{ "type": "bundle", "id": "bundle--605718c9-966a-4258-b84a-0403a64ee2e1", "spec_version": "2.0", "objects": [ { "id": "relationship--9c87b627-de61-42da-a658-7bdb33358754", "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5", "description": "[APT17](https://attack.mitre.org/groups/G0025) obfuscated infrastructure using a multi-layered malware beaconing approach. (Citation: FireEye APT17)", "object_marking_refs": [ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168" ], "external_references": [ { "url": "https://www2.fireeye.com/rs/fireye/images/APT17_Report.pdf", "description": "FireEye Labs/FireEye Threat Intelligence. (2015, May 14). Hiding in Plain Sight: FireEye and Microsoft Expose Obfuscation Tactic. Retrieved January 22, 2016.", "source_name": "FireEye APT17" } ], "source_ref": "intrusion-set--090242d7-73fc-4738-af68-20162f7a5aae", "relationship_type": "uses", "target_ref": "attack-pattern--72c8d526-1247-42d4-919c-6d7a31ca8f39", "type": "relationship", "modified": "2019-03-22T14:21:19.564Z", "created": "2017-12-14T16:46:06.044Z" } ] }