectedId;
+
+ /**
+ * Initialize a list view.
+ *
+ * @param domElement the parent element where the graph is to be located in
+ * a web page
+ * @param nodeDataSet A visjs DataSet instance with graph node data derived
+ * from STIX content
+ * @param edgeDataSet A visjs DataSet instance with graph edge data derived
+ * from STIX content
+ * @param stixIdToObject A Map instance mapping STIX IDs to STIX objects as
+ * Maps, containing STIX content.
+ * @param config A config object
+ */
+ constructor(
+ domElement, nodeDataSet, edgeDataSet, stixIdToObject, config=null
+ )
+ {
+ if (config !== null)
+ config = normalizeConfig(config);
+
+ super(stixIdToObject, config);
+
+ this.#containerRoot = domElement;
+ this.#stixIdToObject = stixIdToObject;
+
+ let doc = domElement.ownerDocument;
+ let ol = doc.createElement("ol");
+
+ nodeDataSet.forEach((item, id) => {
+ let stixObject = stixIdToObject.get(id);
+ let itemText = stixObject.get("type") + ": " + item.label;
+
+ let li = doc.createElement("li");
+ li.id = id;
+ li.className = "list-view-item";
+ ol.append(li);
+ li.append(itemText);
+ });
+
+ edgeDataSet.forEach((item, id) => {
+ let fromItem = nodeDataSet.get(item.from);
+ let toItem = nodeDataSet.get(item.to);
+
+ let itemText = fromItem.label
+ + " " + item.label
+ + " " + toItem.label;
+
+ if (!stixIdToObject.has(id))
+ itemText += " (embedded)";
+
+ let li = doc.createElement("li");
+ li.id = id;
+ li.className = "list-view-item";
+ ol.append(li);
+ li.append(itemText);
+ });
+
+ this.#contentRoot = ol;
+ this.#containerRoot.append(ol);
+
+ this.#selectedId = null;
+ }
+
+ /**
+ * Adds a plain HTML event listener to the content root element of this
+ * view.
+ */
+ on(...args)
+ {
+ this.#contentRoot.addEventListener(...args);
+ }
+
+ /**
+ * Remove all the DOM nodes associated with this view.
+ */
+ destroy()
+ {
+ this.#containerRoot.replaceChildren();
+ }
+
+ /**
+ * Toggle visibility of list items corresponding to STIX objects of the
+ * given type.
+ *
+ * @param stixType the STIX type whose items should be toggled
+ */
+ toggleStixType(stixType)
+ {
+ let listItems = this.#contentRoot.getElementsByTagName("li");
+
+ for (let idx=0; idx < listItems.length; ++idx)
+ {
+ let li = listItems[idx];
+ let stixObject = this.#stixIdToObject.get(li.id);
+
+ if (stixObject && stixObject.get("type") === stixType)
+ li.classList.toggle("hidden");
+ }
+ }
+
+ /**
+ * Set the graph selection to the node corresponding to the given STIX ID.
+ *
+ * @param stixId the STIX ID of the node to select
+ */
+ selectNode(stixId)
+ {
+ let doc = this.#contentRoot.ownerDocument;
+
+ // de-select the previous item, if any
+ if (this.#selectedId)
+ {
+ let oldLi = doc.getElementById(this.#selectedId);
+ if (oldLi)
+ oldLi.classList.remove("list-view-selected");
+ }
+
+ let li = doc.getElementById(stixId);
+ if (li)
+ {
+ li.classList.add("list-view-selected");
+ this.#selectedId = stixId;
+ li.scrollIntoView({block: "nearest"});
+ }
+ }
+}
+
+
+/**
+ * A view of STIX-derived graph data which is a visjs graph.
+ */
+class GraphView extends STIXContentView
+{
+ #nodeDataSet;
+ #edgeDataSet;
+ #network;
+
+ /**
+ * Initialize a graph view.
+ *
+ * @param visjs The visjs-network module
+ * @param domElement the parent element where the graph is to be located in
+ * a web page
+ * @param nodeDataSet A visjs DataSet instance with graph node data derived
+ * from STIX content
+ * @param edgeDataSet A visjs DataSet instance with graph edge data derived
+ * from STIX content
+ * @param stixIdToObject A Map instance mapping STIX IDs to STIX objects as
+ * Maps, containing STIX content.
