2023-04-21 13:25:09 +00:00
{
2023-12-14 14:30:15 +00:00
"Event" : {
"analysis" : "0" ,
"date" : "2022-06-30" ,
"extends_uuid" : "" ,
"info" : "#StopRansomware: MedusaLocker" ,
"publish_timestamp" : "1666694899" ,
"published" : true ,
"threat_level_id" : "1" ,
"timestamp" : "1657009711" ,
"uuid" : "34493f6d-9441-45df-9cb4-4de473709081" ,
"Orgc" : {
"name" : "CIRCL" ,
"uuid" : "55f6ea5e-2c60-40e5-964f-47a8950d210f"
} ,
"Tag" : [
{
"colour" : "#0088cc" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "misp-galaxy:mitre-attack-pattern=\"External Remote Services - T1133\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0088cc" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "misp-galaxy:mitre-attack-pattern=\"Phishing - T1566\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0088cc" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "misp-galaxy:mitre-attack-pattern=\"PowerShell - T1059.001\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0088cc" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "misp-galaxy:mitre-attack-pattern=\"Safe Mode Boot - T1562.009\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0088cc" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "misp-galaxy:mitre-attack-pattern=\"Data Encrypted for Impact - T1486\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0088cc" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#004646" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "type:OSINT" ,
"relationship_type" : ""
} ,
{
"colour" : "#0071c3" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "osint:lifetime=\"perpetual\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0087e8" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "osint:certainty=\"50\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#ffffff" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "tlp:white" ,
"relationship_type" : ""
} ,
{
"colour" : "#000000" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "dnc:malware-type=\"Ransomware\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#39b300" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "enisa:nefarious-activity-abuse=\"ransomware\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#006c6c" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "ecsirt:malicious-code=\"ransomware\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#2c4f00" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "malware_classification:malware-category=\"Ransomware\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#00acd1" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "veris:action:malware:variety=\"Ransomware\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#000000" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "Ransomware" ,
"relationship_type" : ""
} ,
{
"colour" : "#420053" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "ms-caro-malware:malware-type=\"Ransom\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#001739" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "ms-caro-malware-full:malware-type=\"Ransom\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#1f2325" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "Intel 471:GIR=\"1.2.2 - Ransomware-as-a-Service (RaaS)\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0088cc" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "misp-galaxy:malpedia=\"MedusaLocker\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0088cc" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "misp-galaxy:ransomware=\"MedusaLocker\"" ,
"relationship_type" : ""
}
] ,
"Attribute" : [
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680987" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "c98115ff-fa16-480b-aab5-94f7cd6feff6" ,
"value" : "willyhill1960@tutanota.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680987" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "33ed009d-9cb3-4b98-bb68-7976b1df1536" ,
"value" : "unlockfile@cock.li"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680987" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "53d9f2be-dbfa-419c-a553-b80006c9cd7d" ,
"value" : "zlo@keem.ne"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680987" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "4961d7c9-4669-4556-afad-396a98d1af0e" ,
"value" : "unlockmeplease@airmail.cc"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680987" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "4ab3b41b-4f44-40b3-b84c-c48bbadd4903" ,
"value" : "zlo@keemail.me"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680987" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "ad855082-779a-4638-8cf9-724471b140ed" ,
"value" : "unlockmeplease@protonmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680987" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "6a6f0613-1284-4db4-bf63-353ff8bbeb15" ,
"value" : "zlo@tfwno.gf"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680987" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "5c19f454-be75-4f6f-874d-edc17931b5c5" ,
"value" : "willyhill1960@protonmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680987" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "bb793a7e-dc86-432b-9e98-145fff226ad9" ,
"value" : "support@ypsotecs.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680987" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "a1f968f7-e29a-4b36-86fd-3740c71db919" ,
"value" : "support@imfoodst.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680987" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "bdb9b095-3dee-441f-bd0a-2bb8555b8f4f" ,
"value" : "traceytevin@protonmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "0c778edb-d952-4e48-a55a-049893447286" ,
"value" : "support@itwgset.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "0d39bcfa-b8e0-4850-b77f-ca7836958da3" ,
"value" : "unlock_file@aol.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "64359805-055e-470e-9c03-e00e5786bbe2" ,
"value" : "support@novibmaker.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "d0dca853-a828-4480-bf23-24b96f2f90d2" ,
"value" : "unlock_file@outlook.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "d3204522-0b24-452e-8a3a-439533c4db9b" ,
"value" : "support@securycasts.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "ab44f789-8464-4a35-92c8-6714c5f7cd19" ,
"value" : "support@exoprints.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "cd58ff7e-c862-4808-83f3-5d6f66d48e93" ,
"value" : "rewmiller-1974@protonmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "a2d7f1a4-b93b-4e3a-810a-21f3b47695be" ,
"value" : "support@exorints.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "5c524b5d-f40b-4fb1-a603-cf0ee4fc9dd6" ,
"value" : "rpd@keemail.me"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "5bb830fd-d9ad-4d2b-a926-e097275b1d70" ,
"value" : "support@fanbridges.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "2c79df75-48ac-4995-86cf-46ca7d1d74c3" ,
"value" : "soterissylla@wyseil.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "1c3de5f3-6aa7-4cf9-a930-3cb7eeee7add" ,
"value" : "support@faneridges.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "7bfcf076-b946-4025-8d7f-632abcd6ed6c" ,
"value" : "support@careersill.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "06e0d3f6-a98e-48ca-af2d-b75a662b3349" ,
"value" : "perfection@bestkoronavirus.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "704c6093-9063-491f-b4b5-aeae05e0db73" ,
"value" : "karloskolorado@tutanota.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "17ba8ed1-7980-4102-9ba6-c655372e9dab" ,
"value" : "pool1256@tutanota.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "8c00e93e-a932-475c-a44b-671dce7e6b7d" ,
"value" : "kevynchaz@protonmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "d0dd0337-6aa7-4049-acd6-85ef3dcfb6ec" ,
"value" : "rapid@aaathats3as.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "d4c83f23-97d1-469c-b1c6-562024839838" ,
"value" : "korona@bestkoronavirus.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "44d6e0e5-0f3b-4a14-b540-d6f64d3d2647" ,
"value" : "rescuer@tutanota.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "15c2fcd2-629d-41b1-99c7-4245b238a1ba" ,
"value" : "lockperfection@gmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "e4570362-af05-4e6d-8588-e7be5fc5e39b" ,
"value" : "ithelp01@decorous.cyou"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "67af9843-261f-480e-8014-ac89ef9e07ed" ,
"value" : "ithelp01@wholeness.business"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "5b9cfc17-f64b-4e34-bc44-1feb780276bf" ,
"value" : "mulierfagus@rdhos.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "c5ea899f-5e09-41e1-aae2-c30d1a68fed9" ,
"value" : "ithelp02@decorous.cyou"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "54c105da-bbcb-485a-95d1-9bf22d74be7a" ,
"value" : "ithelp02@wholness.business"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "f6aafb4e-1942-465b-bf0e-51e714232845" ,
"value" : "107btc@protonmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "b35fe755-07e9-42d1-a946-26575f5e3e27" ,
"value" : "ithelpresotre@outlook.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "3db0cf25-9be5-43c6-a306-22b3b6744d7a" ,
"value" : "33btc@protonmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "f1bf7d56-2167-492b-838d-6df4bd37e906" ,
"value" : "cmd@jitjat.org"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "bb5a7749-c41f-44ad-b86f-fb383f010431" ,
"value" : "777decoder777@protonmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "5cbe5c53-c6f0-436a-ad95-528db471c389" ,
"value" : "coronaviryz@gmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "98ecee0e-92b0-4a74-a866-4a74624c8c00" ,
"value" : "777decoder777@tfwno.gf"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "3a879352-8790-4003-b493-968e74eb192b" ,
"value" : "dec_helper@dremno.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "45ce0956-c866-437e-916f-9ff4d2279c36" ,
"value" : "andrewmiller-1974@protonmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "60c94b70-6aea-4481-ab03-0610ff8c6725" ,
"value" : "dec_helper@excic.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "ae497c03-1c0a-4b6d-a374-469598af2628" ,
"value" : "angelomartin-1980@protonmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "07cca850-556f-44c2-a350-0a5ed617f8df" ,
"value" : "dec_restore@prontonmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "bdb2556f-698d-481c-a3a9-9acd3f929ff9" ,
"value" : "ballioverus@quocor.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "41558b31-6d45-4343-9ee4-9f6d034c7e52" ,
"value" : "dec_restore1@outlook.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "0a7f65fc-36c3-4d97-ab82-0c4122e3e849" ,
"value" : "beacon@jitjat.org"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "7b4d8106-1954-45a0-9d7d-02d3d7d32eac" ,
"value" : "bitcoin@sitesoutheat.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "79a0d62d-8b08-4744-8bf9-173c0dc8d2b7" ,
"value" : "beacon@msgsafe.io"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "712dfb1a-88d1-483b-ad51-e37944f05b25" ,
"value" : "briansalgado@protonmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "22e9b19d-eb86-4191-9466-326966fc4ea1" ,
"value" : "best666decoder@tutanota.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "345b4871-3ac0-4200-ae81-37aa75fce5a8" ,
"value" : "bugervongir@outlook.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "ff5b02aa-05b5-4c9d-9234-3b6aedb45993" ,
"value" : "bitcoin@mobtouches.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "06708900-d105-4965-b3b1-2fde8eb7c00a" ,
