File size: 1,463 Bytes
5fe70fd
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
{
    "type": "bundle",
    "id": "bundle--81ea8a77-185e-454d-86cb-3ac89bb426d0",
    "spec_version": "2.0",
    "objects": [
        {
            "object_marking_refs": [
                "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
            ],
            "id": "relationship--00aa618f-bcfa-4649-8436-134f9d01e43c",
            "type": "relationship",
            "created": "2020-06-19T21:25:43.683Z",
            "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
            "external_references": [
                {
                    "url": "https://cdn2.hubspot.net/hubfs/3354902/Cybereason%20Labs%20Analysis%20Operation%20Cobalt%20Kitty.pdf",
                    "description": "Dahan, A. (2017). Operation Cobalt Kitty. Retrieved December 27, 2018.",
                    "source_name": "Cybereason Cobalt Kitty 2017"
                }
            ],
            "modified": "2020-06-29T21:37:55.941Z",
            "description": "[Goopy](https://attack.mitre.org/software/S0477) has the ability to communicate with its C2 over DNS.(Citation: Cybereason Cobalt Kitty 2017)\t",
            "relationship_type": "uses",
            "source_ref": "malware--eac3d77f-2b7b-4599-ba74-948dc16633ad",
            "target_ref": "attack-pattern--1996eef1-ced3-4d7f-bf94-33298cabbf72",
            "x_mitre_version": "1.0",
            "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5"
        }
    ]
}