[
  {
    "instruction": "Q: You are given the following description:\nDescription - 3PARA RAT is a remote access tool (RAT) programmed in C++ that has been used by Putter Panda..\n\nIs the following description related to software 3PARA RAT (S0066).\n\nProvide your answer in Yes or No.",
    "context": "",
    "output": "Yes",
    "category": "MitreFlan",
    "instruction_type": "mitre_yes_no_description_software",
    "parsed_raw_data": {
      "question": "You are given the following description:\nDescription - 3PARA RAT is a remote access tool (RAT) programmed in C++ that has been used by Putter Panda..\n\nIs the following description related to software 3PARA RAT (S0066)",
      "yes/no": "Yes",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_yes_no_description_software"
    }
  },
  {
    "instruction": "Q: Is software HAMMERTOSS (S0333) accurately described in the following description:\n\nUBoatRAT is a remote access tool that was identified in May 2017..\n\nProvide your answer in Yes or No.",
    "context": "",
    "output": "No",
    "category": "MitreFlan",
    "instruction_type": "mitre_yes_no_description_software",
    "parsed_raw_data": {
      "question": "Is software HAMMERTOSS (S0333) accurately described in the following description:\n\nUBoatRAT is a remote access tool that was identified in May 2017.",
      "yes/no": "No",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_yes_no_description_software"
    }
  },
  {
    "instruction": "Answer in Yes or No.\n\nQuestion: Is software ZxxZ (S0477) accurately described in the following description:\n\nGoopy is a Windows backdoor and Trojan used by APT32 and shares several similarities to another backdoor used by the group (Denis). Goopy is named for its impersonation of the legitimate Google Updater executable.",
    "context": "",
    "output": "No.\nThe provided context is correlated with Goopy",
    "category": "MitreFlan",
    "instruction_type": "mitre_yes_no_description_software",
    "parsed_raw_data": {
      "question": "Is software ZxxZ (S0477) accurately described in the following description:\n\nGoopy is a Windows backdoor and Trojan used by APT32 and shares several similarities to another backdoor used by the group (Denis). Goopy is named for its impersonation of the legitimate Google Updater executable.",
      "yes/no": "No.\nThe provided context is correlated with Goopy",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_yes_no_description_software"
    }
  },
  {
    "instruction": "Answer in Yes or No.\n\nQuestion: You are given the following description:\nDescription - Ping is an operating system utility commonly used to troubleshoot and verify network connections..\n\nIs the following description related to software Ping (S0097)",
    "context": "",
    "output": "Yes",
    "category": "MitreFlan",
    "instruction_type": "mitre_yes_no_description_software",
    "parsed_raw_data": {
      "question": "You are given the following description:\nDescription - Ping is an operating system utility commonly used to troubleshoot and verify network connections..\n\nIs the following description related to software Ping (S0097)",
      "yes/no": "Yes",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_yes_no_description_software"
    }
  },
  {
    "instruction": "Answer in Yes or No.\n\nQuestion: You are given the following description:\nDescription - Invoke-PSImage takes a PowerShell script and embeds the bytes of the script into the pixels of a PNG image. It generates a one liner for executing either from a file of from the web. Example of usage is embedding the PowerShell code from the Invoke-Mimikatz module and embed it into an image file. By calling the image file from a macro for example, the macro will download the picture and execute the PowerShell code, which in this case will dump the passwords..\n\nIs the following description related to software Invoke-PSImage (S0231)",
    "context": "",
    "output": "Yes",
    "category": "MitreFlan",
    "instruction_type": "mitre_yes_no_description_software",
    "parsed_raw_data": {
      "question": "You are given the following description:\nDescription - Invoke-PSImage takes a PowerShell script and embeds the bytes of the script into the pixels of a PNG image. It generates a one liner for executing either from a file of from the web. Example of usage is embedding the PowerShell code from the Invoke-Mimikatz module and embed it into an image file. By calling the image file from a macro for example, the macro will download the picture and execute the PowerShell code, which in this case will dump the passwords..\n\nIs the following description related to software Invoke-PSImage (S0231)",
      "yes/no": "Yes",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_yes_no_description_software"
    }
  },
  {
