2023-04-21 13:25:09 +00:00
|
|
|
{
|
2023-12-14 14:30:15 +00:00
|
|
|
"Event": {
|
|
|
|
"analysis": "0",
|
|
|
|
"date": "2017-01-26",
|
|
|
|
"extends_uuid": "",
|
|
|
|
"info": "Malware 2017-01-26 (.js in .zip) - Cerber",
|
|
|
|
"publish_timestamp": "1485509878",
|
|
|
|
"published": true,
|
|
|
|
"threat_level_id": "3",
|
|
|
|
"timestamp": "1485448229",
|
|
|
|
"uuid": "588a1640-bcac-4dc1-b9da-435802de0b81",
|
|
|
|
"Orgc": {
|
|
|
|
"name": "CIRCL",
|
|
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
|
|
},
|
|
|
|
"Tag": [
|
|
|
|
{
|
|
|
|
"colour": "#ffffff",
|
|
|
|
"local": "0",
|
|
|
|
"name": "tlp:white",
|
|
|
|
"relationship_type": ""
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"colour": "#3a7300",
|
|
|
|
"local": "0",
|
|
|
|
"name": "circl:incident-classification=\"malware\"",
|
|
|
|
"relationship_type": ""
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"Attribute": [
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "download location",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1485444744",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "url",
|
|
|
|
"uuid": "588a1688-caa4-493b-95c3-406102de0b81",
|
|
|
|
"value": "http://sonnystafgy.top/search.php"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "download location",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1485444744",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "588a1688-489c-4ca2-a4a0-446f02de0b81",
|
|
|
|
"value": "sonnystafgy.top"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "download location",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1485444745",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "ip-dst",
|
|
|
|
"uuid": "588a1689-03dc-42d8-aa16-47f302de0b81",
|
|
|
|
"value": "54.200.117.224"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "downloaded malware",
|
|
|
|
"data": "UEsDBBQACQAIACx8OkpZeDZaTQsDAIABBQAgABwAMzVlMWIyZmNjODk0NWQ4NGMyNDBjNjZkM2IyMGMxMDhVVAkAA8QWiljEFopYdXgLAAEEIQAAAAQhAAAAnbZfsxkP81ePBeLq86LjdDKfFBa9it/2oc4CKnTwlI52y8yZd10p8nF3nINBd9cl0tfvNNYyl1Sshowxc+0GIHU9OEQ6N4CG5Jajh5cpzDk/2atFJUU+8PWT0O7d0LDgr6FuZXIRLvqsCstDO6uHU3hL3un0IyXIxNUJnfQN2X1uU+xR8Ab8ChYEpFIx9eeuPpnpYsxopSbkuMbNF4CV1OdgnCHdZiQp8REE+2/dOn2y26zyeuVvzz40sOnL9XMiApRhfEZSMK+9z3FlduFMwROHbrNZEekktnXGHdo4SjpcbXIYYjXTZaLAAQz2bmkNk0Stgo0iCCUQPH5iFv