321 lines
6.5 MiB
JSON
321 lines
6.5 MiB
JSON
|
{
|
||
|
"Event": {
|
||
|
"analysis": "2",
|
||
|
"date": "2016-09-24",
|
||
|
"extends_uuid": "",
|
||
|
"info": "OSINT - Hunting Libyan Scorpions",
|
||
|
"publish_timestamp": "1526395085",
|
||
|
"published": true,
|
||
|
"threat_level_id": "2",
|
||
|
"timestamp": "1526395066",
|
||
|
"uuid": "57e634d4-4e48-4a7b-82de-46be950d210f",
|
||
|
"Orgc": {
|
||
|
"name": "CIRCL",
|
||
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
||
|
},
|
||
|
"Tag": [
|
||
|
{
|
||
|
"colour": "#004646",
|
||
|
"name": "type:OSINT"
|
||
|
},
|
||
|
{
|
||
|
"colour": "#ffffff",
|
||
|
"name": "tlp:white"
|
||
|
}
|
||
|
],
|
||
|
"Attribute": [
|
||
|
{
|
||
|
"category": "External analysis",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526394581",
|
||
|
"to_ids": false,
|
||
|
"type": "link",
|
||
|
"uuid": "5afaeed5-5af0-4dd9-9744-4e46950d210f",
|
||
|
"value": "https://cyberkov.com/wp-content/uploads/2016/09/Hunting-Libyan-Scorpions-EN.pdf"
|
||
|
},
|
||
|
{
|
||
|
"category": "External analysis",
|
||
|
"comment": "",
|
||
|
"data": "JVBERi0xLjUNCiW1tbW1DQoxIDAgb2JqDQo8PC9UeXBlL0NhdGFsb2cvUGFnZXMgMiAwIFIvTGFuZyhlbi1VUykgL1N0cnVjdFRyZWVSb290IDI0MCAwIFIvTWFya0luZm88PC9NYXJrZWQgdHJ1ZT4+L01ldGFkYXRhIDkwNiAwIFIvVmlld2VyUHJlZmVyZW5jZXMgOTA3IDAgUj4+DQplbmRvYmoNCjIgMCBvYmoNCjw8L1R5cGUvUGFnZXMvQ291bnQgMzQvS2lkc1sgMyAwIFIgMjAgMCBSIDQwIDAgUiA0NSAwIFIgNDcgMCBSIDQ5IDAgUiA1MCAwIFIgNTIgMCBSIDUzIDAgUiA1NCAwIFIgNTUgMCBSIDU2IDAgUiA1NyAwIFIgNTggMCBSIDU5IDAgUiA2MCAwIFIgNjEgMCBSIDYyIDAgUiA2MyAwIFIgNjQgMCBSIDY1IDAgUiA2NiAwIFIgNjkgMCBSIDcwIDAgUiA3MSAwIFIgNzMgMCBSIDc1IDAgUiA3NiAwIFIgNzcgMCBSIDc4IDAgUiA4MCAwIFIgODEgMCBSIDgyIDAgUiA4MyAwIFJdID4+DQplbmRvYmoNCjMgMCBvYmoNCjw8L1R5cGUvUGFnZS9QYXJlbnQgMiAwIFIvUmVzb3VyY2VzPDwvRm9udDw8L0YxIDUgMCBSL0YyIDEyIDAgUi9GMyAxNCAwIFIvRjQgMTYgMCBSPj4vRXh0R1N0YXRlPDwvR1M3IDcgMCBSL0dTOCA4IDAgUj4+L1hPYmplY3Q8PC9JbWFnZTkgOSAwIFIvSW1hZ2UxOCAxOCAwIFI+Pi9Qcm9jU2V0Wy9QREYvVGV4dC9JbWFnZUIvSW1hZ2VDL0ltYWdlSV0gPj4vQW5ub3RzWyAxMSAwIFJdIC9NZWRpYUJveFsgMCAwIDU5NS4zMiA4NDEuOTJdIC9Db250ZW50cyA0IDAgUi9Hcm91cDw8L1R5cGUvR3JvdXAvUy9UcmFuc3BhcmVuY3kvQ1MvRGV2aWNlUkdCPj4vVGFicy9TL1N0cnVjdFBhcmVudHMgMD4+DQplbmRvYmoNCjQgMCBvYmoNCjw8L0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggMTM3OT4+DQpzdHJlYW0NCnicvVldT9tYEH2PlP8wj3ZXubnfH6iqtqVQWFGJXSL1gfbBCSb1lsRsYkqR+uN3xg4tje0NJGaRiGP72nPmzLlzZ26GrxdFdplMCnj5cvi6KJLJ5/QCzoej/PrTcHR3nQ5Pk2k2T4osnw/PbsYFXTpKk4t08eoVvHm7D//0e5xx+vPeCeBggmFKgteCBQmLtN/78ALm/d6bUb83PBQgBOMaRpf9Ho3mIMBocNoygVdnOObdmYPpEl8L0/LMr87e9XvnEcSfYPRHv3eAb/uz33u0dRwLB+/3Ydji8Ju8KPJZu8+HeV507LNiwZYel44+s3+PDyjHQIQKkTOGaUk28b80