+ * @param config A config object
+ */
+ constructor(
+ visjs, domElement, nodeDataSet, edgeDataSet, stixIdToObject,
+ config=null
+ )
+ {
+ if (config !== null)
+ config = normalizeConfig(config);
+
+ super(stixIdToObject, config);
+
+ this.#edgeDataSet = edgeDataSet;
+
+ // Add some node data specific to this view, which enables the icons.
+ // This constructs a new dataset from the old one, to avoid modifying
+ // the original.
+ this.#nodeDataSet = new visjs.DataSet();
+
+ nodeDataSet.forEach((item, id) => {
+ this.#nodeDataSet.add({
+ ...item,
+ group: stixIdToObject.get(id).get("type")
+ });
+ });
+
+ let groups = this.#makeGroups();
+
+ let graphData = {
+ nodes: this.#nodeDataSet,
+ edges: this.#edgeDataSet
+ };
+
+ let graphOpts = {
+ groups: groups,
+ nodes: {
+ color: {
+ border: "black"
+ },
+ font: {
+ size: 20
+ },
+ borderWidth: 2,
+ chosen: {
+ // Enable a drop shadow when a node is selected
+ node: (values, id, selected, hovering) => {
+ if (selected)
+ {
+ values.shadow = true;
+ values.shadowX = values.shadowY = 8;
+ values.borderWidth = 4;
+ }
+ }
+ }
+ },
+ edges: {
+ arrows: "to",
+ width: 3,
+ color: "gray",
+ font: {
+ size: 20
+ }
+ },
+ physics: {
+ solver: "barnesHut",
+ barnesHut: {
+ theta: 0.9,
+ gravitationalConstant: -3000,
+ centralGravity: 0,
+ springConstant: 0.01,
+ springLength: 400
+ },
+ minVelocity: 1,
+ // Set to false if you want to watch the graph stabilize when
+ // it first loads.
+ stabilization: true
+ }
+ };
+
+ this.#network = new visjs.Network(domElement, graphData, graphOpts);
+ }
+
+ /**
+ * Get the underlying visjs Network object. Might be useful in case one
+ * wants to perform operations specific to the library.
+ */
+ get graph()
+ {
+ return this.#network;
+ }
+
+ /**
+ * Get the visjs DataSet object containing graph node data. Useful to
+ * affect changes in the graph.
+ */
+ get nodeDataSet()
+ {
+ return this.#nodeDataSet;
+ }
+
+ /**
+ * Get the visjs DataSet object containing graph edge data. Useful to
+ * affect changes in the graph.
+ */
+ get edgeDataSet()
+ {
+ return this.#edgeDataSet;
+ }
+
+ /**
+ * Convenience event handling method which passes through to the underlying
+ * graph method.
+ */
+ on(...args)
+ {
+ this.graph.on(...args);
+ }
+
+ /**
+ * Dispose of the graph to free up resources.
+ */
+ destroy()
+ {
+ this.graph.destroy();
+ }
+
+ /**
+ * Create a visjs network groups structure. There will be one group per
+ * STIX type present in the data (except "relationship").
+ */
+ #makeGroups()
+ {
+ let [iconURLs, defaultIconURL] = this.legendData;
+
+ let groups = {};
+ for (let [stixType, iconURL] of iconURLs)
+ {
+ groups[stixType] = {
+ shape: "circularImage",
+ image: iconURL,
+ brokenImage: defaultIconURL
+ };
+ }
+
+ return groups;
+ }
+
+ /**
+ * Toggle the display of graph nodes of a particular STIX type.
+ *
+ * @param stixType the STIX type whose nodes should be toggled
+ */
+ toggleStixType(stixType)
+ {
+ let nodes = this.nodeDataSet.get({
+ filter: item => item.group === stixType,
+ fields: ["id", "hidden"]
+ });
+
+ if (nodes.length === 0)
+ return;
+
+ this.enablePhysics();
+
+ // Whether we are hiding or showing nodes of the selected type.
+ // If first node is currently hidden, we must be showing, and vice
+ // versa.
