misp-circl-feed/feeds/circl/misp/e7ba6328-3c18-4578-a7c2-96a151170246.json

996 lines
1 MiB
JSON
Raw Normal View History

2023-04-21 13:25:09 +00:00
{
"Event": {
"analysis": "2",
"date": "2022-08-18",
"extends_uuid": "",
"info": "OSINT - Reservations Requested: TA558 Targets Hospitality and Travel",
"publish_timestamp": "1661327199",
"published": true,
"threat_level_id": "2",
"timestamp": "1661327170",
"uuid": "e7ba6328-3c18-4578-a7c2-96a151170246",
"Orgc": {
"name": "CIRCL",
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
},
"Tag": [
{
"colour": "#004646",
2023-05-19 09:05:37 +00:00
"local": "0",
"name": "type:OSINT",
"relationship_type": ""
2023-04-21 13:25:09 +00:00
},
{
"colour": "#0071c3",
2023-05-19 09:05:37 +00:00
"local": "0",
"name": "osint:lifetime=\"perpetual\"",
"relationship_type": ""
2023-04-21 13:25:09 +00:00
},
{
"colour": "#0087e8",
2023-05-19 09:05:37 +00:00
"local": "0",
"name": "osint:certainty=\"50\"",
"relationship_type": ""
2023-04-21 13:25:09 +00:00
},
{
"colour": "#ffffff",
2023-05-19 09:05:37 +00:00
"local": "0",
"name": "tlp:white",
"relationship_type": ""
2023-04-21 13:25:09 +00:00
},
{
"colour": "#0088cc",
2023-05-19 09:05:37 +00:00
"local": "0",
"name": "misp-galaxy:region=\"005 - South America\"",
"relationship_type": ""
2023-04-21 13:25:09 +00:00
},
{
"colour": "#0088cc",
2023-05-19 09:05:37 +00:00
"local": "0",
"name": "misp-galaxy:target-information=\"Mexico\"",
"relationship_type": ""
2023-04-21 13:25:09 +00:00
},
{
"colour": "#0088cc",
2023-05-19 09:05:37 +00:00
"local": "0",
"name": "misp-galaxy:threat-actor=\"TA558\"",
"relationship_type": ""
2023-04-21 13:25:09 +00:00
}
],
"Attribute": [
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "4008c754-2dc9-43e1-9270-91d20eff4eed",
"value": "warzonecdt.duckdns.org"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "b64ed2cf-929c-454b-b78f-4394e6224d02",
"value": "system11.sslblindado.com"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "c1cf733a-b313-4eaf-a6c8-7c6943cb0cb7",
"value": "successfully.hopto.org"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "5f91f381-5018-4ece-8714-c5262aa45d34",
"value": "success20.hopto.org"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "dc1cb63b-e198-4a98-a538-0db4257acfd0",
"value": "quedabesouro.ddns.net"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "80a5abf2-985c-427f-9303-7a576c98f5b3",
"value": "queda212.duckdns.org"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "b8c2bfbf-d9fe-4b8e-8559-9db5fde85160",
"value": "passagensv.sslblindado.com"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "621b1550-a05b-46fb-a8ef-24f602d8b2b2",
"value": "msin.hopto.org"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "dd383eb5-4b43-4e56-883c-ab6a759b82ab",
"value": "microsofft.sslblindado.com"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "9120e461-179d-437a-9ad7-c20c3a893619",
"value": "googledrives.ddns.net"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "368fe61d-d39d-4dd9-b1a9-51214d7d68c2",
"value": "firefoxsystem.sytes.net"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "100cdf20-c229-43e1-a55b-5074d5cb90aa",
"value": "cdtpitbull.hopto.org"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "628b8bd9-ea2f-4c0c-810a-35269746dfc9",
"value": "cdt2021.zapto.org"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "679581be-827b-4ddd-ba3b-0582bb9fdca1",
"value": "4success.zapto.org"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "c92bb92b-136d-42f7-baa9-04730fb29b3e",
"value": "3030pp.hopto.org"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "hostname",
"uuid": "e229e6bb-fb66-4682-80fe-f6988858c55b",
"value": "111234cdt.ddns.net"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "email-src",
"uuid": "40a458f9-235c-4589-858e-401a7ff8e8f0",
"value": "quickbooks@unimed-corporated.com"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "email-src",
"uuid": "3f682801-330f-4561-91e6-406ba24048e0",
"value": "maringa.turismo@system11.com.br"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "email-src",
"uuid": "d956761d-c690-4ba0-985e-f0681df99701",
"value": "financeiro@unimed-corporated.com"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "email-src",
"uuid": "736ae39c-2800-45cd-b998-6b1a15fb5d57",
"value": "contato@155hotel.com.br"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "url",
"uuid": "e20ff3b6-870b-43d0-8ba4-42e7f3859178",
"value": "http://maringareservas.com.br/seila.rtf"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "url",
"uuid": "23fee22b-8f6a-4d73-b101-9097a98c87e0",
"value": "http://hypemediardf.com.pl/css/css.doc"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "url",
"uuid": "6342d829-3ce8-48c3-b100-c5600260b82d",
"value": "http://corporated.com/tur/turismo.jpg"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "url",
"uuid": "129297ea-88a4-47cd-a071-39895efede47",
"value": "http://corporated.com/microsoft.txt"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "url",
"uuid": "b3ed619c-782e-47ce-8ca1-5dbefad1e733",
"value": "http://cdtmaster.com.br/DadosDaReserva.doc"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "ip-dst",
"uuid": "7a6586bf-59bd-444f-81d8-26229926b154",
"value": "38.132.101.45"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "sha256",
"uuid": "ce4d7592-d674-4d07-b393-0fa36cedfc3a",
"value": "c2b817b02e56624c8ed7944e76a3896556dc2b7482f747f4be88f95e232f9207"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "sha256",
"uuid": "60860d22-7a36-48ce-ba4a-613ecb58691a",
"value": "b57a9f7321216c3410ebcc9d4b09e73a652dee9e750f96b2f6d7d1e39e2923d6"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "sha256",
"uuid": "c2d832d4-fa8e-41f4-8234-4081996997e5",
"value": "7dc70d023b2ee5a941edd925999bb6864343b11758c7dc18309416f2947ddb6e"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "sha256",
"uuid": "51a5665b-fbef-4e5c-b5e7-6ffde7bf1045",
"value": "796c02729c9cd5d37976ddae205226e6339b64859e9980d56cbfc5f461d00910"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "sha256",
"uuid": "136f1cf5-3bd3-48c9-9b05-7493129f9134",
"value": "2f0f99cbac828092c0ec23e12ecb44cbf53f5a671a80842a2447e6114e4f6979"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "sha1",
"uuid": "6ba96613-4864-4184-aa28-54f665d2c2c5",
"value": "c396cfb2744bf92575274b277a6c47fe9566dbff"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": true,
"type": "md5",
"uuid": "20256053-3a6d-401a-802c-540740505140",
"value": "070950303d80db5d2eb93e21aad77d04"
},
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": false,
"type": "vulnerability",
"uuid": "ca630b95-9955-4e4b-b461-cee4a9bd7d9a",
"value": "CVE-2017-8570"
},
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1660894060",
"to_ids": false,
"type": "vulnerability",
"uuid": "00d589c3-2ab7-4587-8f08-77dd869ca869",
"value": "CVE-2017-11882"
}
],
"Object": [
{
"comment": "",
"deleted": false,
"description": "Metadata used to generate an executive level report",
"meta-category": "misc",
"name": "report",
"template_uuid": "70a68471-df22-4e3f-aa1a-5a3be19f82df",
"template_version": "7",
"timestamp": "1660892888",
"uuid": "ba5cbf43-23db-4b15-84f9-f6ea0376e95d",
"Attribute": [
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "link",
"timestamp": "1660892888",
"to_ids": false,
"type": "link",
"uuid": "c0eaa5d0-e310-402e-90fb-61bbee5a0749",
"value": "https://www.proofpoint.com/us/blog/threat-insight/reservations-requested-ta558-targets-hospitality-and-travel"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "summary",
"timestamp": "1660892888",
"to_ids": false,
"type": "text",
"uuid": "8de3129e-f920-4607-8cd2-0fe04b1a8c3b",
"value": "Key Findings:\r\n\r\n TA558 is a likely financially motivated small crime threat actor targeting hospitality, hotel, and travel organizations.\r\n Since 2018, this group has used consistent tactics, techniques, and procedures to attempt to install a variety of malware including Loda RAT, Vjw0rm, and Revenge RAT.\r\n TA558\u2019s targeting focus is mainly on Portuguese and Spanish speakers, typically located in the Latin America region, with additional targeting observed in Western Europe and North America.\r\n TA558 increased operational tempo in 2022 to a higher average than previously observed. \r\n Like other threat actors in 2022, TA558 pivoted away from using macro-enabled documents in campaigns and adopted new tactics, techniques, and procedures."
