2023-04-21 13:25:09 +00:00
{
"Event" : {
"analysis" : "0" ,
"date" : "2019-06-24" ,
"extends_uuid" : "" ,
"info" : "Information stealer malware via fake malicious document as \"University of Luxembourg\"" ,
"publish_timestamp" : "1561370357" ,
"published" : true ,
"threat_level_id" : "3" ,
"timestamp" : "1561369720" ,
"uuid" : "5d108ff9-9c70-4fbe-932d-acd8950d210f" ,
"Orgc" : {
"name" : "CIRCL" ,
"uuid" : "55f6ea5e-2c60-40e5-964f-47a8950d210f"
} ,
"Tag" : [
{
"colour" : "#ffffff" ,
2023-05-19 09:05:37 +00:00
"local" : "0" ,
"name" : "tlp:white" ,
"relationship_type" : ""
2023-04-21 13:25:09 +00:00
} ,
{
"colour" : "#0071c3" ,
2023-05-19 09:05:37 +00:00
"local" : "0" ,
"name" : "osint:lifetime=\"perpetual\"" ,
"relationship_type" : ""
2023-04-21 13:25:09 +00:00
} ,
{
"colour" : "#0087e8" ,
2023-05-19 09:05:37 +00:00
"local" : "0" ,
"name" : "osint:certainty=\"50\"" ,
"relationship_type" : ""
2023-04-21 13:25:09 +00:00
}
] ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1561366544" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "5d109010-3b60-4276-83cf-485a950d210f" ,
"value" : "192.210.146.35"
} ,
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1561366545" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "5d109011-e08c-408a-83a6-4467950d210f" ,
"value" : "http://192.210.146.35/vbc.exe"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"data" : " i V B O R w 0 K G g o A A A A N S U h E U g A A C N g A A A c a C A Y A A A C q Z E 2 Z A A A M S G l D Q 1 B J Q 0 M g U H J v Z m l s Z Q A A S I m V V w d Y U 8 k W n l t S S W i B C E g J v Y l S p E s J o U U Q k C r Y C E k g o c S Y E E T s y L I K r l 1 E w I a u i i i 6 F k D W i r r W R b G 7 l o c i K s q 6 W L C h 8 i Y F d N 3 v v f e 9831 z 758 z 5 / y n Z O 7 c O w D o 1 P C k 0 l x U F 4 A 8 S b 4 s P i K E N S E 1 j U X q B E R g B E j A B j j z + H I p O y 4 u G k A Z v P 9 d 3 t 4 A i P J + 1 U X J 9 c / 5 / y p 6 A q G c D w A S B 3 G G Q M 7 P g / g A A H g J X y r L B 4 D o A / X W M / K l S j w J Y g M Z T B B i q R J n q X G J E m e o c a X K J j G e A / E u A M g 0 H k + W B Y B 2 M 9 S z C v h Z k E f 7 F s S u E o F Y A o A O G e J A v o g n g D g S 4 h F 5 e d O U G N o B h 4 x v e L L + x p k x x M n j Z Q 1 h d S 0 q I Y e K 5 d J c 3 s z / s x 3 / W / J y F Y M x 7 O C g i W S R 8 c q a Y d 9 u 5 U y L U m I a x D 2 S j J h Y i P U h f i 8 W q O w h R q k i R W S S 2 h 415 c s 5 s G e A C b G r g B c a B b E p x O G S 3 J h o j T 4 j U x z O h R i u E L R Q n M 9 N 1 P g u E s r D E j S c N b J p 8 b G D O F P G Y W t 8 G 3 g y V V y l / S l F T h J b w 39 L J O Q O 8 r 8 p E i W m q H P G q A X i 5 B i I t S F m y n M S o t Q 2 m E 2 R i B M z a C N T x C v z t 4 H Y T y i J C F H z Y 1 M y Z e H x G n t Z n n y w X m y R S M y N 0 e C q f F F i p I Z n F 5 + n y t 8 I 4 m a h h J 0 0 y C O U T 4 g e r E U g D A 1 T 145 d F k q S N P V i H d L 8 k H i N 7 y t p b p z G H q c K c y O U e i u I T e U F C R p f P D A f L k g 1 P x 4 j z Y 9 L V O e J Z 2 T z x s a p 88 E L Q T T g g F D A A g o 4 M s A 0 k A 3 E b T 1 N P f C X e i Y c 8 I A M Z A E h c N F o B j 1 S V D M S e E 0 A R e B P i I R A P u Q X o p o V g g K o / z y k V V 9 d Q K Z q t k D l k Q M e Q 5 w H o k A u / K 1 Q e U m G o i W D R 1 A j / k d 0 P s w 1 F w 7 l 3 D 91 b K i J 1 m g U g 7 w s n U F L Y h g x l B h J D C c 64 i Z 4 I O 6 P R 8 N r M B z u u A / u O 5 j t V 3 v C Y 0 I 74 S H h O q G D c H u q u F j 2 X T 0 s M A 50 w A j h m p o z v q 0 Z t 4 O s n n g I H g D 5 I T f O x E 2 A C z 4 a R m L j Q T C 2 J 9 R y N J k r q / + e + 281 f N N 1 j R 3 F l Y J S h l G C K Q 7 f e 2 o 7 a X s O s S h 7 + m 2 H 1 L l m D P W V M z T z f X z O N 50 W w H v U 95 b Y I m w / d g Y 7 g Z 3 D D m N N g I U d w 5 q x i 9 g R J R 5 a R Y 9 U q 2 g w W r w q n x z I I / 5 H P J 4 m p r K T c t d 6127 X T + q 5 f G G h c n 8 E n G n S m T J x l i i f x Y Y 7 v 5 D F l f B H j m C 5 u 7 r 5 A q B 8 j 6 i 3 q d d M 1 f s B Y Z 7 / q i s u A C D A c W B g 4 P B X X T T 0 O g D 3 U W r 3 V 50 D 3 O O 0 L Q A 4 u 4 i v k B W o d b j y Q g B U o A O f K G N g D q y B A 6 z H H X g B f x A M w s B Y E A s S Q S q Y A r s s g u t Z B m a A 2 W A B K A X l Y D l Y A 6 r A R r A F 7 A C 7 w T 7 Q B A 6 D E + A 3 c A F c B t f B H b h 6 u s B z 0 A v e g n 4 E Q U g I H W E g x o g F Y o s 4 I + 6 I D x K I h C H R S D y S i q Q j W Y g E U S C z k Y V I O b I S q U I 2 I 3 X I L 8 g h 5 A R y D m l H b i M P k G 7 k F f I R x V A a a o C a o X b o K N Q H Z a N R a C I 6 G c 1 C p 6 N F a A m 6 F K 1 E a 9 F d a C N 6 A r 2 A X k c 70 O d o H w Y w L Y y J W W I u m A / G w W K x