"value" : "best666decoder@protonmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "adad2178-b001-41c7-9d8d-665338466ba1" ,
"value" : "encrypt2020@outlook.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "e3f397f9-cf27-4506-a0b9-e2825170001e" ,
"value" : "decoder83540@cock.li"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "134be71f-e062-4f19-9763-0aad30721923" ,
"value" : "fast-help@inbox.lv"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "0a7b100d-0abc-4101-a889-d3c96f296aa2" ,
"value" : "decra2019@gmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "1eb5f7c3-c0de-440e-af42-a233a729b2dd" ,
"value" : "fuc_ktheworld1448@outlook.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "bfd0d9d5-aa65-43b8-b9d5-131182ae9b72" ,
"value" : "diniaminius@winrof.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "e3376d83-4f5a-4554-8e11-aa23fcdf7b1a" ,
"value" : "fucktheworld1448@cock.li"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "58c9bf08-3713-4cb5-8b83-8a779c21798a" ,
"value" : "dirhelp@keemail.me"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "888a0a2c-88dd-4b4b-a81e-8a13bb55924a" ,
"value" : "gartaganisstuffback@gmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "479e8bcd-e531-4f93-9848-527e2d5daff2" ,
"value" : "emaila.elaich@iav.ac.ma"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "693aadcb-a601-461e-b510-614b25c68101" ,
"value" : "gavingonzalez@protonmail.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "67c75f8e-5402-4265-9ff5-511f04bb7663" ,
"value" : "emd@jitjat.org"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "12355d43-008c-4ad5-9fe3-f666f4c34e7e" ,
"value" : "gsupp@onionmail.org"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "e86178a8-e72f-4972-b577-06dbb8756067" ,
"value" : "encrypt2020@cock.li"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "68caeb24-1abb-4d17-af6c-d0d4fc357a14" ,
"value" : "gsupp@techmail.info"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "f87c84d1-87de-4194-832e-59252c1b6aac" ,
"value" : "helper@atacdi.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "cf5764cc-526c-4207-b635-c298ae5eb4dd" ,
"value" : "ithelp@decorous.cyou"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "8899c0bb-f1c4-4274-ac97-bc2090888e04" ,
"value" : "helper@buildingwin.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "cf93afb2-47e5-42f2-a742-c937e7976be9" ,
"value" : "ithelp@decorous.cyoum"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "e96cd637-d225-4f31-ae55-0fd7ebf72387" ,
"value" : "helprestore@outlook.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "08716e06-ac1d-4fdd-9467-651e84a3e6a8" ,
"value" : "ithelp@wholeness.business"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656680988" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "ba7f7120-15c8-47ba-965d-c24de237596c" ,
"value" : "helptorestore@outlook.com"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656682727" ,
"to_ids" : true ,
"type" : "email-src" ,
"uuid" : "21472250-40cb-4032-8146-89498d1f1473" ,
"value" : "rescuer@cock.li"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Ransomnote" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656939787" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "a611936d-86f2-4c43-893b-cef4def6ed68" ,
"value" : "how_to_ recover_data.html"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Ransomnote" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656939787" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "612490f6-c0cb-4b85-8418-a7d2695a2e25" ,
"value" : "how_to_recover_data.html.marlock01"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Ransomnote" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656939787" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "e5bf00f7-cde5-4771-8d9c-c60145e29d4a" ,
"value" : "instructions.html"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Ransomnote" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656939787" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "d90bafeb-fcb8-49c0-99d7-8d9ca4b82d6e" ,
"value" : "READINSTRUCTION.html"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Ransomnote" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656939787" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "7ab046c6-1467-4888-85d8-5b9fa65fabdb" ,
"value" : "!!!HOW_TO_DECRYPT!!!"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Ransomnote" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656939787" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "7762779d-92af-4997-aabc-e3d4d53ae21b" ,
"value" : "How_to_recovery.txt"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Ransomnote" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656939787" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "d0b6e769-9762-4dde-8800-5ed9c85e0f7f" ,
"value" : "readinstructions.html"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Ransomnote" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656939787" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "6e8b7970-442d-41e0-a1b1-2b8fd9c3e32a" ,
"value" : "readme_to_recover_files"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Ransomnote" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656939787" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "e8c99bfb-e553-425a-9760-5fc0bb6c8e4f" ,
"value" : "recovery_instructions.html"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Ransomnote" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656939787" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "1e518ccc-1b05-47f0-ae03-f418f7808e4b" ,
"value" : "HOW_TO_RECOVER_DATA.html"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Ransomnote" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656939787" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "7b4397f5-4169-40e2-bebd-b075e1314c68" ,
