95 lines
2.6 KiB
JSON
95 lines
2.6 KiB
JSON
|
{
|
||
|
"Event": {
|
||
|
"analysis": "2",
|
||
|
"date": "2016-06-26",
|
||
|
"extends_uuid": "",
|
||
|
"info": "OSINT Threat Group-4127 Targets Google Accounts by Secureworks",
|
||
|
"publish_timestamp": "1467106144",
|
||
|
"published": true,
|
||
|
"threat_level_id": "1",
|
||
|
"timestamp": "1467106117",
|
||
|
"uuid": "57724297-147c-41e3-86f6-4586950d210f",
|
||
|
"Orgc": {
|
||
|
"name": "CthulhuSPRL.be",
|
||
|
"uuid": "55f6ea5f-fd34-43b8-ac1d-40cb950d210f"
|
||
|
},
|
||
|
"Tag": [
|
||
|
{
|
||
|
"colour": "#ffffff",
|
||
|
"name": "OSINT"
|
||
|
},
|
||
|
{
|
||
|
"colour": "#ffffff",
|
||
|
"name": "tlp:white"
|
||
|
}
|
||
|
],
|
||
|
"Attribute": [
|
||
|
{
|
||
|
"category": "External analysis",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1467105963",
|
||
|
"to_ids": false,
|
||
|
"type": "link",
|
||
|
"uuid": "577242ab-f804-445e-aa47-4b25950d210f",
|
||
|
"value": "https://www.secureworks.com/research/threat-group-4127-targets-google-accounts"
|
||
|
},
|
||
|
{
|
||
|
"category": "Attribution",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1467106014",
|
||
|
"to_ids": false,
|
||
|
"type": "threat-actor",
|
||
|
"uuid": "577242de-0cc0-442f-ba5e-6cfd950d210f",
|
||
|
"value": "APT28"
|
||
|
},
|
||
|
{
|
||
|
"category": "Attribution",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1467106015",
|
||
|
"to_ids": false,
|
||
|
"type": "threat-actor",
|
||
|
"uuid": "577242df-6ccc-444e-95c2-6cfd950d210f",
|
||
|
"value": "Threat Group 4127"
|
||
|
},
|
||
|
{
|
||
|
"category": "Attribution",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1467106015",
|
||
|
"to_ids": false,
|
||
|
"type": "threat-actor",
|
||
|
"uuid": "577242df-a564-4733-bf92-6cfd950d210f",
|
||
|
"value": "Sofacy"
|
||
|
},
|
||
|
{
|
||
|
"category": "Network activity",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1467106117",
|
||
|
"to_ids": true,
|
||
|
"type": "domain",
|
||
|
"uuid": "57724345-8d4c-45da-85e3-06dc950d210f",
|
||
|
"value": "accoounts-google.com"
|
||
|
},
|
||
|
{
|
||
|
"category": "Network activity",
|
||
|
"comment": "",
|
||
|
"deleted": false,
|
||
|
"disable_correlation": false,
|
||
|
"timestamp": "1467106118",
|
||
|
"to_ids": true,
|
||
|
"type": "domain",
|
||
|
"uuid": "57724346-55b8-4d2d-a7b0-06dc950d210f",
|
||
|
"value": "googlesetting.com"
|
||
|
}
|
||
|
]
|
||
|
}
|
||
|
}
|