dvmixDRYgXI8ICj6rrgRvhWdMaXb6DTG2eB7HRMOJhTt41kyTQO8zaFyV2vJrMIhnikPQhsmFBjOjNYPXvjoge0R0M4yacEFz7Sv4sDCyvPySxmP/bt4IKNxrKJ08SUOUR4PTPQ1thHs358xOIkHKiouWC12u2I0Rj8CY10z3VjXjjOHc9NLpldC5cwGINMCFtO1C3+VYG5v44GObtkkFjy6I2Iq8uj0Sx5rJA/v021Z0Td7BtYCs/aJuNdIrD3ygwxOofCeBI5X5MNp0R3t+KCzlvH2oGfz2ESXOZH5++RunBK/qFAh7iX6gOVnIdlSotiEslGaneZiwZThAqRhxmH+kSyA8MyZH3HhdHJLR1GhQvB/Q+8/nzurKBJMWBphMbMJiYlLaOb9WhraOOiew/ALf4Ib5i0oWRI7oxtT+ihpG1EIU4zbFc6dPfgNvwVrQEqtjeEcL8L3eGAb6N0aji8X4GY4h5jvkm8IooIi4GNEE9v7eID68h9jypGglVICRfSdwMNBObeT7Kp8LMOJfy9YR4KtsmrlJMpWr1SLisVDlReAxFu5+YHM0VB6ZImjM6SgSBHWHtzSvSrprDSPn3dr73a/vnoH2hrmKyUD30Jda25+pEFcTOvpTVF6k4JJval+uJ9qMDylSfZ+//gt8O2qGEUIGyo3GZiXndUx7baEUsz4ru01ESS6I0jhGsQxr2pcwN0m0DUgcjsgGqQra8tf2BPModR4wLz36EXx6GZeZPPpTrFsQiMVrhrhqWh201QjDlwElXoqjpNsfJfM4YwSz4QSWb6gr9e4Ri07h6htOdt3o6qmLLW1suy6xC2WqFKXOI2oSfx4/jVdFtk0KTAHdyClmnkp0XnRZn5nyTTYs0y5ZntAfZGgPnZyHiXPYBurtKDafK1k2blRhZpU/yPBWEUw3kIw9WNjXNDTBRwsab5h74i66h6E4Lg+e9DSU36ogUhm10k2nVMbOEoW3cfZ+lJjzdanaZmT0fZRNv3cuXHNNWWaFuOD7u0JxYRos3e6yLHUu8T/7Cp9jtmMNb8DFRSToSF5XV7dpLgEouQSqsZ3Tu91tWP/ZEwbgE1pXHeXxmlDCquULUCY7kDI4Bj2OYor2h96KhC7LRBhaoWBcVSgSIt46sXm6OR0D1CS2Jb46DNps6CmI91RHXUYSmFEVBuMTXy4rbcr63xgp+JDVbfVNy0PsQDSEVzfjKkOuqKSKKOPCVxky5KaBZFU9nw38SBExY8h+W4LVhNWZQNNqRasm0jz2xb/2I+tk1apWeAhdFa5he7x0RZQZ/jE1u1lO0DhqfPrDOGW/R1qTa6VY455Q3uBut6Ii111vWYLm/7gWmz5jm1ZTsmv2dawa1uaFuBmW2dU3F1T/ljlVx/NxuXW2G41Vw2FIoW1RXJISU1yzHDCdmwWBaTbnN8o44e7A2CUIZMrAMJ5OvwEILCitNWPMMIa2raWWHZhmbfamfj5UwxWvdVvMaXBfwFkhZuzDQplbmRzdHJlYW0NCmVuZG9iag0KNSAwIG9iag0KPDwvVHlwZS9Gb250L1N1YnR5cGUvVHJ1ZVR5cGUvTmFtZS9GMS9CYXNlRm9udC9CQ0RFRUUrQ2FsaWJyaS9FbmNvZGluZy9XaW5BbnNpRW5jb2RpbmcvRm9udERlc2NyaXB0b3IgNiAwIFIvRmlyc3RDaGFyIDMyL0xhc3RDaGFyIDEyNC9XaWR0aHMgODc3IDAgUj4+DQplbmRvYmoNCjYgMCBvYmoNCjw8L1R5cGUvRm9udERlc2NyaXB0b3IvRm9udE5hbWUvQkNERUVFK0NhbGlicmkvRmxhZ3MgMzIvSXRhbGljQW5nbGUgMC9Bc2NlbnQgNzUwL0Rlc2NlbnQgLTI1MC9DYXBIZWlnaHQgNzUwL0F2Z1dpZHRoIDUyMS9NYXhXaWR0aCAxNzQzL0ZvbnRXZWlnaHQgNDAwL1hIZWlnaHQgMjUwL1N0ZW1WIDUyL0ZvbnRCQm94WyAtNTAzIC0yNTAgMTI0MCA3NTBdIC9Gb250RmlsZTIgODc1IDAgUj4+DQplbmRvYmoNCjcgMCBvYmoNCjw8L1R5cGUvRXh0R1N0YXRlL0JNL05vcm1hbC9jYSAxPj4NCmVuZG9iag0KOCAwIG9iag0KPDwvVHlwZS9FeHRHU3RhdGUvQk0vTm9ybWFsL0NBIDE+Pg0KZW5kb2JqDQo5IDAgb2JqDQo8PC9UeXBlL1hPYmplY3QvU3VidHlwZS9JbWFnZS9XaWR0aCAxMjIvSGVpZ2h0IDE1Mi9Db2xvclNwYWNlL0RldmljZVJHQi9CaXRzUGVyQ29tcG9uZW50IDgvSW50ZXJwb2xhdGUgZmFsc2UvU01hc2sgMTAgMCBSL0ZpbHRlci9GbGF0ZURlY29kZS9MZW5ndGggMjI0NDM+Pg0Kc3RyZWFtDQp4nNxdh19Ux9pml2XpvXfpbenLLogidkEFe2I0RY299xpjRdOsqKAiSu/bKAuxJGo0do2JSaQ3Ufwnvmdmzh4WxBSjN/d+8xuOZ+fMzHnnmXfeMuVoYPBfHgSG5lYmXoHOk+b5f3
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526394739",