"value" : "recovery_instruction.html"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "6cf5fc69-f09f-45c6-908b-fe9dc78dbaaf" ,
"value" : "14oxnsSc1LZ5M2cPZeQ9rFnXqEvPCnZikc"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "e03b46ad-ad4b-4610-a73c-51243858e0d6" ,
"value" : "1DRxUFhvJjGUdojCzMWSLmwx7Qxn79XbJq"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "75f8faf6-f1b1-4fd3-b365-0a07396f9fcb" ,
"value" : "18wRbb94CjyTGkUp32ZM7krCYCB9MXUq42"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "21d949a7-ce94-481f-bf25-9577e78eb5f2" ,
"value" : "1AbRxRfP6yHePpi7jmDZkS4Mfpm1ZiatH5"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "1dfdd7c2-8484-4072-b350-db4a02947152" ,
"value" : "1Edcufenw1BB4ni9UadJpQh9LVx9JGtKpP"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "afea7ac1-28ec-4b95-908c-91088400557b" ,
"value" : "1DyMbw6R9PbJqfUSDcK5729xQ57yJrE8BC"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "dabd44a8-95a9-4d94-8d1d-18dc4a8ba58a" ,
"value" : "184ZcAoxkvimvVZaj8jZFujC7EwR3BKWvf"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "296f5194-d6b7-4026-a431-c804532fce0e" ,
"value" : "14oH2h12LvQ7BYBufcrY5vfKoCq2hTPoev"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "dd719fdd-1c43-4b28-aefe-c00da93ae6af" ,
"value" : "bc1qy34v0zv6wu0cugea5xjlxagsfwgunwkzc0xcjj"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "53346bef-c79c-42c5-8b8e-7af05f2e0506" ,
"value" : "bc1q9jg45a039tn83jk2vhdpranty2y8tnpnrk9k5q"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "43e5bd1f-437b-46e0-9599-b67e34fd9249" ,
"value" : "bc1qz3lmcw4k58n79wpzm550r5pkzxc2h8rwmmu6xm"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "fd604bdb-98bb-464e-80fc-8a2b9b7cca62" ,
"value" : "1AereQUh8yjNPs9Wzeg1Le47dsqC8NNaNM"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "7af3cba0-fdf2-4ca9-981e-d5fdccafcaaa" ,
"value" : "1DeNHM2eTqHp5AszTsUiS4WDHWkGc5UxHf"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "aadf4226-5cac-4d18-a705-36d48bd5dbcb" ,
"value" : "1HEDP3c3zPwiqUaYuWZ8gBFdAQQSa6sMGw"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "756ac5e4-684c-4861-aaf3-65aa27e8755a" ,
"value" : "1HdgQM9bjX7u7vWJnfErY4MWGBQJi5mVWV"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "1f979729-5e8f-467c-9998-4e7e2a550ab2" ,
"value" : "1nycdn9ebxht4tpspu4ehpjz9ghxlzipll"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "b65ba82b-36f1-4237-b170-da9c50dee3dc" ,
"value" : "12xd6KrWVtgHEJHKPEfXwMVWuFK4k1FCUF"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "bd73085f-9605-4a38-b447-f34e04b8372a" ,
"value" : "1HZHhdJ6VdwBLCFhdu7kDVZN9pb3BWeUED"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "266f4b5e-1ab7-486d-8296-fca9d7d176a5" ,
"value" : "1PormUgPR72yv2FRKSVY27U4ekWMKobWjg"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "381bb06f-04f0-42f9-8284-60e9ba61da6f" ,
"value" : "14cATAzXwD7CQf35n8Ea5pKJPfhM6jEHak"
} ,
{
"category" : "Financial fraud" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1656941038" ,
"to_ids" : true ,
"type" : "btc" ,
"uuid" : "3ab44efb-7487-4b85-833f-41e7351e03e1" ,
"value" : "1PopeZ4LNLanisswLndAJB1QntTF8hpLsD"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "fd141de6-e44b-426b-96f4-41b9099981b3" ,
"value" : "http://gvlay6u4g53rxdi5.onion/6-iSm1B1Ehljh8HYuXGym4Xyu1WdwsR2Av-6tXiw1BImsqoLh7pd207Rl6XYoln7sId"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "b10225b9-1578-47e8-81f1-b80bfe381eaa" ,
"value" : "http://gvlay6u4g53rxdi5.onion/8-grp514hncgblilsjtd32hg6jtbyhlocr5pqjswxfgf2oragnl3pqno6fkqcimqin"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "df2dd421-1329-4b7e-b9de-93eb6b2b3c2b" ,
"value" : "http://gvlay6y4g53rxdi5.onion/21-8P4ZLCsMETPaLw9MkSlXJsNZWdHe0rxjt-XmBgZLWlm5ULGFCOJFuVdEymmxysofwu"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "c83df49e-e37b-4e6a-9951-19fc4c17c638" ,
"value" : "http://gvlay6u4g53rxdi5.onion/2l-8P4ZLCsMTPaLw9MkSlXJsNZWdHeOrxjtE9lck1MuXPYo29daQys6gomZZXUImN7Z"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "1fdbb119-e0d0-48f4-9c59-93f8297a4910" ,
"value" : "http://gvlay6u4g53rxdi5.onion/21-8P4ZLCsMTPaLw9MkSlXJsNZWdHe0rxjt-DcaE9HeHywqSHvdcIwOndCS4PuWASX8g"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "ca361320-8559-48db-8036-c8cc508610e3" ,
"value" : "http://gvlay6u4g53rxdi5.onion/21-8P4ZLCsMTPaLw9MkSlXJsNZWdHe0rxjt-kB4rQXGKyxGiLyw7YDsMKSBjyfdwcyxo"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "a1540724-c8da-4131-b7a4-1995510c4c43" ,
"value" : "http://gvlay6u4g53rxdi5.onion/21-8P4ZLCsMTPaLw9MkSlXJsNZWdHe0rxjt-bET6JbB9vEMZ7qYBPqUMCxOQExFx4iOi"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "8a803583-a6d1-434c-90f1-3ec952fe558e" ,
"value" : "http://gvlay6u4g53rxdi5.onion/8-MO0Q7O97Hgxvm1YbD7OMnimImZJXEWaG-RbH4TvdwVTGQB3X6VOUOP3lgO6YOJEOW"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "9d36edd8-2236-4956-b553-e3950cbfa4a9" ,
"value" : "http://gvlay6u4g53rxdi5.onion/8-gRp514hncgb1i1sjtD32hG6jTbUh1ocR-Uola2Fo30KTJvZX0otYZgTh5txmKwUNe"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "be9673eb-dc13-4edf-ab0f-96a64c73e118" ,
"value" : "http://gvlay6u4g53rxdi5.onion/21-E6UQFCEuCn4KvtAh4TonRTpyHqFo6F6L-OWQwD1w1Td7hY7IGUUjxmHMoFSQW6blg"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "bb17a48c-ce0a-4cdc-8e2b-009387b7add5" ,
"value" : "http://gvlay6u4g53rxdi5.onion/21-E6UQFCEuCn4KvtAh4TonRTpyHqFo6F6L-uGHwkkWCoUtBbZWN50sSS4Ds8RABkrKy"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "5ff5592b-4f1d-4245-8ec7-af0ea19d683c" ,
"value" : "http://gvlay6u4g53rxdi5.onion/21-E6UQFCEuCn4KvtAh4TonRTpyHqFo6F6L-Tj3PRnQlpHc9OftRVDGAWUulvE80yZbc"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "c672869e-486b-40ae-996e-8a1bf986b776" ,
"value" : "http://gvlay6u4g53rxdi5.onion/8-Ww5sCBhsL8eM4PeAgsfgfa9lrqa81r31-tDQRZCAUe4164X532j9Ky16IBN9StWTH"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "a9e0fda9-1e32-4cef-8b3d-466d51654a15" ,
