7109 lines
No EOL
239 KiB
JSON
7109 lines
No EOL
239 KiB
JSON
{
|
|
"Event": {
|
|
"analysis": "0",
|
|
"date": "2019-09-20",
|
|
"extends_uuid": "",
|
|
"info": "OSINT - Emotet Updated C2 Info 9/20",
|
|
"publish_timestamp": "1575971434",
|
|
"published": true,
|
|
"threat_level_id": "3",
|
|
"timestamp": "1569224580",
|
|
"uuid": "5d886859-bb5c-45b5-b922-4925950d210f",
|
|
"Orgc": {
|
|
"name": "CIRCL",
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
},
|
|
"Tag": [
|
|
{
|
|
"colour": "#0088cc",
|
|
"local": false,
|
|
"name": "misp-galaxy:banker=\"Geodo\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#0088cc",
|
|
"local": false,
|
|
"name": "misp-galaxy:malpedia=\"Emotet\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#0088cc",
|
|
"local": false,
|
|
"name": "misp-galaxy:malpedia=\"Geodo\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#0088cc",
|
|
"local": false,
|
|
"name": "misp-galaxy:mitre-malware=\"Emotet - S0367\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#0088cc",
|
|
"local": false,
|
|
"name": "misp-galaxy:tool=\"Emotet\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#004646",
|
|
"local": false,
|
|
"name": "type:OSINT",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#0071c3",
|
|
"local": false,
|
|
"name": "osint:lifetime=\"perpetual\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#0087e8",
|
|
"local": false,
|
|
"name": "osint:certainty=\"50\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#ffffff",
|
|
"local": false,
|
|
"name": "tlp:white",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#002642",
|
|
"local": false,
|
|
"name": "osint:source-type=\"microblog-post\"",
|
|
"relationship_type": ""
|
|
}
|
|
],
|
|
"Object": [
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "Microblog post like a Twitter tweet or a post on a Facebook wall.",
|
|
"meta-category": "misc",
|
|
"name": "microblog",
|
|
"template_uuid": "8ec8c911-ddbe-4f5b-895b-fbff70c42a60",
|
|
"template_version": "7",
|
|
"timestamp": "1569222450",
|
|
"uuid": "5d886f32-8f08-47e7-9a75-4d01950d210f",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "post",
|
|
"timestamp": "1569222450",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "5d886f32-6a44-48bf-ac41-4e53950d210f",
|
|
"value": "#Emotet Updated C2 Info 9/20"
|
|
},
|
|
{
|
|
"category": "Other",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "type",
|
|
"timestamp": "1569222451",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "5d886f33-1c68-4fce-afd3-4ebf950d210f",
|
|
"value": "Twitter"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "embedded-link",
|
|
"timestamp": "1569222451",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "5d886f33-426c-48d0-be5d-4ffe950d210f",
|
|
"value": "https://t.co/VF5P9PbOZ0?amp=1"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "embedded-link",
|
|
"timestamp": "1569222451",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "5d886f33-7640-4f93-86ab-4ed0950d210f",
|
|
"value": "https://pastebin.com/J6gWAUp6"
|
|
},
|
|
{
|
|
"category": "Other",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "username",
|
|
"timestamp": "1569222451",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "5d886f33-8e48-4a77-b26b-406a950d210f",
|
|
"value": "lazyactivist192"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "link",
|
|
"timestamp": "1569222451",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "5d886f33-c294-45f8-98a8-4653950d210f",
|
|
"value": "https://mobile.twitter.com/lazyactivist192/status/1175123567220051969"
|
|
},
|
|
{
|
|
"category": "Other",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "state",
|
|
"timestamp": "1569222451",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "5d886f33-fcd0-4119-9607-40af950d210f",
|
|
"value": "Informative"
|
|
},
|
|
{
|
|
"category": "Other",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "creation-date",
|
|
"timestamp": "1569222451",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "5d886f33-0dfc-4efa-bce0-4082950d210f",
|
|
"value": "2019-09-20T21:04:00"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223435",
|
|
"uuid": "76a41ee3-91f6-4b02-a0c5-48ba294c6232",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223436",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "b5f5937f-255d-432a-ba61-babd383d2192",
|
|
"value": "190.117.206.153"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223436",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "c68d2d47-ffff-43e7-9272-d9e7b4c4bb4b",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223436",
|
|
"uuid": "a2fcc428-aab0-4f80-8030-6a0d13218fdf",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223437",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "3b59f0a9-7d79-46e9-a0ed-85c99eb83908",
|
|
"value": "179.62.18.56"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223437",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "3714ba0f-1e69-48f7-b246-7ca6fd83c506",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223437",
|
|
"uuid": "08bcd0be-171e-4d6c-b581-be191a3ce004",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223437",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "9ae3c85e-a8d4-48c4-b75a-9b5851c47073",
|
|
"value": "123.168.4.66"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223437",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "20ad7abc-b76c-4f34-aee7-912dc6fea5ea",
|
|
"value": "22"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223438",
|
|
