Intel 471 Indicators - Malware Intelligence CDF
The web format of this guide reflects the most current release. Guides for older iterations are available in PDF format.
Integration Details
ThreatQuotient provides the following details for this integration:
| Current Integration Version | 2.0.0 |
| Compatible with ThreatQ Versions | >= 5.24.0 |
| Support Tier | ThreatQ Supported |
Introduction
The Intel 471 Indicators - Malware Intelligence integration returns a list of indicators that match filter criteria from the following endpoint:
- Intel 471 Indicator - Malware Intelligence - retrieves indicator intelligence and YARA signatures from the Intel 471 cloud Indicators stream and ingests them into ThreatQ as Indicator and Signature objects with associated attributes.
The integration ingests the following system objects:
- Indicators
- Indicator Attributes
- Signatures
- Signature Attributes
Prerequisites
The following is required to run the integration:
- An Intel 471 Client ID.
- An Intel 471 Client Secret.
Installation
Perform the following steps to install the integration:
The same steps can be used to upgrade the integration to a new version.
- Log into https://marketplace.threatq.com/.
- Locate and download the integration file.
- Navigate to the integrations management page on your ThreatQ instance.
- Click on the Add New Integration button.
- Upload the integration file using one of the following methods:
- Drag and drop the file into the dialog box
- Select Click to Browse to locate the integration file on your local machine
ThreatQ will inform you if the feed already exists on the platform and will require user confirmation before proceeding. ThreatQ will also inform you if the new version of the feed contains changes to the user configuration. The new user configurations will overwrite the existing ones for the feed and will require user confirmation before proceeding.
- If prompted, select the individual feeds to install and click Install. The feed will be added to the integrations page.
You will still need to configure and then enable the feed.
Configuration
ThreatQuotient does not issue API keys for third-party vendors. Contact the specific vendor to obtain API keys and other integration-related credentials.
To configure the integration:
- Navigate to your integrations management page in ThreatQ.
- Select the Commercial option from the Category dropdown (optional).
If you are installing the integration for the first time, it will be located under the Disabled tab.
- Click on the integration entry to open its details page.
- Enter the following parameters under the Configuration tab:
Parameter Description Client ID Enter your Intel 471 Client ID. Client Secret Enter your Intel 471 Client Secret Fetch GIR Names Enable this parameter to include each GIR name with its corresponding path. Disable it to use the raw GIR paths. This parameter is enabled by default Indicator Type Select an indicator type to send as the type query parameter. Options include: - ALL
- Domain
- File
- IPv4 (default)
- URL
- YARA
Selecting
ALLomits the parameter and retrieves all available indicator types. This may produce a large result set and require thousands of paginated API requests. Select specific values whenever possible to reduce API usage.Threat Type Select a threat type to send as the threat_typequery parameter. Options include:- ALL
- Malware (default)
- Bulletproof Hosting
Selecting
ALLomits the parameter and may return a large result set requiring thousands of paginated API requests. Select specific values whenever possible to reduce API usage.Confidence Select a confidence level to send as the confidencequery parameter. Options include:- ALL (default)
- High
- Medium
- Low
Selecting
ALLomits the parameter.Text Filter Optional - Enter text to filter the indicators returned by the feed. Example: btmob.Malware Family Name Optional - Enter a malware family name to filter the returned indicators. Example: btmob.GIRs Optional - Enter one or more comma-separated GIR paths, or enter my_girsorcompany_pirsto retrieve indicators from those GIR collections. Example:1.1.5,2.1.3.Page Size Enter the number of records to request per page. Valid values range from 1to1000. The default value is1000.Enable SSL Certificate Verification Enable this parameter if the feed should validate the host-provided SSL certificate. Disable Proxies Enable this parameter if the feed should not honor proxies set in the ThreatQ UI. - Review any additional settings, make any changes if needed, and click on Save.
- Click on the toggle switch, located above the Additional Information section, to enable it.
ThreatQ Mapping
Intel 471 Indicators - Malware Intelligence
The Intel 471 Indicators - Malware Intelligence feed retrieves indicator intelligence and YARA signatures from the Intel 471 cloud Indicators stream and ingests them into ThreatQ as Indicator and Signature objects with associated attributes.