|
||
|
"to_ids": false,
|
||
|
"type": "attachment",
|
||
|
"uuid": "5afaef73-fc68-4474-a2f7-3556950d210f",
|
||
|
"value": "Hunting-Libyan-Scorpions-EN.pdf"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload delivery",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526394802",
|
||
|
"to_ids": true,
|
||
|
"type": "sha256",
|
||
|
"uuid": "5afaefb2-e71c-4bde-8835-48e0950d210f",
|
||
|
"value": "9d8e5ccd4cf543b4b41e4c6a1caae1409076a26ee74c61c148dffd3ce87d7787"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload delivery",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526394802",
|
||
|
"to_ids": true,
|
||
|
"type": "sha256",
|
||
|
"uuid": "5afaefb2-d584-4a0d-8ee9-4ee7950d210f",
|
||
|
"value": "4e656834a93ce9c3df40fe9a3ee1efcccc728e7ea997dc2526b216b8fd21cbf6"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload delivery",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526394803",
|
||
|
"to_ids": true,
|
||
|
"type": "sha256",
|
||
|
"uuid": "5afaefb3-84fc-45fe-bf6b-463a950d210f",
|
||
|
"value": "e66d795d0c832ad16381d433a13a2cb57ab097d90e9c73a1178a95132b1c0f70"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload delivery",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526394803",
|
||
|
"to_ids": true,
|
||
|
"type": "md5",
|
||
|
"uuid": "5afaefb3-76e0-4886-b83a-4e5f950d210f",
|
||
|
"value": "1738ecf69b8303934bb10170bcef8926"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload delivery",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526394803",
|
||
|
"to_ids": true,
|
||
|
"type": "md5",
|
||
|
"uuid": "5afaefb3-1448-4f67-8702-4a4d950d210f",
|
||
|
"value": "93ebc337c5fe4794d33df155986a284d"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload delivery",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526394804",
|
||
|
"to_ids": true,
|
||
|
"type": "md5",
|
||
|
"uuid": "5afaefb4-9288-4529-8480-461a950d210f",
|
||
|
"value": "1c8a1aa75d514d9b1c7118458e0b8a14"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload delivery",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526394804",
|
||
|
"to_ids": true,
|
||
|
"type": "sha1",
|
||
|
"uuid": "5afaefb4-d238-43d2-bde4-4146950d210f",
|
||
|
"value": "41096b7f808a91ee773bbba304ea2cd0fa42519d"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload delivery",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526394805",
|
||
|
"to_ids": true,
|
||
|
"type": "sha1",
|
||
|
"uuid": "5afaefb5-eb00-463a-91e0-4c37950d210f",
|
||
|
"value": "46d832a9c1d6c34edffee361aca3de65db1b7932"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload delivery",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526394805",
