[
  {
    "instruction": "Answer which mitre software is related to the description: The software a VPN-like network proxy tool that can relay traffic between a C2 server and a victim. It was first seen in May 2013 and reportedly used by APT28 during the compromise of the Democratic National Committee.\n\nA. RogueRobin, B. Cobalt Strike, C. XTunnel, D. Cryptoistic\nAnswer:",
    "context": "",
    "output": "C. XTunnel",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_software",
    "parsed_raw_data": {
      "question": "Answer which mitre software is related to the description: The software a VPN-like network proxy tool that can relay traffic between a C2 server and a victim. It was first seen in May 2013 and reportedly used by APT28 during the compromise of the Democratic National Committee.",
      "options": "A. RogueRobin, B. Cobalt Strike, C. XTunnel, D. Cryptoistic",
      "choice": "C. XTunnel",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_software"
    }
  },
  {
    "instruction": "Answer which mitre software is related to the description: The software is an open source, cross-platform post-exploitation/command and control platform. The software is designed to \"plug-n-play\" with various agents and communication channels. Deployed The software C2 servers have been observed as part of potentially malicious infrastructure.\n\nPossible answers:\nA. Mythic, B. Akira, C. TSCookie, D. LoudMiner",
    "context": "",
    "output": "A. Mythic",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_software",
    "parsed_raw_data": {
      "question": "Answer which mitre software is related to the description: The software is an open source, cross-platform post-exploitation/command and control platform. The software is designed to \"plug-n-play\" with various agents and communication channels. Deployed The software C2 servers have been observed as part of potentially malicious infrastructure.",
      "options": "A. Mythic, B. Akira, C. TSCookie, D. LoudMiner",
      "choice": "A. Mythic",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_software"
    }
  },
  {
    "instruction": "Answer which mitre software is related to the description: The software is a custom in-memory backdoor used by Threat Group-3390.\n\nPossible answers:\nA. pngdowner, B. HyperBro, C. njRAT, D. DOGCALL",
    "context": "",
    "output": "B. HyperBro",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_software",
    "parsed_raw_data": {
      "question": "Answer which mitre software is related to the description: The software is a custom in-memory backdoor used by Threat Group-3390.",
      "options": "A. pngdowner, B. HyperBro, C. njRAT, D. DOGCALL",
      "choice": "B. HyperBro",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_software"
    }
  },
  {
    "instruction": "Answer which mitre software is related to the description: The software is a fully featured, multi-platform backdoor Trojan written using the Microsoft .NET framework.\n\nPossible answers:\nA. Hancitor, B. RobbinHood, C. ConnectWise, D. Kazuar",
    "context": "",
    "output": "D. Kazuar",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_software",
    "parsed_raw_data": {
      "question": "Answer which mitre software is related to the description: The software is a fully featured, multi-platform backdoor Trojan written using the Microsoft .NET framework.",
      "options": "A. Hancitor, B. RobbinHood, C. ConnectWise, D. Kazuar",
      "choice": "D. Kazuar",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_software"
    }
  },
  {
    "instruction": "Q: Give the MITRE ATT&CK software relevant to the following:\nThe software is malware that was used by Sandworm Team in a worldwide attack starting on June 27, 2017. While The software appears as a form of ransomware, its main purpose was to destroy data and disk structures on compromised systems; the attackers never intended to make the encrypted data recoverable. As such, The software may be more appropriately thought of as a form of wiper malware. The software contains worm-like features to spread itself across a computer network using the SMBv1 exploits EternalBlue and EternalRomance.\n\nOptions:\nA. FrameworkPOS, B. NotPetya, C. SQLRat, D. Hydraq",
    "context": "",
    "output": "B. NotPetya",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_software",
    "parsed_raw_data": {
      "question": "Give the MITRE ATT&CK software relevant to the following:\nThe software is malware that was used by Sandworm Team in a worldwide attack starting on June 27, 2017. While The software appears as a form of ransomware, its main purpose was to destroy data and disk structures on compromised systems; the attackers never intended to make the encrypted data recoverable. As such, The software may be more appropriately thought of as a form of wiper malware. The software contains worm-like features to spread itself across a computer network using the SMBv1 exploits EternalBlue and EternalRomance.",
      "options": "A. FrameworkPOS, B. NotPetya, C. SQLRat, D. Hydraq",
      "choice": "B. NotPetya",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_software"
    }
  },
  {
    "instruction": "Q: Answer which mitre software is related to the description: The software is ransomware variant written in Golang that first appeared in mid-December 2019 and has been used against multiple sectors, including energy, healthcare, and automotive manufacturing, which in some cases resulted in significant operational disruptions. The software has used a hard-coded kill-list of processes, including some associated with common ICS software platforms (e.g., GE Proficy, Honeywell HMIWeb, etc), similar to those defined in MegaCortex.\n\nOptions:\nA. GrimAgent, B. Crimson, C. ShimRat, D. EKANS",