N C w T k 2 F z s T K s A q v F G r A W + D 9 f x T q w H u w D T s Q Z O A t 3 g S s 4 E k / C + f h 0 f C 6 + B K / C d + C N + C n 8 K v 4 A 78 W / E O g E U 4 I z w Y / A J U w g Z B F m E E o J F Y R t h I O E 0 / B p 6 i K 8 J R K J T K I 90 R s + j a n E b O I s 4 h L i e u I e 4 n F i O 7 G T 2 E c i k Y x J z q Q A U i y J R 8 o n l Z L W k X a R j p G u k L p I 78 l a Z A u y O z m c n E a W k I v J F e S d 5 K P k K + Q n 5 H 6 K L s W W 4 k e J p Q g o M y n L K F s p L Z R L l C 5 K P 1 W P a k 8 N o C Z S s 6 k L q J X U B u p p 6 l 3 q a y 0 t L S s t X 63 x W m K t + V q V W n u 1 z m o 90 P p A 0 6 c 50 T i 0 S T Q F b S l t O + 0 47 T b t N Z 1 O t 6 M H 0 9 P o + f S l 9 D r 6 S f p 9 + n t t h v Z I b a 62 Q H u e d r V 2 o / Y V 7 R c 6 F B 1 b H b b O F J 0 i n Q q d / T q X d H p 0 K b p 2 u h x d n u 5 c 3 W r d Q 7 o 3 d f v 0 G H p u e r F 6 e X p L 9 H b q n d N 7 q k / S t 9 M P 0 x f o l + h v 0 T + p 38 n A G N Y M D o P P W M j Y y j j N 6 D I g G t g b c A 2 y D c o N d h u 0 G f Q a 6 h u O N k w 2 L D S s N j x i 2 M H E m H Z M L j O X u Y y 5 j 3 m D + X G Y 2 T D 2 M O G w x c M a h l 0 Z 9 s 5 o u F G w k d C o z G i P 0 X W j j 8 Y s 4 z D j H O M V x k 3 G 90 x w E y e T 8 S Y z T D a Y n D b p G W 4 w 3 H 84 f 3 j Z 8 H 3 D / z B F T Z 1 M 401 n m W 4 x v W j a Z 2 Z u F m E m N V t n d t K s x 5 x p H m y e b b 7 a / K h 5 t w X D I t B C b L H a 4 p j F M 5 Y h i 83 K Z V W y T r F 6 L U 0 t I y 0 V l p s t 2 y z 7 r e y t k q y K r f Z Y 3 b O m W v t Y Z 1 q v t m 617 r W x s B l n M 9 u m 3 u Y P W 4 q t j 63 I d q 3 t G d t 3 d v Z 2 K X Y / 2 j X Z P b U 3 s u f a F 9 n X 2991 o D s E O U x 3 q H W 45 k h 0 9 H H M c V z v e N k J d f J 0 E j l V O 11 y R p 29 n M X O 653 b R x B G + I 6 Q j K g d c d O F 5 s J 2 K X C p d 3 k w k j k y e m T x y K a R L 0 b Z j E o b t W L U m V F f X D 1 d c 123 u t 5 x 0 3 c b 61 b s 1 u L 2 y t 3 J n e 9e7 X 7 N g + 4 R 7 j H P o 9 n j 5 W j n 0 c L R G 0 b f 8 m R 4 j v P 80 b P V 87 O X t 5 f M q 8 G r 29 v G O 927 x v u m j 4 F P n M 8 S n 7 O + B N 8 Q 33 m + h 30 / + H n 55 f v t 8 / v L 38 U / x 3 + n / 9 M x 9 m O E Y 7 a O 6 Q y w C u A F b A 7 o C G Q F p g d u C u w I s g z i B d U G P Q y 2 D h Y E b w t + w n Z k Z 7 N 3 s V + E u I b I Q g 6 G v O P 4 c e Z w j o d i o R G h Z a F t Y f p h S W F V Y f f D r c K z w u v D e y M 8 I 2 Z F H I 8 k R E Z F r o i 8 y T X j 8 r l 13 N 6 x 3 m P n j D 0 V R Y t K i K q K e h j t F C 2 L b h m H j h s 7 b t W 4 u z G 2 M Z K Y p l g Q y 41 d F X s v z j 5 u e t y v 44 n j 48 Z X j 38 c 7 x Y / O / 5 M A i N h a s L O h L e J I Y n L E u 8 k O S Q p k l q T d Z I n J d c l v 0 s J T V m Z 0 j F h 1 I Q 5 E y 6 k m q S K U 5 v T S G n J a d v S + i a G T V w z s W u S 56 T S S T c m 208 u n H x u i s m U 3 C l H p u p M 5 U 3 d n 0 5 I T 0 n f m f 6 J F 8 u r 5 f V l c D N q M n r 5 H P 5 a / n N B s G C 1 o F s Y I F w p f J I Z k L k y 82 l W Q N a q r G 5 R k K h C 1 C P m i K v E L 7 M j s z d m v 8 u J z d m e M 5 C b k r s n j 5 y X n n d I o i / J k Z y a Z j 6 t c F q 71 F l a K u 2 Y 7 j d 9 z f R e W Z R s m x y R T 5 Y 35 x v A D / a L C g f F D 4 o H B Y E F 1 Q X v Z y T P 2 F + o V y g p v D j T a e b i m U + K w o t + n o X P 4 s 9 q n W 0 5e8 H s B 3 P Y c z b P R e Z m z G 2 d Z z 2 v Z F 7 X / I j 5 O x Z Q F + Q s + L 3 Y t X h l 8 Z u F K Q t b S s x K 5 p d 0 / h D x Q 32 p d q m s 9 O a P / j 9 u X I Q v E i 9 q W + y x e N 3 i L 2 W C s v P l r u U V 5 Z + W 8 J e c / 8 n t p 8 q f B p Z m L m 1 b 5 r V s w 3 L i c s n y G y u C V u x Y q b e y a G X n q n G r G l e z V p e t f r N m 6 p p z F a M r N q 6 l r l W s 7 a i M r m x e Z 7 N u + b p P V a K q 69 U h 1 X t q T G s W 17 x b L 1 h / Z U P w h o a N Z h v L N 37 c J N 50 a 3 P E 5 s Z a u 9 q K L c Q t B V s e b 0 3 e e u Z n n 5 / r t p l s K 9 / 2 e b t k e 8 e O + B 2 n 6 r z r 6 n a a 7 l x W j 9 Y r 6 r t 3 T d p 1 e X f o 7 u Y G l 4 b N e 5 h 7 y v e C v Y q 9 z 35 J / + X G v q h 9 r f t 99 j c c s D 1 Q c 5 B x s K w R a Z z Z 2 N s k a u p o T m 1 u P z T 2 U G u L f 8 v B X 0 f + u v 2 w 5 e H q I 4 Z H l h 2 l H i 0 5 O n C s 6 F j f c e n x n h N Z J z p b p 7 b e O T n h 5 L V T 40 + 1 n Y 46 f f a 38 N 9 O n m G f O X Y 24 O z h c 37 n D p 33 O d 90 w e t C 40 X P i w d / 9 / z 9 Y J t X W + M l 70 v N l 30 v t 7 S P a T 96 J e j K i a u h V 3 + 7 x r 124 X r M 9 f Y b S T d u 3 Z x 0 s + O W 4 N b T 27 m 3 X / 5 R 8 E f / n f l 3 C X f L 7 u n e q 7 h v e r / 2 X 47 / 2 t P h 1 X H k Q e i D i w 8 T H t 7 p 5 H c + f y R / 9 K m r 5 D H 9 c c U T i y d 1 T 92 f H u 4 O 7778 b O K z r u f S 5 / 0 9 p X / q / V n z w u H F g b + C / 7 r Y O 6 G 366 X s 5 c C r J a + N X 29 / M / p N a 19 c 3 / 23 e W / 735 W 9 N 36 / 44 P P h z M f U z 4 + 6 Z / x i f S p 8 r P j 55 Y v U V / u D u Q N D E h 5 M p
