212 lines
8.9 KiB
JSON
212 lines
8.9 KiB
JSON
|
{
|
||
|
"type": "bundle",
|
||
|
"id": "bundle--5e149458-bdf4-4f6a-8e1c-8f1102de0b81",
|
||
|
"objects": [
|
||
|
{
|
||
|
"type": "identity",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2020-01-07T14:30:16.000Z",
|
||
|
"modified": "2020-01-07T14:30:16.000Z",
|
||
|
"name": "CIRCL",
|
||
|
"identity_class": "organization"
|
||
|
},
|
||
|
{
|
||
|
"type": "report",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "report--5e149458-bdf4-4f6a-8e1c-8f1102de0b81",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2020-01-07T14:30:16.000Z",
|
||
|
"modified": "2020-01-07T14:30:16.000Z",
|
||
|
"name": "OSINT - Spam via mobile phone",
|
||
|
"published": "2020-01-07T14:30:41Z",
|
||
|
"object_refs": [
|
||
|
"x-misp-attribute--5e149483-95c4-46dc-8175-4add02de0b81",
|
||
|
"x-misp-attribute--5e149489-9f8c-4ed9-947c-4bb002de0b81",
|
||
|
"observed-data--5e1494af-98cc-4fa7-b699-8f2202de0b81",
|
||
|
"url--5e1494af-98cc-4fa7-b699-8f2202de0b81",
|
||
|
"x-misp-attribute--5e1495f7-7e3c-426a-ab56-460802de0b81",
|
||
|
"x-misp-object--5e14956e-c830-4caa-b8b3-46a802de0b81",
|
||
|
"relationship--eba134a0-e755-4cb0-bc5a-3b9c0a3af79c",
|
||
|
"relationship--b4c0be3c-2527-48e5-9cb9-b8794c2533f5",
|
||
|
"relationship--1b12fe1b-0135-4b7b-bd6a-d303b188aa48"
|
||
|
],
|
||
|
"labels": [
|
||
|
"Threat-Report",
|
||
|
"misp:tool=\"MISP-STIX-Converter\"",
|
||
|
"circl:incident-classification=\"scam\"",
|
||
|
"type:OSINT",
|
||
|
"osint:lifetime=\"perpetual\"",
|
||
|
"osint:certainty=\"50\"",
|
||
|
"misp-galaxy:financial-fraud=\"Vishing\""
|
||
|
],
|
||
|
"object_marking_refs": [
|
||
|
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "x-misp-attribute",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "x-misp-attribute--5e149483-95c4-46dc-8175-4add02de0b81",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2020-01-07T14:24:03.000Z",
|
||
|
"modified": "2020-01-07T14:24:03.000Z",
|
||
|
"labels": [
|
||
|
"misp:type=\"phone-number\"",
|
||
|
"misp:category=\"Financial fraud\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
],
|
||
|
"x_misp_category": "Financial fraud",
|
||
|
"x_misp_type": "phone-number",
|
||
|
"x_misp_value": "+4917071524639"
|
||
|
},
|
||
|
{
|
||
|
"type": "x-misp-attribute",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "x-misp-attribute--5e149489-9f8c-4ed9-947c-4bb002de0b81",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2020-01-07T14:24:09.000Z",
|
||
|
"modified": "2020-01-07T14:24:09.000Z",
|
||
|
"labels": [
|
||
|
"misp:type=\"phone-number\"",
|
||
|
"misp:category=\"Financial fraud\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
],
|
||
|
"x_misp_category": "Financial fraud",
|
||
|
"x_misp_type": "phone-number",
|
||
|
"x_misp_value": "+33606117967"
|
||
|
},
|
||
|
{
|
||
|
"type": "observed-data",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "observed-data--5e1494af-98cc-4fa7-b699-8f2202de0b81",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2020-01-07T14:24:47.000Z",
|
||
|
"modified": "2020-01-07T14:24:47.000Z",
|
||
|
"first_observed": "2020-01-07T14:24:47Z",
|
||
|
"last_observed": "2020-01-07T14:24:47Z",
|
||
|
"number_observed": 1,
|
||
|
"object_refs": [
|
||
|
"url--5e1494af-98cc-4fa7-b699-8f2202de0b81"
|
||
|
],
|
||
|
"labels": [
|
||
|
"misp:type=\"link\"",
|
||
|
"misp:category=\"External analysis\""
|
||
|
]
|
||
|
},
|
||
|
{
|
||
|
"type": "url",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "url--5e1494af-98cc-4fa7-b699-8f2202de0b81",
|
||
|
"value": "https://who-calls.me.uk/phone/08081896207"
|
||
|
},
|
||
|
{
|
||
|
"type": "x-misp-attribute",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "x-misp-attribute--5e1495f7-7e3c-426a-ab56-460802de0b81",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2020-01-07T14:30:15.000Z",