|
||
|
"to_ids": true,
|
||
|
"type": "sha1",
|
||
|
"uuid": "5afaefb5-42a4-4a7d-a826-416f950d210f",
|
||
|
"value": "2e2d1315c47db73ba8facb99240ca6c085a9acbc"
|
||
|
},
|
||
|
{
|
||
|
"category": "Network activity",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526394887",
|
||
|
"to_ids": true,
|
||
|
"type": "ip-dst",
|
||
|
"uuid": "5afaf007-fdcc-4753-9989-1869950d210f",
|
||
|
"value": "41.208.110.46"
|
||
|
},
|
||
|
{
|
||
|
"category": "Network activity",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526394940",
|
||
|
"to_ids": true,
|
||
|
"type": "hostname",
|
||
|
"uuid": "5afaf03c-5aec-463e-9584-474d950d210f",
|
||
|
"value": "samsung.ddns.me"
|
||
|
},
|
||
|
{
|
||
|
"category": "Network activity",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526394972",
|
||
|
"to_ids": true,
|
||
|
"type": "hostname",
|
||
|
"uuid": "5afaf05c-36d4-470e-914e-3537950d210f",
|
||
|
"value": "collge.myq-see.com"
|
||
|
},
|
||
|
{
|
||
|
"category": "Network activity",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526395000",
|
||
|
"to_ids": true,
|
||
|
"type": "hostname",
|
||
|
"uuid": "5afaf078-7330-4b67-bbe8-3537950d210f",
|
||
|
"value": "sara2011.no-ip.biz"
|
||
|
},
|
||
|
{
|
||
|
"category": "Network activity",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526395046",
|
||
|
"to_ids": true,
|
||
|
"type": "hostname",
|
||
|
"uuid": "5afaf0a6-74d4-442d-b7e3-4444950d210f",
|
||
|
"value": "winmeif.myq-see.com"
|
||
|
},
|
||
|
{
|
||
|
"category": "Network activity",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1526395063",
|
||
|
"to_ids": true,
|
||
|
"type": "hostname",
|
||
|
"uuid": "5afaf0b7-77c4-4e09-8ef4-4d6a950d210f",
|
||
|
"value": "wininit.myq-see.com"
|
||
|
}
|
||
|
],
|
||
|
"Object": [
|
||
|
{
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"description": "File object describing a file with meta-information",
|
||
|
"meta-category": "file",
|
||
|
"name": "file",
|
||
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
||
|
"template_version": "11",
|
||
|
"timestamp": "1526394869",
|
||
|
"uuid": "cf08eeff-6adc-4055-b07b-85e896626093",
|
||
|
"ObjectReference": [
|
||
|
{
|
||
|
"comment": "",
|
||
|
"object_uuid": "cf08eeff-6adc-4055-b07b-85e896626093",
|
||
|
"referenced_uuid": "a850600c-54f1-4a14-b31c-9593edb9fbb5",
|
||
|
"relationship_type": "analysed-with",
|
||
|
"timestamp": "1526394874",
|
||
|
"uuid": "5afaeffa-5894-4122-9e0e-353702de0b81"
|
||
|
}
|
||
|
],
|
||
|
"Attribute": []
|
||
|
},
|
||
|
{
