2023-12-14 14:30:15 +00:00
|
|
|
{"Event": {"info": "M2M - Trickbot 2017-07-19 : mac1 : \"12345678 - True\n Telecom Invoice for June 2017\" - \"2017-06-Bill.PDF\"", "Tag": [{"colour": "#ffffff", "exportable": true, "name": "tlp:white"}, {"colour": "#0088cc", "exportable": true, "name": "misp-galaxy:tool=\"Trick Bot\""}], "publish_timestamp": "0", "timestamp": "1500470452", "analysis": "1", "Attribute": [{"comment": "", "category": "Artifacts dropped", "uuid": "596f5959-5868-4caf-b7cc-4b21950d210f", "timestamp": "1500470442", "to_ids": true, "value": "89eae47c0fe12a7409dc42304dbb737f", "disable_correlation": false, "object_relation": null, "type": "md5"}, {"comment": "", "category": "Artifacts dropped", "uuid": "596f595a-9750-40b7-870c-4445950d210f", "timestamp": "1500470442", "to_ids": true, "value": "f9650f8f6d8953dbfef206a4783cdd56", "disable_correlation": false, "object_relation": null, "type": "md5"}, {"comment": "", "category": "Network activity", "uuid": "596f595a-b2e0-4390-9955-4fb5950d210f", "timestamp": "1500470442", "to_ids": true, "value": "http://aarontax.com/83b7bf3", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "", "category": "Network activity", "uuid": "596f595a-d1ac-4178-ae43-4f59950d210f", "timestamp": "1500470442", "to_ids": true, "value": "aarontax.com", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "aarontax.com", "category": "Network activity", "uuid": "596f595b-3ad8-4f64-b362-4170950d210f", "timestamp": "1500470442", "to_ids": false, "value": "107.180.2.55", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "", "category": "Network activity", "uuid": "596f595b-dc3c-43c8-9214-178c950d210f", "timestamp": "1500470442", "to_ids": true, "value": "http://aromozames.ru/83b7bf3", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "", "category": "Network activity", "uuid": "596f595b-cbbc-41ed-9dfd-4cc5950d210f", "timestamp": "1500470442", "to_ids": true, "value": "aromozames.ru", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "aromozames.ru", "category": "Network activity", "uuid": "596f595b-3680-41f5-8c88-4d3c950d210f", "timestamp": "1500470442", "to_ids": false, "value": "193.124.183.74", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "aromozames.ru", "category": "Network activity", "uuid": "596f595b-ce14-4638-80f9-19ef950d210f", "timestamp": "1500470442", "to_ids": false, "value": "193.124.188.89", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "", "category": "Network activity", "uuid": "596f595b-e4f8-40ee-a785-47e0950d210f", "timestamp": "1500470442", "to_ids": true, "value": "http://atlon-mebel.ru/83b7bf3", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "", "category": "Network activity", "uuid": "596f595c-8394-4c57-9148-4190950d210f", "timestamp": "1500470442", "to_ids": true, "value": "atlon-mebel.ru", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "atlon-mebel.ru", "category": "Network activity", "uuid": "596f595c-85e8-493d-b029-1864950d210f", "timestamp": "1500470442", "to_ids": false, "value": "178.159.252.126", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "", "category": "Network activity", "uuid": "596f595c-24a0-4abd-9083-447e950d210f", "timestamp": "1500470442", "to_ids": true, "value": "http://atsxpress.com/83b7bf3", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "", "category": "Network activity", "uuid": "596f595d-349c-491d-bdc7-1ab5950d210f", "timestamp": "1500470442", "to_ids": true, "value": "atsxpress.com", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "atsxpress.com", "category": "Network activity", "uuid": "596f595d-9be4-4c27-b5e5-4821950d210f", "timestamp": "1500470442", "to_ids": false, "value": "23.252.3.51", "disable_correlation": false, "object_relation":
|