"uuid": "9f58478d-390c-4962-94ef-b092c76ca7d7",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223438",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "2ac4716a-0c1f-4a11-8d70-bec4a1d1b157",
|
|
"value": "178.249.187.151"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223438",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "bdaebc0b-8c95-4c95-8c9c-47d55262ea63",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223438",
|
|
"uuid": "d96b761a-cfd4-4a3b-99b6-dce8f0b1dbe2",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223439",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "5527dd67-1a5a-4ea3-9d67-6ed12de286d2",
|
|
"value": "217.199.160.224"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223439",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "ea8a322c-092b-4ae6-b2dd-2006180d09df",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223439",
|
|
"uuid": "6a1eb45d-2192-46d6-b060-f8af4dcfb42c",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223439",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "b6e6169a-6c0b-4de1-acc1-c7f614fc9b79",
|
|
"value": "62.75.150.240"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223439",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "0266e8a9-e129-49c5-90fd-dd236308f09c",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223440",
|
|
"uuid": "958c252a-3068-44be-8db9-bfd72f0d65b1",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223440",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "54c081e0-5832-439c-b455-344a897552c5",
|
|
"value": "71.244.60.230"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223440",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "dfe77cca-09d5-446d-847e-95eb7de41707",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223440",
|
|
"uuid": "e2e1aae9-2844-4a8a-93d6-83e4eff0451a",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223441",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "0a0b2184-d617-4bf8-bb90-734bf320b642",
|
|
"value": "119.59.124.163"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223449",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "ff4b843e-bfa2-44a0-b709-cf7e0ed4a884",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223457",
|
|
"uuid": "63f78ee0-9a16-4542-993c-d1ba9aee9fcd",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223458",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "adaf97a1-cd46-4cd3-92ab-5ef363879ccc",
|
|
"value": "211.229.116.97"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223458",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "eaf6d6a3-e6f9-42a4-8cc2-e1da76ffee04",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223458",
|
|
"uuid": "f28db915-cf7b-4a96-9537-f555d0f1f230",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223458",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "9c8705c0-0acc-45ab-b82f-eac6abbf8319",
|
|
"value": "190.38.14.52"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223458",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "491ab093-cd67-4d12-a8a9-67d13304e158",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223459",
|
|
"uuid": "aec90097-b2fd-47f5-b59d-c91ce7376225",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223459",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "b9d893f2-9541-4525-a3b1-4daf7d0fe2da",
|
|
"value": "217.113.27.158"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223459",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "d15e0337-66d1-401f-8a0a-6d773e9a790b",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223460",
|
|
"uuid": "c32c4e9b-168d-4dc8-b60f-354591555fd4",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223460",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "81919e68-0f51-473f-8565-e28a75cfcc0a",
|
|
"value": "203.25.159.3"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223460",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "1783fc2a-d086-4d19-8b56-fa69688fd897",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223460",
|
|
"uuid": "11fc8970-3c3e-461d-b3b9-265229cd593d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223460",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "60dac571-dcbc-48ed-b34c-ee8054ca5565",
|
|
"value": "190.19.42.131"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223461",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "0f0c580a-66bd-430d-85c3-a1034b203e4c",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223461",
|
|
"uuid": "7e6f8354-469c-4c5f-8d7a-aa515941b86f",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223461",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "2a57eba8-08be-44d5-82c3-cf0ad33f64cf",
|
|
"value": "187.188.166.192"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223461",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "6f6d3a56-65e1-46ac-b0d5-2a7851e87643",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223461",
|
|
"uuid": "45c01ecd-1f62-4110-9560-0a86c7564b3b",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223462",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "bae059cc-bd55-4311-aa74-b4c8c92a0563",
|
|
"value": "51.15.8.192"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223462",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "0e5e4016-c75a-4766-b43a-9bc2998c66fc",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223462",
|
|
"uuid": "40211feb-03bd-4f5d-bbb8-760bbeb5c88a",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223462",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "1134dce0-0fe5-4a97-8b61-3a1ac50c9e54",