+ let hiding = !nodes[0].hidden;
+
+ let toggledNodes = [];
+ let toggledEdges = [];
+
+ // An edge could connect two nodes of the same type. Ensure we don't
+ // toggle an edge more than once!
+ let toggledEdgeIds = new Set();
+
+ for (let node of nodes)
+ {
+ // Toggling the node is simple
+ toggledNodes.push({
+ id: node.id, hidden: hiding, physics: !hiding
+ });
+
+ // Toggling the edges is more complex...
+ let edgesForNode = this.edgeDataSet.get({
+ // find (a) edges connecting to 'node'; (b) edges with the
+ // right visibility; (c) edges we have not already seen.
+ filter: item => (item.from === node.id || item.to === node.id)
+ && !item.hidden === hiding && !toggledEdgeIds.has(item.id),
+ fields: ["id", "from", "to"]
+ });
+
+ if (hiding)
+ {
+ // simple case: unconditionally hide everything
+ for (let edge of edgesForNode)
+ {
+ toggledEdges.push({
+ id: edge.id, hidden: true, physics: false
+ });
+ toggledEdgeIds.add(edge.id);
+ }
+ }
+ else
+ {
+ // showing is a more complex case: gotta check the other ends
+ // of the edges. Only show if the other end is also visible
+ // or of the selected type (meaning it will become visible).
+ for (let edge of edgesForNode)
+ {
+ let otherEndId;
+ if (edge.from === node.id)
+ otherEndId = edge.to;
+ else
+ otherEndId = edge.from;
+
+ let otherEndNode = this.nodeDataSet.get(
+ otherEndId,
+ {fields: ["group", "hidden"]}
+ );
+
+ if (!otherEndNode.hidden
+ || otherEndNode.group === stixType)
+ {
+ toggledEdges.push({
+ id: edge.id, hidden: false, physics: true
+ });
+ toggledEdgeIds.add(edge.id);
+ }
+ }
+ }
+ }
+
+ this.nodeDataSet.updateOnly(toggledNodes);
+ this.edgeDataSet.updateOnly(toggledEdges);
+ }
+
+ /**
+ * Set the graph selection to the node corresponding to the given STIX ID.
+ */
+ selectNode(stixId)
+ {
+ this.graph.selectNodes([stixId]);
+ }
+
+ /**
+ * Enable physics in this graph view
+ */
+ enablePhysics()
+ {
+ this.#network.setOptions( { physics: true } );
+ }
+
+ /**
+ * Disable physics in this graph view
+ */
+ disablePhysics()
+ {
+ this.#network.setOptions( { physics: false } );
+ }
+}
+
+
+/**
+ * Create a network edge object from the given STIX relationship object, if
+ * possible. If source or target_ref refers to an unknown object, the edge
+ * can't be created and null is returned.
+ *
+ * @param stixRel a STIX relationship object
+ * @param stixIdToObject A Map instance mapping STIX IDs to STIX objects as
+ * Maps, containing STIX content.
+ * @return An visjs network edge object, or null if one could not be created
+ */
+function edgeForRelationship(stixRel, stixIdToObject)
+{
+ let sourceRef = stixRel.get("source_ref");
+ let targetRef = stixRel.get("target_ref");
+ let relType = stixRel.get("relationship_type");
+
+ let edge = null;
+ if (stixIdToObject.has(sourceRef) && stixIdToObject.has(targetRef))
+ {
+ // check STIX types just in case
+ if (isStixIdValidForNode(sourceRef) && isStixIdValidForNode(targetRef))
+ edge = makeEdgeObject(
+ sourceRef, targetRef, relType, stixRel.get("id")
+ );
+ }
+ else
+ console.warn(
+ "Skipped relationship %s %s %s: missing endpoint object(s)",
+ sourceRef, relType, targetRef
+ );
+
+ return edge;
+}
+
+
+/**
+ * Generate values from stixValue according to the given path.
+ *
+ * A property path is a string in a dot-delimited syntax: property names
+ * concatenated with dots in between. This syntax is used to locate values
+ * within a JSON-like structure which is a composition of Maps and arrays.
+ * In this syntax, array properties are not indexed. All array elements are
+ * automatically searched. If the last path element is array-valued, its
+ * elements are individually generated, you don't get the whole array at once.