GET https://api.intel471.cloud/integrations/indicators/v1/indicators/stream
Items in .indicators[] where .type is not yara create one or more ThreatQ Indicator objects, while items whose .type is yara create ThreatQ Signature objects of type YARA.
Sample Response:
{
"count": 1,
"cursor_next": "NTg2ZDYwOWUtNzhmMS00MDY5LTg3M2QtYTI5MWRjNzBhNTYyOjE3ODY4NDI0NjA4MjA6ZThhZWE2NTI0ZjBhOWI2MGQ4OTUwNmNkYjc2M2ExYjg3ODg0MWJiYw",
"indicators": [
{
"activity": {
"first_seen_ts": "2026-08-11T20:28:31Z",
"last_seen_ts": "2026-08-15T20:28:49Z"
},
"classification": {
"girs": [
{
"path": "1.1.2",
"name": "Mobile malware"
},
{
"path": "1.1.4",
"name": "Banking trojan malware"
},
{
"path": "1.4.4",
"name": "Android"
}
]
},
"confidence": 50,
"data": {
"ipv4": {
"ip_address": "130.94.40.138",
"geo_ip": {
"country": "Singapore",
"country_code": "SG",
"city": "Singapore",
"isp": {
"isp": "LIGHT NODE LIMITED",
"organization": "LIGHT NODE LIMITED",
"autonomous_system": "AS154177 LIGHT NODE LIMITED",
"network": "130.94.0.0/18"
}
}
}
},
"description": "btmob controller IPv4",
"expiration_ts": "2026-09-11T20:28:57Z",
"id": "malware-indicator--3f5e3ccb-76bd-53b7-b2f0-04041045c888",
"kill_chain_phases": [
{
"kill_chain_name": "mitre-attack",
"phase_name": "command_and_control"
}
],
"pattern": "[ipv4-addr:value = '130.94.40.138']",
"pattern_type": "stix",
"pattern_version": "2.1",
"threat": {
"type": "malware",
"data": {
"malware": {
"id": "malware--58bc1e16-a79e-5436-abe8-0576d0ad354b",
"family": "btmob",
"version": "BT-v5.0.1"
},
"malware_family": {
"id": "malware-family--7398e343-b9ae-56c8-ba12-30ac9541e9cd",
"name": "btmob"
}
}
},
"type": "ipv4"
}
]
}
Direct Indicators Table Mapping
ThreatQuotient provides the following default mapping for direct indicators:
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
.indicators[].type |
Indicator.Type |
N/A |
.indicators[].activity.first_seen_ts |
ipv4, domain, email, file, url |
Drives the type-specific mapping below. |
.indicators[].data.ipv4.ip_address |
Indicator.Value |
IP Address |
.indicators[].activity.first_seen_ts |
130.94.40.138 |
Only when .type == "ipv4". |
.indicators[].data.domain |
Indicator.Value |
FQDN |
.indicators[].activity.first_seen_ts |
fdaccfl.ru |
Only when .type == "domain". |
.indicators[].data.email |
Indicator.Value |
Email Address |
.indicators[].activity.first_seen_ts |
mobilitylog@gthltd.buzz |
Only when .type == "email". |
.indicators[].data.url |
Indicator.Value |
URL |
.indicators[].activity.first_seen_ts |
tcp://103.212.136.208:9090 |
Only when .type == "url". |
.indicators[].data.file.md5 |
Indicator.Value |
MD5 |
.indicators[].activity.first_seen_ts |
253f2dbdc2a9e2a0cfb8dbc8bc8f874b |
File records create a separate indicator for each populated hash. |
.indicators[].data.file.sha1 |
Indicator.Value |
SHA-1 |
.indicators[].activity.first_seen_ts |
ac206745aadf006663b22c1916703ee43c987027 |
File records create a separate indicator for each populated hash. |
.indicators[].data.file.sha256 |
Indicator.Value |
SHA-256 |
.indicators[].activity.first_seen_ts |
e330752b3750a012cb4c97a9b6e2c55bfce0ad4e5ccb5c0ec4f3019b4ddf00c5 |
File records create a separate indicator for each populated hash. |
Common Indicator Attributes Table Mapping
ThreatQuotient provides the following default mapping for common indicator attributes. These mappings are applied to every non-YARA indicator. Empty or absent values are not ingested.