|
|
"value": "23.92.22.225"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223462",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "51d614dd-907c-4652-95c9-992e6f479346",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223463",
|
|
"uuid": "94a117c6-5527-4f11-8676-e4c7295e2b02",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223463",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "1727db22-3554-4223-a57f-2cda2381b032",
|
|
"value": "189.166.68.89"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223463",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "c262f59d-a521-421b-9bec-7f337c0b739a",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223463",
|
|
"uuid": "236f8e20-7ef3-4170-b9ce-97d90ad1a750",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223463",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "789e204f-5b6b-42a8-a8af-6a37663df9ff",
|
|
"value": "88.250.223.190"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223464",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "f78a55c7-ee77-4330-bb47-2df95e8c2251",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223464",
|
|
"uuid": "09eec299-ee64-42a6-b8ea-413fd45fc10c",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223464",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "e6bce684-0d83-4b7d-907a-45af3fee7449",
|
|
"value": "189.129.4.186"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223464",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "06393c55-f7d5-4eb1-9209-c2a958fd30e8",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223464",
|
|
"uuid": "f6ad609b-b611-475e-8c71-eed4255c282b",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223465",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "f899b3cc-cc98-4f26-be93-dcc13fe68ccc",
|
|
"value": "86.42.166.147"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223465",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "54640d96-09bf-448b-9300-3225d01cae68",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223465",
|
|
"uuid": "9427ce2c-0b7a-4637-9857-5a8e965dfb73",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223465",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "92cf320c-7a46-4f20-a04a-ef0f8552f78a",
|
|
"value": "46.163.144.228"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223465",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "a12c7a63-f995-4c74-9125-dd45a4bf802c",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223465",
|
|
"uuid": "194563d8-f799-4188-94cb-0e767bf51414",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223466",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "60129555-575e-45bb-883d-d81938d4ce44",
|
|
"value": "109.104.79.48"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223467",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "f9a9c642-5208-4674-a32d-f4cb66f9e4b0",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223467",
|
|
"uuid": "990ccbd6-096b-4843-b941-e5057fc07b4c",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223467",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "c837f9e1-fbaa-46b9-9d12-67e00e97ea5c",
|
|
"value": "181.81.143.108"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223467",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "9e2813e3-e188-4827-8180-ebd23cfc63f6",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223467",
|
|
"uuid": "13d735ae-351a-40b8-8c33-828bdf1509c2",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223468",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "27f0b970-3215-496e-baf7-f8db7ff6591d",
|
|
"value": "183.82.97.25"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223468",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "de349126-2c4e-4e3a-b40e-19e0c00aa38b",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223468",
|
|
"uuid": "a847996e-4948-4eff-b5d0-e199238a9d02",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223468",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "71e9e65a-721d-40db-98aa-9ecc8995dfc9",
|
|
"value": "190.230.60.129"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223468",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "4f2db0ae-9401-4528-aec6-f77f291b5151",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223469",
|
|
"uuid": "253bf7d7-38cb-4960-aea3-e82f63c6d30b",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223469",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "a2c6f744-485c-4c6f-837a-91ec530ecdf1",
|
|
"value": "81.169.140.14"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223469",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "02350d03-900e-4de0-a62c-7f85f5ad9e33",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223469",
|
|
"uuid": "f5cfa2cb-bb4b-446c-bc9f-9a7ad9ea0aca",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223469",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "25477de6-7f0b-4e14-a9fb-b30004589b5e",
|
|
"value": "79.143.182.254"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223470",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "a1c64bc9-e98e-48eb-995e-fc4f18c500d0",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223470",
|
|
"uuid": "ea9a37fc-b920-49a2-830c-368dac9fb27c",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223470",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "c3172b85-6f31-41c3-860c-91bcff37ea1c",
|
|
