2023-04-21 13:25:09 +00:00
|
|
|
{
|
2023-12-14 14:30:15 +00:00
|
|
|
"Event": {
|
|
|
|
"analysis": "0",
|
|
|
|
"date": "2016-07-18",
|
|
|
|
"extends_uuid": "",
|
|
|
|
"info": "Malspam 2016-07-18 .wsf->.gif (campaign: \"RE: firstname.lastname\")",
|
|
|
|
"publish_timestamp": "1468848929",
|
|
|
|
"published": true,
|
|
|
|
"threat_level_id": "3",
|
|
|
|
"timestamp": "1468848886",
|
|
|
|
"uuid": "578cd192-e448-45a8-abca-497a950d210f",
|
|
|
|
"Orgc": {
|
|
|
|
"name": "CIRCL",
|
|
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
|
|
},
|
|
|
|
"Tag": [
|
|
|
|
{
|
|
|
|
"colour": "#ffffff",
|
2024-04-05 12:15:17 +00:00
|
|
|
"local": false,
|
2023-12-14 14:30:15 +00:00
|
|
|
"name": "tlp:white",
|
|
|
|
"relationship_type": ""
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"colour": "#3a7300",
|
2024-04-05 12:15:17 +00:00
|
|
|
"local": false,
|
2023-12-14 14:30:15 +00:00
|
|
|
"name": "circl:incident-classification=\"malware\"",
|
|
|
|
"relationship_type": ""
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"Attribute": [
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "download location",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1468846566",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "url",
|
|
|
|
"uuid": "578cd1e6-e39c-4f9f-89ad-44cd950d210f",
|
|
|
|
"value": "http://hotgoolrw.top/admin.php?f=1.gif"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "download location",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1468846566",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "filename",
|
|
|
|
"uuid": "578cd1e6-462c-4373-9a98-470c950d210f",
|
|
|
|
"value": "hotgoolrw.top"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "download location",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1468846567",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "ip-dst",
|
|
|
|
"uuid": "578cd1e7-89f0-401a-a679-4be5950d210f",
|
|
|
|
"value": "23.95.114.10"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "actual malware",
|
|
|
|
"data": "UEsDBBQACQAIADds8khwG1/LAGkDAIa4AwAgABwANzdjYTZkMDY1NDRmN2EwNmFiYzY4ZDQ3M2YwZDhmYjhVVAkAA7najFe52oxXdXgLAAEEIQAAAAQhAAAA276ZOMkxln65VJFrX6m4oRC7tYKOrhkR8ezx6N7c47ryjZD4XCc0WYVQHnCWowTpuruLdmAkU7XfyXJjKmyLRwBQDcGaL8H7e8qsEZBbId0gjhvH8uMcoIE99tDqqd6Dki3Xk6FVh4drpyIWBm4q+aYdJWF5M863XMlcXeDLhhQe8pcDVIC0BzC8n4sf85sS98tFOuG7eSET00L+QOlwqAGY2bZXqeUp796BLveWVsX7Z8/5lkxzfcrw0luoVgYXMaS+NxeNDAvuJa2wfAD0w5m2cM8jtGW7Vlgxa5yUkKECki6C+z6rQ4VhmjSC6lFf5/4zsPmMsNWibtp/