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
.indicators[].id |
Indicator.Attribute |
Indicator ID |
.indicators[].activity.first_seen_ts |
malware-indicator--3f5e3ccb-... |
Replaces the legacy indicator UID. |
.indicators[].description |
Indicator.Attribute |
Description |
.indicators[].activity.first_seen_ts |
Indicator used by btmob malware |
Ingest when present. |
.indicators[].confidence |
Indicator.Attribute |
Confidence |
.indicators[].activity.first_seen_ts |
50 |
Integer value returned by the new API. |
.indicators[].expiration_ts |
Indicator.Attribute |
Expires At |
.indicators[].activity.first_seen_ts |
2026-09-11T20:28:57Z |
ISO 8601 timestamp. |
.indicators[].activity.first_seen_ts |
Indicator.Attribute |
First Seen |
.indicators[].activity.first_seen_ts |
2026-08-11T20:28:31Z |
Also used as the indicator published date. |
.indicators[].activity.last_seen_ts |
Indicator.Attribute |
Last Seen |
.indicators[].activity.first_seen_ts |
2026-08-15T20:28:49Z |
ISO 8601 timestamp. |
.indicators[].pattern |
Indicator.Attribute |
Pattern |
.indicators[].activity.first_seen_ts |
[ipv4-addr:value = '130.94.40.138'] |
STIX pattern for direct indicators. |
.indicators[].pattern_type |
Indicator.Attribute |
Pattern Type |
.indicators[].activity.first_seen_ts |
stix |
Ingest when present. |
.indicators[].pattern_version |
Indicator.Attribute |
Pattern Version |
.indicators[].activity.first_seen_ts |
2.1 |
Ingest when present. |
.indicators[].kill_chain_phases[].phase_name |
Indicator.Attribute |
MITRE Tactics |
.indicators[].activity.first_seen_ts |
command_and_control |
Multi-valued. |
.indicators[].classification.girs[] |
Indicator.Attribute |
Intelligence Requirement |
.indicators[].activity.first_seen_ts |
1.1.5 - Information-stealer malware |
With Fetch GIR Names enabled, use path - name; otherwise use the raw path. |
.indicators[].threat.type |
Indicator.Attribute |
Threat Type |
.indicators[].activity.first_seen_ts |
malware |
Values observed include malware and bulletproof_hosting. |
.indicators[].threat.data.malware.id |
Indicator.Attribute |
Malware ID |
.indicators[].activity.first_seen_ts |
malware--f12da3fa-... |
Malware threats only, when present. |
.indicators[].threat.data.malware.family |
Indicator.Attribute |
Malware Family |
.indicators[].activity.first_seen_ts |
btmob |
Malware threats only; use this value first and fall back to .threat.data.malware_family.name. |
.indicators[].threat.data.malware.version |
Indicator.Attribute |
Threat Version |
.indicators[].activity.first_seen_ts |
0.7d |
Malware threats only, when present. |
.indicators[].threat.data.malware.variant |
Indicator.Attribute |
Malware Variant |
.indicators[].activity.first_seen_ts |
v3_variant_a |
Malware threats only, when present. |
.indicators[].threat.data.malware_family.id |
Indicator.Attribute |
Malware Family ID |
.indicators[].activity.first_seen_ts |
malware-family--f12da3fa-... |
Malware threats only, when present. |
.indicators[].threat.data.malware_family.name |
Indicator.Attribute |
Malware Family Name |
.indicators[].activity.first_seen_ts |
btmob |
Malware threats only, when present. |
Bulletproof Hosting Indicator Attributes Table Mapping
ThreatQuotient provides the following default mapping for Bulletproof hosting indicator attributes.
Records with .indicators[].threat.type = bulletproof_hosting use the direct and IPv4 mappings.
