118 lines
5.3 MiB
JSON
118 lines
5.3 MiB
JSON
|
{
|
||
|
"Event": {
|
||
|
"analysis": "0",
|
||
|
"date": "2016-09-16",
|
||
|
"extends_uuid": "",
|
||
|
"info": "OSINT - ELF.Rex",
|
||
|
"publish_timestamp": "1515753296",
|
||
|
"published": true,
|
||
|
"threat_level_id": "3",
|
||
|
"timestamp": "1474017220",
|
||
|
"uuid": "57dbb75c-4ebc-4856-96fc-4095950d210f",
|
||
|
"Orgc": {
|
||
|
"name": "CIRCL",
|
||
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
||
|
},
|
||
|
"Tag": [
|
||
|
{
|
||
|
"colour": "#ffffff",
|
||
|
"name": "tlp:white"
|
||
|
},
|
||
|
{
|
||
|
"colour": "#670080",
|
||
|
"name": "ms-caro-malware:malware-platform=\"Linux\""
|
||
|
}
|
||
|
],
|
||
|
"Attribute": [
|
||
|
{
|
||
|
"category": "External analysis",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1474017136",
|
||
|
"to_ids": false,
|
||
|
"type": "link",
|
||
|
"uuid": "57dbb770-3714-46ee-80d4-44f7950d210f",
|
||
|
"value": "https://twitter.com/benkow_/status/776683844011450368"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload installation",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1474017191",
|
||
|
"to_ids": true,
|
||
|
"type": "sha256",
|
||
|
"uuid": "57dbb7a7-2d74-4f94-9d99-45ac950d210f",
|
||
|
"value": "ab2b707d7993aee44ad98bf55fdd9ff02c00fa422abeb8eb10d9f275f5f6e55a"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload installation",
|
||
|
"comment": "- Xchecked via VT: ab2b707d7993aee44ad98bf55fdd9ff02c00fa422abeb8eb10d9f275f5f6e55a",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1474017220",
|
||
|
"to_ids": true,
|
||
|
"type": "sha1",
|
||
|
"uuid": "57dbb7c4-0b0c-43c2-b639-488302de0b81",
|
||
|
"value": "6fb2c6abe37f7a1fe4683105c3d2490e758e5aa9"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload installation",
|
||
|
"comment": "- Xchecked via VT: ab2b707d7993aee44ad98bf55fdd9ff02c00fa422abeb8eb10d9f275f5f6e55a",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1474017220",
|
||
|
"to_ids": true,
|
||
|
"type": "md5",
|
||
|
"uuid": "57dbb7c4-2bf0-4b57-90d6-4b5d02de0b81",
|
||
|
"value": "864d639dee07f5da2af5dfa375b21d5e"
|
||
|
},
|
||
|
{
|
||
|
"category": "External analysis",
|
||
|
"comment": "- Xchecked via VT: ab2b707d7993aee44ad98bf55fdd9ff02c00fa422abeb8eb10d9f275f5f6e55a",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1474017221",
|
||
|
"to_ids": false,
|
||
|
"type": "link",
|
||
|
"uuid": "57dbb7c5-cc2c-4683-b3f8-442302de0b81",
|
||
|
"value": "https://www.virustotal.com/file/ab2b707d7993aee44ad98bf55fdd9ff02c00fa422abeb8eb10d9f275f5f6e55a/analysis/1474010565/"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload delivery",
|
||
|