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1561366801" ,
"to_ids" : false ,
"type" : "attachment" ,
"uuid" : "5d1090bf-b54c-4508-b9ae-f19b950d210f" ,
"value" : "Screenshot 2019-06-24 at 10.58.10.png"
} ,
{
"category" : "External analysis" ,
"comment" : "" ,
"data" : " i V B O R w 0 K G g o A A A A N S U h E U g A A A + w A A A N t C A Y A A A A K N f H 1 A A A K w m l D Q 1 B J Q 0 M g U H J v Z m l s Z Q A A S I m V l w d U k 9 k S g O //pzdaINIJvQlSBAJICT106WAjJIGEEmNCELAjiytYEREBRdEFEQXXAogdC7ZFsQDWDbKIqKtYEBWV9wOPsPveee+dN+fMuV8mc2fm3nPnnPkBoODZIlE6rARAhjBTHOHvRY+LT6Dj+gAWUAAOGAFDNkciYoaHBwNEpta/y6cuAI2vd63GY/37//9VlLk8CQcAKBzhJK6Ek4HwcUTfcETiTABQ+xG74dJM0ThfRVhVjBSI8ONxTpnkoXFOmmA0esInKsIbYXUA8GQ2W5wCANkIsdOzOClIHLIPwjZCrkCIMPIbuHP4bC7CSF4wMyNj8TjLEDZL+kuclL/FTJLHZLNT5Dx5lgnB+wgkonR2zv95Hf9bMtKlUzlMECXzxQERyEpD7qwnbXGQnIVJoWFTLOBO+E8wXxoQPcUciXfCFHPZPkHyvemhwVOcLPBjyeNksqKmmCfxjZxi8eIIea5ksTdzitni6bzStGi5nc9jyePn8qNipzhLEBM6xZK0yKBpH2+5XSyNkNfPE/p7Tef1k589Q/KX8wpY8r2Z/KgA+dnZ0/XzhMzpmJI4eW1cno/vtE+03F+U6SXPJUoPl/vz0v3ldklWpHxvJvIgp/eGy+8wlR0YPsUgHASAYEAHXsAHhAB7YAecgA0Ambzs8TcKvBeLcsSCFH4mnYl0GY/OEnKsZ9LtbGydARjv2ckn8aFnohchGn7aJnoLAANRKHnalqQFwKmFSPttnbYZ3gCAdAyA844cqThr0jbeTgADiEARqAINoAsMgRmwQmpzBK7AE/iCQBAGokA8WAg4gA8ygBgsBcvBGlAAisAWsB2UgyqwDxwAh8FR0AxOgwvgCrgBboP74BGQgX7wCgyBT2AUgiAcRIGokAakBxlDlpAdxIDcIV8oGIqA4qFEKAUSQlJoObQWKoKKoXJoL1QH/QqdhC5A16BO6AHUCw1C76GvMAomw6qwDmwCz4IZMBMOgqPgBXAKvATOhfPhTXAZXA0fgpvgC/AN+D4sg1/BwyiAIqFoKH2UFYqB8kaFoRJQySgxaiWqEFWKqkY1oFpR7ai7KBnqNeoLGoumouloK7QrOgAdjeagl6BXojegy9EH0E3oS+i76F70EPoHhoLRxlhiXDAsTBwmBbMUU4ApxdRgTmAuY+5j+jGfsFgsDWuKdcIGYOOxqdhl2A3YXdhG7HlsJ7YPO4zD4TRwljg3XBiOjcvEFeB24g7hzuHu4Ppxn/EkvB7eDu+HT8AL8Xn4UvxB/Fn8HfwAfpSgRDAmuBDCCFxCDmEzYT+hlXCL0E8YJSoTTYluxChiKnENsYzYQLxMfEz8QCKRDEjOpLkkAWk1qYx0hHSV1Ev6QlYhW5C9yfPJUvImci35PPkB+QOFQjGheFISKJmUTZQ6ykXKU8pnBaqCtQJLgauwSqFCoUnhjsIbRYKisSJTcaFirmKp4jHFW4qvlQhKJkreSmyllUoVSieVupWGlanKtsphyhnKG5QPKl9TfqGCUzFR8VXhquSr7FO5qNJHRVENqd5UDnUtdT/1MrVfFatqqspSTVUtUj2s2qE6pKaiNlstRi1brULtjJqMhqKZ0Fi0dNpm2lFaF+3rDJ0ZzBm8GetnNMy4M2NEXUvdU52nXqjeqH5f/asGXcNXI01jq0azxhNNtKaF5lzNpZq7NS9rvtZS1XLV4mgVah3VeqgNa1toR2gv096nfVN7WEdXx19HpLNT56LOa12arqduqm6J7lndQT2qnrueQK9E75zeS7oanUlPp5fRL9GH9LX1A/Sl+nv1O/RHDUwNog3yDBoNnhgSDRmGyYYlhm2GQ0Z6RiFGy43qjR4aE4wZxnzjHcbtxiMmpiaxJutMmk1emKqbskxzTetNH5tRzDzMlphVm90zx5ozzNPMd5nftoAtHCz4FhUWtyxhS0dLgeUuy86ZmJnOM4Uzq2d2W5GtmFZZVvVWvdY062DrPOtm6zezjGYlzNo6q33WDxsHm3Sb/TaPbFVsA23zbFtt39tZ2HHsKuzu2VPs/exX2bfYv5ttOZs3e/fsHgeqQ4jDOoc2h++OTo5ixwbHQScjp0SnSqduhiojnLGBcdUZ4+zlvMr5tPMXF0eXTJejLm9drVzTXA+6vphjOoc3Z/+cPjcDN7bbXjeZO9090X2Pu8xD34PtUe3xzNPQk+tZ4znANGemMg8x33jZeIm9TniNeLt4r/A+74Py8fcp9OnwVfGN9i33fepn4JfiV+835O/gv8z/fAAmIChga0A3S4fFYdWxhgKdAlcEXgoiB0UGlQc9C7YIFge3hsAhgSHbQh6HGocKQ5vDQBgrbFvYk3DT8CXhp+Zi54bPrZj7PMI2YnlEeyQ1clHkwchPUV5Rm6MeRZtFS6PbYhRj5sfUxYzE+sQWx8riZsWtiLsRrxkviG9JwCXEJNQkDM/znbd9Xv98h/kF87sWmC7IXnBtoebC9IVnFikuYi86lohJjE08mPiNHcauZg8nsZIqk4Y43pwdnFdcT24Jd5DnxivmDSS7JRcnv0hxS9mWMsj34JfyXwu8BeWCd6kBqVWpI2lhabVpY+mx6Y0Z+IzEjJNCFWGa8NJi3cXZiztFlqICkWyJy5LtS4bEQeIaCSRZIGnJVEWGo5tSM+lP0t4s96yKrM9LY5Yey1bOFmbfzLHIWZ8zkOuX+8sy9DLOsrbl+svXLO9dwVyxdyW0Mmll2yrDVfmr+lf7rz6whrgmbc1veTZ5xXkf18aubc3XyV+d3/eT/0/1BQoF4oLuda7rqn5G/yz4uWO9/fqd638UcguvF9kUlRZ928DZcH2j7cayjWObkjd1bHbcvHsLdotwS9dWj60HipWLc4v7toVsayqhlxSWfNy+aPu10tmlVTuIO6Q7ZGXBZS07jXZu2fmtnF9+v8KrorFSu3J95cgu7q47uz13N1TpVBVVfd0j2NOz139vU7VJdek+7L6sfc/3x+xv/4XxS12NZk1RzfdaYa3sQMSBS3VOdXUHtQ9urofrpfWDh+Yfun3Y53BLg1XD3kZaY9ERcER65OWvib92HQ062naMcazhuPHxyhPUE4VNUFNO01Azv1nWEt/SeTLwZFura+uJU9anak/rn644o3Zm81ni2fyzY+dyzw2fF51/fSHlQl/borZHF+Mu3rs091LH5aDLV6/4XbnYzmw/d9Xt6ulrLtdOXmdcb77heKPppsPNE785/Haiw7Gj6ZbTrZbbzrdbO+d0nr3jcefCXZ+7V+6x7t24H3q/syu6q6d7fresh9vz4kH6g3cPsx6OPlr9GPO48InSk9Kn2k+rfzf/vVHmKDvT69N781nks0d9nL5Xf0j++Naf/5zyvHRAb6Duhd2L04N+g7dfznvZ/0r0avR1wZ/Kf1a+MXtz/K3n25tDcUP978Tvxt5v+KDxofbj7I9tw+HDTz9lfBodKfys8fnAF8aX9q+xXwdGl37DfSv7bv699UfQj8djGWNjIraYPTEKoBCFk5MBeF8LACUeAOptAIjzJmfqCYEmvwMmCPwnnpy7J8QRgNrVAER7AjA+ou1BVmNEyQiHI2uUJ4Dt7eX6T5Ek29tNxiI1I6NJ6djYB2R+xJkD8L17bGy0eWzsew1S7ENkjvk0OcuPCxMJih9ANuHvbRwB/yr/AEDBD6MC23hEAAABnmlUWHRYTUw6Y29tLmFkb2JlLnhtcAAAAAAAPHg6eG1wbWV0YSB4bWxuczp4PSJhZG9iZTpuczptZXRhLyIgeDp4bXB0az0iWE1QIENvcmUgNS40LjAiPgogICA8cmRmOlJERiB4bWxuczpyZGY9Imh0dHA6Ly93d3cudzMub3JnLzE5OTkvMDIvMjItcmRmLXN5bnRheC1ucyMiPgogICAgICA8cmRmOkRlc2NyaXB0aW9uIHJkZjphYm91dD0iIgogICAgICAgICAgICB4bWxuczpleGlmPSJodHRwOi8vbnMuYWRvYmUuY29tL2V4aWYvMS4wLyI+CiAgICAgIC
