{"Event": {"info": "OSINT - Igexin advertising network put user privacy at risk", "Tag": [{"colour": "#850048", "exportable": true, "name": "workflow:todo=\"create-missing-misp-galaxy-cluster-values\""}, {"colour": "#ffffff", "exportable": true, "name": "tlp:white"}, {"colour": "#00223b", "exportable": true, "name": "osint:source-type=\"blog-post\""}, {"colour": "#211c1c", "exportable": true, "name": "Android Malware"}, {"colour": "#001a40", "exportable": true, "name": "ms-caro-malware-full:malware-platform=\"AndroidOS\""}], "publish_timestamp": "0", "timestamp": "1521801926", "analysis": "2", "Attribute": [{"comment": "", "category": "External analysis", "uuid": "5ab38772-7708-4eaa-89e2-442e950d210f", "timestamp": "1521795039", "to_ids": false, "value": "https://blog.lookout.com/igexin-malicious-sdk", "Tag": [{"colour": "#00223b", "exportable": true, "name": "osint:source-type=\"blog-post\""}], "disable_correlation": false, "object_relation": null, "type": "link"}, {"comment": "", "category": "Network activity", "uuid": "5ab4ab2b-92d8-4dff-9ce3-4e4e950d210f", "timestamp": "1521789739", "to_ids": true, "value": "http://sdk.open.phone.igexin.com/api.php", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "", "category": "External analysis", "uuid": "5ab4ab77-e424-444d-ae43-4d9e950d210f", "timestamp": "1521795046", "to_ids": false, "value": "The Lookout Security Intelligence team has discovered an advertising software development kit (SDK) called Igexin that had the capability of spying on victims through otherwise benign apps by downloading malicious plugins. Over 500 apps available on Google Play used the Igexin ad SDK. While not all of these applications have been confirmed to download the malicious spying capability, Igexin could have introduced that functionality at their convenience. Apps containing the affected SDK were downloaded over 100 million times across the Android ecosystem.", "Tag": [{"colour": "#00223b", "exportable": true, "name": "osint:source-type=\"blog-post\""}], "disable_correlation": false, "object_relation": null, "type": "comment"}], "extends_uuid": "", "published": false, "date": "2017-08-21", "Orgc": {"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f", "name": "CIRCL"}, "threat_level_id": "3", "uuid": "5ab3841d-971c-47f8-9324-45d9950d210f"}}