"comment":"Phishing used against Apple employees + others, this would be dropped by script that they are attempting to get piped to bash via a SMS/iMessage request. This is just a simple pyinstaller wrapped pupy script which beacons back to tipok.gotdns.ch",
"comment":"Phishing used against Apple employees + others, this would be dropped by script that they are attempting to get piped to bash via a SMS/iMessage request. This is just a simple pyinstaller wrapped pupy script which beacons back to tatiano96.zapto.org",
"comment":"Phishing used against Apple employees + others, this would be dropped by script that they are attempting to get piped to bash via a SMS/iMessage request. This is just a simple pyinstaller wrapped pupy script which beacons back to tipok.gotdns.ch",
"comment":"Phishing used against Apple employees + others, this would be dropped by script that they are attempting to get piped to bash via a SMS/iMessage request. This is just a simple pyinstaller wrapped pupy script which beacons back to tipok.gotdns.ch",
"comment":"Phishing used against Apple employees + others, this would be dropped by script that they are attempting to get piped to bash via a SMS/iMessage request. This is just a simple pyinstaller wrapped pupy script which beacons back to tipok.gotdns.ch",
"comment":"Phishing used against Apple employees + others, this would be dropped by script that they are attempting to get piped to bash via a SMS/iMessage request. This is just a simple pyinstaller wrapped pupy script which beacons back to tipok.gotdns.ch",
"comment":"Phishing used against Apple employees + others, this would be dropped by script that they are attempting to get piped to bash via a SMS/iMessage request. This is just a simple pyinstaller wrapped pupy script which beacons back to tipok.gotdns.ch",
"deleted":false,
"disable_correlation":true,
"object_relation":"detection-ratio",
"timestamp":"1519986227",
"to_ids":false,
"type":"text",
"uuid":"5a992633-db0c-4e94-bdf4-4bec02de0b81",
"value":"1/60"
},
{
"category":"Other",
"comment":"Phishing used against Apple employees + others, this would be dropped by script that they are attempting to get piped to bash via a SMS/iMessage request. This is just a simple pyinstaller wrapped pupy script which beacons back to tipok.gotdns.ch",
"deleted":false,
"disable_correlation":false,
"object_relation":"last-submission",
"timestamp":"1519986227",
"to_ids":false,
"type":"datetime",
"uuid":"5a992633-896c-4657-8f26-471002de0b81",
"value":"2018-03-02T09:01:58"
}
]
},
{
"comment":"",
"deleted":false,
"description":"File object describing a file with meta-information",
"comment":"Phishing used against Apple employees + others, this would be dropped by script that they are attempting to get piped to bash via a SMS/iMessage request. This is just a simple pyinstaller wrapped pupy script which beacons back to tatiano96.zapto.org",
"comment":"Phishing used against Apple employees + others, this would be dropped by script that they are attempting to get piped to bash via a SMS/iMessage request. This is just a simple pyinstaller wrapped pupy script which beacons back to tatiano96.zapto.org",
"comment":"Phishing used against Apple employees + others, this would be dropped by script that they are attempting to get piped to bash via a SMS/iMessage request. This is just a simple pyinstaller wrapped pupy script which beacons back to tatiano96.zapto.org",
"comment":"Phishing used against Apple employees + others, this would be dropped by script that they are attempting to get piped to bash via a SMS/iMessage request. This is just a simple pyinstaller wrapped pupy script which beacons back to tatiano96.zapto.org",
"comment":"Phishing used against Apple employees + others, this would be dropped by script that they are attempting to get piped to bash via a SMS/iMessage request. This is just a simple pyinstaller wrapped pupy script which beacons back to tatiano96.zapto.org",
"deleted":false,
"disable_correlation":true,
"object_relation":"detection-ratio",
"timestamp":"1519986229",
"to_ids":false,
"type":"text",
"uuid":"5a992635-0854-453f-a479-4c9d02de0b81",
"value":"1/60"
},
{
"category":"Other",
"comment":"Phishing used against Apple employees + others, this would be dropped by script that they are attempting to get piped to bash via a SMS/iMessage request. This is just a simple pyinstaller wrapped pupy script which beacons back to tatiano96.zapto.org",