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1561367259" ,
"to_ids" : false ,
"type" : "attachment" ,
"uuid" : "5d109146-9ef4-4c7c-a4e5-1398950d210f" ,
"value" : "Screenshot 2019-06-24 at 10.52.49.png"
} ,
{
"category" : "Network activity" ,
"comment" : "C&C" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1561367184" ,
"to_ids" : true ,
"type" : "hostname" ,
"uuid" : "5d109290-c340-41bc-a519-225e950d210f" ,
"value" : "tikonainternetservices.co.in"
} ,
{
"category" : "Network activity" ,
"comment" : "C&C" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1561367193" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "5d109299-8430-4cfa-ae74-225e950d210f" ,
"value" : "http://tikonainternetservices.co.in/assets/img/png/evif/fre.php"
} ,
{
"category" : "Network activity" ,
"comment" : "C&C" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1561367200" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "5d1092a0-eabc-45ed-b86b-225e950d210f" ,
"value" : "103.195.185.115"
}
] ,
"Object" : [
{
"comment" : "stage 2 " ,
"deleted" : false ,
"description" : "File object describing a file with meta-information" ,
"meta-category" : "file" ,
"name" : "file" ,
"template_uuid" : "688c46fb-5edb-40a3-8273-1af7923e2215" ,
"template_version" : "17" ,
"timestamp" : "1561369239" ,
"uuid" : "5d109035-0558-4547-bb37-4b1d950d210f" ,
"ObjectReference" : [
{
"comment" : "" ,
"object_uuid" : "5d109035-0558-4547-bb37-4b1d950d210f" ,
"referenced_uuid" : "82e82c45-cee3-4d0b-bcd5-445021615dcf" ,
"relationship_type" : "analysed-with" ,
"timestamp" : "1561369295" ,
"uuid" : "5d109acf-9f70-4c24-a335-be4f950d210f"
}
] ,
"Attribute" : [
{
"category" : "Payload delivery" ,
"comment" : "" ,
"data" : " U E s D B B Q A C Q A I A A t H 2E4 U d 94 G j r k C A A C g D Q A g A B w A O D k 4 O T Y 3 M m R i N G Q y O D N m N m M 4 Z T V i O T d l Z G E 0 M j Z l Z j R V V A k A A z W Q E F 0 1 k B B d d X g L A A E E I Q A A A A Q h A A A A n u p 8 H B H D i s 8 + y U n L d 4 o k / P Y R R X t 8 j T A T p V t Z S H q e b A y Z F P f W e A t A 0 D W I u C C x 2 C i x W s M d 4 g 1 a s P j o D z L Z / U r 0 O 48 N e / Q M N 9 S Y I 4 m j k I 0 k M + E u 7 M p L V d t k M v g 8 H r 3 J g B K / p C V z w L m 0 9 T s J q 0 T 84 Q 3 h O f q 4 i D 6 Z 6 d e R q j w l s l 6 i z x j 2 e E M F A m Q e M e H Y o V + V j p W u F K 11 A c B 3 C k J g 2 X x r f o H 34 q I n j h U a r c p Y X a L F f F 3 n e U M L P M H H T p N 5 B / B 9 f x S y a w f A R b b l Z / X e 0 c 1 Y a 0 k v C K 1e14 f z C Q u V T Y / x k 97 I 48 v j q r 2 u E 3 Y V Y h X O C x R r r C O p O f a X N A d g w W C A 7 i C G s x k m Z K V + 6 l y t E o K j g w 5 n J T Y e m F u d a M k C s Z z s 8 F G F G 65 o D D 7 P J j a B I C 6 e J X 2 U b n m M 5 p W s W + J s a 7 G v k k I r 1 A E u J R Q v m L r s Y H 5 W A N 7 q i k X 9 P I j b 1 W b O J S X O C B s / x n 26 l H I b k s d L z T 2 J f b K p p 9 Q d U f / G / K m 0 q Y r l v f S d x H B g H E J V 2 C Y T c y m w a D B M s J L c E I w Z K n L 9 O U W J a d F U b t 3 X F h l K i x g y T L L h K O Y Z u / L P J y U H 26 O L 9 R m Q y p V k P L c + k 4 m t u V V n + u j I K / J J S d 0 L y R b L 9 Q d B b C m X m H u 20 L W 2 C B r N L n T j i A q y c A S d t I k W h r o J j 9 G c F / 9 F B P 4 J v Z g h l K j s D / F 52 L 1 d Y K U e E d I s W M S Q s 2 + U G c o F S y 6 b n I 2 + m v L n s t 700 j J 5 / G v L h P N d m N o I H s 6 H a C i g i W f W c / x E o f 336 I h T y b f i a d l W 4 X d V V D a V 0 w J e j q u E c C c N I b B P 7 Y 5 b k 1 I E e 8 i 0 h 8 r a H E s t y 8 d b o o a u M a U 8 B n r J Z w o K f / 2 H B z n 81 r t m G r P P 2 V J s O L m q 4 F m 6 y i E A O d U X 0 P A n T Y k Q A t K I 9 A D W P G u I u n b I x T b u 94 W 6 e b D Z b H X S G a 7 C N + j l J Y c 0 I Z / 40 C p v 15 L R Z t j G Q 3 r O D q x 5 Z F u x D v B T h U e 3 z M q Q l / D m A W 8 w J I Z 39 Z g 7 M L m Q M c 60 k r O x 83 P W 11 f r T b y F H F R J B X f Z z j h h h I H O t P F U t h e 7 T E 53 c c H u 6 H / 99 X U 8 a 8 Z d m E 8 D E i 1 P H Q m U Z n Y 5 h X 8 D 9 s r s m Y Z O 0e2 M J 85 q 3 j B a E s l s U m W n M u Y Q w O j 3 r f 74 h h U 661 U z f i x T E 24 y X l V R U d E C f e s d E m u x G B f T 9 w e N f s I G U k u Y y s P L P T 428 s i X B T c + Q 9 c y i m Y I 75 N T 4 w Y b o t w 1 Z 3 P J M 5 p K 4 L + e s 4 s 9 w t 3 F O t I w A N S x L X p g g P k w r C c 7 i y Z + V 6 W R U V w 48 / 8 P H i L W 5 d c q N 5 e j 6 W p m b E o U z f R K I V W Y 8 f l l x 1 C g O o a 2 n 8 x 4 J M P m h Z Z g 9 S h q 12 c E i + //IDPGdyJ4WKuFsceR6RfRXNFMC04o2BilrvrW/kJpQPKOoo2uwtTNUGa6MIXQwDjOYJhBfQhgVonaZN8TxDT0v/DMRsbEk+hgle6XfhO25ZHUeyY7P1uevC+fSsJ2htuiEg22ljCe+s13S4WctYvM//6ZOv1hFi4+BjdvIFufBoAq4N3kUT1ql8A+zTK/ohanbLwvPyHVb9m/zaS1Z+kBXZ51Jp57lUI3otMyiIQ5YouwiUWbk5lr82YwPEAVPwQdy+YcDNhFJKqSlJFa5utN40vZCsaAUVXtSIzqTf37SaMAOV8rzzl4LS/NB1SL4KgSCS75EHgzGpGFXh9wWzGmT860nbFz4igarMAjLAaN+7hKMVPxT/EEyaGH090hlC6cvSLjqgI9ddCwy4z6BBeFfocHNIdorYg4yuVXPCMTslL+uNqFA7IrCCsYd8l55/8H2vQFSc80YVfgtfZKtlqYEZiCZB5yM2yM6PGqx0KA+ZphR5iGmWNjwFPdVSKTS4kRFjVedLAtZc+meMRZxp4ZWMqq6DhmJD4p5cA/Aue1fv+9E+aWTjgHsn4VHYXPyi9yEe9o7MWbKves8nL6cEf4XlQ30+1ezos29lLid1r63+QIpVeERfovNHwkRowVGRM7sUkQgMLdGcGsyCOUO3KJSimymsoJ3qkcDo26e1SEHeTMkJRwItLC97mwMK9+vf02AtRjkqXSNKAYZeq1gEHwSp/9Gkq1M81j2pHheT0cWJV/j6eUqM5jWr7d/d8UE6KhC4wz88gLdpnjcRIbNwRoH0fk+Ew2j5/RsFpQJk01AkEcFVDc4lm0kuKlybxGqzoyNsYnIOcVZTrUYmPvp8oe5cmxOHMDB/os4XYk2MRzHdMJEYLXQzAxp9A08FoU/b2KeUbvvHrXOUhyIQaMa1I0E5lvhoufi8KGJrj+NfPSuu1UEQY3wkQFubeTBoQq9haVcZr7NAXaHO9zx12KkgSsxKiQNB90UrveV8wfc75USiGZbaNsboMTIrbsoq8HcdNn3hyByOxbUCXQZgHVB6BOftp23JOTJUU2YShg+PswdCmTJ3CX1Rx93Hlg74qqoNDlQSLieIOPoK/l5h0mJxRRNi9EQleFt/xr41ZTlikt68HWAfewi1qWw5raK4daLHZSFalB38jRGQFVdsKeYkZSvIiu3VurNL5xwHDqtyoHNigC9cI2Q/eO6yO+dZAQtg+YJt9ibms9riHxrxoamjuurGUGssVr1JdQDGsSaDW8YjBj7OAJ2vPdH4vg6mLdEDulCb0Sz79HRiICT+uATpjVUXBBivS6ceHnQ6GeUP067Xnxe7asXHAsFIxhNo5FtzuqPQ0G+8K/gnAxdycKeIkgueIIztjhbBzxfuQP1kTCDus2AYjTfDm/aQ5fYhslkUBd673oj6+lFBL7M7J7hz7kwfXa++vX3n7zTUJ+zEaqtR83cO13sPV/ZE6V7sH8qZdgeiPJFgrsz2F+Vtnmcyklo8NSEiLfoSDPsgcfDkjCcFjrSNRtUCm/oyt426tch1HLpOPivPNxW3oxR1Kc/O8f5aOYuFOzYl1Hcp2kTqpoKiwKoIGYAsdO7RE6s2hKdeg8GD8czXRGsdZUJPm9BjsFhQKR9nBlsv9Yc2FtlS9mKu4Rzl6HBG1vZ5YasikmxgAlah9MWAOfV/7iIeAuJHfKcuKFXiRHQoOjIj3cqqjUZleU/1V3YKzBuFy2qx9Ac+NIxbH4LEBXszwlh8yG4mr43/T6HWaSzIifha3tC0evV5HrrVCdXsOL+s6CXdB1NwzuZbaKIG4/7wKU6WSIDD9byAMqlU5vSAljY+SJzwRtD2gWYgEcBD4qYE5a2iXnSwSdFKr3HPHgaCez8CQ4Hf1k6U1AcDbp/C+O86Ifm9L1/FOiyBoeSvCzd+DFTgT3YTCmjJv1G3agBm3trb2E9E/kBBa9GubhhNk7611LSk3pD+33t9nFzWnbL5JUzzqBryGod4S3WHTrdlJiyqJ/xjbAldaLihA70g0evXmZvKl1w0mDqZ33+T3bgbXjQ2WW7cbH7vhjyK8uG1ooE/q7u0EjQnKC1Ek5/z3yy07D1SvALvowAvfzIiGJBww5hf5rr4fXDUgJgqz/66JEzeY7nEYOV5ihclw2FpspP+cR5ulCVHNGKwcuiiTugu+sO96W2yLx1Pb6SkamZ6Myus2L0JHESQ6wzD4d1e0e0JccksQswTbJBlkyaMmmP9ui5+xHvu7NbGrY7LUneEr2bMZeEd1KqwYtROmHzqP97lYrus4+BQ1smGxoXYSP4BH705TeE//L4TVt2Gra4zn4GCe2MX8CvvHa8R/JRpJTxogzSE71AjOWnBY1hHQ0kRl1Kzt7VmIzEwNUY92p/9LKIBPDZzCOQ2JZMH3Z/JkIKkLWp/lsUSoYl8ZEhg2S6xR59K/l5e8mWFts1gCohZI+OlzWqWM8N59nH43A6qfJY2oMQpqRVKq29SwOT9Zcj/tsTUPju6oL+dIXchkF/QGHUui9KdPeY/yG/f69b3akMt/T5oi+10TlLcVxe+H2q7LPbKDRzfN/hqYpu2WuUZF541dvUzpA3oH0xSIvSJyuIsxbyDSFDqz5h37b//bBJaNo4XwoEOKGLV5mjpqntfOaKCGCcd74gczD/BXYWo6bDXhtIT
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "malware-sample" ,
"timestamp" : "1561366582" ,
"to_ids" : true ,
"type" : "malware-sample" ,
"uuid" : "5d109036-2cb4-40cb-8f1e-4725950d210f" ,
"value" : "vbc.exe|8989672db4d283f6c8e5b97eda426ef4"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "filename" ,
"timestamp" : "1561366584" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "5d109038-9e54-4fdd-bb98-4c4f950d210f" ,
"value" : "vbc.exe"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "md5" ,
"timestamp" : "1561366586" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "5d10903a-59b4-4ffd-9ebb-474f950d210f" ,
"value" : "8989672db4d283f6c8e5b97eda426ef4"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha1" ,
"timestamp" : "1561366588" ,
"to_ids" : true ,
"type" : "sha1" ,
"uuid" : "5d10903c-48a8-45be-ba40-4813950d210f" ,
"value" : "7cae4abd0b632e822d3163bf62435e658cab76c4"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha256" ,
"timestamp" : "1561366589" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "5d10903d-7b1c-48f9-8529-457d950d210f" ,
"value" : "c6b68af5a397b24d5573bbcbb6abd8ffe45550e428f2649e7ce99f6ae15148d3"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "size-in-bytes" ,
"timestamp" : "1561366589" ,
"to_ids" : false ,
"type" : "size-in-bytes" ,
"uuid" : "5d10903d-f780-4b4a-a082-428f950d210f" ,
"value" : "892928"
}
]
} ,
{
"comment" : "contains CVE-2017-11882 exploit" ,
"deleted" : false ,
"description" : "File object describing a file with meta-information" ,
"meta-category" : "file" ,
"name" : "file" ,
"template_uuid" : "688c46fb-5edb-40a3-8273-1af7923e2215" ,
"template_version" : "17" ,
"timestamp" : "1561369720" ,
"uuid" : "5d109086-8630-41fd-be51-4867950d210f" ,
"ObjectReference" : [
{
"comment" : "" ,
"object_uuid" : "5d109086-8630-41fd-be51-4867950d210f" ,
"referenced_uuid" : "06a06fa2-3b56-4455-89e0-8abfa77ffac9" ,
"relationship_type" : "analysed-with" ,
"timestamp" : "1561369295" ,
"uuid" : "5d109acf-a980-4629-9635-be4f950d210f"
} ,
{