    "context": "",
    "output": "D. EKANS",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_software",
    "parsed_raw_data": {
      "question": "Answer which mitre software is related to the description: The software is ransomware variant written in Golang that first appeared in mid-December 2019 and has been used against multiple sectors, including energy, healthcare, and automotive manufacturing, which in some cases resulted in significant operational disruptions. The software has used a hard-coded kill-list of processes, including some associated with common ICS software platforms (e.g., GE Proficy, Honeywell HMIWeb, etc), similar to those defined in MegaCortex.",
      "options": "A. GrimAgent, B. Crimson, C. ShimRat, D. EKANS",
      "choice": "D. EKANS",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_software"
    }
  },
  {
    "instruction": "Q: Answer which mitre software is related to the description: The software is a software suite and network that provides increased anonymity on the Internet. It creates a multi-hop proxy network and utilizes multilayer encryption to protect both the message and routing information. The software utilizes \"Onion Routing,\" in which messages are encrypted with multiple layers of encryption; at each step in the proxy network, the topmost layer is decrypted and the contents forwarded on to the next node until it reaches its destination.\n\nOptions:\nA. Tor, B. Starloader, C. StreamEx, D. StrifeWater",
    "context": "",
    "output": "A. Tor",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_software",
    "parsed_raw_data": {
      "question": "Answer which mitre software is related to the description: The software is a software suite and network that provides increased anonymity on the Internet. It creates a multi-hop proxy network and utilizes multilayer encryption to protect both the message and routing information. The software utilizes \"Onion Routing,\" in which messages are encrypted with multiple layers of encryption; at each step in the proxy network, the topmost layer is decrypted and the contents forwarded on to the next node until it reaches its destination.",
      "options": "A. Tor, B. Starloader, C. StreamEx, D. StrifeWater",
      "choice": "A. Tor",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_software"
    }
  },
  {
    "instruction": "Question: Tell me which MITRE software is referred to in the following description:\n\nThe software is a highly configurable .NET-based crypter that has been possibly active since at least August 2015. The software has been used to deliver popular information stealers, RATs, and payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit.\nA. DarkTortilla, B. MoonWind, C. esentutl, D. Exaramel for Linux\nAnswer:",
    "context": "",
    "output": "A. DarkTortilla",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_software",
    "parsed_raw_data": {
      "question": "Tell me which MITRE software is referred to in the following description:\n\nThe software is a highly configurable .NET-based crypter that has been possibly active since at least August 2015. The software has been used to deliver popular information stealers, RATs, and payloads such as Agent Tesla, AsyncRat, NanoCore, RedLine, Cobalt Strike, and Metasploit.",
      "options": "A. DarkTortilla, B. MoonWind, C. esentutl, D. Exaramel for Linux",
      "choice": "A. DarkTortilla",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_software"
    }
  },
  {
    "instruction": "Which MITRE ATT&CK software is described in the following:\nThe software is a point of sale (POS) malware used by FIN6 to steal payment card data from sytems that run physical POS devices.\nA. FrameworkPOS, B. PowerSploit, C. TINYTYPHON, D. GreyEnergy",
    "context": "",
    "output": "A. FrameworkPOS",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_software",
    "parsed_raw_data": {
      "question": "Which MITRE ATT&CK software is described in the following:\nThe software is a point of sale (POS) malware used by FIN6 to steal payment card data from sytems that run physical POS devices.",
      "options": "A. FrameworkPOS, B. PowerSploit, C. TINYTYPHON, D. GreyEnergy",
      "choice": "A. FrameworkPOS",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_software"
    }
  },
  {
    "instruction": "Q: Give the MITRE ATT&CK software relevant to the following:\nThe software is a virus, data stealer, and wiper that presents itself as ransomware targeting macOS systems. The software was first seen in 2020 distributed via trojanized pirated versions of popular macOS software on Russian forums sharing torrent links. Even though The software presents itself as ransomware, since the dynamically generated encryption key is never sent to the attacker it may be more appropriately thought of as a form of wiper malware.\n\nA. ThiefQuest, B. SharpDisco, C. SHARPSTATS, D. Crimson\nA:",
    "context": "",
    "output": "A. ThiefQuest",
    "category": "MitreFlan",
    "instruction_type": "mitre_options_software",
    "parsed_raw_data": {
      "question": "Give the MITRE ATT&CK software relevant to the following:\nThe software is a virus, data stealer, and wiper that presents itself as ransomware targeting macOS systems. The software was first seen in 2020 distributed via trojanized pirated versions of popular macOS software on Russian forums sharing torrent links. Even though The software presents itself as ransomware, since the dynamically generated encryption key is never sent to the attacker it may be more appropriately thought of as a form of wiper malware.",
      "options": "A. ThiefQuest, B. SharpDisco, C. SHARPSTATS, D. Crimson",
      "choice": "A. ThiefQuest",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_options_software"
    }
  }
]