"value": "109.169.86.13"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223470",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "a4edb5c8-dbe2-4ee7-8de0-2c3f8a5b3a2b",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223471",
|
|
"uuid": "5708d69c-b034-4d4a-917f-22c825b8e5d7",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223471",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "59c063bd-9de5-467a-a165-5c98747cc4d2",
|
|
"value": "187.155.233.46"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223471",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "b19e3f96-620f-4b28-b937-97833ac8c8fa",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223471",
|
|
"uuid": "77fa2b43-d168-4d22-a310-bec1a8e1848d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223471",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "f1b53400-6925-4164-9231-33a0c7908fd3",
|
|
"value": "87.106.77.40"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223471",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "346269d6-d325-4eac-8f28-06e96ba84add",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223472",
|
|
"uuid": "ac75d7e6-58b7-4179-82dc-a0592ec73ba1",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223472",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "edf49137-ad21-427b-8430-1cffe577474e",
|
|
"value": "62.75.160.178"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223472",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "50e351d1-9c4c-461e-bafa-434a79b65dba",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223473",
|
|
"uuid": "21059445-77cd-4a53-b76f-e87db4254b42",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223473",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "52f1c75c-c548-46d3-b240-503cbb3c122d",
|
|
"value": "149.62.173.247"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223473",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "7a101511-01bc-4ebc-8971-e3e214081df1",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223474",
|
|
"uuid": "df6ec355-9f08-4a6c-bbe7-6bfe5354059c",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223474",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "1f0a3602-303c-410e-98b5-ed7c99eb8cc0",
|
|
"value": "190.1.37.125"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223474",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "d26f54ba-717b-4dae-aeda-df957bf2c2e1",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223474",
|
|
"uuid": "fb9bdf21-4c82-4f3d-a42a-7d1a70f6a682",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223474",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "df6c1ef1-b8c3-4980-b29b-f3a0bf805822",
|
|
"value": "190.221.50.210"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223475",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "5501f04d-4d37-4ef9-b4b1-415d1b8979de",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223475",
|
|
"uuid": "091df058-8a13-449b-8261-29802d1557e3",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223475",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "5970655e-738b-4110-8e5d-2dafd5ab8b51",
|
|
"value": "217.199.175.216"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223475",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "ab5d703c-ed24-4476-a9fb-8a96780a0c3b",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223475",
|
|
"uuid": "252cae34-8b6b-418a-81ae-15baf2d93370",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223476",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "f36bf15c-65ae-4020-8d5b-386ddd17b460",
|
|
"value": "46.28.111.142"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223476",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "01621408-7051-4782-bc13-7f9b462a0b68",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223476",
|
|
"uuid": "5ee1ea21-215b-4a0f-b84b-41818ff3cc88",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223476",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "290afb54-e850-4bb9-8606-ffdb09d18f6a",
|
|
"value": "5.196.35.138"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223476",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "0d44c103-5a0e-4fec-b9a4-1bc75c31efde",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223477",
|
|
"uuid": "845fd27f-38b2-4f3e-8217-37b10f14e14b",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223477",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "ecfdc110-a13f-43d2-890c-f1da087ed5a3",
|
|
"value": "46.21.105.59"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223478",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "7e682853-9037-497a-8762-c98131748d82",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223478",
|
|
"uuid": "e671fad4-2d1a-4bc8-9414-be81a7c0e8d6",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223478",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "bb00bd42-39ac-4ea6-accb-f52d00873450",
|
|
"value": "200.57.102.71"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223478",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "9622f9f9-a0d0-4547-9735-dffbaf3275cd",
|
|
"value": "8443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223478",
|
|
"uuid": "d3a95be3-d2b9-4508-bc4f-20ae5cf6a657",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223479",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "403ee5e6-302b-42c3-86e3-9afbea662aba",
|
|
"value": "151.80.142.33"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223479",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "b347d815-4435-4677-ac2e-b60c0717b8c1",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223479",