+WsWJmGEfqoKcWkPUnGE0q3vqkc0NOsYxsFiXcOM0ymNvZtnYamT6FGsuitJ9uv6xREjyU4PQIpVRQtPaCOY7HN41juvL8fXkqhSf3Ye7GKL6PUePlq5wMzSZsKYeS21rDwESEqjq0EJjJ4Y3MduaX6Y4jjNv4bDmIhW0YOdf4EHFSQyyKOczPrPk81acG/3nXB89PF2Qa95X2W5yQ9ZKPD9kzXs3PAPNZV6Y1k/zaMaPkR7OcQGoM0Hdsugu1JCzrcpno/F6KlFIz3M1eRRs9BfP5ZfmLYM5ib90/FkZwnb2tmtMmbBCGHZMZR4WWIlvy1MeYXmbwnD01C4g1RMRMvEQsfevD4muW415prl/JJFkNDfDVFZApS64NEj6WjR6+pgDk+z1oOxcDbdLWmpIrd56VHbKGpeMFFB14LGKTj8wIS9ezTOJYnF7vczqoh/VUPvV74nevqY+6NqPJnwkjthtwEuBm5l5xNc2HypYBVcbIRfJIKd16ivLQjkysC4/e/vaL2DJAEWwfGuNqY+8Ai1NsE+zBWQCeEharXSmH+Ok6go++5VDVJpi1WyiDolg97xVfKHOUFcagwRysCXxy0WrcsSyaUUExusyiAWQjs95cnxdfskPgNkRqzND1IJ13GxywnLSkE2S0rNQ1VzW8yLIuE/rqOiXSdd3xVlPZhbI4Wl6YJNcaWpn6GB55L0DFWuLg1E/SiokdYEUjBvfovla9Wwmp07YyPmild9gUb7MaUNFBraXB4NOsI4kLQ7jjW2Z+BZpzMolTU/fVSKQ7gw2a+B+1lKp8h9H5T78DlewEfR6nCm6hHKea5ilESjVbrPFsXfehzRjIpAfeNWx+TmHo8qXyIj28TsFodyhy5c57+kcXU6giF5q1+QcYE8NYLX/cVEWN4mZzIUKVgwpeUQzyRQPnw/fc6cDlM3uq/sQzevcGZempZY+xEi6RcT+RJEEHB7FljfUxILaF/f4CEgXpkb9Yq47LCJJ5s71o/dxMTh5JeutYLCnh03Pkmt6FOGD8zwZYFxRaGoWNpjU0NxaV6l125wphM65LShMP5R1uSyOIIMY4x6NAcytxDZpvad8HBWw4xdWaCn4P+iRssnBPO1B7ZQYGZ9ee7pcY3VpB/kfMDte2CLR68FxLH5yOuKDO48poMcreeJq4m9w55tCSKPeTzcYiTuegD1NAEBbYS66cSXYETqLM7zD9puNBIgtQXzpVgo7pmXts3G1m0mhcT2GSHh/TrxubR2BrjctJTHjao5I5G/7mrUIecsCDmSLqxwFtK0pZYgC6Sy/mHDC0Iwq8McdYSHzQO3ZijXXk8zw32lWdTSRGgI1XNuauj49BXe9iuMG3E+P0uv7g6Se+sTjtmvDNriPO7tYyzjds6N0OmN6eTaaFt2LU9YKEOHy9Kf1+PIi9axEH/gOTZSK0bvoWFPYdQNoXQoPKCrnGznDJd4eBanvAyyg2NC9exQSRigNf/6dsYvi88jTAyyuKQBkx3OpT0TMfCSPaFZAUqk35PDFnC9HMAGdb4PrmKzeXZ1YrcAH6toHppTwWplDoMe4nVVYu9r6lo1hfHZ90ZopjlnmGROv3r55+AZfTELAczjAqB3dj+qFhMhc/SNYv680yGBVZpHznkWYmspXYebRwIClTN0mIJTQcCSv0ODyXMpTpIx9kIugNJlphyfEX3jx7dJgfbf3wXXiYkOYwsNncBwKYIvNHLaC6/xCfWKBk4svEpreCl4e11hj6oIiLzXLCXAVQOYRVvxyOSdA36vX4lBKPSywtFpADEDrXEFtFqrsJU1Tg05WQLYspwe+wVsRj04QfPEAMOk9KmeiMVB1QBLfl7djW8qdAHqR4/m2wp5m40ChfOE5XI67HModDu0+FJB2j7oUXmHaKB0awIfSfga7IgOoFKhxb1c4P3MUPg0Eh6Z/5yxorKhDPxruOTj8P3fb8RoZwtWExJoIEt+0wxgbqBhqFx11dmhWOJPMst5sVPiLPTjpr5PLuKAN3BdK1Yh+IuLDIeoW+wz4/1WZW2/I3inLC28hXzzjVONaiwI2Q5eDH0PzuMZTH3/daqONJkXojvYRBNHaEAuXRtyiBojb5H9hkzRFsOuGBatpsglLBsT0gCluketRXRHuXn+gRR3WdVx+mNlCdc6wBAiHKaUrWzAzVjffplPqTk9TYbag2J/pnxXfCjVrjzAhQpbiKdZgrdRY2TMWxU05ijE4bIjm8lKSnixw583hzP3tQNYEokmTSfoAwWDbyltxELAP4wYNArIz0T1esLwS4v6irBqmEZLEkwJ73vo8KgF/8XdBrnTx7Siik83LPVE1apUItCYWjiJM5sDMgqZCeJ5kwA4bIYgbzFL8MX5utTXS+A/8/Cy5x2kZOAUFYf/vUqVphxVYfD4FRw4vVZN6aLbwzzAvovknl6a5I5qDLgEqEnqywj8TFKdFpEdUo5IJmrUnQ+NJGgVs6oSih1yIYe8odHXmneQn5h3jh7JhswP+LGle8LXlc+pGCh0X7f04DStNaVODBALwXUSnXTZMv7dxhOFpe5VuMV4OJWvhn9DDTzktxa8Ey/Ma1GV98AmTJJtrArzU3WEvTiJxySYRW66I1M5rLWpILbEeHEu/K/vqxbpwxcVjnIOTYz9yVRVjSR6hzDMy3splg2L4g5HZ+sbq1WDcMlMpKJTPk6Qr7MtxK0qLsLRJ+FtsbBk1OplGq+FCs3/Wkb4weKKT/MeN8YL6ML0SoxYN/yQGTHL5Gr2+du9JYpr1G+YaNp+sgExPMmZpX9p4/FSwy191PnCzjhiNcFldFw9OIFWFa0yUgNv6zbFHcGtNgxOIg8NAxhMfTvVoz2mydz4/9CGUwPnZMQ0tbNanwGJRe6rVi2tKgW5itSY+HrTc962hhi2LUidah20ovNbCQpHyyXOIHNSdkl/3/NUH3aO5PtdLCpqmhYNPLgcUN5ULKFGVYcx36HxV2HkOU6Qdp/8Y8ydT263PPXnmon2yu9Lt1vh5MyRrpDTEuon4XSSgs7p6ywjvhNjEiObZgHb2Yg1+DclAS6G7tC5nW+mtcr2F+G0AlgT6B8+QLKYG+QCjE0FdHUvU7jTiUbMbQBW94SGeg7jDErd9yWAr3LFk3W2C5rzEnTps4pm9/QGbaEn+qk5hjNHc0ACG6OgzqfOaT1FEQrP75+E0G17aRvmAWo2bXS8LxBhp4LckE+EqcgwNK0XqI51pmcURzK5r1l17fyLUJtofVb50xHNqz5cLQsLZlMtYpN4wEBXkTjxRzZCxKtN9/He+xLsev9yrCzp600vMQw+CE7KJgu5TJ1GLLPzZKJXJRbfOMM3MyYEPWsGlO8tXyC37RA1B3Ckp4WmbXonLBdBajYESMs0Hbe+kiuGoU95t78Vd1cNYj3Yp2Q3NvoR2JqfcIUGfEiqBtXXnI1glC0wtV/c7kqluBrXCTZk2H4IWzPvP2xykLX9WzjHtvI5g4N3O44tuBAKzVsmqXpwjEvprgmWB2u+TTpaBTv3/WHIYg9q4ww8rcvoYWkURh3O02xPhGcDleRlWzffVBcofvHley/KTG1WWCir0+09/dWbS3cGkpXtERZVNHeAg6/ezS9qnS1XEm+MQ9QSSMD1
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1485444804",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "malware-sample",
|
|
|
|
"uuid": "588a16c4-481c-4684-9a1f-4b1102de0b81",
|
|
|
|
"value": "1|35e1b2fcc8945d84c240c66d3b20c108"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "downloaded malware",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1485444805",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "filename|sha1",
|
|
|
|
"uuid": "588a16c5-d85c-4db8-ac1c-468202de0b81",
|
|
|
|
"value": "1|aa9dc6afeea7d2e580ab57be53d7c5db2633e67c"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "downloaded malware",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1485444807",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "filename|sha256",
|
|
|
|
"uuid": "588a16c7-827c-4cc8-ad23-448702de0b81",
|
|
|
|
"value": "1|18b47db36839677a9c52150e93e76104ed0c5bd33cd12e5cce99c4727f12c6bc"
|
|
|
|
}
|
2023-04-21 13:25:09 +00:00
|
|
|
]
|
2023-12-14 14:30:15 +00:00
|
|
|
}
|
2023-04-21 13:25:09 +00:00
|
|
|
}
|