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "type",
"timestamp": "1660892888",
"to_ids": false,
"type": "text",
"uuid": "4b432ccd-99e2-4bf5-b619-2c4fe09068f7",
"value": "Blog"
}
]
},
{
"comment": "",
"deleted": false,
"description": "Metadata used to generate an executive level report",
"meta-category": "misc",
"name": "report",
"template_uuid": "70a68471-df22-4e3f-aa1a-5a3be19f82df",
"template_version": "7",
"timestamp": "1660893407",
"uuid": "de7a3de5-9870-48e3-9d3d-8a02af97a3c8",
"Attribute": [
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "link",
"timestamp": "1660893407",
"to_ids": false,
"type": "link",
"uuid": "7d50063e-e8ec-4fbe-9bb0-625fadb0bb47",
"value": "https://otx.alienvault.com/pulse/62fe1e074b82e798cd731a70/"
}
]
},
{
"comment": "",
"deleted": false,
"description": "Email object describing an email with meta-information",
"meta-category": "network",
"name": "email",
"template_uuid": "a0c666e0-fc65-4be8-b48f-3423d788b552",
"template_version": "18",
"timestamp": "1660911109",
"uuid": "9c9a982c-a37e-4e24-85f6-0bb85d0365cf",
"Attribute": [
{
"category": "External analysis",
"comment": "",
"data": "iVBORw0KGgoAAAANSUhEUgAAAtQAAAKSCAYAAADyLEyBAAAYb2lDQ1BJQ0MgUHJvZmlsZQAAWIWVWQc8le3fv+6zz7HPsffeZO+9994kHOtYccxQIskqUSFKJZmVSqESkYZSRg9JEsmoFCoqI+9t1P95n+f9vO/nvT6f676+53f9rt+61v07NwBcnb6RkWEIRgDCI2KoDqYG/G7uHvzYKYAFPAAP2ICSLzk6Ut/OzgrA5Xf738vSIIA22ucyG7L+3f+/FqJ/QDQZAMgLxn7+0eRwGN8FAJVGjqTGAIAxgulC8TGRGzgYxsxU2EAYJ2/goC18dAP7beGKTR4nB0MYNwOAo/X1pQYBQN8J0/njyEGwHPp3cB8xwp8SAbP+gLEOOdjXHwAuNZhHOjx89waGKxCH+SNhnAtjNb+/yQz6b/L9/sj39Q36g7f82iw4I0p0ZJjvnv9naP7vEh4W+1uHKFxpg6lmDhv+wzEcCt1tuYFpYTwb4WdjuxFrGP+g+G/FHQAEITjWzHmLH8FNjjaE4wdYYSzn72tkCWNuGJtEhNlYbdP9Aikm5jCGVwsigRJj7rQ9NjMg2thxW+Yp6m4H2984kGqovz32si91U+8Gf2dsqLP+tvyh4ADz3/K/JQY7ucKYAACSEEdxsYExPYyZo0MdLbd4kIKJwYY2v3mosQ4b9gvDWC0gwtRgSz7SK5Bq4rDNHxke/dtfZEYwxdxmGxfHBDuZbcUHWUv23bSfHcaNARH6zr/lBES7Wf32xT/AyHjLd+SzgAjnbX+Ro5ExBg7bY+cjw+y2+VG4gDDTDbogjDmj4xy3x6K0YuDFuSUfZRUZY+e0ZSfKJ8TXwm7LHlQcsAKGwAjwg1i4+oHdIARQns02zcK/tnpMgC+ggiAQAGS2Kb9HuG72RMBPR5AIPsEoAET/GWew2RsA4mD62h/q1lMGBG72xm2OCAVTMA4HliAM/h27OSrijzYX8A6mUP6lnQzbGgbXjb5/0/RhitU2Jfa3XH6G35wYY4wRxgxjgpFAcaJ0UJooK/ipB1cFlBpK/be1/+FHT6H70G/RA+gx9MtdlDTqP2yxBmOwfJNtj/3+7jFKFJapjDJAacPSYckoVhQnkEEpwXr0UbqwZmWYarht94bv/P+Dn388+FvMt/nwcngEng2vhxf/50h6SXrlP1I2Ivr3+GzZ6vcnqoZ/ev6p3/BvcfaHW8t/ciIzkQ3Ih8h2ZBeyBdkE+JFtyGZkN/LOBv6zht5trqHf2hw27QmF5VD+pc93W+dGJKPl6uTey61u94GYgISYjQ1muDtyD5USFBzDrw/fAgH85hFkWWl+BTkFBQA27pStY+qrw+ZdAbH2/IdGPgiA6jwA+OX/0MK/AnAF3uP81v+hiXjD2wwDQPUUOZYat0VDbTzQ8GnAAO8oDsALhIA47JECUAGaQA8YAwtgC5yAO/CG4xwMr2cqiAfJIBVkgBxwFJwAJeAMOA+qwSVwDTSBFtAOHoAnoBcMgFfw+pkEH8E8WAIrEARhITqIBHFAfJAIJAUpQGqQDmQMWUEOkDvkAwVBEVAslAwdgHKgAqgEOgfVQFehm1A71AX1QS+hceg99AVaRiARtAhmBA9CFLEDoYbQR1ginBA7EUGIKEQiIh1xBFGMKEdcRDQi2hFPEAOIMcRHxCISIGmQrEgBpAxSDWmItEV6IAORVOQ+ZDayEFmOvIy8Bc/0c+QYchb5E4VBkVD8KBl4DZuhnFFkVBRqHyoXVYKqRjWiOlHPUeOoedQvNB2aGy2F1kCbo93QQeh4dAa6EF2JvoG+D++mSfQSBoNhxYhhVOHd6I4JwSRhcjGnMfWYu5g+zARmEYvFcmClsNpYW6wvNgabgT2JvYhtw/ZjJ7E/cDQ4PpwCzgTngYvApeEKcbW4Vlw/bhq3gmfEi+A18LZ4f/wefB6+An8L34OfxK8QmAhiBG2CEyGEkEooJlwm3CeMEL7S0NAI0qjT2NNQaPbTFNNcoXlEM07zk5ZIK0lrSOtFG0t7hLaK9i7tS9qvdHR0onR6dB50MXRH6Gro7tGN0v2gJ9HL0pvT+9On0JfSN9L3039mwDOIMOgzeDMkMhQyNDD0MMwy4hlFGQ0ZfRn3MZYy3mR8wbjIRGKSZ7JlCmfKZapl6mKaIWKJokRjoj8xnXieeI84QUKShEiGJDLpAKmCdJ80yYxhFmM2Zw5hzmG+xPyMeZ6FyKLE4sKSwFLKcodljBXJKspqzhrGmsd6jXWQdZmNh02fLYAti+0yWz/bd3Yudj32APZs9nr2AfZlDn4OY45QjnyOJo7XnChOSU57znjOMs77nLNczFyaXGSubK5rXMPcCG5JbgfuJO7z3N3cizy8PKY8kTwnee7xzPKy8urxhvAe523lfc9H4tPho/Ad52vj+8DPwq/PH8ZfzN/JPy/ALWAmECtwTuCZwIqgmKCzYJpgveBrIYKQmlCg0HGhDqF5YT5ha+Fk4TrhYRG8iJpIsEiRyEOR76Jioq6ih0SbRGfE2MXMxRLF6sRGxOnEdcWjxMvF/5LASKhJhEqcluiVREgqSwZLlkr2SCGkVKQoUqel+qTR0urSEdLl0i9kaGX0ZeJk6mTGZVllrWTTZJtkP+8Q3uGxI3/Hwx2/5JTlwuQq5F7JE+Ut5NPkb8l/UZBUICuUKvylSKdoopii2Ky4oCSlFKBUpjSkTFK2Vj6k3KG8pqKqQlW5rPJeVVjVR/WU6gs1ZjU7tVy1R+podQP1FPUW9Z8aKhoxGtc05jRlNEM1azVntMS0ArQqtCa0BbV9tc9pj+nw6/jonNUZ0xXQ9dUt132rJ6Tnr1epN60voR+if1H/s4GcAdXghsF3Qw3DvYZ3jZBGpkbZRs+MicbOxiXGoyaCJkEmdSbzpsqmSaZ3zdBmlmb5Zi/MeczJ5jXm8xaqFnstOi1pLR0tSyzfWklaUa1uWSOsLayPWY/YiNhE2DTZAltz22O2r+3E7KLsbttj7O3sS+2nHOQdkh0eOpIcdznWOi45GTjlOb1yFneOde5wYXDxcqlx+e5q5FrgOua2w22v2xN3TneKe7MH1sPFo9Jj0dPY84TnpJeyV4bX4E6xnQk7u7w5vcO87+xi2OW7q8EH7ePqU+uz6mvrW+676Gfud8pvnmxILiJ/9NfzP+7/PkA7oCBgOlA7sCBwJkg76FjQ+2Dd4MLgWYohpYSyEGIWcibke6htaFXoephrWH04Ltwn/GYEMSI0onM37+6E3X2RUpEZkWNRGlEnouapltTKaCh6Z3RzDDP88t4dKx57MHY8TieuNO5HvEt8QwJTQkRC9x7JPVl7phNNEi8koZLISR3JAsmpyeN79fee2wft89vXkSKUkp4yud90f3UqITU09WmaXFpB2rcDrgdupfOk70+fOGh6sC6DPoOa8eKQ5qEzmahMSuazLMWsk1m/sv2zH+fI5RTmrOaScx8flj9cfHj9SOCRZ3kqeWVHMUcjjg7m6+ZXFzAVJBZMHLM+1nic/3j28W8ndp3oKlQqPFNEKIotGiu2Km4+KXzy6MnVkuCSgVKD0vpT3KeyTn0/7X+6v0yv7PIZnjM5Z5bPUs4OnTM911guWl54HnM+7vxUhUvFwwtqF2oqOStzKteqIqrGqh2qO2tUa2pquWvz6hB1sXXvL3pd7L1kdKn5sszlc/Ws9TlXwJXYKx+u+lwdvGZ5raNBreHydZHrp26QbmQ3Qo17GuebgpvGmt2b+25a3Oy4pXnrxm3Z21UtAi2ld1ju5LUSWtNb19sS2xbvRt6dbQ9qn+jY1fHqntu9vzrtO5/dt7z/6IHJg3sP9R+2PdJ+1NKl0XXzsdrjpicqTxq7lbtvPFV+euOZyrPGHtWe5l713lt9Wn2t/br97c+Nnj/4y/yvJwM2A32DzoNDL7xejA35D828DHu5MBw3vPJq/wh6JPs14+vCUe7R8jcSb+rHVMbujBuNd791fPtqgjzx8V30u9XJ9Cm6qcJpvumaGYWZlvcm73s/eH6Y/Bj5cWU24xPTp1OfxT9fn9Ob6553m59coC6sf8n9yvG16pvSt45Fu8XRpfClle/ZPzh+VP
"deleted": false,
"disable_correlation": true,
"object_relation": "screenshot",
"timestamp": "1660911109",
"to_ids": false,
"type": "attachment",
"uuid": "45b86eeb-9e57-4f79-98f2-ce23f5ae2c69",
"value": "Screen Shot 2022-08-16 at 11.54.40 AM.png"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "subject",
"timestamp": "1660911109",
"to_ids": false,
"type": "email-subject",
"uuid": "69d60167-3d1b-4f8c-897a-302d96e9946e",
"value": "Corrigir data da reserva para o dia 03"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "attachment",
"timestamp": "1660911109",
"to_ids": true,
"type": "email-attachment",
"uuid": "5e89e5f8-2760-487c-a918-0d0b6de256d0",
"value": "Booking - Dados da Reserva.docx"
}
]
},
{
"comment": "",
"deleted": false,
"description": "File object describing a file with meta-information",
"meta-category": "file",
"name": "file",
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
"template_version": "24",
"timestamp": "1660911335",
"uuid": "8809def6-57c4-40fb-b31c-db538af6bad6",
"ObjectReference": [
{
"comment": "",
"object_uuid": "8809def6-57c4-40fb-b31c-db538af6bad6",
"referenced_uuid": "9c9a982c-a37e-4e24-85f6-0bb85d0365cf",
"relationship_type": "contained-within",
"timestamp": "1660911335",
"uuid": "fb423122-e7ac-42d7-a1bc-cf8e861119ba"
}
],
"Attribute": [
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "text",
"timestamp": "1660911276",
"to_ids": false,
"type": "text",
"uuid": "0cad5bc2-e4df-4e41-95b2-0875f3947acf",
"value": "Author\u201d: C.D.T Original"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha256",
"timestamp": "1660911276",
"to_ids": true,
"type": "sha256",
"uuid": "5e2c51cf-8007-49b0-ac6d-5938811e8f9e",
"value": "796c02729c9cd5d37976ddae205226e6339b64859e9980d56cbfc5f461d00910"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "filename",
"timestamp": "1660911276",
"to_ids": true,
"type": "filename",
"uuid": "c65fb712-197d-47f6-8958-c3c81d7a6adb",
"value": "Booking - Dados da Reserva.docx"
}
]
},
{
"comment": "",
"deleted": false,
"description": "File object describing a file with meta-information",
"meta-category": "file",
"name": "file",
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
"template_version": "24",
"timestamp": "1661171267",
"uuid": "20c2cfc4-4abe-42e5-ac49-5759447323a8",
"ObjectReference": [
{
"comment": "",
"object_uuid": "20c2cfc4-4abe-42e5-ac49-5759447323a8",
"referenced_uuid": "dfac55b4-672a-45b3-aaa6-0e60dbdbaf96",
"relationship_type": "contained-within",
"timestamp": "1661171267",
"uuid": "626e1483-32c7-45ee-a481-2d71e94c7d1f"