"value" : "http://gvlay6u4g53rxdi5.onion/21-wIq5kK9gGKiTmyups1U6fABj1VnXIYRB-I5xek6PG2EbWlPC7C1rXfsqJBlWlFFfY"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "domain" ,
"uuid" : "254b2b47-8712-40df-b8ec-f6140f34d140" ,
"value" : "qd7pcafncosqfqu3ha6fcx4h6sr7tzwagzpcdcnytiw3b6varaeqv5yd.onion"
} ,
{
"category" : "Network activity" ,
"comment" : "TOR Addresses" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1657002132" ,
"to_ids" : true ,
"type" : "url" ,
"uuid" : "59178c14-47de-41bc-80e2-3797d651a49f" ,
"value" : "http://medusacegu2ufmc3kx2kkqicrlcxdettsjcenhjena6uannk5f4ffuyd.onion/leakdata/paigesmusic-leakdata-closed-part1"
}
] ,
"Object" : [
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002472" ,
"uuid" : "bde85597-f1de-410d-b8a7-271f8e0f4b89" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002472" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "29a9d2ac-2876-414c-aff6-5e3077f66e5c" ,
"value" : "195.123.246.138"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002472" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "162128e2-4fc3-4b9b-a522-380fccea3210" ,
"value" : "2021-11-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002499" ,
"uuid" : "3cbfada9-55da-4fe9-8acf-7987b0ae934f" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002499" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "3d891026-590c-48dc-a4df-7b5398e8b0e2" ,
"value" : "138.124.186.221"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002499" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "174ea217-04c2-4368-b503-53f87bdbeccc" ,
"value" : "2021-11-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002538" ,
"uuid" : "34704201-a988-4218-979a-0311b49efe49" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002538" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "ec6825d1-6533-4a34-94ed-2efe868829a9" ,
"value" : "159.223.0.9"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002538" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "b33451ac-3010-46bd-8e22-05de11bde376" ,
"value" : "2021-11-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002605" ,
"uuid" : "0f267df7-a56e-48cb-959e-48e18538a218" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002605" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "ac844b7a-4d71-47c0-b6c2-c243081ebc5c" ,
"value" : "45.146.164.141"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002605" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "40147337-d8c4-4aa0-962e-2a94e5bb4cc1" ,
"value" : "2021-11-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002667" ,
"uuid" : "0cbf72ae-eb07-4fda-ace9-1ce40c9d89a8" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002667" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "ea908c2f-d8bc-4772-b57c-2dd536b767d5" ,
"value" : "185.220.101.35"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002667" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "c8b5a35b-23a9-427a-9ff2-c3c444c65def" ,
"value" : "2021-11-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002694" ,
"uuid" : "9d61fa66-4dce-4cf0-9ac7-689385585954" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002694" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "84a0a97e-8dc2-4999-91f1-7c28c3e7e61b" ,
"value" : "185.220.100.249"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002694" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "b00955b1-7bf9-4bc4-a73e-38a973beb01e" ,
"value" : "2021-09-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002712" ,
"uuid" : "991ea7de-2222-4272-a317-e97ad6bd13fb" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002712" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "f0803210-f7aa-4c39-8273-f25b2b6c0210" ,
"value" : "50.80.219.149"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002712" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "0900fd2a-e8f2-424d-a3d0-984ebbe6e994" ,
"value" : "2021-09-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002737" ,
"uuid" : "6bcc63cf-e0df-45f9-a1f0-5c94f2ad6c2b" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002737" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "9a1c3347-381e-45ff-94b1-ea52c5b55c7e" ,
"value" : "185.220.101.146"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002737" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "cd38065d-4481-450c-8c28-733350dc002f" ,
"value" : "2021-09-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002759" ,
"uuid" : "b5d96350-0cf6-48a5-8ef0-03d26303d1a6" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002759" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "4be58ee1-b1ef-45fb-ba5f-e8c5c711a170" ,
"value" : "185.220.101.252"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002759" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "02383919-6187-4cb6-aa6a-9c70fa105aeb" ,
"value" : "2021-09-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002776" ,
"uuid" : "02ac26a2-5aea-491b-8344-7abc13dec002" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002777" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "32d2c5c8-cac7-41fc-a67d-8b317c92b55e" ,
"value" : "179.60.150.97"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002777" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "aa7eab91-a2c7-4bd8-8cea-7c8fa81c5a39" ,
"value" : "2021-09-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002797" ,
"uuid" : "56a00c45-d1bc-48e7-9c07-3ac05572a9fe" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002797" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "7aa7bc6d-92f5-4b5e-962a-ab341034f5c9" ,
"value" : "84.38.189.52"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002797" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "77770af4-71bf-4274-a216-b80f21199d45" ,