"comment" : "" ,
"object_uuid" : "5d109086-8630-41fd-be51-4867950d210f" ,
"referenced_uuid" : "5d109bff-e5cc-4732-8eac-4dcd950d210f" ,
"relationship_type" : "uses" ,
"timestamp" : "1561369720" ,
"uuid" : "5d109c78-9dd0-40ec-b680-1398950d210f"
}
] ,
"Attribute" : [
{
"category" : "Payload delivery" ,
"comment" : "" ,
"data" : " U E s D B B Q A C Q A I A D V H 2E65 u o S W V l M B A J h 9 A Q A g A B w A N 2 R k Y j F k O W M y N T Q 4 N 2 Q 4 N W N i N j g 3 N j g y Y j h h N G Z i N 2 R V V A k A A 4 a Q E F 2 G k B B d d X g L A A E E I Q A A A A Q h A A A A h P r e k x x 1 P g w H 3 n 9 W / b 55 O O f h q e 3 i / j I q F / 5 x 1 + Z 0 i K 8 x j r M c 5 i L h c 0 G Q F u s Q f M b e A V / U n 0 q + c E F 1 L U 12 g y 2 C O / k U I c w y X d 81 g B w E 7 r V p + F p b 8 k F f 2 v B K 0 z S N 2 w v R K t 4 P u 9 T z b s P x 76 U V Q f t 7 J u t 0 0 v N a I K a Y k 6 q r s D T v p 5 G Z G t + 0 H F Z I / f T q d Q h 7 c u w r w m Y D E l X 48 e R v 7 R D x q J y q U A h i y f I h 8 N Y x l g + J m V l q V R c b j r z 9 U u K + b 57 G X d 6 E R t I Z o 52 H M Z 7 k J u k y j J l a + X l 4 K n V U J F n J V B 6 C N i 721 L G I R v k z A F v v O P 3 b s y A 2 M f 1 d f J G / r K W j M d k j a Z y z K b R H R F v 6 u S D H 8 M q m N 7 v b C j S e V p L v d M x D s b r K 5 R 2 Y j Y 2 u d l o V Y n b n / h k 9 B n K 2 r q n y M p 1 O e I C 59 K A Q W O X P 4 H d K U C i U + x L v 6 K l + V R N 8 r s 0 k Q t S w f w G Y c S p v 2 + g Q 55 D d j f D W m t e D 3 a 2 G x W 1 i U R h d V I 4 M S j w 7 D 3 y y 1 S R y N 1 R M q t V F Q G Q X L v O u a x 1 g 6 n P G N w j 4 B L z G B X U w N 3 n l c C E R L 5 U s m 3 L v 8 T V P V M K k y I t O F 9 j I o c S W R W 4 J Q U 9 o s X x Q M q Q C o e I w Y 0 9 I A F / a p s W E P H W z X H Q I c l q r E f m k r M E S H C K t t / R 6 M h D i d a 16 k I l c K M 1 p b t + t 6 D U r B V I O c P s w O M h Y P v s V u r Q k 3 K i Z T Y 4 c P m Q 6 p g n 1 S 80 + J P 9 s l O Q Z z K h B + n v 3 z y m n 0 T 7 a i 8 j B A p s h z n F W q Q z R J f 78 v a f n V + m S g i v y V s o 78 M G u W Y m 9 q E s c d e v 4 M g Q z 8 N W T 7 D F c L X l y 9 M H Z 7 Z Y w t R 1 s f a R G y e k o k 4 z w y m j w c t 9 v G k w Y z h e T V g 4 K u m Z o / 8 N z n B B r u k I 7 D d q R P F y 6 n 42 H z A q U e 2 W 6 V I p 1E5 c I 5 J r y E h 7 t z i 9 y T R S m m O c w o C K y y a Q F k a l y j x l 6 f p 4 j e B B I e B m D 7 V l J o p c X 5 R t T c f M N n S N M b 47 C x d + w w P M o 7 o S 60 p C X c 3 s d o j N o W F d n P 0 N + M v c p z j o u O k e J c H R S Z C 8 + a E 0 z C c E O i y v v / a f I / 9 O r r 5 n J w D 8 J 6 n y d e M b s 8 o 3 L L W r 7 J o a K 9 J I q C W L J t j Q R R + n g k q y 9 O f p O w V x O J 8 e f g Z B M V 81 J Y 2 + y j 6 o Y 3 J i N N O 0 637 d Z j E Q b H i J Y + t j s s I 3 w + T 5 Z t i m D J P j x 1 b 3 z j o D G I 8 r R 9 m I Y r i 2 Q 4 z g 2 L U 7 F y g l D l 7 t A t c 33 r K 15 n F g g r n T c 8 h 8 p D 3 M h V H L j Y o F F H 3 H S F 0 l N L v + U k b i 1 I G F t X l 3 I i L e 1 s d M o u w S V K u P S Q f Z 8 Z B r F n k x C L Q a 0 O y R p q q M h 0 Q R W l 9 f U + g 6 z F i e V O K R y Q k h Z F N 5 o y O F N y p f D 24 / U f L z d u q v 0 4 l s Y 3 d v 5 X 1 Z P n W v N N C e Z B w d H g J F 7 U h T K L Q A q n I t m 28 T S B W b / t m F y r p Q / N 4 q b / k s k 9 X k w 5 y J U n z I D N U X c G J D B P p f Z V F 8 R E S r B Z P e 4 j + W T 0 C B O N 7 g v 55 s f e p p B h j Z O w V 4 l w A s E R o T 9 b g R 9 b m T 644 y i K N B 2 p E f w z 7 x U / z A A B Y x o 4 i h m Q 9 a s b W / f b z j g 3 T U J p o 8 T E f k F r D q o 2 Y F B z Q m u F q t L O B L R y I / F T S u 3 A b Z f 5 B z t V x r B Q 9535 L k r G b m J Q z O q c 4 C 22 z Y q A e K J S C M z b m g 5 i C p X h o t 9 b 3 L w t r 0 27 P V 4 O q W x g R a Z / + o I d Q F 8 r G A k Y 2 M 63 B t h s T J R b 6 v Z q 6 j B / 5 q h w D m T y 1 S e q u L d y 5 G G + b J U n T u H 69 M 5 v P R C 1 l 6 x 4 N 97 G / h B i o C y Z W j q F j I y / W u + + w h p 8 c e d O P 5 z X 8 v 4 Z H e v Z d Z I 0 u Q Z 0 O n G 1 r C 8 V g n l N v j m f i / C m I 7 W V w 3 I M / P x R A i V 2 C a f j V r 2 w v B / j 0 b i x s H B w r P 9 B x 0 h S H N i 5 l l C G 8 w 1 s q P 6 H W N v w K R D w v 2 n M o J b Z X o r P O r 73 a p 0E9 O L m I H V 7 w Y l X v z J q P s G M 9 K f U L f l q h e d J T y j J v d j e 6 e K 7 g S C j 0 4 / H S i h P y y s F a z y T u / k 6 X C 7 P 2 L P C x o m 3 S l w L B 0 34 G Q 1 N h M D R o 7 y w 7 l k l x Q Q i e a q e k C t L F y 7 w U K e y + N 6 N I 8 e C Y Z b 3 y t q 6 C F k 0 3 j E y I v p G z x M H q F 8 g D N Y f T a n 0 Q h t m R v R 0 L B T O b o 9 Z D L 1 q h N n 5 F u 8 R k k L s w H u d u / 0 1 