    "instruction": "Q: Is software YAHOYAH (S0452) accurately described in the following description:\n\nUSBferry is an information stealing malware and has been used by Tropic Trooper in targeted attacks against Taiwanese and Philippine air-gapped military environments. USBferry shares an overlapping codebase with YAHOYAH, though it has several features which makes it a distinct piece of malware..\n\nProvide your answer in Yes or No.",
    "context": "",
    "output": "No.\nThe provided context is related to USBferry",
    "category": "MitreFlan",
    "instruction_type": "mitre_yes_no_description_software",
    "parsed_raw_data": {
      "question": "Is software YAHOYAH (S0452) accurately described in the following description:\n\nUSBferry is an information stealing malware and has been used by Tropic Trooper in targeted attacks against Taiwanese and Philippine air-gapped military environments. USBferry shares an overlapping codebase with YAHOYAH, though it has several features which makes it a distinct piece of malware.",
      "yes/no": "No.\nThe provided context is related to USBferry",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_yes_no_description_software"
    }
  },
  {
    "instruction": "Answer in Yes or No.\n\nQuestion: You are given the following description:\nDescription - Ecipekac is a multi-layer loader that has been used by menuPass since at least 2019 including use as a loader for P8RAT, SodaMaster, and FYAnti..\n\nIs the following description related to software NGLite (S0624)",
    "context": "",
    "output": "No.\nThe correct answer is Ecipekac",
    "category": "MitreFlan",
    "instruction_type": "mitre_yes_no_description_software",
    "parsed_raw_data": {
      "question": "You are given the following description:\nDescription - Ecipekac is a multi-layer loader that has been used by menuPass since at least 2019 including use as a loader for P8RAT, SodaMaster, and FYAnti..\n\nIs the following description related to software NGLite (S0624)",
      "yes/no": "No.\nThe correct answer is Ecipekac",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_yes_no_description_software"
    }
  },
  {
    "instruction": "Q: You are given the following description:\nDescription - MoleNet is a downloader tool with backdoor capabilities that has been observed in use since at least 2019..\n\nIs the following description related to software CrackMapExec (S0553).\n\nProvide your answer in Yes or No.",
    "context": "",
    "output": "No.\nThe correct answer is MoleNet",
    "category": "MitreFlan",
    "instruction_type": "mitre_yes_no_description_software",
    "parsed_raw_data": {
      "question": "You are given the following description:\nDescription - MoleNet is a downloader tool with backdoor capabilities that has been observed in use since at least 2019..\n\nIs the following description related to software CrackMapExec (S0553)",
      "yes/no": "No.\nThe correct answer is MoleNet",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_yes_no_description_software"
    }
  },
  {
    "instruction": "Answer in Yes or No.\n\nQuestion: You are given the following description:\nDescription - DnsSystem is a .NET based DNS backdoor, which is a customized version of the open source tool DIG.net, that has been used by HEXANE since at least June 2022..\n\nIs the following description related to software Mythic (S1021)",
    "context": "",
    "output": "No.\nThe provided context is correlated with DnsSystem",
    "category": "MitreFlan",
    "instruction_type": "mitre_yes_no_description_software",
    "parsed_raw_data": {
      "question": "You are given the following description:\nDescription - DnsSystem is a .NET based DNS backdoor, which is a customized version of the open source tool DIG.net, that has been used by HEXANE since at least June 2022..\n\nIs the following description related to software Mythic (S1021)",
      "yes/no": "No.\nThe provided context is correlated with DnsSystem",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_yes_no_description_software"
    }
  },
  {
    "instruction": "Q: You are given the following description:\nDescription - Naid is a trojan used by Elderwood to open a backdoor on compromised hosts..\n\nIs the following description related to software Naid (S0205).\n\nProvide your answer in Yes or No.",
    "context": "",
    "output": "Yes",
    "category": "MitreFlan",
    "instruction_type": "mitre_yes_no_description_software",
    "parsed_raw_data": {
      "question": "You are given the following description:\nDescription - Naid is a trojan used by Elderwood to open a backdoor on compromised hosts..\n\nIs the following description related to software Naid (S0205)",
      "yes/no": "Yes",
      "category": [
        "MITREFlan"
      ],
      "instruction_type": "mitre_yes_no_description_software"
    }
  }
]