"comment":"\"HTTP POST traffic on port 8080 to copayapi.host (which currently resolves to 51.38.112.212 and previously resolved to 145.249.104.239) or 111.90.151.134 indicates compromised and exfiltrated wallet private keys.\"",
"deleted":false,
"disable_correlation":false,
"timestamp":"1543268542",
"to_ids":true,
"type":"domain",
"uuid":"5bfc68be-0b50-47a2-a33e-16c502de0b81",
"value":"copayapi.host"
},
{
"category":"Network activity",
"comment":"\"HTTP POST traffic on port 8080 to copayapi.host (which currently resolves to 51.38.112.212 and previously resolved to 145.249.104.239) or 111.90.151.134 indicates compromised and exfiltrated wallet private keys.\"",
"deleted":false,
"disable_correlation":false,
"timestamp":"1543268543",
"to_ids":true,
"type":"ip-dst",
"uuid":"5bfc68bf-51a0-4f93-84ff-16c502de0b81",
"value":"51.38.112.212"
},
{
"category":"Network activity",
"comment":"\"HTTP POST traffic on port 8080 to copayapi.host (which currently resolves to 51.38.112.212 and previously resolved to 145.249.104.239) or 111.90.151.134 indicates compromised and exfiltrated wallet private keys.\"",
"deleted":false,
"disable_correlation":false,
"timestamp":"1543268543",
"to_ids":true,
"type":"ip-dst",
"uuid":"5bfc68bf-4798-421d-b09f-16c502de0b81",
"value":"145.249.104.239"
},
{
"category":"Network activity",
"comment":"\"HTTP POST traffic on port 8080 to copayapi.host (which currently resolves to 51.38.112.212 and previously resolved to 145.249.104.239) or 111.90.151.134 indicates compromised and exfiltrated wallet private keys.\"",
"deleted":false,
"disable_correlation":false,
"timestamp":"1543268544",
"to_ids":true,
"type":"ip-dst",
"uuid":"5bfc68c0-af3c-4165-8243-16c502de0b81",
"value":"111.90.151.134"
},
{
"category":"Attribution",
"comment":"copayapi.host's SOA record indicates the domain registrant's email address is \"kvlguuvh@sharklasers.co\" (very likely a throwaway email address).",
"deleted":false,
"disable_correlation":false,
"timestamp":"1543268846",
"to_ids":true,
"type":"dns-soa-email",
"uuid":"5bfc68ef-2698-4780-b1f5-45c902de0b81",
"value":"kvlguuvh@sharklasers.co"
},
{
"category":"Social network",
"comment":"The GitHub account of the event-stream hijacker: https://github.com/right9ctrl (email address right9ctrl@outlook.com)",
"deleted":false,
"disable_correlation":false,
"timestamp":"1543268635",
"to_ids":false,
"type":"github-username",
"uuid":"5bfc691b-da14-4228-997c-40e802de0b81",
"value":"right9ctrl"
},
{
"category":"Network activity",
"comment":"The NPM account of the event-stream hijacker: https://www.npmjs.com/~right9ctrlh",
"deleted":false,
"disable_correlation":false,
"timestamp":"1543268714",
"to_ids":false,
"type":"url",
"uuid":"5bfc696a-2a8c-4e1d-9f1c-4ef902de0b81",
"value":"https://www.npmjs.com/~right9ctrl"
},
{
"category":"Network activity",
"comment":"The GitHub repo for the malicious flat-map package: https://github.com/hugeglass/flatmap-stream",