l B n X H P w K x u Y Y e 96 A t R G r V L O r Z 1 M 1e8 b z s Y A W 69 E g E T w J U 0 T A q S J m p w r R 54 f i t w 3 Z a w g D p 91 R R e q T f u 7 y t n f v x Q 3 a t 3 u 8 O + f y L w 4 n k 2 s i H y j 7 f c k F r S g Q 1 h z 4 x y B c 78 / Q 89 m c M a O 80 U J H e a t M C 1 V 5 u 21 y A f A v V S 56 f 9 Y o F t k G n H Z 8 w 6 r w P g m j B d 65 E V U 916 + l D k j m X s e 8 b 5 N c i 3 O 5e6 z B e U Y 7 + L 59e9 P P T C h w 5 B X 6 f V U b q K 7 T D X C m A K + l E b g c W Q e 9 C 6 s D 40 O g d B p p m K G r Z k L W Y L p v a u k g K f n 0 f D r d l 9 o u u W 7 R q 4 a W 9 m f M N 2 Y v 72 c H L 2 P T 3 I m k F 3 c a U j i 9 Z n M f p i P F e X U 9 d l F 9 x W o m d 4 h Q 3 T a 8 I 7 f q p Y 4 g 7 g p x P t 841 K h C j E j B I / + w v e N f s 6 a a S y u G d P 2 X s 4 s S d B H d t 4 J 6 d y 8 l 2 c v a p J 73 m j g V U J S 2 H / k I f 6 h A h S t 5 E O I G F A H 1 r r a y y Y j S q O f k V s w K y F M o E m P Z f 0 0 a o J o A 8 P q p q e H I s 4 m H j G 4 V i g 0 6 l b n S e M R T q Z t W T K y m k b S C d a E H x r z v w M Z Y 5 C Z S X c y w S x k K f F F r t n l 2 z 2 y a 2 M Q o F 27 T q O 4 U h T M i q b Z E 156 E j S K t N m 1 + G + v C L X i D C a i a W 7 q L W F B c A q U s / w V 6 Q i 2 n N K h I F d o a H G k R F X 1 x Z S r d o t g L T N J 7 Q x T z j S o 7 o Y Q U / M G z C b W w d g c A R 73 B n M f W l X 7 G f V Q t z Q A 7 G O f L L W G s S u 235 N I x v 6 g a 1 y b w i N G G o r c J 0 v 0 s F G R r w d M Y J d u j d a 5 v D / G T H X 6 u S P T X S i S C T H H Q r r y p / o c I 4 O R K w E o I P i x 6 g V I H B 8 g k Y 4 P g o 5 o s Z 92 Y 4 i f I h W + A K / Y R B N O i P N 7 p S / H 7 P k H c 6 m G S z l o F x w 0 P 4 M X y w w u i 6 I 1 I n i E N g f I Y h 3 f A I h w 6 H w 6 H h U n D N h S a y U J 395 S h y L e O s Y l H i 7 F L B x X b M 8 z 11 P m z E 8 X A u a G 8 l x y A q P o e J A h T C L 8 i X T A J y Z s o A t D U W A a + n 7 v 5 b F V v t V o g t 0 I y n 6 L d c B 8 D n g P x y u r T S a I + y I 379 U v w W d 4 i p J A 5 a l 94 d / V g 8 + i F H v h w 6 o l b 7 f e A Z m U e 4 F 9 P W c / w t 2 i Y J f C 7 O i q D I y H j h 2 g 7 E C g H V b 6 F P t 7 N Z f u s d Z b X G 0 81 G p L C x R O F w z a r 3 G C r d V v l D T 4 T f 7 w 0 z i f m x j n S + d p W X N 8 x 43 i B b h 4 n o b J W Z l p f + Y d g V c R d B m q R p G I T h a K C w z D h G + Y 1 K h V 6 L d 8 A M T U s 37 S f n M x A R k d P 6 F 9 M J f l K I Q 1 Z c + 3 Y e J u a Y h M Z 9 G T V t 12 T / V e 4 + u v q h Q K Q o d 3 G T O Z 9 G V H 1 w T + + 5 V N b 2 c N V P o S 9 U W C 6 X 2 D b 0 K c C j d q Y 9 j 54 y l B F w p l P F J 2 r i m H X r y u S p y w q h z 7 m A H P a C x g 1 o f P s e a 8 S 5 C 8 B y j b / 0 D N W l V I 9 v e a Z j r h Q i D s t Q u v D m w U y S z 5 u r C t F q Y A o + P R 7 S V M b E / i P q z 9 m 4 D 7 I B 1 n a e S r r V C k Y e t H T 9 j R 0 o A a W q c X o V v X M / S J 9 q X c B l l k Y 9 v N 8 a J b U I g z / 5 z M s J Z b o 33 / p Z m X d 8 c A V p T 85 R C D 0 b 2 g n 6 N 6 S G 1 S Y U L G 4 d m 7 e p 3 G y S E P r X X J Q z I W y e q t 0 j 5 k s y Y h 9 k 6 j A C O S V d V f r o a D k 1 U p F H h K g v 0 R L O R S g v M 3 s m w A Z o z n l E y V + d 1 h H B Y O f c m 0 A t W i 1 U / y z S n S R I c D p / I y S n B L 3 P o 7 Z A Z M L r d k u u f D m B Q 88 P P Q t 3 R b A 9 B S j 4 j t T z h i 1 T x U i r I 5 F h I Q 8 m 1 j 98 N W o J H L L Y S w R 9 B r b g z 9 A u e i S 6 A L c 4 t S K R T g F r B m C w U F R A / G r z R J G Q 1 w Q C 5 u N h B 0 y E B j W + m 9 C 0 N r G O B H A p H E o O 5 K 4 f n x W Q q 4 t w w q k K p o B Y q F f I j Q B z B 7 x J b n x d o H B I v 41 D f N I n T V d s Z 6 W 0 7 s y G E Z 7 I k J H c E D m Z e Q n r f i U 2 R 3 B 8 v 5 K U h r E U I 3 q e W j D D h b x s q w 4 g 6 / W T R k L d p y B 7 l / 0 G u f X L m i M K t A Y e G m V B
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "malware-sample" ,
"timestamp" : "1561366664" ,
"to_ids" : true ,
"type" : "malware-sample" ,
"uuid" : "5d109088-d4e0-4f7e-9292-4e64950d210f" ,
"value" : "OFFER ANFORDERN (Universit\u00c3\u00a9 du Luxembourg) EUI894BU4633.xlsx|7ddb1d9c25487d85cb687682b8a4fb7d"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "filename" ,
"timestamp" : "1561366664" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "5d109088-c53c-4038-acd4-4850950d210f" ,
"value" : "OFFER ANFORDERN (Universit\u00c3\u00a9 du Luxembourg) EUI894BU4633.xlsx"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "md5" ,
"timestamp" : "1561366664" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "5d109088-c7c8-4a62-ae2b-4544950d210f" ,
"value" : "7ddb1d9c25487d85cb687682b8a4fb7d"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha1" ,