}
],
"Attribute": [
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "text",
"timestamp": "1661170240",
"to_ids": false,
"type": "text",
"uuid": "5f28d374-5ff0-4ba5-b497-a1d7117dc2bf",
"value": "Attachment \u201cAuthor\u201d: msword\r\n\r\nAttachment \u201cLast Saved By\u201d: Richard"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha256",
"timestamp": "1661170240",
"to_ids": true,
"type": "sha256",
"uuid": "51a99aba-7af6-41ee-9267-d2fc8869b07c",
"value": "7dc70d023b2ee5a941edd925999bb6864343b11758c7dc18309416f2947ddb6e"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "filename",
"timestamp": "1661170240",
"to_ids": true,
"type": "filename",
"uuid": "d4a28b03-375d-4fa9-9609-36444b0268b8",
"value": "RESERVA.docx"
}
]
},
{
"comment": "",
"deleted": false,
"description": "Email object describing an email with meta-information",
"meta-category": "network",
"name": "email",
"template_uuid": "a0c666e0-fc65-4be8-b48f-3423d788b552",
"template_version": "18",
"timestamp": "1661170571",
"uuid": "dfac55b4-672a-45b3-aaa6-0e60dbdbaf96",
"Attribute": [
{
"category": "External analysis",
"comment": "",
"data": "iVBORw0KGgoAAAANSUhEUgAAA58AAAHvCAYAAADTrGuUAAAYb2lDQ1BJQ0MgUHJvZmlsZQAAWIWVWQc8le3fv+6zz7HPsffeZO+9994kHOtYccxQIskqUSFKJZmVSqESkYZSRg9JEsmoFCoqI+9t1P95n+f9vO/nvT6f676+53f9rt+61v07NwBcnb6RkWEIRgDCI2KoDqYG/G7uHvzYKYAFPAAP2ICSLzk6Ut/OzgrA5Xf738vSIIA22ucyG7L+3f+/FqJ/QDQZAMgLxn7+0eRwGN8FAJVGjqTGAIAxgulC8TGRGzgYxsxU2EAYJ2/goC18dAP7beGKTR4nB0MYNwOAo/X1pQYBQN8J0/njyEGwHPp3cB8xwp8SAbP+gLEOOdjXHwAuNZhHOjx89waGKxCH+SNhnAtjNb+/yQz6b/L9/sj39Q36g7f82iw4I0p0ZJjvnv9naP7vEh4W+1uHKFxpg6lmDhv+wzEcCt1tuYFpYTwb4WdjuxFrGP+g+G/FHQAEITjWzHmLH8FNjjaE4wdYYSzn72tkCWNuGJtEhNlYbdP9Aikm5jCGVwsigRJj7rQ9NjMg2thxW+Yp6m4H2984kGqovz32si91U+8Gf2dsqLP+tvyh4ADz3/K/JQY7ucKYAACSEEdxsYExPYyZo0MdLbd4kIKJwYY2v3mosQ4b9gvDWC0gwtRgSz7SK5Bq4rDNHxke/dtfZEYwxdxmGxfHBDuZbcUHWUv23bSfHcaNARH6zr/lBES7Wf32xT/AyHjLd+SzgAjnbX+Ro5ExBg7bY+cjw+y2+VG4gDDTDbogjDmj4xy3x6K0YuDFuSUfZRUZY+e0ZSfKJ8TXwm7LHlQcsAKGwAjwg1i4+oHdIARQns02zcK/tnpMgC+ggiAQAGS2Kb9HuG72RMBPR5AIPsEoAET/GWew2RsA4mD62h/q1lMGBG72xm2OCAVTMA4HliAM/h27OSrijzYX8A6mUP6lnQzbGgbXjb5/0/RhitU2Jfa3XH6G35wYY4wRxgxjgpFAcaJ0UJooK/ipB1cFlBpK/be1/+FHT6H70G/RA+gx9MtdlDTqP2yxBmOwfJNtj/3+7jFKFJapjDJAacPSYckoVhQnkEEpwXr0UbqwZmWYarht94bv/P+Dn388+FvMt/nwcngEng2vhxf/50h6SXrlP1I2Ivr3+GzZ6vcnqoZ/ev6p3/BvcfaHW8t/ciIzkQ3Ih8h2ZBeyBdkE+JFtyGZkN/LOBv6zht5trqHf2hw27QmF5VD+pc93W+dGJKPl6uTey61u94GYgISYjQ1muDtyD5USFBzDrw/fAgH85hFkWWl+BTkFBQA27pStY+qrw+ZdAbH2/IdGPgiA6jwA+OX/0MK/AnAF3uP81v+hiXjD2wwDQPUUOZYat0VDbTzQ8GnAAO8oDsALhIA47JECUAGaQA8YAwtgC5yAO/CG4xwMr2cqiAfJIBVkgBxwFJwAJeAMOA+qwSVwDTSBFtAOHoAnoBcMgFfw+pkEH8E8WAIrEARhITqIBHFAfJAIJAUpQGqQDmQMWUEOkDvkAwVBEVAslAwdgHKgAqgEOgfVQFehm1A71AX1QS+hceg99AVaRiARtAhmBA9CFLEDoYbQR1ginBA7EUGIKEQiIh1xBFGMKEdcRDQi2hFPEAOIMcRHxCISIGmQrEgBpAxSDWmItEV6IAORVOQ+ZDayEFmOvIy8Bc/0c+QYchb5E4VBkVD8KBl4DZuhnFFkVBRqHyoXVYKqRjWiOlHPUeOoedQvNB2aGy2F1kCbo93QQeh4dAa6EF2JvoG+D++mSfQSBoNhxYhhVOHd6I4JwSRhcjGnMfWYu5g+zARmEYvFcmClsNpYW6wvNgabgT2JvYhtw/ZjJ7E/cDQ4PpwCzgTngYvApeEKcbW4Vlw/bhq3gmfEi+A18LZ4f/wefB6+An8L34OfxK8QmAhiBG2CEyGEkEooJlwm3CeMEL7S0NAI0qjT2NNQaPbTFNNcoXlEM07zk5ZIK0lrSOtFG0t7hLaK9i7tS9qvdHR0onR6dB50MXRH6Gro7tGN0v2gJ9HL0pvT+9On0JfSN9L3039mwDOIMOgzeDMkMhQyNDD0MMwy4hlFGQ0ZfRn3MZYy3mR8wbjIRGKSZ7JlCmfKZapl6mKaIWKJokRjoj8xnXieeI84QUKShEiGJDLpAKmCdJ80yYxhFmM2Zw5hzmG+xPyMeZ6FyKLE4sKSwFLKcodljBXJKspqzhrGmsd6jXWQdZmNh02fLYAti+0yWz/bd3Yudj32APZs9nr2AfZlDn4OY45QjnyOJo7XnChOSU57znjOMs77nLNczFyaXGSubK5rXMPcCG5JbgfuJO7z3N3cizy8PKY8kTwnee7xzPKy8urxhvAe523lfc9H4tPho/Ad52vj+8DPwq/PH8ZfzN/JPy/ALWAmECtwTuCZwIqgmKCzYJpgveBrIYKQmlCg0HGhDqF5YT5ha+Fk4TrhYRG8iJpIsEiRyEOR76Jioq6ih0SbRGfE2MXMxRLF6sRGxOnEdcWjxMvF/5LASKhJhEqcluiVREgqSwZLlkr2SCGkVKQoUqel+qTR0urSEdLl0i9kaGX0ZeJk6mTGZVllrWTTZJtkP+8Q3uGxI3/Hwx2/5JTlwuQq5F7JE+Ut5NPkb8l/UZBUICuUKvylSKdoopii2Ky4oCSlFKBUpjSkTFK2Vj6k3KG8pqKqQlW5rPJeVVjVR/WU6gs1ZjU7tVy1R+podQP1FPUW9Z8aKhoxGtc05jRlNEM1azVntMS0ArQqtCa0BbV9tc9pj+nw6/jonNUZ0xXQ9dUt132rJ6Tnr1epN60voR+if1H/s4GcAdXghsF3Qw3DvYZ3jZBGpkbZRs+MicbOxiXGoyaCJkEmdSbzpsqmSaZ3zdBmlmb5Zi/MeczJ5jXm8xaqFnstOi1pLR0tSyzfWklaUa1uWSOsLayPWY/YiNhE2DTZAltz22O2r+3E7KLsbttj7O3sS+2nHOQdkh0eOpIcdznWOi45GTjlOb1yFneOde5wYXDxcqlx+e5q5FrgOua2w22v2xN3TneKe7MH1sPFo9Jj0dPY84TnpJeyV4bX4E6xnQk7u7w5vcO87+xi2OW7q8EH7ePqU+uz6mvrW+676Gfud8pvnmxILiJ/9NfzP+7/PkA7oCBgOlA7sCBwJkg76FjQ+2Dd4MLgWYohpYSyEGIWcibke6htaFXoephrWH04Ltwn/GYEMSI0onM37+6E3X2RUpEZkWNRGlEnouapltTKaCh6Z3RzDDP88t4dKx57MHY8TieuNO5HvEt8QwJTQkRC9x7JPVl7phNNEi8koZLISR3JAsmpyeN79fee2wft89vXkSKUkp4yud90f3UqITU09WmaXFpB2rcDrgdupfOk70+fOGh6sC6DPoOa8eKQ5qEzmahMSuazLMWsk1m/sv2zH+fI5RTmrOaScx8flj9cfHj9SOCRZ3kqeWVHMUcjjg7m6+ZXFzAVJBZMHLM+1nic/3j28W8ndp3oKlQqPFNEKIotGiu2Km4+KXzy6MnVkuCSgVKD0vpT3KeyTn0/7X+6v0yv7PIZnjM5Z5bPUs4OnTM911guWl54HnM+7vxUhUvFwwtqF2oqOStzKteqIqrGqh2qO2tUa2pquWvz6hB1sXXvL3pd7L1kdKn5sszlc/Ws9TlXwJXYKx+u+lwdvGZ5raNBreHydZHrp26QbmQ3Qo17GuebgpvGmt2b+25a3Oy4pXnrxm3Z21UtAi2ld1ju5LUSWtNb19sS2xbvRt6dbQ9qn+jY1fHqntu9vzrtO5/dt7z/6IHJg3sP9R+2PdJ+1NKl0XXzsdrjpicqTxq7lbtvPFV+euOZyrPGHtWe5l713lt9Wn2t/br97c+Nnj/4y/yvJwM2A32DzoNDL7xejA35D828DHu5MBw3vPJq/wh6JPs14+vCUe7R8jcSb+rHVMbujBuNd791fPtqgjzx8V30u9XJ9Cm6qcJpvumaGYWZlvcm73s/eH6Y/Bj5cWU24xPTp1OfxT9fn9Ob6553m59coC6sf8n9yvG16pvSt45Fu8XRpfClle/ZPzh+VP
"deleted": false,
"disable_correlation": true,
"object_relation": "screenshot",
"timestamp": "1661170571",
"to_ids": false,
"type": "attachment",
"uuid": "28729bfe-effc-44bb-9a29-b16e10fcb4d6",
"value": "Screen Shot 2022-08-16 at 11.54.57 AM.png"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "subject",
"timestamp": "1661170571",
"to_ids": false,
"type": "email-subject",
"uuid": "7a5f80ad-2e7d-4766-8777-09e8e3cf9ca2",
"value": "RESERVA"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "attachment",
"timestamp": "1661170571",
"to_ids": true,
"type": "email-attachment",
"uuid": "f3bd0654-e46a-4dab-8c03-eef6d45039ef",
"value": "RESERVA.docx"
}
]
},
{
"comment": "",
"deleted": false,
"description": "File object describing a file with meta-information",
"meta-category": "file",
"name": "file",
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
"template_version": "24",
"timestamp": "1661174273",
"uuid": "ccc9024a-2748-4e43-bba0-df53f0332f5e",
"ObjectReference": [
{
"comment": "",
"object_uuid": "ccc9024a-2748-4e43-bba0-df53f0332f5e",
"referenced_uuid": "46cbebab-5fb3-4286-beac-500e45976ff0",
"relationship_type": "contained-within",
"timestamp": "1661174273",
"uuid": "0215a3c7-754c-4cd8-88c8-f4c7722edfe4"
}
],
"Attribute": [
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha256",
"timestamp": "1661173129",
"to_ids": true,
"type": "sha256",
"uuid": "22fbf0a2-30d6-4803-b76a-a14ad4a32091",
"value": "c2b817b02e56624c8ed7944e76a3896556dc2b7482f747f4be88f95e232f9207"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "filename",
"timestamp": "1661173129",
"to_ids": true,
"type": "filename",
"uuid": "e5ef1ff3-b7e5-4b67-915d-32896965f371",
"value": "reserva.ppa"
}
]
},
{
"comment": "",
"deleted": false,
"description": "Email object describing an email with meta-information",
"meta-category": "network",
"name": "email",
"template_uuid": "a0c666e0-fc65-4be8-b48f-3423d788b552",
"template_version": "18",
"timestamp": "1661173959",
"uuid": "46cbebab-5fb3-4286-beac-500e45976ff0",
"Attribute": [
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "subject",
"timestamp": "1661173959",
"to_ids": false,
"type": "email-subject",
"uuid": "b45ed2bf-0867-4c72-ab01-dbcd4b0d300d",
"value": "Or\u00e7amento Conferencistas - 515449939"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "from-display-name",
"timestamp": "1661173959",
"to_ids": false,
"type": "email-src-display-name",
"uuid": "ab01f74c-0890-4b38-ae52-cc252ba7c699",
"value": "Oab Brasil"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "from",
"timestamp": "1661173959",