"value" : "2021-09-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002829" ,
"uuid" : "455dca2e-ac35-4510-a2a0-676ef484e431" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002829" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "e4c88d9c-bb5f-4b30-8c97-efe106f5913c" ,
"value" : "94.232.43.63"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002829" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "7e83fb94-0ea0-4089-9054-75d4f27ad20d" ,
"value" : "2021-07-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002858" ,
"uuid" : "5279ad55-77fe-4c42-a5db-25bfd83994fc" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002858" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "5a283f7c-ad60-4a82-8a35-272748a20dfb" ,
"value" : "108.11.30.103"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002858" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "f799e651-4208-432a-bb8c-089da52ef1aa" ,
"value" : "2021-04-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002872" ,
"uuid" : "86d04351-b977-4aca-b9c4-dabdae42c5aa" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002872" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "5a2d3dd8-b95a-44c3-b360-f139c49860c9" ,
"value" : "194.61.55.94"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002872" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "2747abf3-a1bf-432c-b5da-12234bb106b0" ,
"value" : "2021-04-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002899" ,
"uuid" : "e32c9026-d991-4161-9de8-d3f9b73fb0c4" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002899" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "975ced96-da90-44cb-af2d-be1a2215490f" ,
"value" : "198.50.233.202"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002899" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "b91ec0a2-119e-464c-b34f-a7e83de23422" ,
"value" : "2021-04-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002940" ,
"uuid" : "9e1ac15c-56fe-49b3-b889-f69fea7a8096" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002940" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "f61cc350-b251-4491-b014-de69c0a990da" ,
"value" : "40.92.90.105"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002940" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "fb03ffc7-7c52-49df-a096-c43a041fe4b0" ,
"value" : "2021-01-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002977" ,
"uuid" : "15bb11c8-7ef2-4207-a542-7777bc2cb09f" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002977" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "f5788e36-4979-47de-9394-4b2492604750" ,
"value" : "188.68.216.23"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002977" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "baa72145-7fbb-411b-8b90-f3630125b290" ,
"value" : "2020-12-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657002996" ,
"uuid" : "9d3ce22e-70a1-4298-a721-3de55bb33f03" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657002996" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "945c30ee-49ff-4c0d-9cd3-c6701ae00f41" ,
"value" : "87.251.75.71"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657002996" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "22092cfd-4e04-4128-9be5-11cc535e8b2c" ,
"value" : "2020-12-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657003029" ,
"uuid" : "4cdd7f32-7a9a-4e59-9378-1a6f044522a3" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657003029" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "eabe43c6-a0b5-4062-bec2-f92f4d1c4901" ,
"value" : "196.240.57.20"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657003029" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "fae87ca6-e96c-4876-8c41-fea355ce269f" ,
"value" : "2020-10-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657003047" ,
"uuid" : "118a311b-d391-4e9f-8f56-8e5a44895306" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657003047" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "8fd2684e-a2cf-415f-b305-eb57dd8358ed" ,
"value" : "198.0.198.5"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657003047" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "0c72e650-efab-4e3e-81bb-82098bdbd993" ,
"value" : "2020-08-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657003368" ,
"uuid" : "688cdd57-4ca8-4835-b385-88b788473014" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657003368" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "8495a1b3-74b6-4bd2-b61a-f35820ac6e4a" ,
"value" : "194.5.220.122"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657003368" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "41b7fc50-bb35-4a77-b94d-c4d13a341e86" ,
"value" : "2020-03-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657003492" ,
"uuid" : "506c144c-3b58-4e70-9a9d-a25791af430c" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657003492" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "ed97b544-d1e8-4219-af98-0a1c1ca7c2fb" ,
"value" : "194.5.250.124"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657003492" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "7c37eb20-5291-4cf7-9848-9de914bb68c4" ,
"value" : "2020-03-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657003508" ,
"uuid" : "f866c7ec-03de-4b97-b15f-541e480e9372" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657003508" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "5c5cf34d-2982-4386-baff-6594fa504c84" ,
"value" : "194.5.220.124"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657003508" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "80421b11-16d7-4e49-a889-e0eea044cd42" ,
"value" : "2020-03-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "A domain/hostname and IP address seen as a tuple in a specific time frame." ,
"meta-category" : "network" ,