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
.indicators[].data.ipv4.ip_address |
Indicator.Value |
IP Address |
.indicators[].activity.first_seen_ts |
61.82.2.181 |
The supplied sample is IPv4 and applies only when type is ipv4. |
.indicators[].threat.type |
Indicator.Attribute |
Threat Type |
.indicators[].activity.first_seen_ts |
bulletproof_hosting |
Identifies Bulletproof Hosting records. |
.indicators[].threat.data.bulletproof_hosting.provider |
Indicator.Attribute |
Bulletproof Hosting Provider |
.indicators[].activity.first_seen_ts |
ccweb |
Only when threat.type is bulletproof_hosting. |
File Indicator Attributes Table Mapping
ThreatQuotient provides the following default mapping for file indicator attributes. This applies to each related MD5, SHA-1, and SHA-256 indicator.
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
.indicators[].data.file.type |
Indicator.Attribute |
File Type |
.indicators[].activity.first_seen_ts |
PEEXE_x86 |
File indicators only. |
.indicators[].data.file.size |
Indicator.Attribute |
File Size |
.indicators[].activity.first_seen_ts |
221184 |
File indicators only. |
.indicators[].data.file.ssdeep |
Indicator.Attribute |
SSDEEP |
.indicators[].activity.first_seen_ts |
3072:zGWSdk... |
File indicators only. |
IPv4 Indicator Attributes Table Mapping
ThreatQuotient provides the following default mapping for IPv4 indicatgor attributes:
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
.indicators[].data.ipv4.geo_ip.country |
Indicator.Attribute |
Country |
.indicators[].activity.first_seen_ts |
South Korea |
IPv4 indicators only, when present. |
.indicators[].data.ipv4.geo_ip.country_code |
Indicator.Attribute |
Country Code |
.indicators[].activity.first_seen_ts |
KR |
IPv4 indicators only, when present. |
.indicators[].data.ipv4.geo_ip.city |
Indicator.Attribute |
City |
.indicators[].activity.first_seen_ts |
Yeongwol-gun |
IPv4 indicators only, when present. |
.indicators[].data.ipv4.geo_ip.subdivision[] |
Indicator.Attribute |
Subdivision |
.indicators[].activity.first_seen_ts |
Gangwon-do |
IPv4 indicators only; multi-valued. |
.indicators[].data.ipv4.geo_ip.isp.isp |
Indicator.Attribute |
ISP |
.indicators[].activity.first_seen_ts |
KT |
IPv4 indicators only, when present. |
.indicators[].data.ipv4.geo_ip.isp.organization |
Indicator.Attribute |
Organization |
.indicators[].activity.first_seen_ts |
KT |
IPv4 indicators only, when present. |
.indicators[].data.ipv4.geo_ip.isp.autonomous_system |
Indicator.Attribute |
Autonomous System |
.indicators[].activity.first_seen_ts |
AS4766 Korea Telecom |
IPv4 indicators only, when present. |
.indicators[].data.ipv4.geo_ip.isp.network |
Indicator.Attribute |
Network |
.indicators[].activity.first_seen_ts |
61.82.0.0/18 |
IPv4 indicators only, when present. |
YARA Signatures Table Mapping
ThreatQuotient provides the following default mapping for YARA Signatures. Each item where .indicators[].type == "yara" creates one ThreatQ signature of type YARA, rather than a direct indicator.