|
||
|
"modified": "2020-01-07T14:30:15.000Z",
|
||
|
"labels": [
|
||
|
"misp:type=\"phone-number\"",
|
||
|
"misp:category=\"Financial fraud\"",
|
||
|
"misp:to_ids=\"True\""
|
||
|
],
|
||
|
"x_misp_category": "Financial fraud",
|
||
|
"x_misp_type": "phone-number",
|
||
|
"x_misp_value": "+448081896207"
|
||
|
},
|
||
|
{
|
||
|
"type": "x-misp-object",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "x-misp-object--5e14956e-c830-4caa-b8b3-46a802de0b81",
|
||
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
||
|
"created": "2020-01-07T14:29:50.000Z",
|
||
|
"modified": "2020-01-07T14:29:50.000Z",
|
||
|
"labels": [
|
||
|
"misp:name=\"microblog\"",
|
||
|
"misp:meta-category=\"misc\""
|
||
|
],
|
||
|
"x_misp_attributes": [
|
||
|
{
|
||
|
"type": "text",
|
||
|
"object_relation": "type",
|
||
|
"value": "Twitter",
|
||
|
"category": "Other",
|
||
|
"uuid": "5e14956f-8074-4f08-9427-46a802de0b81"
|
||
|
},
|
||
|
{
|
||
|
"type": "text",
|
||
|
"object_relation": "post",
|
||
|
"value": "Weird stuff happening on my phone. Call from German number, then from a French number. Both left voice mails with a robot voice reading out some numbers.\r\n\r\nA phone number verification service?\r\n\r\nAnyone recognise them? \r\n\u00f0\u0178\u2021\u00a9\u00f0\u0178\u2021\u00aa +4917071524639\r\n\u00f0\u0178\u2021\u00ab\u00f0\u0178\u2021\u00b7 +33606117967",
|
||
|
"category": "Other",
|
||
|
"uuid": "5e149574-5d60-4fbc-aed0-46a802de0b81"
|
||
|
},
|
||
|
{
|
||
|
"type": "link",
|
||
|
"object_relation": "link",
|
||
|
"value": "https://twitter.com/edent/status/1214494432046800896",
|
||
|
"category": "External analysis",
|
||
|
"uuid": "5e149574-e274-4c99-961a-46a802de0b81"
|
||
|
},
|
||
|
{
|
||
|
"type": "text",
|
||
|
"object_relation": "verified-username",
|
||
|
"value": "Verified",
|
||
|
"category": "Other",
|
||
|
"uuid": "5e149574-d618-4224-84bf-46a802de0b81"
|
||
|
},
|
||
|
{
|
||
|
"type": "text",
|
||
|
"object_relation": "state",
|
||
|
"value": "Informative",
|
||
|
"category": "Other",
|
||
|
"uuid": "5e149574-6690-46ee-a413-46a802de0b81"
|
||
|
}
|
||
|
],
|
||
|
"x_misp_meta_category": "misc",
|
||
|
"x_misp_name": "microblog"
|
||
|
},
|
||
|
{
|
||
|
"type": "relationship",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "relationship--eba134a0-e755-4cb0-bc5a-3b9c0a3af79c",
|
||
|
"created": "2020-01-07T14:29:03.000Z",
|
||
|
"modified": "2020-01-07T14:29:03.000Z",
|
||
|
"relationship_type": "includes",
|
||
|
"source_ref": "x-misp-object--5e14956e-c830-4caa-b8b3-46a802de0b81",
|
||
|
"target_ref": "x-misp-attribute--5e149483-95c4-46dc-8175-4add02de0b81"
|
||
|
},
|
||
|
{
|
||
|
"type": "relationship",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "relationship--b4c0be3c-2527-48e5-9cb9-b8794c2533f5",
|
||
|
"created": "2020-01-07T14:29:25.000Z",
|
||
|
"modified": "2020-01-07T14:29:25.000Z",
|
||
|
"relationship_type": "includes",
|
||
|
"source_ref": "x-misp-object--5e14956e-c830-4caa-b8b3-46a802de0b81",
|
||
|
"target_ref": "x-misp-attribute--5e149489-9f8c-4ed9-947c-4bb002de0b81"
|
||
|
},
|
||
|
{
|
||
|
"type": "relationship",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "relationship--1b12fe1b-0135-4b7b-bd6a-d303b188aa48",
|
||
|
"created": "2020-01-07T14:29:50.000Z",
|
||
|
"modified": "2020-01-07T14:29:50.000Z",
|
||
|
"relationship_type": "includes",
|
||
|
"source_ref": "x-misp-object--5e14956e-c830-4caa-b8b3-46a802de0b81",
|
||
|
"target_ref": "observed-data--5e1494af-98cc-4fa7-b699-8f2202de0b81"
|
||
|
},
|
||
|
{
|
||
|
"type": "marking-definition",
|
||
|
"spec_version": "2.1",
|
||
|
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
|
||
|
"created": "2017-01-20T00:00:00.000Z",
|
||
|
"definition_type": "tlp",
|
||
|
"name": "TLP:WHITE",
|
||
|
"definition": {
|
||
|
"tlp": "white"
|
||
|
}
|
||
|
}
|
||
|
]
|
||
|
}
|