"name" : "domain-ip" ,
"template_uuid" : "43b3b146-77eb-4931-b4cc-b66c60f28734" ,
"template_version" : "10" ,
"timestamp" : "1657003702" ,
"uuid" : "62183cf6-8688-4102-bfa8-eaa7d4aa611c" ,
"Attribute" : [
{
"category" : "Network activity" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "ip" ,
"timestamp" : "1657003702" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "4691e8e4-95be-4fae-ba5c-562088c7c687" ,
"value" : "104.210.72.161"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "last-seen" ,
"timestamp" : "1657003702" ,
"to_ids" : false ,
"type" : "datetime" ,
"uuid" : "c7577228-a23b-4610-8dc5-5214d335f7b6" ,
"value" : "2019-11-01T00:00:00+00:00"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "Metadata used to generate an executive level report" ,
"meta-category" : "misc" ,
"name" : "report" ,
"template_uuid" : "70a68471-df22-4e3f-aa1a-5a3be19f82df" ,
"template_version" : "5" ,
"timestamp" : "1657009711" ,
"uuid" : "79844e5f-4db1-493a-a006-20e5e4309117" ,
"Attribute" : [
{
"category" : "External analysis" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "link" ,
"timestamp" : "1657009711" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "a6d6f274-c7e0-4fb8-8c84-e8e66680a338" ,
"value" : "https://www.cisa.gov/uscert/ncas/alerts/aa22-181a"
} ,
{
"category" : "External analysis" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "link" ,
"timestamp" : "1657009711" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "3eceb8cf-bd52-4c01-a95f-5c1e60e75b35" ,
"value" : "https://www.cisa.gov/uscert/sites/default/files/publications/AA22-181A_stopransomware_medusalocker.pdf"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "summary" ,
"timestamp" : "1657009711" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "c4ccb926-906e-41ff-8588-f4380fde0638" ,
"value" : "The Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), the Department of the Treasury, and the Financial Crimes Enforcement Network (FinCEN) are releasing this CSA to provide information on MedusaLocker ransomware. Observed as recently as May 2022, MedusaLocker actors predominantly rely on vulnerabilities in Remote Desktop Protocol (RDP) to access victims\u2019 networks. The MedusaLocker actors encrypt the victim's data and leave a ransom note with communication instructions in every folder containing an encrypted file. The note directs victims to provide ransomware payments to a specific Bitcoin wallet address. MedusaLocker appears to operate as a Ransomware-as-a-Service (RaaS) model based on the observed split of ransom payments. Typical RaaS models involve the ransomware developer and various affiliates that deploy the ransomware on victim systems. MedusaLocker ransomware payments appear to be consistently split between the affiliate, who receives 55 to 60 percent of the ransom; and the developer, who receives the remainder."
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "type" ,
"timestamp" : "1657009711" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "81705f55-816b-4006-92c5-fb40d55adeb6" ,
"value" : "Alert"
} ,
{
"category" : "External analysis" ,
"comment" : "" ,
"data" : " J V B E R i 0 x L j Y N J e L j z 9 M N C j E 1 N T A g M C B v Y m o N P D w v T G l u Z W F y a X p l Z C A x L 0 w g N j Q 4 N z g z L 0 8 g M T U 1 M i 9 F I D Q w N T Y 4 M C 9 O I D E x L 1 Q g N j Q 4 M j I 1 L 0 g g W y A 1 O D g g N D M 2 X T 4 + D W V u Z G 9 i a g 0 g I C A g I C A g I C A g D Q o x N T k w I D A g b 2 J q D T w 8 L 0 R l Y 29 k Z V B h c m 1 z P D w v Q 29 s d W 1 u c y A 1 L 1 B y Z W R p Y 3 R v c i A x M j 4 + L 0 Z p b H R l c i 9 G b G F 0 Z U R l Y 29 k Z S 9 J R F s 8 M k Z B M 0 Y z N U U 0 Q z U 3 M 0 M 0 Q T h C O E N F R D M x N j R F R j Y 3 N T I + P D I 4 N j U 4 Q z B B N z g 4 O U J D N D Z B Q U M z N T Z G N z F F Q k Y 2 N j M y P l 0 v S W 5 k Z X h b M T U 1 M C A 3 M l 0 v S W 5 m b y A x N T Q 5 I D A g U i 9 M Z W 5 n d G g g M T c 0 L 1 B y Z X Y g N j Q 4 M j I 2 L 1 J v b 3 Q g M T U 1 M S A w I F I v U 2 l 6 Z S A x N j I y L 1 R 5 c G U v W F J l Z i 9 X W z E g M y A x X T 4 + c 3 R y Z W F t D Q p o 3 m J i Z G A Q Y G B i Y G D 5 A C I Z V o F I J k k Q y Z E B Z u u C y S Y Q y T o L r N I d L P I S T D 4 F i 8 i D 2 V 0 g k n E R W O U E s L g T m B Q H i + u B x W V A p P U K E M n s A h Y P A 5 H 8 n 4 E k 4 + Z M E D t 3 K Y h U U g K R q l k g 8 d T / I L b e D x D p + w R s V y G I l O 0 H s 3 O B J J O C I o j N l Q w i s 4 R B Z H o k W E Q C Z E L K c h C b O x 5 I / p 7 r w c D E y M A 2 F + x f B s Y h Q / 5 n + G P 9 G C D A A B q W H O A N C m V u Z H N 0 c m V h b Q 1 l b m R v Y m o N c 3 R h c n R 4 c m V m D Q o w D Q o l J U V P R g 0 K I C A g I C A g I A 0 K M T Y y M S A w I G 9 i a g 0 8 P C 9 D I D Q w N i 9 G a W x 0 Z X I v R m x h d G V E Z W N v Z G U v S S A 0 M j g v T G V u Z 3 R o I D M 0 M C 9 P I D M 5 M C 9 T I D I 3 N j 4 + c 3 R y Z W F t D Q p o 3 m J g Y G A C o m 8 M b A w M Q t s Y h B k Q Q J i B F S j K w s A x I Q D E 5 T E 4 c F i L i V e D s a n B b g L v B k Y b o B j j b b b 6 A 8 + u G F Y 39 I R N W a q d / I g B G Q g c k 5 l 5 T p N z k q 9 b a G S B s 0 T R M k e 30 B i B Y 3 I p I q k B z h K V E w K n O v I k P g M K s h i 2 z 2 S V D A G p B w q G A b l q l V C G x c x n j i p X U k M b e R L P q W h C 2 D M Y m J T N K j o 6 O h o Y G J X T Q Q w G B v Y K I A 9 I M D C U I z P Y y k G S j G B S 0 L 0 C r E U U r A W P X 4 A c Z Q a O o L l A W g 2 I N c C e C W M Q Z H j Y e K T B 6 o H S A S U F / i P M a o z 9 j E 8 a f B k 0 G 5 w X y C f w s z B u Y D 4 m u 5 J h N 1 D 7 y 6 s z Z m 60 c Z 6 h K m I U 0 p 3 R O f G A 4 I a X J 1 j i 7 K d x 8 Z r c m 9 l w 0 M L N V S D A 22 S X w z T G u b D A U m X g L D U E O Q O I l o N t 5 i y 7 A a T 5 G R h C d s C D 1 J y B 80E4 R B W T