+ * Because arrays are transparently searched, a property path does not
+ * necessarily identify a unique location in a structure.
+ *
+ * Property paths shouldn't begin or end with a dot, there should be no
+ * adjacent dots, and the path should not be empty. Property names can't
+ * contain dots; there is no escaping. But this should be okay since STIX
+ * property names should not contain dots.
+ *
+ * For example, given structure:
+ * {
+ * "a": [
+ * {"b": 1},
+ * {
+ * "b": {
+ * "c": [2, 3]
+ * }
+ * }
+ * ]
+ * }
+ *
+ * Paths and results include:
+ * "a" -> {"b": 1}, {"b": {"c": [2, 3]}} (two results)
+ * "a.b" -> 1, {"c": [2, 3]} (two results)
+ * "a.b.c" -> 2, 3 (two results)
+ * "a.b.c.d" -> (no results)
+ *
+ * @param stixValue The value to search, as a Map or an array
+ * @param propPath The path to follow
+ * @param index The index of one of the dots in propPath, or -1. This keeps
+ * track of which path component we're on through recursive calls. The
+ * path component extends from the character after "index" to the next
+ * occurrence of ".", or to the end of the string. If -1, the current
+ * path component is the first one. The initial call should let this
+ * parameter default to -1.
+ */
+function* getValuesAtPath(stixValue, propPath, index=-1)
+{
+ if (Array.isArray(stixValue))
+ {
+ // pass-through array elements
+ for (let elt of stixValue)
+ yield* getValuesAtPath(elt, propPath, index);
+ }
+
+ else if (stixValue instanceof Map)
+ {
+ let nextDotIdx = propPath.indexOf(".", index+1);
+ let pathStep;
+
+ if (nextDotIdx === -1)
+ pathStep = propPath.substring(index+1);
+ else
+ pathStep = propPath.substring(index+1, nextDotIdx);
+
+ if (pathStep.length > 0)
+ {
+ if (stixValue.has(pathStep))
+ {
+ let propValue = stixValue.get(pathStep);
+
+ if (nextDotIdx === -1)
+ {
+ // End of path; just yield whatever we have
+ if (Array.isArray(propValue))
+ yield* propValue;
+ else
+ yield propValue;
+ }
+ else
+ yield* getValuesAtPath(propValue, propPath, nextDotIdx);
+ }
+ }
+ else if (nextDotIdx !== -1)
+ // Ignore empty path steps, e.g. two adjacent dots.
+ yield* getValuesAtPath(stixValue, propPath, nextDotIdx);
+ }
+}
+
+
+/**
+ * Search a STIX object according to embedded relationship information
+ * based on property paths, and create graph edge structures.
+ *
+ * @param stixObject The STIX object to search
+ * @param stixIdToObject A Map instance mapping STIX IDs to STIX objects as
+ * Maps, containing STIX content.
+ * @param relInfo An array of [, , ]
+ * triples which describes what to search for within the object and how
+ * to create the edges.
+ * @return An array of edge objects
+ */
+function edgesFromPropertyPaths(stixObject, stixIdToObject, relInfo)
+{
+ let sourceId = stixObject.get("id");
+ let edges = [];
+
+ for (let [propPath, edgeLabel, forward] of relInfo)
+ {
+ for (let ref of getValuesAtPath(stixObject, propPath))
+ {
+ if (isStixIdValidForNode(ref))
+ {
+ if (stixIdToObject.has(ref))
+ {
+ let edgeSrc, edgeDst;
+
+ // "forward" edge direction is referrer->referent
+ // "backward" is referent->referrer
+ if (forward)
+ [edgeSrc, edgeDst] = [sourceId, ref];
+ else
+ [edgeSrc, edgeDst] = [ref, sourceId];
+
+ let edge = makeEdgeObject(edgeSrc, edgeDst, edgeLabel);
+
+ edges.push(edge);
+ }
+ else
+ console.warn(
+ "Skipped embedded relationship %s %s %s: target object"
+ + " missing",
+ sourceId, propPath, ref
+ );
+ }
+ }
+ }
+
+ return edges;
+}
+
+
+/**
+ * Create visjs network edges for embedded relationships within the given
+ * object.
