2023-04-21 13:25:09 +00:00
|
|
|
{
|
2023-12-14 14:30:15 +00:00
|
|
|
"Event": {
|
|
|
|
"analysis": "0",
|
|
|
|
"date": "2016-04-07",
|
|
|
|
"extends_uuid": "",
|
|
|
|
"info": "Kegotip downloader",
|
|
|
|
"publish_timestamp": "1460042110",
|
|
|
|
"published": true,
|
|
|
|
"threat_level_id": "3",
|
|
|
|
"timestamp": "1460041633",
|
|
|
|
"uuid": "570669fe-4138-40e0-ba49-4990950d210f",
|
|
|
|
"Orgc": {
|
|
|
|
"name": "CIRCL",
|
|
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
|
|
},
|
|
|
|
"Tag": [
|
|
|
|
{
|
|
|
|
"colour": "#ffffff",
|
|
|
|
"local": "0",
|
|
|
|
"name": "tlp:white",
|
|
|
|
"relationship_type": ""
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"colour": "#3a7300",
|
|
|
|
"local": "0",
|
|
|
|
"name": "circl:incident-classification=\"malware\"",
|
|
|
|
"relationship_type": ""
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"Attribute": [
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Imported via the freetext import.",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1460038205",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "md5",
|
|
|
|
"uuid": "57066a3d-774c-439d-8d24-37e9950d210f",
|
|
|
|
"value": "f563f980e99a91fe011fe331bea190d6"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "download location (down)",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1460038205",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "url",
|
|
|
|
"uuid": "57066a3d-e7f8-4e8b-aa04-37e9950d210f",
|
|
|
|
"value": "http://51.255.70.98/"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "download location (down)",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1460038206",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "ip-dst",
|
|
|
|
"uuid": "57066a3e-4528-40bf-a8b0-37e9950d210f",
|
|
|
|
"value": "51.255.70.98"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Imported via the freetext import. - Xchecked via VT: f563f980e99a91fe011fe331bea190d6",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1460039609",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "sha256",
|
|
|
|
"uuid": "57066fb9-05d4-40ff-8078-4bfe02de0b81",
|
|
|
|
"value": "0ea08351e522eda5e3abb1b5b0cf921784b5bfd4eda31ad44ffa5d28ac76d3f7"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Imported via the freetext import. - Xchecked via VT: f563f980e99a91fe011fe331bea190d6",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1460039609",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "sha1",
|
|
|
|
"uuid": "57066fb9-2e90-497d-ab82-417d02de0b81",
|
|
|
|
"value": "e26dc11326c8ec4a0399b149741f667e9219da87"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1460039610",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "link",
|
|
|
|
"uuid": "57066fba-86dc-4ad4-91e2-4d9802de0b81",
|
|
|
|
"value": "https://www.virustotal.com/file/0ea08351e522eda5e3abb1b5b0cf921784b5bfd4eda31ad44ffa5d28ac76d3f7/analysis/1459963946/"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Imported via the freetext import.",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1460041615",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "md5",
|
|
|
|
"uuid": "5706778f-cd40-4fed-824c-8ef7950d210f",
|
|
|
|
"value": "d22500f4cc2abf32642a0862fd1d135d"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Imported via the freetext import. - Xchecked via VT: d22500f4cc2abf32642a0862fd1d135d",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1460041633",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "sha256",
|
|
|
|
"uuid": "570677a1-6d90-4e02-aed2-bac602de0b81",
|
|
|
|
"value": "e9958ef800594203e541f25a70dddf2eda71ecce7bee33c9054a79776e6a0b5d"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Imported via the freetext import. - Xchecked via VT: d22500f4cc2abf32642a0862fd1d135d",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1460041634",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "sha1",
|
|
|
|
"uuid": "570677a2-7534-419b-ba03-bac602de0b81",
|
|
|
|
"value": "d69e52c7949bed85fd37129809f50c8277352d47"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1460041634",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "link",
|
|
|
|
"uuid": "570677a2-8510-46c1-bb67-bac602de0b81",
|
|
|
|
"value": "https://www.virustotal.com/file/e9958ef800594203e541f25a70dddf2eda71ecce7bee33c9054a79776e6a0b5d/analysis/1460039225/"
|
|
|
|
}
|
2023-04-21 13:25:09 +00:00
|
|
|
]
|
2023-12-14 14:30:15 +00:00
|
|
|
}
|
2023-04-21 13:25:09 +00:00
|
|
|
}
|