2023-04-21 13:25:09 +00:00
|
|
|
{
|
|
|
|
"Event": {
|
|
|
|
"analysis": "2",
|
|
|
|
"date": "2016-08-25",
|
|
|
|
"extends_uuid": "",
|
|
|
|
"info": "The Million Dollar Dissident - Citizen lab report",
|
|
|
|
"publish_timestamp": "1472160888",
|
|
|
|
"published": true,
|
|
|
|
"threat_level_id": "1",
|
|
|
|
"timestamp": "1472160818",
|
|
|
|
"uuid": "57bf5c07-6b40-428e-8f68-4a9a02de0b81",
|
|
|
|
"Orgc": {
|
|
|
|
"name": "CIRCL",
|
|
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
|
|
},
|
|
|
|
"Tag": [
|
|
|
|
{
|
|
|
|
"colour": "#ffffff",
|
2023-05-19 09:05:37 +00:00
|
|
|
"local": "0",
|
|
|
|
"name": "tlp:white",
|
|
|
|
"relationship_type": ""
|
2023-04-21 13:25:09 +00:00
|
|
|
}
|
|
|
|
],
|
|
|
|
"Attribute": [
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "Visiting a maliciously crafted website may lead to arbitrary code execution",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472158793",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "vulnerability",
|
|
|
|
"uuid": "57bf5c49-b2d4-46fe-be18-48de02de0b81",
|
|
|
|
"value": "CVE-2016-4657"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "An application may be able to disclose kernel memory",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472158794",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "vulnerability",
|
|
|
|
"uuid": "57bf5c4a-4fb8-4ba4-bf12-43a002de0b81",
|
|
|
|
"value": "CVE-2016-4655"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "An application may be able to execute arbitrary code with kernel privileges",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472158794",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "vulnerability",
|
|
|
|
"uuid": "57bf5c4a-42a0-439f-a09b-424002de0b81",
|
|
|
|
"value": "CVE-2016-4656"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472158906",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf5cba-f4d4-4e08-8947-4f0602de0b81",
|
|
|
|
"value": "webadv.co"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472159023",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "hostname",
|
|
|
|
"uuid": "57bf5d2f-03ac-495c-b2ee-4ca402de0b81",
|
|
|
|
"value": "sms.webadv.co"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472159075",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf5d63-418c-40ef-891f-bbe202de0b81",
|
|
|
|
"value": "aalaan.tv"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472159075",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf5d63-9bb4-422c-9fd4-bbe202de0b81",
|
|
|
|
"value": "manoraonline.net"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160759",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63f7-a014-4993-a207-452602de0b81",
|
|
|
|
"value": "icloudcacher.com"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160759",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "email-src",
|
|
|
|
"uuid": "57bf63f7-1ba4-406a-9183-40a502de0b81",
|
|
|
|
"value": "pn1g3p@sigaint.org"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160759",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63f7-c680-4764-a0a9-4ab802de0b81",
|
|
|
|
"value": "asrarrarabiya.com"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160759",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63f7-d1fc-44bb-b79a-4f9f02de0b81",
|
|
|
|
"value": "asrararabiya.co"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160760",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63f8-cff8-4563-bf0f-442802de0b81",
|
|
|
|
"value": "asrararablya.com"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160760",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63f8-9c74-43ca-af31-4f9302de0b81",
|
|
|
|
"value": "smser.net"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160760",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "url",
|
|
|
|
"uuid": "57bf63f8-0fa8-4299-ae08-4e9a02de0b81",
|
|
|
|
"value": "https://smser.net/9918216t/"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160760",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "url",
|
|
|
|
"uuid": "57bf63f8-cd20-4f04-8922-4c5e02de0b81",
|
|
|
|
"value": "https://smser.net/redirect.aspx"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160761",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63f9-d07c-4093-8192-47a902de0b81",
|
|
|
|
"value": "icrcworld.com"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160761",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63f9-592c-407d-b7a2-45a802de0b81",
|
|
|
|
"value": "redcrossworld.com"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160761",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63f9-1b80-4a8a-a813-452e02de0b81",
|
|
|
|
"value": "topcontactco.com"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160761",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "ip-dst",
|
|
|
|
"uuid": "57bf63f9-9828-45fe-92a2-458802de0b81",
|
|
|
|
"value": "52.8.153.44"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160761",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "ip-dst",
|
|
|
|
"uuid": "57bf63f9-d13c-4e8f-8b69-45d002de0b81",
|
|
|
|
"value": "52.8.52.166"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160762",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "ip-dst",
|
|
|
|
"uuid": "57bf63fa-e31c-4867-9c96-485402de0b81",
|
|
|
|
"value": "162.209.103.68"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160762",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63fa-92f0-4057-8460-497902de0b81",
|
|
|
|
"value": "thainews.asia"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160762",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63fa-2ec4-4995-b49b-402402de0b81",
|
|
|
|
"value": "kenyasms.org"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160762",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "ip-dst",
|
|
|
|
"uuid": "57bf63fa-8144-43c6-95a8-4fdd02de0b81",
|
|
|
|
"value": "82.80.202.200"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160762",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63fa-7bd8-42b8-b201-420602de0b81",
|
|
|
|
"value": "qaintqa.com"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160763",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "ip-dst",
|
|
|
|
"uuid": "57bf63fb-a494-4932-ac6b-488102de0b81",
|
|
|
|
"value": "82.80.202.204"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160763",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "ip-dst",
|
|
|
|
"uuid": "57bf63fb-b044-4b6e-93da-437202de0b81",
|
|
|
|
"value": "54.251.49.214"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160763",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "hostname",
|
|
|
|
"uuid": "57bf63fb-306c-47eb-99bb-467c02de0b81",
|
|
|
|
"value": "mail1.nsogroup.com"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160764",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63fc-8480-424b-86fe-4f0502de0b81",
|
|
|
|
"value": "nsoqa.com"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160764",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63fc-3f58-484c-9a94-42ce02de0b81",
|
|
|
|
"value": "ooredoodeals.com"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160764",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63fc-1174-429c-a55a-4bb402de0b81",
|
|
|
|
"value": "alawaeltech.com"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160764",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63fc-7fb0-460d-b13c-42e502de0b81",
|
|
|
|
"value": "bahrainsms.co"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160764",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "filename",
|
|
|
|
"uuid": "57bf63fc-ccf0-4d09-95dd-45e702de0b81",
|
|
|
|
"value": "damanhealth.online"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160765",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "filename",
|
|
|
|
"uuid": "57bf63fd-24f4-4d24-8286-47f202de0b81",
|
|
|
|
"value": "uaenews.online"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160765",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57bf63fd-e708-4449-941f-4ae902de0b81",
|
|
|
|
"value": "turkeynewsupdates.com"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160817",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "url",
|
|
|
|
"uuid": "57bf6431-0c20-437f-814a-41f202de0b81",
|
|
|
|
"value": "http://fb-accounts.com/1074139s/"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1472160817",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "url",
|
|
|
|
"uuid": "57bf6432-a068-405a-ae08-4b7802de0b81",
|
|
|
|
"value": "http://unonoticias.net/3423768s/"
|
|
|
|
}
|
|
|
|
]
|
|
|
|
}
|
|
|
|
}
|