"comment": "Unpacked go compiled binaries",
|
||
|
"data": "UEsDBBQACQAIAH1LMEl3cgRp+T8/AED+lQAgABwAMzNlYzE1Mjc2MWQzN2EzNDk0MzM1NzJkZjRiNmRmYzdVVAkAAx6721ceu9tXdXgLAAEEIQAAAAQhAAAAJbXGGB3il//+rRKiGXqi0yUd4rjL6I7x4YFqvq+vAD//9+gOg5mYJRBE7vyFEFbe+VDsJBABMjm1JFO+h9pYL+rTsMeQe+Nd62ISpg+RHlGzmRORhsj6sbE2K0yfF3GodM7hv4BO4wHT3OurC67IX+7DCAOy+Q2eSP845JV1PJsz3BEODsNL9TONT+/qf+DTSKIPV+FWlYbc/HHYYVOKVlwwlfIwwjbjl5dHMZlWl0hbTg7jwOxkqhvo4UwOq+C9/EuglCOyBS8Uko4p+2i1KH6ajeNIzL0Mm7ENFhOl2DXXLRuhTpy4QwMUfcWwvwUSj43aJaZHhclmeMLb/aWOpujPsG0OJcjKh9u+3qBnHpDmJuzdmVvc2tTxpdQFdZVnUaAKnTMwyqkgRIi2dGaaeZgEbiec00OUNwSnT8eEwAyLVXDwTdBjJJZQ7ZHc7EvE9pLru4kFueiaw623Aiz9/Nl9+qGS5eai5v2DJ7Td9a8vjseCwNOjis+0irE6OLUhMrDFNB8WQgfptXj8J0w3hBrJ+ye7N1oFkXhzZ5Yz0EiTE9Yaom2XYkZ1U5YE83jIqS1wxo0yh/GtiZ0NwI2xzFqJZo7RRmsrp7LukECtjUawEy30ZEsanpGP2vByXt3F3fIh3oRvU6wi4pEQ+qGor5OAo6d/dwtz7b9WZd/6whoYQOCuimDtKp2Gzx2e97n4pGSvL31dkKYK2TMGFU6oV7u+k8aFsLc6OELiWadFyAL9C0oOcerLV5rWBrReLp/UIFDZGFc3Ns3XXhYS8fcxVQpGC7KszU3mdFxcy21ltU1md7qL7iYGSWcx9o8XIfFIxBNj6twhrDoS3cEMHFyhX7w2H5XIxVptVleOczxS4MYRT06wO63YuPH8jezl8mF9htIuuXkB2xAxDeqco4BwfznmAQhFHH8mz4MDiwxweawJA6ub6nDQZoOW3nngfKVT4iYPVpQQFwFVJosdcjd/Dv6Ny2qnKzObHFbrIX3s1hdgls9xumqD0m52tfMKLUkeY36L14Pff+1wHL4a+fZV/7U1pVB2LAkB1DNoWEF6ffTGUCYF9gCnDiI13fQjuOOuUgnSCQWodf029YrjW2ziaI0Vu/6Na3UsZKlKL5aqH11aPxIicAHM9MzgVOfZnjrMWMRW/zh209imP2jBorFTklcdunSbIZoFc4ClSqq7Pop83XsitY05ezmh7cSdHue2gbUNVAhVNKe6vjD8bEweKTB9s/mcQRK2CzTHHzkkev9PD79penoMZkcTvVAa2lSepEAq/stOlMy5cqxZKapOVO0od5CRgAFf1Y2OFy/237MJE/z1HvU5DlPwZMOdkukzlTqbfzlv3hx9MNUEvxX53g3v1BFlVgpx3ZBlCp4Ns4xR9qecInt5wEGJ9ULyYt1nRnouQKB9Nqq0HZQrez2c0qDxvPbx8joU2HOf1hdlmj83qb4PcUDJ4o/oL9D3hSiISYAyq0tzz+5HDOXC92oHr2sh8aP2csPxMurzzALyPQt2I9h8M2vREbKisE1OPb3RFHAEcAqqKBVDPdnA3aWSITG4VtAT1XrALszOYT6BpE1r9Wbba1y8gNWyo9CoIJfWTVS7akYIkQT/lsM4L5IHGGCWP1TtSB0Mq+TX8Hhgnm0aozab17qlhnMIOGcu1mzyuT9LIRrbvgsdp1znZBl/ajWzpOa1wv0JcAZN3kwusJ9YTAkaXODGTaV7LVGWkZVTooQRvUJ5TDTJPW4sD1xl61Xrt92qgkjtzE/W2UzMc0hEypvbxe7rnHf9BtueO+QZ/Rt8dOAaqvD/vIvGkJMWpI1hkgg/Kj8PKkScG4TSSWkaQaxUt0XGd+nutG5RirjpTnQbKlUC7RkDzLjmGmdOdHBV7i8bupO6wYxQBFR7XoM6UoYf/ySnfEbWk+mvDyPE9YdhgD1qq4gPwyFukYlc9huUg64yCMIaIsGET8a2wzxcmPgT54gp59xmQNRILHtORvCq1jexW471yIa2jVMSc+3f6IOsNZjTTQqTxen5vo3l8NHNm6TReQAo9GpdHcGHZ11voqiBdLYAo5eMOpXNHXiptjrHpPNjr/smIWq7/oZR5PByxZjhu2/CnpOZ4IMWI72S99Y950uzCk/yEe0SdweoBmJES1Cm2EJknxB1Nvbk5/ucnMIK/XGXoboWsqKdSsBfhoYEj/cghUFUHeOcMJYV8EH9NF+1touIplIo5YacoaggdNcJGq/EdWu6Bw7eMHuQ8iz7kDuws11GFaUsRAdIXr6mCwpCSUusn4MGDlxzCFLxlbra70HO4eBy6y43Q9h7UQuSV2x1y+mgU4FQDQ08NoiCsB2D1TvkmKX/yRoFejzKXrxzP9K0khdS3PTM2Igi7uK4EQ7yMl2vS0rnUYppKYxzWHo9oxIhCTQU3pm/snLXbgEDh0FUucdSPGxzd05PwQCvOs5Cy6vY69YtPFgRQIwp9ssq/hxKPig1AnzG2DRqBVdWpBQ1SeyR33MQ88eNXewkmlxqE4JFS7KfqUu7wkY26N9W6qHfn3E5t74sep5SCQ+rp7tfSRSUI9YDLC6qHsf1+FfUhY+nZJ4Dy0TGIhZcb5xblaYeMt22MNkWQND/KElVAvAwZbVg+LKscxpwqkNxPthYgYX/IDrZlrkFuvp2M+0trfwyGLq6bN8+q8yQRZLaWiH+7CLQh6IUIs4Rm5DOxE+peHaDUcOTebKwr78oNIXbiYhpmECztCFSmUaveCQ1JMC6wtCd6yfYIiVmBH5Xq5hCa7dqQUTLZMK5/rjSbypQcTvAPtnbzLebb0l0O9UURv3bB8MrWsyvbtCLUWNEBD8GodqgtPkNBfOo+lCk1rdkhzQBPBFSw/5eX9IHXM3xXIodyNZIFY7iZfly1T+SbAl7JoSZGE4XM2NXQltT42v1161Rf5sWHNshZaRxSKhBO9tqrp9s9pCcZEOmoHGIGg25GXoDt2xM8k8VUZT7F8pYJRQvzABfa+HozCmPbWn0utb0EqB+DhUeWW3l04Zewizr5wIVefTpjG+WV0BoUKVjvRePwaOmfphfNFtQ0agfC4oDY3pQW77XVfJb4NgC03uy98vxS/joOmzh4cvrdIjlHVdLdT8KgNeRLrwpBwGPibDe0JQBv4xLktpebWbBfiQCxG3LpxqU9qSNsJeJTbKEM2z1eIF3C+uvUEBCzPKgIwOZjFHjHB2ooKRWgr5fscX/m/CMxVZtz6tMO3HfZCTBv4QNUjGMVqWSb6aS8Q/U2gijlD7GlgOjZr0mkcxUSOYW/iG5FpcsKV0JqQftlig3zMI9aFahf8gYcUoRm3RYpAk56eJCcpiAh5g4Zn835vmUHftHeylBKUh8b/LsYt5l+BTRHtu4SauPVt71Fl2F9N9nmTwHRXq080qHw4pWZUIvO9YCCUZKBe2NLRrFTQtANpRsdTh8PF7dzK2wsQK6Zc+wrQsDRLgReqZfkM8mng09/iQl3Shbk1tTb4HKR6QFWH0g9DNNwny2AnU+1iLv8+NV54gj4yU8RCBOu3eQ9afdbGUUFovuk2IAmeoomPUNoSgEf/0r8qHdgt2jSg2tPkr8QPQ2qxAqUOiNPZYgKl6iFpgcApm4CTFUMBQI94UjF4/ZUgWhdMRWVWG8x0dQlydRL/CkYst08dvslBy0/S49ywraUDPtPKZnzR1Ocv5dg65nLhp+7kkHO0+H+7XSXNdJ/ka8v1nJkMS/jHunQjGZp2KkEDOuBzIf2Y/K6osubBB7NgLEazyrWI6hliwWOWSit+6UHa4RkYsWpkbBwhHKSprSMUtRr88aJGXlEUnaxDpV3nLCMjZGTtXIFM2FRPhVrUqlmXhenwCBUN4d3VMSgnMNMV18myK+sQLwjw5HWaAUDV9CzmDbzBCknniY/pZKxL/xZ5eaRvdtV3pbgMslXqEvMk+YcidVz3QQ4oCa4/VeXdDmeRB7L7RYcmsp/E
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1474018079",
|
||
|
"to_ids": true,
|
||
|
"type": "malware-sample",
|
||
|
"uuid": "57dbbb1f-058c-4ca7-8c1b-42c8950d210f",
|
||
|
"value": "ab2b707d7993aee44ad98bf55fdd9ff02c00fa422abeb8eb10d9f275f5f6e55a|33ec152761d37a349433572df4b6dfc7"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload delivery",
|
||
|
"comment": "Unpacked go compiled binaries",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1474018080",
|
||
|
"to_ids": true,
|
||
|
"type": "filename|sha1",
|
||
|
"uuid": "57dbbb20-c468-43b1-a6e2-453d950d210f",
|
||
|
"value": "ab2b707d7993aee44ad98bf55fdd9ff02c00fa422abeb8eb10d9f275f5f6e55a|2c514212637e9d8d8861de4efd4a0062831f75d5"
|
||
|
},
|
||
|
{
|
||
|
"category": "Payload delivery",
|
||
|
"comment": "Unpacked go compiled binaries",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1474018081",
|
||
|
"to_ids": true,
|
||
|
"type": "filename|sha256",
|
||
|
"uuid": "57dbbb21-2da0-4b8b-8e30-449d950d210f",
|
||
|
"value": "ab2b707d7993aee44ad98bf55fdd9ff02c00fa422abeb8eb10d9f275f5f6e55a|8a7c548a47c7cbd120b2f262797834e8aa8d6441082571f5d125c9a0ed4c75d4"
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
}
|