"to_ids": true,
"type": "email-src",
"uuid": "9c2a9596-95d3-4e1f-9baf-490071b66d92",
"value": "fernando1540@bol[.]com[.]br"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "attachment",
"timestamp": "1661173959",
"to_ids": true,
"type": "email-attachment",
"uuid": "61581e3d-4806-42d8-b965-bf584dc994d6",
"value": "reserva.ppa"
},
{
"category": "External analysis",
"comment": "",
"data": "iVBORw0KGgoAAAANSUhEUgAAA7UAAAIdCAYAAADiYVoCAAAYb2lDQ1BJQ0MgUHJvZmlsZQAAWIWVWQc8le3fv+6zz7HPsffeZO+9994kHOtYccxQIskqUSFKJZmVSqESkYZSRg9JEsmoFCoqI+9t1P95n+f9vO/nvT6f676+53f9rt+61v07NwBcnb6RkWEIRgDCI2KoDqYG/G7uHvzYKYAFPAAP2ICSLzk6Ut/OzgrA5Xf738vSIIA22ucyG7L+3f+/FqJ/QDQZAMgLxn7+0eRwGN8FAJVGjqTGAIAxgulC8TGRGzgYxsxU2EAYJ2/goC18dAP7beGKTR4nB0MYNwOAo/X1pQYBQN8J0/njyEGwHPp3cB8xwp8SAbP+gLEOOdjXHwAuNZhHOjx89waGKxCH+SNhnAtjNb+/yQz6b/L9/sj39Q36g7f82iw4I0p0ZJjvnv9naP7vEh4W+1uHKFxpg6lmDhv+wzEcCt1tuYFpYTwb4WdjuxFrGP+g+G/FHQAEITjWzHmLH8FNjjaE4wdYYSzn72tkCWNuGJtEhNlYbdP9Aikm5jCGVwsigRJj7rQ9NjMg2thxW+Yp6m4H2984kGqovz32si91U+8Gf2dsqLP+tvyh4ADz3/K/JQY7ucKYAACSEEdxsYExPYyZo0MdLbd4kIKJwYY2v3mosQ4b9gvDWC0gwtRgSz7SK5Bq4rDNHxke/dtfZEYwxdxmGxfHBDuZbcUHWUv23bSfHcaNARH6zr/lBES7Wf32xT/AyHjLd+SzgAjnbX+Ro5ExBg7bY+cjw+y2+VG4gDDTDbogjDmj4xy3x6K0YuDFuSUfZRUZY+e0ZSfKJ8TXwm7LHlQcsAKGwAjwg1i4+oHdIARQns02zcK/tnpMgC+ggiAQAGS2Kb9HuG72RMBPR5AIPsEoAET/GWew2RsA4mD62h/q1lMGBG72xm2OCAVTMA4HliAM/h27OSrijzYX8A6mUP6lnQzbGgbXjb5/0/RhitU2Jfa3XH6G35wYY4wRxgxjgpFAcaJ0UJooK/ipB1cFlBpK/be1/+FHT6H70G/RA+gx9MtdlDTqP2yxBmOwfJNtj/3+7jFKFJapjDJAacPSYckoVhQnkEEpwXr0UbqwZmWYarht94bv/P+Dn388+FvMt/nwcngEng2vhxf/50h6SXrlP1I2Ivr3+GzZ6vcnqoZ/ev6p3/BvcfaHW8t/ciIzkQ3Ih8h2ZBeyBdkE+JFtyGZkN/LOBv6zht5trqHf2hw27QmF5VD+pc93W+dGJKPl6uTey61u94GYgISYjQ1muDtyD5USFBzDrw/fAgH85hFkWWl+BTkFBQA27pStY+qrw+ZdAbH2/IdGPgiA6jwA+OX/0MK/AnAF3uP81v+hiXjD2wwDQPUUOZYat0VDbTzQ8GnAAO8oDsALhIA47JECUAGaQA8YAwtgC5yAO/CG4xwMr2cqiAfJIBVkgBxwFJwAJeAMOA+qwSVwDTSBFtAOHoAnoBcMgFfw+pkEH8E8WAIrEARhITqIBHFAfJAIJAUpQGqQDmQMWUEOkDvkAwVBEVAslAwdgHKgAqgEOgfVQFehm1A71AX1QS+hceg99AVaRiARtAhmBA9CFLEDoYbQR1ginBA7EUGIKEQiIh1xBFGMKEdcRDQi2hFPEAOIMcRHxCISIGmQrEgBpAxSDWmItEV6IAORVOQ+ZDayEFmOvIy8Bc/0c+QYchb5E4VBkVD8KBl4DZuhnFFkVBRqHyoXVYKqRjWiOlHPUeOoedQvNB2aGy2F1kCbo93QQeh4dAa6EF2JvoG+D++mSfQSBoNhxYhhVOHd6I4JwSRhcjGnMfWYu5g+zARmEYvFcmClsNpYW6wvNgabgT2JvYhtw/ZjJ7E/cDQ4PpwCzgTngYvApeEKcbW4Vlw/bhq3gmfEi+A18LZ4f/wefB6+An8L34OfxK8QmAhiBG2CEyGEkEooJlwm3CeMEL7S0NAI0qjT2NNQaPbTFNNcoXlEM07zk5ZIK0lrSOtFG0t7hLaK9i7tS9qvdHR0onR6dB50MXRH6Gro7tGN0v2gJ9HL0pvT+9On0JfSN9L3039mwDOIMOgzeDMkMhQyNDD0MMwy4hlFGQ0ZfRn3MZYy3mR8wbjIRGKSZ7JlCmfKZapl6mKaIWKJokRjoj8xnXieeI84QUKShEiGJDLpAKmCdJ80yYxhFmM2Zw5hzmG+xPyMeZ6FyKLE4sKSwFLKcodljBXJKspqzhrGmsd6jXWQdZmNh02fLYAti+0yWz/bd3Yudj32APZs9nr2AfZlDn4OY45QjnyOJo7XnChOSU57znjOMs77nLNczFyaXGSubK5rXMPcCG5JbgfuJO7z3N3cizy8PKY8kTwnee7xzPKy8urxhvAe523lfc9H4tPho/Ad52vj+8DPwq/PH8ZfzN/JPy/ALWAmECtwTuCZwIqgmKCzYJpgveBrIYKQmlCg0HGhDqF5YT5ha+Fk4TrhYRG8iJpIsEiRyEOR76Jioq6ih0SbRGfE2MXMxRLF6sRGxOnEdcWjxMvF/5LASKhJhEqcluiVREgqSwZLlkr2SCGkVKQoUqel+qTR0urSEdLl0i9kaGX0ZeJk6mTGZVllrWTTZJtkP+8Q3uGxI3/Hwx2/5JTlwuQq5F7JE+Ut5NPkb8l/UZBUICuUKvylSKdoopii2Ky4oCSlFKBUpjSkTFK2Vj6k3KG8pqKqQlW5rPJeVVjVR/WU6gs1ZjU7tVy1R+podQP1FPUW9Z8aKhoxGtc05jRlNEM1azVntMS0ArQqtCa0BbV9tc9pj+nw6/jonNUZ0xXQ9dUt132rJ6Tnr1epN60voR+if1H/s4GcAdXghsF3Qw3DvYZ3jZBGpkbZRs+MicbOxiXGoyaCJkEmdSbzpsqmSaZ3zdBmlmb5Zi/MeczJ5jXm8xaqFnstOi1pLR0tSyzfWklaUa1uWSOsLayPWY/YiNhE2DTZAltz22O2r+3E7KLsbttj7O3sS+2nHOQdkh0eOpIcdznWOi45GTjlOb1yFneOde5wYXDxcqlx+e5q5FrgOua2w22v2xN3TneKe7MH1sPFo9Jj0dPY84TnpJeyV4bX4E6xnQk7u7w5vcO87+xi2OW7q8EH7ePqU+uz6mvrW+676Gfud8pvnmxILiJ/9NfzP+7/PkA7oCBgOlA7sCBwJkg76FjQ+2Dd4MLgWYohpYSyEGIWcibke6htaFXoephrWH04Ltwn/GYEMSI0onM37+6E3X2RUpEZkWNRGlEnouapltTKaCh6Z3RzDDP88t4dKx57MHY8TieuNO5HvEt8QwJTQkRC9x7JPVl7phNNEi8koZLISR3JAsmpyeN79fee2wft89vXkSKUkp4yud90f3UqITU09WmaXFpB2rcDrgdupfOk70+fOGh6sC6DPoOa8eKQ5qEzmahMSuazLMWsk1m/sv2zH+fI5RTmrOaScx8flj9cfHj9SOCRZ3kqeWVHMUcjjg7m6