| Feed Data Path | ThreatQ Entity | ThreatQ Object Type or Attribute Key | Published Date | Examples | Notes |
|---|---|---|---|---|---|
YARA |
Signature.Type |
N/A |
.indicators[].activity.first_seen_ts |
YARA |
Constant value. |
.indicators[].data.yara.title |
Signature.Name |
N/A |
.indicators[].activity.first_seen_ts |
crysome |
Primary signature name. |
.indicators[].data.yara.signature |
Signature.Value |
YARA |
.indicators[].activity.first_seen_ts |
rule cr... { ... } |
Full YARA rule text. |
.indicators[].id |
Signature.Attribute |
Signature ID |
.indicators[].activity.first_seen_ts |
malware-indicator--2098b5b3-... |
N/A |
.indicators[].type |
Signature.Attribute |
Indicator Type |
.indicators[].activity.first_seen_ts |
yara |
N/A |
.indicators[].confidence |
Signature.Attribute |
Confidence |
.indicators[].activity.first_seen_ts |
85 |
N/A |
.indicators[].activity.first_seen_ts |
Signature.Attribute |
First Seen |
.indicators[].activity.first_seen_ts |
2026-08-14T11:16:22Z |
Also used as the signature published date. |
.indicators[].activity.last_seen_ts |
Signature.Attribute |
Last Seen |
.indicators[].activity.first_seen_ts |
2026-09-07T17:23:53Z |
N/A |
.indicators[].pattern |
Signature.Attribute |
Pattern |
.indicators[].activity.first_seen_ts |
rule cr... { ... } |
N/A |
.indicators[].pattern_type |
Signature.Attribute |
Pattern Type |
.indicators[].activity.first_seen_ts |
yara |
N/A |
.indicators[].pattern_version |
Signature.Attribute |
Pattern Version |
.indicators[].activity.first_seen_ts |
4 |
N/A |
.indicators[].classification.girs[] |
Signature.Attribute |
Intelligence Requirement |
.indicators[].activity.first_seen_ts |
1.1.5 - Information-stealer malware |
Apply the same Fetch GIR Names behavior as indicators. |
.indicators[].threat.type |
Signature.Attribute |
Threat Type |
.indicators[].activity.first_seen_ts |
malware |
N/A |
.indicators[].threat.data.malware_family.id |
Signature.Attribute |
Malware Family ID |
.indicators[].activity.first_seen_ts |
malware-family--... |
When present. |
.indicators[].threat.data.malware_family.name |
Signature.Attribute |
Malware Family |
.indicators[].activity.first_seen_ts |
crysome |
When present. |
Average Feed Run
Object counts and Feed runtime are supplied as generalities only - objects returned by a provider can differ based on credential configurations and Feed runtime may vary based on system resources and load.
| Metric | Result |
|---|---|
| Run Time | 3 minutes |
| Indicators | 983 |
| Indicator Attributes | 16,304 |
| Signature | 2 |
| Signature Attributes | 24 |
Change Log
- Version 2.0.0
- Updated the integration to use the Intel 471 cloud API and corresponding cloud schema mappings.
- Added support for client credential authentication, configurable filters, and page-size settings.
- Added Unix millisecond conversion for the
fromparameter and cursor-based pagination within each feed run. - Removed the following configuration parameters:
- Email Address
- API Key
-
Added the following new configuration parameters:
- Client ID: Specifies the Intel 471 Client ID used as the HTTP Basic authentication username.
- Client Secret: Specifies the Intel 471 Client Secret used as the HTTP Basic authentication password.
- Fetch GIR Names: Controls whether GIR names are included with their corresponding paths. Enabled by default.
- Threat Type: Filters indicators by threat type. Available options include
ALL,Malware(default), andBulletproof Hosting. - Confidence: Filters indicators by confidence level. Available options include
ALL(default),High,Medium, andLow. - Text Filter: Filters returned indicators using the specified text.
- Malware Family Name: Filters returned indicators by malware family name.
- GIRs: Filters returned indicators using specified GIR paths or the
my_girsorcompany_pirscollections. - Page Size: Specifies the number of records requested per page, from
1to1000. The default value is1000. - Enable SSL Verification: Controls whether the integration verifies the endpoint’s SSL certificate. Enabled by default.
- Disable Proxies: Controls whether the integration bypasses proxies configured in ThreatQ. Disabled by default.
- Added additional options to the Indicator Type configuration parameter.
- Updated the minimum ThreatQ version to 5.24.0.
- Version 1.2.0
- Updated the endpoint to use the streaming API.
- Removed the Count user configuration option.
- Version 1.1.1
- Fixed feed name typo.
- Version 1.1.0
- Added ability to ingest all indicator types at once.
- Version 1.0.0
- Initial release.
PDF Guides
| Document | ThreatQ Version |
|---|---|
| Intel 471 Indicators - Malware Intelligence CDF Guide v2.0.0 | 5.24.0 or Greater |
| Intel 471 Indicators - Malware Intelligence CDF Guide v1.2.0 | 4.41.0 or Greater |
| Intel 471 Indicators - Malware Intelligence CDF Guide v1.1.1 | 4.41.0 or Greater |
| Intel 471 Indicators - Malware Intelligence CDF Guide v1.1.0 | 4.37.0 or Greater |
| Intel 471 Indicators - Malware Intelligence CDF Guide v1.0.0 | 4.37.0 or Greater |