O E C A A Q C M I n X c D Q p l b m R z d H J l Y W 0 N Z W 5 k b 2 J q D T E 1 N T E g M C B v Y m o N P D w v T G F u Z y j + / w B F A E 4 A L Q B V A F M p L 0 1 h c m t J b m Z v P D w v T W F y a 2 V k I H R y d W U + P i 9 N Z X R h Z G F 0 Y S A 1 M y A w I F I v T 3 V 0 b G l u Z X M g N z E g M C B S L 1 B h Z 2 V M Y X l v d X Q v T 25 l Q 29 s d W 1 u L 1 B h Z 2 V z I D E 1 N D Y g M C B S L 1 N 0 c n V j d F R y Z W V S b 290 I D g 0 I D A g U i 9 U e X B l L 0 N h d G F s b 2 c + P g 1 l b m R v Y m o N M T U 1 M i A w I G 9 i a g 0 8 P C 9 B b m 5 v d H M g M T U 5 M S A w I F I v Q 29 u d G V u d H N b M T U 1 N i A w I F I g M T U 1 N y A w I F I g M T U 2 M C A w I F I g M T U 2 M y A w I F I g M T U 2 N C A w I F I g M T U 2 N S A w I F I g M T U 2 N y A w I F I g M T U 2 O S A w I F J d L 0 N y b 3 B C b 3 h b M C 4 w I D A u M C A 2 M T I u M C A 3 O T I u M F 0 v R 3 J v d X A g M T Y y M C A w I F I v T W V k a W F C b 3 h b M C 4 w I D A u M C A 2 M T I u M C A 3 O T I u M F 0 v U G F y Z W 50 I D E 1 N D c g M C B S L 1 J l c 291 c m N l c z w 8 L 0 V 4 d E d T d G F 0 Z T w 8 L 0 d T M C A x N T k 1 I D A g U j 4 + L 0 Z v b n Q 8 P C 9 D M l 8 w I D E 2 M D A g M C B S L 1 R U M C A x N j A y I D A g U i 9 U V D E g M T Y w N C A w I F I v V F Q y I D E 2 M D Y g M C B S L 1 R U M y A x N j A 4 I D A g U i 9 U V D Q g M T Y x M C A w I F I v V F Q 1 I D E 2 M T I g M C B S L 1 R U N i A x N j E 0 I D A g U i 9 U V D c g M T Y x N i A w I F I + P i 9 Q c m 9 j U 2 V 0 W y 9 Q R E Y v V G V 4 d C 9 J b W F n Z U N d L 1 h P Y m p l Y 3 Q 8 P C 9 J b T A g M T U 2 O C A w I F I v S W 0 x I D E 1 O D I g M C B S L 0 l t M i A x N T g 0 I D A g U i 9 J b T M g M T U 4 N S A w I F I v S W 0 0 I D E 1 O D c g M C B S L 0 l t N S A x N T g 5 I D A g U j 4 + P j 4 v U m 90 Y X R l I D A v U 3 R y d W N 0 U G F y Z W 50 c y A w L 1 R h Y n M v U y 9 U e X B l L 1 B h Z 2 U + P g 1 l b m R v Y m o N M T U 1 M y A w I G 9 i a g 0 8 P C 9 G a W x 0 Z X I v R m x h d G V E Z W N v Z G U v R m l y c 3 Q g M j g 3 L 0 x l b m d 0 a C A x N z k 2 L 0 4 g M z A v V H l w Z S 9 P Y m p T d G 0 + P n N 0 c m V h b Q 0 K a N 60 m W 1 T 2 z g Q g P + K P s J 0 i C V Z r 51 O 5 p J Q a O a g t I S W X p l 8 M I k B D 0 m c S U x b / v 3 t S r Y T u 3 n v 3 X i M Z W l X u 5 K e X c m B S c s I J U x a T q T E Z 0 i Y V l g Q h F u D B U k E d y K K S O a a N J H K N R l i m M C C J V Z x w h S l x G p X Y I R R Y 7 E E r y F n W I K + j V F Y g s 4 Z l 1 i S h K v Q Y E k R b o z A k i Y h s 0 7 O k F C E r s 6 S 0 E i s Y 5 Q I x k I s M S K k p F j i R B i G / U G D Z O i 3 A s e k U K 5 V E m m k x p I i o O X k N F F C o F f M Q M m i z 8 w S J U P U g P E q q R m 5 c x N D y b W f m b w g 8 g K 4 n R f K G i f c f / c u a H k b 8 B a 0 e / D e g + v m d R o H 7 X Q 2 j G f B L a H N Z v 5 y R 0 G O 9 o M P Q T e 4 j g c Z W J U N 45 w z D Z w q D Q 8 D X s P T K t E P e i / 3 G f Z 1 k U y e f a + t y S T N m s 3 C s D n U s G Y N Z W C m u G j A x B M u Z E P A 4 r J Q N r j S O 1 i 2 B 1 o W X D b A C p G 8 o a 0 x R I a s I c O Q q L C h O b d b L H d 75 C E a z c H U Z f A x n Y 2 j U d A B d x o 0 u P q U t 1 x 9 u i Q s 6 L V I N n u J g 95 l N H 8 G 0 U n s + 3 r / K z v v Z V E W B 4 P I 6 a V T r + f 6 v 0 K X k 8 n j U X c Y T 7 I k e z 0 G p x + T e T Z 7 P W o N 0 / v 4 G N y b T k f x G J p x l O j T f I A v j F I Z d L q n v R j K U l M 3 P Z 1 o + i F O H p 8 y o i k N T m M v e s I 5 D c 5 G 0 e O c i O A s n W T t d v o L J g r r C X P I Q 2 d 913 Q W j Z P R 61 H v d X y f j o 59 V T K K O d p g z g Z W f Y z G c X D 76 Z / 33 Y s 3 X v T y x j X 0 s l m c D Z 6 K u c K q W + + Q A I e 6 W T R K B q 3 J 4 y g m N O h l 8 f g r 0 d J P F I q i w 7 N k m q W z 4 F s + D k n 9 q N v R P E a R 36 z i F L z O o a v u 5 C H 1 y c T N R P f 0 J j 3 v n l 5 G 0 6 C Y 3 O D 0 F k d K a 7 Z 84 k G l A g V Q R h H 0 i y + 8 C 27 v G K d 3 E P r 9 f r N 557 J U H p R r v f N L M I x g F q F 57 j M a m n o / G a R D W P n S u Z M P p X m 0 S I O b 9 M s k A a E Y l J Q f V O l K F Q R B l x e e q c X C h 1 z m C x / y x c q f K C V d G + E w G 66 D y u K 3 Z k l U X 3 t e X f v O 1 / O b q + 9 v n O T B S 2 / M 5 q V n t r r 0 N a P l F N 4 m k 9 Z k n p T v Z 8 l s n n W e o l k x 6 u W 1 x g 0 E h 3 I R 5 T J M s s X M Q w g 7 l 5 Y n H 7 a v y u S D v W H 2 N L + D 7 I k Z F P M N b H G 4 Q k p B h o N 9 L 4 T 8 g j e 2 o A S W C 2 m U 3 O V e 7 h 0 v R m F 7 Q Q N 4 Q + Z y t 3 u H 3 U q D I L 47 A 9 Q 7 g p 0 Y M O x k o d 7 p 5 X K l X l 62 Q p R 9 Y 7037 P / 6 o Z W u U V p x s S y j d b i x H Z 9 o u T 4 k n A b X X u h B W e c 6 x b 3 f h Z a W J x u j u 78 c H N a a 7 b F h 1 V J s S N h c X W z A p m F R f 2 t o q G p o n F 91 r n v X n t I T j / 3 e E X L C e B 4 j l u 8 X I 6 u t H x o q Y S 1 U h N k S K m J 9 q F A S Q i R 5 m v y 1 K U x W r v Y + I U E r A U F L w 0 U o 0 L W B 8 L v h / x P + Q 9 E v p 69 f 3 Q x Y F X i 5 B L x W K 4 G H o y y 2 A f D W z e l 24 k 2 V + M 8 X r e + d b z l z 7 X Q 0 3 J F 6 v Z Z 6 B l v a X t i v d 2 E H 9 K V Z g b 6 s o Q + p Y y P 62 q 5 G v w C 8 e v m V 3612 N Y / V v 7 R M 1 / 5 p D L r j 4 w B I g b e c w R o t U q 1 N j y U t 1 a M D N 56 W / O g g 1 V Z a w i 207 M 1 J c X 5 g o f p D S v 4 g N e o a H 3 z b K c J u S o 2 H x P 4 q c l Z n Q F q y s H w Y K L S K / E c 3 Z D + U W X 6 i f S w v D g t F T k T y i p b i X u K v 7 E E v 8 m d 1 x 5 Z i C U n w c w n J k K
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "report-file" ,
"timestamp" : "1657009711" ,
"to_ids" : false ,
"type" : "attachment" ,
"uuid" : "0ea5c6a7-d215-4c63-b8cc-7dccfad867ea" ,
"value" : "AA22-181A_stopransomware_medusalocker.pdf"
}
]
}
2023-04-21 13:25:09 +00:00
]
2023-12-14 14:30:15 +00:00
}
2023-04-21 13:25:09 +00:00
}