+ZXFzAVJBZMHLM+1nic/3j28W8ndp3oKlQqPFNEKIotGiu2Km4+KXzy6MnVkuCSgVKD0vpT3KeyTn0/7X+6v0yv7PIZnjM5Z5bPUs4OnTM911guWl54HnM+7vxUhUvFwwtqF2oqOStzKteqIqrGqh2qO2tUa2pquWvz6hB1sXXvL3pd7L1kdKn5sszlc/Ws9TlXwJXYKx+u+lwdvGZ5raNBreHydZHrp26QbmQ3Qo17GuebgpvGmt2b+25a3Oy4pXnrxm3Z21UtAi2ld1ju5LUSWtNb19sS2xbvRt6dbQ9qn+jY1fHqntu9vzrtO5/dt7z/6IHJg3sP9R+2PdJ+1NKl0XXzsdrjpicqTxq7lbtvPFV+euOZyrPGHtWe5l713lt9Wn2t/br97c+Nnj/4y/yvJwM2A32DzoNDL7xejA35D828DHu5MBw3vPJq/wh6JPs14+vCUe7R8jcSb+rHVMbujBuNd791fPtqgjzx8V30u9XJ9Cm6qcJpvumaGYWZlvcm73s/eH6Y/Bj5cWU24xPTp1OfxT9fn9Ob6553m59coC6sf8n9yvG16pvSt45Fu8XRpfClle/ZPzh+VP
"deleted": false,
"disable_correlation": true,
"object_relation": "screenshot",
"timestamp": "1661173959",
"to_ids": false,
"type": "attachment",
"uuid": "fa9f4e47-a874-43b6-9622-f1fb83854cef",
"value": "Screen Shot 2022-08-16 at 11.55.35 AM.png"
}
]
},
{
"comment": "",
"deleted": false,
"description": "Email object describing an email with meta-information",
"meta-category": "network",
"name": "email",
"template_uuid": "a0c666e0-fc65-4be8-b48f-3423d788b552",
"template_version": "18",
"timestamp": "1661176848",
"uuid": "3c167f94-5bac-465c-9765-b48cab0fddf5",
"Attribute": [
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "reply-to",
"timestamp": "1661176848",
"to_ids": false,
"type": "email-reply-to",
"uuid": "04f5efd4-1db2-4c71-8a2b-d4cf4fdda962",
"value": "cdt[name]cdt@gmail[.]com"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "subject",
"timestamp": "1661176848",
"to_ids": false,
"type": "email-subject",
"uuid": "dd0394d0-3832-45fe-bdf7-8b77bfaff6a7",
"value": "Reserva"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "from-display-name",
"timestamp": "1661176848",
"to_ids": false,
"type": "email-src-display-name",
"uuid": "3c7c8bd0-0021-4540-a92b-9c2d1c26c066",
"value": "Financeiro UNIMED"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "from",
"timestamp": "1661176848",
"to_ids": true,
"type": "email-src",
"uuid": "88f0384e-5aff-4d6b-b129-924a22601ca0",
"value": "financeiro@unimed-corporated[.]com"
},
{
"category": "External analysis",
"comment": "",
"data": "iVBORw0KGgoAAAANSUhEUgAABCIAAAJFCAYAAAAI8FaLAAAYb2lDQ1BJQ0MgUHJvZmlsZQAAWIWVWQc8le3fv+6zz7HPsffeZO+9994kHOtYccxQIskqUSFKJZmVSqESkYZSRg9JEsmoFCoqI+9t1P95n+f9vO/nvT6f676+53f9rt+61v07NwBcnb6RkWEIRgDCI2KoDqYG/G7uHvzYKYAFPAAP2ICSLzk6Ut/OzgrA5Xf738vSIIA22ucyG7L+3f+/FqJ/QDQZAMgLxn7+0eRwGN8FAJVGjqTGAIAxgulC8TGRGzgYxsxU2EAYJ2/goC18dAP7beGKTR4nB0MYNwOAo/X1pQYBQN8J0/njyEGwHPp3cB8xwp8SAbP+gLEOOdjXHwAuNZhHOjx89waGKxCH+SNhnAtjNb+/yQz6b/L9/sj39Q36g7f82iw4I0p0ZJjvnv9naP7vEh4W+1uHKFxpg6lmDhv+wzEcCt1tuYFpYTwb4WdjuxFrGP+g+G/FHQAEITjWzHmLH8FNjjaE4wdYYSzn72tkCWNuGJtEhNlYbdP9Aikm5jCGVwsigRJj7rQ9NjMg2thxW+Yp6m4H2984kGqovz32si91U+8Gf2dsqLP+tvyh4ADz3/K/JQY7ucKYAACSEEdxsYExPYyZo0MdLbd4kIKJwYY2v3mosQ4b9gvDWC0gwtRgSz7SK5Bq4rDNHxke/dtfZEYwxdxmGxfHBDuZbcUHWUv23bSfHcaNARH6zr/lBES7Wf32xT/AyHjLd+SzgAjnbX+Ro5ExBg7bY+cjw+y2+VG4gDDTDbogjDmj4xy3x6K0YuDFuSUfZRUZY+e0ZSfKJ8TXwm7LHlQcsAKGwAjwg1i4+oHdIARQns02zcK/tnpMgC+ggiAQAGS2Kb9HuG72RMBPR5AIPsEoAET/GWew2RsA4mD62h/q1lMGBG72xm2OCAVTMA4HliAM/h27OSrijzYX8A6mUP6lnQzbGgbXjb5/0/RhitU2Jfa3XH6G35wYY4wRxgxjgpFAcaJ0UJooK/ipB1cFlBpK/be1/+FHT6H70G/RA+gx9MtdlDTqP2yxBmOwfJNtj/3+7jFKFJapjDJAacPSYckoVhQnkEEpwXr0UbqwZmWYarht94bv/P+Dn388+FvMt/nwcngEng2vhxf/50h6SXrlP1I2Ivr3+GzZ6vcnqoZ/ev6p3/BvcfaHW8t/ciIzkQ3Ih8h2ZBeyBdkE+JFtyGZkN/LOBv6zht5trqHf2hw27QmF5VD+pc93W+dGJKPl6uTey61u94GYgISYjQ1muDtyD5USFBzDrw/fAgH85hFkWWl+BTkFBQA27pStY+qrw+ZdAbH2/IdGPgiA6jwA+OX/0MK/AnAF3uP81v+hiXjD2wwDQPUUOZYat0VDbTzQ8GnAAO8oDsALhIA47JECUAGaQA8YAwtgC5yAO/CG4xwMr2cqiAfJIBVkgBxwFJwAJeAMOA+qwSVwDTSBFtAOHoAnoBcMgFfw+pkEH8E8WAIrEARhITqIBHFAfJAIJAUpQGqQDmQMWUEOkDvkAwVBEVAslAwdgHKgAqgEOgfVQFehm1A71AX1QS+hceg99AVaRiARtAhmBA9CFLEDoYbQR1ginBA7EUGIKEQiIh1xBFGMKEdcRDQi2hFPEAOIMcRHxCISIGmQrEgBpAxSDWmItEV6IAORVOQ+ZDayEFmOvIy8Bc/0c+QYchb5E4VBkVD8KBl4DZuhnFFkVBRqHyoXVYKqRjWiOlHPUeOoedQvNB2aGy2F1kCbo93