2023-12-14 14:30:15 +00:00
|
|
|
{"Event": {"info": "M2M - Locky Affid=3/Trickbot \"mac1\" 2017-10-24 : \"Scan\n Data\" - \"Scan_654321.doc\"", "Tag": [{"colour": "#ffffff", "exportable": true, "name": "tlp:white"}, {"colour": "#006c6c", "exportable": true, "name": "ecsirt:malicious-code=\"ransomware\""}, {"colour": "#0088cc", "exportable": true, "name": "misp-galaxy:ransomware=\"Locky\""}, {"colour": "#0088cc", "exportable": true, "name": "misp-galaxy:tool=\"Trick Bot\""}], "publish_timestamp": "0", "timestamp": "1508919794", "analysis": "1", "Attribute": [{"comment": "", "category": "Artifacts dropped", "uuid": "59f04970-5654-4d7f-a5f6-4900950d210f", "timestamp": "1508919785", "to_ids": true, "value": "8b746248f1b810ce11e231acc5953510", "disable_correlation": false, "object_relation": null, "type": "md5"}, {"comment": "", "category": "Artifacts dropped", "uuid": "59f04970-451c-4d46-9990-44c9950d210f", "timestamp": "1508919785", "to_ids": true, "value": "73e6d72a8d7707eeef0a1b670404796c", "disable_correlation": false, "object_relation": null, "type": "md5"}, {"comment": "", "category": "Artifacts dropped", "uuid": "59f04970-5574-4c89-80d3-415f950d210f", "timestamp": "1508919785", "to_ids": true, "value": "6bf84d641c52c1d222986901006e854d", "disable_correlation": false, "object_relation": null, "type": "md5"}, {"comment": "", "category": "Network activity", "uuid": "59f04970-8654-4ec8-a61f-4e6e950d210f", "timestamp": "1508919785", "to_ids": true, "value": "http://boydcanvas.com/JHhdg33", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "", "category": "Network activity", "uuid": "59f04970-62d8-45c0-b802-42c9950d210f", "timestamp": "1508919785", "to_ids": true, "value": "boydcanvas.com", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "boydcanvas.com", "category": "Network activity", "uuid": "59f04971-ed94-4507-bcde-4f79950d210f", "timestamp": "1508919785", "to_ids": false, "value": "72.11.0.73", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "", "category": "Network activity", "uuid": "59f04971-7bdc-4dc3-9780-4bf6950d210f", "timestamp": "1508919785", "to_ids": true, "value": "http://bunder.nl/JHhdg33", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "", "category": "Network activity", "uuid": "59f04971-a530-453c-a589-4f76950d210f", "timestamp": "1508919785", "to_ids": true, "value": "bunder.nl", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "bunder.nl", "category": "Network activity", "uuid": "59f04971-d7cc-4d93-9aed-4014950d210f", "timestamp": "1508919785", "to_ids": false, "value": "85.17.104.144", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "", "category": "Network activity", "uuid": "59f04972-1760-4309-8c2a-445f950d210f", "timestamp": "1508919785", "to_ids": true, "value": "http://burka.ch/JHhdg33", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "", "category": "Network activity", "uuid": "59f04972-7f44-4f2b-b68c-4e93950d210f", "timestamp": "1508919785", "to_ids": true, "value": "burka.ch", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "burka.ch", "category": "Network activity", "uuid": "59f04972-cc3c-49c5-95f8-476f950d210f", "timestamp": "1508919785", "to_ids": false, "value": "94.231.83.185", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "", "category": "Network activity", "uuid": "59f04972-0fdc-43c6-b961-4fc9950d210f", "timestamp": "1508919785", "to_ids": true, "value": "http://bwos.be/JHhdg33", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "", "category": "Network activity", "uuid": "59f04972-9138-43ec-b6d7-415d950d210f", "timestamp": "1508919785", "to_ids": true, "value": "bwos.be", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "bwos.be", "category": "Network activity", "uuid": "59f04973-db0c-44f9-b901-4638950d210f", "tim
|