2023-12-14 14:30:15 +00:00
|
|
|
{"Event": {"info": "M2M - Locky Affid=3, \".asasin\" 2017-11-02 : \"12_Invoice_3456\" - \"001_1234.doc\"", "Tag": [{"colour": "#ffffff", "exportable": true, "name": "tlp:white"}, {"colour": "#006c6c", "exportable": true, "name": "ecsirt:malicious-code=\"ransomware\""}, {"colour": "#0088cc", "exportable": true, "name": "misp-galaxy:ransomware=\"Locky\""}], "publish_timestamp": "1510259156", "timestamp": "1510259162", "analysis": "1", "Attribute": [{"comment": "", "category": "Artifacts dropped", "uuid": "5a044f71-4498-467c-ab71-48ff950d210f", "timestamp": "1510259155", "to_ids": true, "value": "26671a0b08b87754a72ab3d0c2256059", "disable_correlation": false, "object_relation": null, "type": "md5"}, {"comment": "", "category": "Network activity", "uuid": "5a044f72-27b4-401e-89b0-4ab9950d210f", "timestamp": "1510259155", "to_ids": true, "value": "http://nozovent.net/Jmdnaf36dd", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "", "category": "Network activity", "uuid": "5a044f72-adcc-4152-89f8-4ee9950d210f", "timestamp": "1510259155", "to_ids": true, "value": "nozovent.net", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "nozovent.net", "category": "Network activity", "uuid": "5a044f72-e3ac-4b5d-978a-cda3950d210f", "timestamp": "1510259155", "to_ids": false, "value": "167.114.138.110", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "", "category": "Network activity", "uuid": "5a044f72-a9c8-4ddd-b446-991b950d210f", "timestamp": "1510259155", "to_ids": true, "value": "http://pccreatief.nl/Jmdnaf36dd", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "", "category": "Network activity", "uuid": "5a044f73-d3b8-4499-9158-cdb1950d210f", "timestamp": "1510259155", "to_ids": true, "value": "pccreatief.nl", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "pccreatief.nl", "category": "Network activity", "uuid": "5a044f73-cba0-4e88-89e8-cdab950d210f", "timestamp": "1510259155", "to_ids": false, "value": "85.25.192.252", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "", "category": "Network activity", "uuid": "5a044f73-3948-40c5-a2f7-cc6f950d210f", "timestamp": "1510259155", "to_ids": true, "value": "http://plaissetty.com/Jmdnaf36dd", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "", "category": "Network activity", "uuid": "5a044f73-8444-4c98-9302-48f9950d210f", "timestamp": "1510259155", "to_ids": true, "value": "plaissetty.com", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "plaissetty.com", "category": "Network activity", "uuid": "5a044f74-fcac-4eff-aed4-4414950d210f", "timestamp": "1510259155", "to_ids": false, "value": "91.121.183.59", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "", "category": "Network activity", "uuid": "5a044f74-fa18-495a-87e8-20a6950d210f", "timestamp": "1510259155", "to_ids": true, "value": "http://ro.isuzu.it/Jmdnaf36dd", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "", "category": "Network activity", "uuid": "5a044f74-5734-481a-a7dc-cd35950d210f", "timestamp": "1510259155", "to_ids": true, "value": "ro.isuzu.it", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "ro.isuzu.it", "category": "Network activity", "uuid": "5a044f74-5c24-4898-9219-4ac3950d210f", "timestamp": "1510259155", "to_ids": false, "value": "95.110.189.247", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "", "category": "Network activity", "uuid": "5a044f75-9a44-415e-88a7-cda3950d210f", "timestamp": "1510259155", "to_ids": true, "value": "http://sirbis.de/Jmdnaf36dd", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "", "category": "Network activity", "uuid": "5a044f75-6c00-4ebc-8fae-991b950d210f", "timestamp": "1510259155", "to_ids": true, "value":
|