QQeh4dAa6EF2JvoG+D++mSfQSBoNhxYhhVOHd6I4JwSRhcjGnMfWYu5g+zARmEYvFcmClsNpYW6wvNgabgT2JvYhtw/ZjJ7E/cDQ4PpwCzgTngYvApeEKcbW4Vlw/bhq3gmfEi+A18LZ4f/wefB6+An8L34OfxK8QmAhiBG2CEyGEkEooJlwm3CeMEL7S0NAI0qjT2NNQaPbTFNNcoXlEM07zk5ZIK0lrSOtFG0t7hLaK9i7tS9qvdHR0onR6dB50MXRH6Gro7tGN0v2gJ9HL0pvT+9On0JfSN9L3039mwDOIMOgzeDMkMhQyNDD0MMwy4hlFGQ0ZfRn3MZYy3mR8wbjIRGKSZ7JlCmfKZapl6mKaIWKJokRjoj8xnXieeI84QUKShEiGJDLpAKmCdJ80yYxhFmM2Zw5hzmG+xPyMeZ6FyKLE4sKSwFLKcodljBXJKspqzhrGmsd6jXWQdZmNh02fLYAti+0yWz/bd3Yudj32APZs9nr2AfZlDn4OY45QjnyOJo7XnChOSU57znjOMs77nLNczFyaXGSubK5rXMPcCG5JbgfuJO7z3N3cizy8PKY8kTwnee7xzPKy8urxhvAe523lfc9H4tPho/Ad52vj+8DPwq/PH8ZfzN/JPy/ALWAmECtwTuCZwIqgmKCzYJpgveBrIYKQmlCg0HGhDqF5YT5ha+Fk4TrhYRG8iJpIsEiRyEOR76Jioq6ih0SbRGfE2MXMxRLF6sRGxOnEdcWjxMvF/5LASKhJhEqcluiVREgqSwZLlkr2SCGkVKQoUqel+qTR0urSEdLl0i9kaGX0ZeJk6mTGZVllrWTTZJtkP+8Q3uGxI3/Hwx2/5JTlwuQq5F7JE+Ut5NPkb8l/UZBUICuUKvylSKdoopii2Ky4oCSlFKBUpjSkTFK2Vj6k3KG8pqKqQlW5rPJeVVjVR/WU6gs1ZjU7tVy1R+podQP1FPUW9Z8aKhoxGtc05jRlNEM1azVntMS0ArQqtCa0BbV9tc9pj+nw6/jonNUZ0xXQ9dUt132rJ6Tnr1epN60voR+if1H/s4GcAdXghsF3Qw3DvYZ3jZBGpkbZRs+MicbOxiXGoyaCJkEmdSbzpsqmSaZ3zdBmlmb5Zi/MeczJ5jXm8xaqFnstOi1pLR0tSyzfWklaUa1uWSOsLayPWY/YiNhE2DTZAltz22O2r+3E7KLsbttj7O3sS+2nHOQdkh0eOpIcdznWOi45GTjlOb1yFneOde5wYXDxcqlx+e5q5FrgOua2w22v2xN3TneKe7MH1sPFo9Jj0dPY84TnpJeyV4bX4E6xnQk7u7w5vcO87+xi2OW7q8EH7ePqU+uz6mvrW+676Gfud8pvnmxILiJ/9NfzP+7/PkA7oCBgOlA7sCBwJkg76FjQ+2Dd4MLgWYohpYSyEGIWcibke6htaFXoephrWH04Ltwn/GYEMSI0onM37+6E3X2RUpEZkWNRGlEnouapltTKaCh6Z3RzDDP88t4dKx57MHY8TieuNO5HvEt8QwJTQkRC9x7JPVl7phNNEi8koZLISR3JAsmpyeN79fee2wft89vXkSKUkp4yud90f3UqITU09WmaXFpB2rcDrgdupfOk70+fOGh6sC6DPoOa8eKQ5qEzmahMSuazLMWsk1m/sv2zH+fI5RTmrOaScx8flj9cfHj9SOCRZ3kqeWVHMUcjjg7m6+ZXFzAVJBZMHLM+1nic/3j28W8ndp3oKlQqPFNEKIotGiu2Km4+KXzy6MnVkuCSgVKD0vpT3KeyTn0/7X+6v0yv7PIZnjM5Z5bPUs4OnTM911guWl54HnM+7vxUhUvFwwtqF2oqOStzKteqIqrGqh2qO2tUa2pquWvz6hB1sXXvL3pd7L1kdKn5sszlc/Ws9TlXwJXYKx+u+lwdvGZ5raNBreHydZHrp26QbmQ3Qo17GuebgpvGmt2b+25a3Oy4pXnrxm3Z21UtAi2ld1ju5LUSWtNb19sS2xbvRt6dbQ9qn+jY1fHqntu9vzrtO5/dt7z/6IHJg3sP9R+2PdJ+1NKl0XXzsdrjpicqTxq7lbtvPFV+euOZyrPGHtWe5l713lt9Wn2t/br97c+Nnj/4y/yvJwM2A32DzoNDL7xejA35D828DHu5MBw3vPJq/wh6JPs14+vCUe7R8jcSb+rHVMbujBuNd791fPtqgjzx8V30u9XJ9Cm6qcJpvumaGYWZlvcm73s/eH6Y/Bj5cWU24xPTp1OfxT9fn9Ob6553m59coC6sf8n9yvG16pvSt45Fu8XRpfClle/ZPzh+VP
"deleted": false,
"disable_correlation": true,
"object_relation": "screenshot",
"timestamp": "1661176848",
"to_ids": false,
"type": "attachment",
"uuid": "dbfcf35f-8af5-4b0a-9fb4-8df9ef2864e2",
"value": "Screen Shot 2022-08-16 at 11.56.23 AM.png"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "attachment",
"timestamp": "1661176848",
"to_ids": true,
"type": "email-attachment",
"uuid": "37efae0c-d320-403a-a0ce-ef02dcf9c513",
"value": "OficioCircularencaminhadoaoSetorFinanceiroUNIMED.docx"
}
]
},
{
"comment": "",
"deleted": false,
"description": "File object describing a file with meta-information",
"meta-category": "file",
"name": "file",
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
"template_version": "24",
"timestamp": "1661176898",
"uuid": "aba989e1-7952-4225-8f27-be5a626323db",
"ObjectReference": [
{
"comment": "",
"object_uuid": "aba989e1-7952-4225-8f27-be5a626323db",
"referenced_uuid": "3c167f94-5bac-465c-9765-b48cab0fddf5",
"relationship_type": "contained-within",
"timestamp": "1661176898",
"uuid": "699322da-f736-4c84-96bf-36afb109f43a"
}
],
"Attribute": [
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha256",
"timestamp": "1661176873",
"to_ids": true,
"type": "sha256",
"uuid": "2b3c2c55-20ce-4495-beb0-f52d1df0a9bc",
"value": "2f0f99cbac828092c0ec23e12ecb44cbf53f5a671a80842a2447e6114e4f6979"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "filename",
"timestamp": "1661176873",
"to_ids": true,
"type": "filename",
"uuid": "27b17f46-2457-4f2a-8d67-93cb88ceefc0",
"value": "OficioCircularencaminhadoaoSetorFinanceiroUNIMED.docx"
}
]
}
]
}
}