+ *
+ * @param stixObject a STIX object
+ * @param stixIdToObject A Map instance mapping STIX IDs to STIX objects as
+ * Maps, containing STIX content.
+ * @param config A config object containing user preferences regarding
+ * embedded relationships
+ * @return An array of edge objects
+ */
+function edgesForEmbeddedRelationships(stixObject, stixIdToObject, config=null)
+{
+ let stixType = stixObject.get("type");
+
+ let typeAgnosticRels = embeddedRelationships.get(null);
+ let typeSpecificRels = embeddedRelationships.get(stixType);
+
+ let userTypeAgnosticRels = null;
+ let userTypeSpecificRels = null;
+
+ if (config)
+ {
+ // Can't have null keys in JSON or javascript (plain objects), so use
+ // an empty string. Put type-agnostic config there.
+ if (config.has(""))
+ {
+ let typeConfig = config.get("");
+ if (typeConfig.has("embeddedRelationships"))
+ userTypeAgnosticRels = typeConfig.get("embeddedRelationships");
+ }
+
+ if (config.has(stixType))
+ {
+ let typeConfig = config.get(stixType);
+ if (typeConfig.has("embeddedRelationships"))
+ userTypeSpecificRels = typeConfig.get("embeddedRelationships");
+ }
+ }
+
+ let allRels = [];
+
+ if (typeAgnosticRels)
+ allRels.push(...typeAgnosticRels);
+
+ if (typeSpecificRels)
+ allRels.push(...typeSpecificRels);
+
+ if (userTypeAgnosticRels)
+ allRels.push(...userTypeAgnosticRels);
+
+ if (userTypeSpecificRels)
+ allRels.push(...userTypeSpecificRels);
+
+ let edges = edgesFromPropertyPaths(stixObject, stixIdToObject, allRels);
+
+ return edges;
+}
+
+
+/**
+ * Make node and edge datasets derived from STIX content, representing a graph.
+ *
+ * @param stixIdToObject A Map instance mapping STIX IDs to STIX objects as
+ * Maps, containing STIX content.
+ * @param config A config object containing preferences for naming graph
+ * elements and creating additional edges from embedded relationships;
+ * null to use defaults
+ * @return 2-tuple consisting of an array of nodes and array of edges.
+ */
+function makeNodesAndEdges(stixIdToObject, config=null)
+{
+ // List of graph nodes, where each list element is whatever visjs needs
+ // to represent the node. This is a plain javascript object with an
+ // "id" property at least, to identify the node.
+ let nodes = [];
+
+ // List of links/edges for the graph, where each list element is whatever
+ // visjs needs to represent the edge. This is a plain javascript object
+ // with "from" and "to" properties at least, whose values are the IDs of
+ // the linked nodes.
+ let edges = [];
+
+ // Used to uniquefy names. E.g. first "foo" gets the name, then others
+ // will be "foo(2)", "foo(3)", etc. This map keeps track of those counts.
+ // Maps the "base" name as computed for the STIX object, to a count.
+ let nameCounts = new Map();
+
+ // Map STIX IDs to the node names we use in the graph.
+ let stixIdToName = new Map();
+
+ for (let object of stixIdToObject.values())
+ {
+ let stixType = object.get("type");
+
+ if (stixType === "relationship")
+ {
+ let edge = edgeForRelationship(object, stixIdToObject);
+
+ if (edge)
+ edges.push(edge);
+ }
+ // check STIX type for suitability just in case
+ else if (isStixTypeValidForNode(stixType))
+ {
+ let name = nameForStixObject(
+ object, stixIdToName, nameCounts, config
+ );
+ let node = makeNodeObject(name, object);
+ nodes.push(node);
+
+ let embeddedRelEdges = edgesForEmbeddedRelationships(
+ object, stixIdToObject, config
+ );
+
+ // Seems like there ought to be a better way to extend one array
+ // with the contents of another.
+ edges.push(...embeddedRelEdges);
+ }
+ }
+
+ return [nodes, edges];
+}
+
+
+/**
+ * Handler for when graph stabilizes: disable physics so that dragging a node
+ * only moves that node and all others stay where they are.