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"description": "VirusTotal report",
|
||
|
"meta-category": "misc",
|
||
|
"name": "virustotal-report",
|
||
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
||
|
"template_version": "2",
|
||
|
"timestamp": "1526394868",
|
||
|
"uuid": "a850600c-54f1-4a14-b31c-9593edb9fbb5",
|
||
|
"Attribute": []
|
||
|
},
|
||
|
{
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"description": "File object describing a file with meta-information",
|
||
|
"meta-category": "file",
|
||
|
"name": "file",
|
||
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
||
|
"template_version": "11",
|
||
|
"timestamp": "1526394872",
|
||
|
"uuid": "2cbd399e-6423-4649-b234-ffcd3dca9398",
|
||
|
"ObjectReference": [
|
||
|
{
|
||
|
"comment": "",
|
||
|
"object_uuid": "2cbd399e-6423-4649-b234-ffcd3dca9398",
|
||
|
"referenced_uuid": "4a94a5d1-5967-4028-adf2-b900291f8b40",
|
||
|
"relationship_type": "analysed-with",
|
||
|
"timestamp": "1526394875",
|
||
|
"uuid": "5afaeffb-3040-449a-af34-353702de0b81"
|
||
|
}
|
||
|
],
|
||
|
"Attribute": []
|
||
|
},
|
||
|
{
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"description": "VirusTotal report",
|
||
|
"meta-category": "misc",
|
||
|
"name": "virustotal-report",
|
||
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
||
|
"template_version": "2",
|
||
|
"timestamp": "1526394871",
|
||
|
"uuid": "4a94a5d1-5967-4028-adf2-b900291f8b40",
|
||
|
"Attribute": []
|
||
|
},
|
||
|
{
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"description": "File object describing a file with meta-information",
|
||
|
"meta-category": "file",
|
||
|
"name": "file",
|
||
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
||
|
"template_version": "11",
|
||
|
"timestamp": "1526394875",
|
||
|
"uuid": "f8939924-ce54-40ea-8744-9ba61335b548",
|
||
|
"ObjectReference": [
|
||
|
{
|
||
|
"comment": "",
|
||
|
"object_uuid": "f8939924-ce54-40ea-8744-9ba61335b548",
|
||
|
"referenced_uuid": "71f29082-0567-4b34-8076-6ce923945e31",
|
||
|
"relationship_type": "analysed-with",
|
||
|
"timestamp": "1526394875",
|
||
|
"uuid": "5afaeffb-3a98-4c4c-824b-353702de0b81"
|
||
|
}
|
||
|
],
|
||
|
"Attribute": []
|
||
|
},
|
||
|
{
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"description": "VirusTotal report",
|
||
|
"meta-category": "misc",
|
||
|
"name": "virustotal-report",
|
||
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
||
|
"template_version": "2",
|
||
|
"timestamp": "1526394873",
|
||
|
"uuid": "71f29082-0567-4b34-8076-6ce923945e31",
|
||
|
"Attribute": []
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
}
|