"timestamp" : "1561366665" ,
"to_ids" : true ,
"type" : "sha1" ,
"uuid" : "5d109089-1f30-491d-95a5-48b6950d210f" ,
"value" : "0117724817462bb8e09b5b507155eae32b878449"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha256" ,
"timestamp" : "1561366667" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "5d10908b-d3f0-4ff2-9185-4183950d210f" ,
"value" : "e5df9ce468a2510c86d8808083e5c3326385596fba864546491922b2ea9802df"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "size-in-bytes" ,
"timestamp" : "1561366667" ,
"to_ids" : false ,
"type" : "size-in-bytes" ,
"uuid" : "5d10908b-4340-42b8-b9ba-46f9950d210f" ,
"value" : "97688"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "VirusTotal report" ,
"meta-category" : "misc" ,
"name" : "virustotal-report" ,
"template_uuid" : "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4" ,
"template_version" : "2" ,
"timestamp" : "1561369251" ,
"uuid" : "82e82c45-cee3-4d0b-bcd5-445021615dcf" ,
"Attribute" : [
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "last-submission" ,
"timestamp" : "1561366589" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "2a229a87-b8e4-4cc7-831d-e26ef40f2638" ,
"value" : "2019-06-24T08:53:28"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "permalink" ,
"timestamp" : "1561366589" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "1e3e649c-40b2-4248-ace4-b1e4473b0994" ,
"value" : "https://www.virustotal.com/file/c6b68af5a397b24d5573bbcbb6abd8ffe45550e428f2649e7ce99f6ae15148d3/analysis/1561366408/"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "detection-ratio" ,
"timestamp" : "1561366589" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "51e91f86-4230-4d52-8ca7-e953ea7b751f" ,
"value" : "9/72"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "VirusTotal report" ,
"meta-category" : "misc" ,
"name" : "virustotal-report" ,
"template_uuid" : "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4" ,
"template_version" : "2" ,
"timestamp" : "1561369273" ,
"uuid" : "06a06fa2-3b56-4455-89e0-8abfa77ffac9" ,
"Attribute" : [
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "last-submission" ,
"timestamp" : "1561366667" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "ed7f64d3-34ac-4e4b-8f83-6812e65083e7" ,
"value" : "2019-06-24T08:29:00"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "permalink" ,
"timestamp" : "1561366667" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "7fc14672-8789-4925-8e53-4678c3dac150" ,
"value" : "https://www.virustotal.com/file/e5df9ce468a2510c86d8808083e5c3326385596fba864546491922b2ea9802df/analysis/1561364940/"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "detection-ratio" ,
"timestamp" : "1561366667" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "fe8cc977-f43e-4d41-bf03-59cea17692ae" ,
"value" : "11/59"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "Vulnerability object describing a common vulnerability enumeration which can describe published, unpublished, under review or embargo vulnerability for software, equipments or hardware." ,
"meta-category" : "vulnerability" ,
"name" : "vulnerability" ,
"template_uuid" : "81650945-f186-437b-8945-9f31715d32da" ,
"template_version" : "5" ,
"timestamp" : "1561369599" ,
"uuid" : "5d109bff-e5cc-4732-8eac-4dcd950d210f" ,
"Attribute" : [
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "state" ,
"timestamp" : "1561369599" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "5d109bff-33a8-436a-a83f-407e950d210f" ,
"value" : "Published"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "description" ,
"timestamp" : "1561369602" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "5d109c02-652c-42ea-a798-4165950d210f" ,
"value" : "The vulnerability is caused by the Equation Editor, to which fails to properly handle OLE objects in memory."
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "summary" ,
"timestamp" : "1561369603" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "5d109c03-596c-4d60-aead-4f8e950d210f" ,
"value" : "Microsoft Office 2007 Service Pack 3, Microsoft Office 2010 Service Pack 2, Microsoft Office 2013 Service Pack 1, and Microsoft Office 2016 allow an attacker to run arbitrary code in the context of the current user by failing to properly handle objects in memory, aka \"Microsoft Office Memory Corruption Vulnerability\". This CVE ID is unique from CVE-2017-11884."
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "id" ,
"timestamp" : "1561369610" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "5d109c0a-bdc8-4ff1-a32a-49a9950d210f" ,
"value" : "CVE-2017-11882"
}
]
}
]
}
}