+ *
+ * @param event a visjs-network event object with the number of iterations it
+ * took to stabilize the graph
+ * @param view the visjs Graphview instance
+ */
+function stabilizedHandler(event, view)
+{
+ view.disablePhysics();
+}
+
+
+/**
+ * Filter STIX objects according to criteria in the given config. The config
+ * must be a Map; if it contains "include" and/or "exclude" keys, the
+ * corresponding value is criteria used to filter the objects. "include"
+ * causes matching objects to be included and the rest excluded; "exclude"
+ * causes matching objects to be excluded and the rest included. Both keys can
+ * be present and both types of filtering will happen.
+ *
+ * See mongoishMatchObject() for information on criteria.
+ *
+ * @param stixObjects an array of STIX objects (as Maps)
+ * @param config Configuration data, as a Map
+ * @return An array containing STIX objects which passed the filters
+ */
+function filterStixObjects(stixObjects, config)
+{
+ if (config.has("include"))
+ {
+ let filterCriteria = config.get("include");
+ stixObjects = stixObjects.filter(
+ obj => mongoishMatchObject(obj, filterCriteria)
+ );
+ }
+
+ if (config.has("exclude"))
+ {
+ let filterCriteria = config.get("exclude");
+ stixObjects = stixObjects.filter(
+ obj => !mongoishMatchObject(obj, filterCriteria)
+ );
+ }
+
+ return stixObjects;
+}
+
+
+/**
+ * Make graph data from the given STIX content.
+ *
+ * @param visjs the visjs module
+ * @param stixContent STIX content as a STIX object, array of objects, or
+ * bundle of objects, or any of those as JSON
+ * @param config Config settings as a Map or object, or as JSON
+ * @return A 3-tuple include the node DataSet, edge DataSet, and normalized
+ * STIX content as a Map instance from STIX ID to a Map instance
+ * containing a STIX object.
+ */
+function makeGraphData(visjs, stixContent, config=null)
+{
+ if (config !== null)
+ config = normalizeConfig(config);
+
+ let stixObjects = normalizeContent(stixContent);
+ stixObjects = filterStixObjects(stixObjects, config);
+
+ let stixIdToObject = new Map();
+
+ for (let object of stixObjects)
+ stixIdToObject.set(object.get("id"), object);
+
+ let [nodes, edges] = makeNodesAndEdges(stixIdToObject, config);
+
+ let nodeDataSet = new visjs.DataSet(nodes);
+ let edgeDataSet = new visjs.DataSet(edges);
+
+ return [nodeDataSet, edgeDataSet, stixIdToObject];
+}
+
+
+/**
+ * Create a graph view of the given data. The content will be added to the
+ * webpage DOM under the given element.
+ *
+ * @param visjs The visjs-network module
+ * @param domElement the parent element where the graph is to be located in a
+ * web page
+ * @param nodeDataSet A visjs DataSet instance with graph node data derived
+ * from STIX content
+ * @param edgeDataSet A visjs DataSet instance with graph edge data derived
+ * from STIX content
+ * @param stixIdToObject A Map instance mapping STIX IDs to STIX objects as
+ * Maps, containing STIX content. Graph data can be looked up here, to
+ * obtain full details about the STIX objects.
+ * @param config A config object. Relevant preferences include those for
+ * customizing iconography.
+ * @return The graph view object. May be used perform certain actions on the
+ * view, e.g. dispose of it.
+ */
+function makeGraphView(
+ visjs, domElement, nodeDataSet, edgeDataSet, stixIdToObject, config=null
+)
+{
+ let view = new GraphView(
+ visjs, domElement, nodeDataSet, edgeDataSet, stixIdToObject, config
+ );
+
+ // Add some handlers to enable some hard-coded behavior.
+ view.on("stabilized", e => stabilizedHandler(e, view));
+
+ return view;
+}
+
+
+/**
+ * Create and return an object which is this file's module.
+ */
+function makeModule(visjs)
+{
+ let module = {
+ makeGraphData: (stixContent, config=null) =>
+ makeGraphData(visjs, stixContent, config),
+ makeGraphView: (...args) => makeGraphView(visjs, ...args),
+ makeListView: (...args) => new ListView(...args)
+ };
+
+ return module;
+}
+
+
+define(["nbextensions/stix2viz/vis-network"], makeModule);