"value":"The \u00e2\u20ac\u0153DragonOK\u00e2\u20ac\u009d group in particular is known\r\nto use password-protected documents\r\ndelivered as attachments in emails, with the\r\npassword listed in the contents of the email.\r\nThis method probably is used to evade\r\ndetection by AV software, gateway firewalls\r\nand malware sandboxes. One such example\r\nusing the password \u00e2\u20ac\u0153888888\u00e2\u20ac\u009d is shown in\r\nFigure 2 and Figure 6, and has been observed\r\nby FireEye7 before. Another similar sample\r\nwas referenced by the \u00e2\u20ac\u0153contagio\u00e2\u20ac\u009d blog8 and\r\nused the password \u00e2\u20ac\u01538861\u00e2\u20ac\u009d."
},
{
"category":"Attribution",
"comment":"Password for password-protected documents sent as emails",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429110507",
"to_ids":false,
"type":"text",
"uuid":"552e7eeb-8194-435b-b481-2d36950d210b",
"value":"8861"
},
{
"category":"Attribution",
"comment":"Password for password-protected documents sent as emails",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111364",
"to_ids":true,
"type":"hostname",
"uuid":"552e8244-b3dc-49e3-bcfc-2d36950d210b",
"value":"ph.moafee.com"
},
{
"category":"Network activity",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111364",
"to_ids":true,
"type":"hostname",
"uuid":"552e8244-20e4-40d3-95ff-2d36950d210b",
"value":"mofa.mozjlla.com"
},
{
"category":"Network activity",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111364",
"to_ids":true,
"type":"hostname",
"uuid":"552e8244-e150-41a4-9d09-2d36950d210b",
"value":"acer.moafee.com"
},
{
"category":"Network activity",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111364",
"to_ids":true,
"type":"hostname",
"uuid":"552e8244-87c8-404e-9fb8-2d36950d210b",
"value":"del.moafee.com"
},
{
"category":"Network activity",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111364",
"to_ids":true,
"type":"hostname",
"uuid":"552e8244-77f4-4e25-8c3c-2d36950d210b",
"value":"jnt.moafee.com"
},
{
"category":"Network activity",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111364",
"to_ids":true,
"type":"hostname",
"uuid":"552e8244-ce08-4176-826d-2d36950d210b",
"value":"pcg.moafee.com"
},
{
"category":"Network activity",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111364",
"to_ids":true,
"type":"hostname",
"uuid":"552e8244-063c-465d-bf3e-2d36950d210b",
"value":"sslc.moafee.com"
},
{
"category":"Network activity",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111364",
"to_ids":true,
"type":"hostname",
"uuid":"552e8244-cd38-4e11-91fc-2d36950d210b",
"value":"at.moafee.com"
},
{
"category":"Network activity",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111365",
"to_ids":true,
"type":"hostname",
"uuid":"552e8245-d288-4cab-8f4e-2d36950d210b",
"value":"lw.moafee.com"
},
{
"category":"Network activity",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111365",
"to_ids":true,
"type":"hostname",
"uuid":"552e8245-fb5c-4894-acbc-2d36950d210b",
"value":"ks.moafee.com"
},
{
"category":"Network activity",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111365",
"to_ids":true,
"type":"hostname",
"uuid":"552e8245-4598-409f-8170-2d36950d210b",
"value":"oa.moafee.com"
},
{
"category":"Network activity",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111365",
"to_ids":true,
"type":"hostname",
"uuid":"552e8245-7c08-4e42-9079-2d36950d210b",
"value":"xxpp.moafee.com"
},
{
"category":"Network activity",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111365",
"to_ids":true,
"type":"hostname",
"uuid":"552e8245-7f9c-4a95-9705-2d36950d210b",
"value":"hp.moafee.com"
},
{
"category":"Network activity",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111365",
"to_ids":true,
"type":"hostname",
"uuid":"552e8245-9ae4-44fd-b87b-2d36950d210b",
"value":"gumm.mozjlla.com"
},
{
"category":"Network activity",
"comment":"Linked to Moafee group and resolved to 58.64.201.229",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111365",
"to_ids":true,
"type":"hostname",
"uuid":"552e8245-18b4-4a5c-9550-2d36950d210b",
"value":"msn.moafee.com"
},
{
"category":"Attribution",
"comment":"",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111395",
"to_ids":false,
"type":"comment",
"uuid":"552e8263-d674-438e-bd0e-2d36950d210b",
"value":"During this same time frame, the HTRAN client\r\nat 58.64.201.229 was observed\r\nattempting to connect to a number of different\r\nbackend HTRAN servers. All of these HTRAN\r\nservers were located in the Guangdong\r\nProvince and operated by CHINANET."
},
{
"category":"Network activity",
"comment":"",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111427",
"to_ids":true,
"type":"hostname",
"uuid":"552e8283-3244-45ca-a9f8-2d3e950d210b",
"value":"phi.crabdance.com"
},
{
"category":"Network activity",
"comment":"",
"deleted":false,
"disable_correlation":false,
"timestamp":"1429111492",
"to_ids":true,
"type":"ip-dst",
"uuid":"552e82c4-b61c-45ab-82d5-2d37950d210b",
"value":"98.126.91.66"
},
{
"category":"Network activity",
"comment":"Destination of connections from HTRAN proxy running on 98.126.91.66",