pJxrF20cTEaoD6AN2PHm2OCdGNy8eMRsMepDkKli1AnJPbaJrPEbu+VK2npKI5KPRgl4ZxnJiqxkfkgqybFgzRBB+MJBJfcxsL4tefsyJd6wjdqZ6Or/ZhmJ8kKeFsxAebA+OycyvURwUj8paVynmPrlMFdeSirukxiZVop0AWFE41O0k7dkq/jW9zcYbFr5HF3GNBtBQbsJLvBqswDS8xILpm2FL936g1Izl4sS5S3p2CZswVbag9Jk1FMpLXJuts4Pug8JB8AqEY5WuajcNNHZYbj1Bg6oO8i87CdvQBewXBSROc43GdgyWeg3AYF6+NImOmI0SnsV6JZ/5b6kSERKDezG0Xicb6sb1a1PKhQ3U1i+tVSPzH6pAAGvEWF4zsYSiDjLSHcCXaVEKimeywSUQxwSDzJgyDnqURRkCsRLlcq1G4XhpJzs20vwhsfP7WV1E/04tbJrPlfPS09FazOV7VTALlHoZlPXIMemAp7yrEudtRXFd0BJNNBv+LvRveSsvPDl+gKRtAGzSl0w9wTMVldOA+F6cktTmC1M1wTJ/0n2E6T0y7u1Ebx/J+kG3+4aAjzcTpRnQ569ABM28IaFgVuPPYLOVdB/eqed/OULFNaGFcIf2glv2OgzOr0VpXMbndaoh+uo1PB2+jkuH/WzuZ9SYRiYUPigT1ezNgmL7yQhAFOjHJnt7ULZStTtRsxCXCzImrpQr9vMvGH75LwC4NjwLBOo7ywSZL8T9Tqep6h0+Nrlr2UzRYDtSbkmdJ8PoC2Iq0NQzUmE3X/Y/IHZUk1m7SqecYuZSd5eaA7excd6MmoFNPWbF2j4lhKg2HcTCLvjPZ3IdphQ0yo0EGNMjVEVMdDaHGH2cJZjXec8COylR0T8y91WRlT5WEpFUNdEAO3fFiaJh3cjl+9oFO7AVci+QqiAmTsymBoOP9UjIeWllDGTHSV5ki8UOC/HQqVHEZN9KmaOTMDePVjbFByuk3sLAYwZ8w7qcL92qsWDwMKwqXXzzMQBebGEtAsuutFDGKzgly+4sbZ+002Q9TSVKbNtPEf1YlIV479peCleiGlz3wDTEXdvJwCa/+b0RluhkSgOO6p0qBoXbhVOeMIskg3VUIoW+gyIeCqKMs7vG7s5aCI60VrAG0Ol1PIp1NBGsmQH7MoEX8L5JN73nnHjnoAFW6MVfurNpHJsJq4At5pWMjeJS/FD5hg3e49wPs/kjkKUqUzSS32f8tzoKUHAbwwMjrHZCkVHp3RuBXamGE1KpZRIOrhazdtUCqoUUmNn2HIIMNaY9Y3zylC4aO9HXq186EMWfi61neluT9RjIMWv0c1JQF/7uPYNqOPrMgh/fL3WVoTVglr0lwlfXaQceRf9bb499PuNucBZ/hPnAIzBEghwhmQNlLxdCM6KbQisESYbdC9kRlqoiAhoovETgt0dsqvMqyav43NWQ4JV6MikIC4un8zdanMhOCnZkyVzOGE1uKihS0wyZBBvwqpGu6CDVus9ZaSp3oD4e7QQA1oFo6Jd0lPM16FyvVvNzYqVzJUq+ws+rsvCB2ctuuQGawvgY7O0+cmjazmFVogm1sISguZaIv5jqno5MSTEquIW6pmIxgCymkBy4jy9b83/Cv148fooc5quMxd1Qlj+b8yKwb8Yi9N3Nqq5/qfkO9oYb0zb/FUekHQiP/kpA4v6wlODn2ISglHMZOnVmviDRB82cS4C2q+zKzOCT6xh13olOzqpIH/MCU/CDjNJTGTrHr2K9KTF8tfXX4qO6pXYqfnoE413MyJTfw4PGVBO5d24uhO/loUlQLQAwG6ZpyhEKQ7OwXh59LJ6qIJu0GPN0neIn+8H0i9pEJxqtBf2aqEZhlGJsw7VQImcBdb14CKIjWmfzXedl5GwX05UWUzAiWtudaLjAE6MOzReP99H5BzarmLrG2kmphX4TjWM4muv1lLYxrpURdvKyztNjT7CSZzBiHCoNlh2V5FA3j4PpxV8zazM5WiirzO+z+CGAoRHpBYfdP9BemxBG0yOAvPS4aMmrStcbxt1kfv7icIotR2WRBoU2tY4gEuhCCOvOou/qNuuhXcAkYiqL0J6km7a/myFcdJKP8pfsdp/7wU2dTVYxqFzh12PoUd+TLbOD2HkQ/RpWmMyS/yuZFHPHTgf/PZBUNokC7SYWHLuYZI1lxp82eK0lD6vIWacDAinA5st6gVwKZfaX/oTgQWiD7U2vFuGhnL/pGQx9WsuktbGoNT0yojBj1ZaTXEdIgk9GeqQny0+RSyoqImbA7EUYao33CKcKi9fWalH8hcv1YGMn/OecWjoOMCbLVcyj3VcXrJ19WTx3UnOoXD5dmnPPBB0Q52XWiY5aNNcJH7xlZMgxZ8dBgbWGBJQGY2Zgf+ssLjxSjv7PLkg0RuzHqugXwzdJZY30n7k4q+h6n9UlgYk9Ji7FCDSfq1uKIMKey7eXSNuu6PXQB3iXyypbyhCK244+xsBMT5iqnhPIx4YK6dXgsHDyTJ7LQkpsEjLtbOpQRVCwd9te2Zqtm3YqwE8ZXiUe8dmNvdcHT+/TGla8wZlb38Ukacc7By1ICGgvrxtwaMbQ+eU5XUMaCaQ0kFtP0DIJ5zCYzDI7iV5ojkSHJkaaFk6ohVJ3GFQw6h2+0has6kgMRtL63xpyRNJ+t/1PikYgURhcHWi94+5NBBC02gtnO/LiJ+h/eukwnAp3zh9u8AJ7EitSIaXR/vr+0OcBbyzkLYL0R8J6CuEiQD5mLZXuB4AiXB/9kafpU8EXRXjh9w9AygCuJBfqMLvOwW03w01gK5iwj/nLWmignx0vkWL48y6k+gbzF8HamS2xA+Em2VDaAcPVy9AUEgVTQSdvbD1JOCF1PbYxPq4xDrGeuoQ4qwbfSTFlqF5wK6eU5uCiJq32v3FnB2iaAQinLDaagkyLoSegbAqGYf46k2MQck8Vm3q076HjxiC9RpRvdLIiiS/bQhA0/t1R9jHvq/Dx7G8DUBNOUaN4PH6widW7LDAuxHzLFiEl6ERse4O4of7l10HKSXkPLeaRYAF4YwkTqSAQ9yBeiY0nn6CPxYLlujZLCBTwBg/Myvkur5JWESFCASYT5ejzt3lO1pbzTXW3g2X4crp52Ce6rcvKG9RWGYqx/ICFbmv2yTPelOSa+T5D1PP6/MLm448XdNsnaoPX+zL/uSVVwnAtN/Tk27FKVMe0rWRJ7BwT4AZuWAyKhFp3H1fVQm1AcpABFCl4ZTB4nMplxUjb8c7lepYLr1B61h+G0zABWdFux7nW/3MwIw/wzxd4H4OLlQ1QFTUoXf11pnLQbOUxR0UkQEkvIDy/B54imtSHcJQKU0hGceRlWk9GFRddZrtVPvGSvxRVPyfqFGG4gsw3FI6xjIiJAv/aad++O3o6yhD6NvN9GLk97HgaASYswS/pbxS7bIogXA+VHIZqS0u0qHa1p2O82sJ7G2/MZzP5EVD1+wvawhyJx+BCGftYTbOybN7pMGHr0Qqys0RVbELE3jxM7MSohYCryyiVhu7bTQ5sc21G7RqimmEJzLa2NT7WEUjrwh1tXsvCXVo6skKZ4fLdDj25q3gu8iVqfMOoXdd0YlzdS2iKByrmqSQlaz53P/j/OyW2q
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1468848839",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "malware-sample",
|
|
|
|
"uuid": "578cdab9-78c4-489f-8a5f-4586950d210f",
|
|
|
|
"value": "1.gif|77ca6d06544f7a06abc68d473f0d8fb8"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1468848826",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "filename|sha1",
|
|
|
|
"uuid": "578cdaba-3008-431f-b7d2-44a4950d210f",
|
|
|
|
"value": "1.gif|bc4bde1cee2e29324f967f7966c38e174a41a992"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1468848827",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "filename|sha256",
|
|
|
|
"uuid": "578cdabb-00c8-43d6-a797-4b97950d210f",
|
|
|
|
"value": "1.gif|49a7b3f92077a131aaac8a3ce2cb335542d137296f6ddc820495b7b4feac495c"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "- Xchecked via VT: 49a7b3f92077a131aaac8a3ce2cb335542d137296f6ddc820495b7b4feac495c",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1468848886",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "link",
|
|
|
|
"uuid": "578cdaf6-8720-469c-a1d7-42ea02de0b81",
|
|
|
|
"value": "https://www.virustotal.com/file/49a7b3f92077a131aaac8a3ce2cb335542d137296f6ddc820495b7b4feac495c/analysis/1468848626/"
|
|
|
|
}
|
2023-04-21 13:25:09 +00:00
|
|
|
]
|
2023-12-14 14:30:15 +00:00
|
|
|
}
|
2023-04-21 13:25:09 +00:00
|
|
|
}
|