|
|
"uuid": "29848c4b-48d6-433c-aea6-3a06ee8f6a7f",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223479",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "447837cb-6f29-4568-96e1-52949bd27cd9",
|
|
"value": "138.68.106.4"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223479",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "17921111-2f89-43cc-a1b4-9bdf06ecf929",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223480",
|
|
"uuid": "9ae7bba2-3250-4816-a632-ba5c28edbd6d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223480",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "d3263b5c-d97f-4ebf-9362-8810089d3f9d",
|
|
"value": "119.92.51.40"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223480",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "e638661a-8ba4-4346-9586-525f626df082",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223480",
|
|
"uuid": "ac71bf2c-9e6f-4446-89b8-f0ea0669a043",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223481",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "3edee7c9-825e-4ff3-885b-3516f07a95c0",
|
|
"value": "89.188.124.145"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223481",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "aea6fcb8-8cf3-49f8-8afc-c30249b8269a",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223481",
|
|
"uuid": "88565c71-b4c4-43cd-a4c4-caa65b377978",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223482",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "1cc71469-be41-4e19-8fc1-30068f2e8f2b",
|
|
"value": "178.79.163.131"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223482",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "1d8a33dc-f280-4cce-9c76-4036c6967721",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223482",
|
|
"uuid": "48558194-4ba8-47ee-b674-794ada02eaeb",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223482",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "a498e44e-8d38-4f44-9777-d104c4ade71e",
|
|
"value": "200.21.90.6"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223483",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "c52dc45d-d476-423b-8fb7-7b4378d9ecef",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223483",
|
|
"uuid": "e9a2aa8e-48ce-4a50-9c68-31b141afeb7f",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223483",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "64ecf19e-75c5-491e-98dd-46614e50deb0",
|
|
"value": "114.79.134.129"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223483",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "3607b572-3e85-49ec-9db6-a62f6f173387",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223484",
|
|
"uuid": "66c3b574-142a-4a65-8ecd-d0082847d4a1",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223484",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "e046a0b6-ad00-4a26-8e41-4fc82247e2f4",
|
|
"value": "190.200.64.180"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223484",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "2dbcf4fe-7da6-4621-b197-a83b2f064e89",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223484",
|
|
"uuid": "d0efd73d-ddab-4eab-b67b-a9557ca11ee0",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223484",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "24cf2726-387a-4c07-893e-2dffeebb780a",
|
|
"value": "190.104.253.234"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223485",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "f5e29e47-13b5-400d-bec2-ff51f3b79986",
|
|
"value": "990"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223485",
|
|
"uuid": "09567fda-98fb-4ca6-b386-c535e20b727b",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223485",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "c127954a-6bea-415a-b970-b8ab2d36e40c",
|
|
"value": "71.244.60.231"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223485",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "6dcd70b3-a784-4c92-ae4b-089c09385971",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223486",
|
|
"uuid": "cc2734d3-bfa0-4c78-b6f7-c5cfad4bc598",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223486",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "a89199ab-a036-440d-ba02-1b7bc7d1abb8",
|
|
"value": "91.205.215.57"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223486",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "fa432d8d-88e7-4eb3-a888-e30a662d6426",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223486",
|
|
"uuid": "a3d5f68c-090d-418b-a694-0d6b1b9b9127",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223487",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "718f2a06-5a7e-4ebc-93d2-76c1db7a3db8",
|
|
"value": "189.187.141.15"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223487",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "4adc5cbb-dd8b-42a6-885d-674eb7096bae",
|
|
"value": "50000"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223487",
|
|
"uuid": "029d5990-722b-4455-8114-ae80dceed1f8",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223487",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "fc44b1de-f24c-474e-b207-47c431a0d270",
|
|
"value": "91.83.93.124"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223487",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "0691b78e-9b73-4834-a9fc-ed039f5fb2de",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223488",
|
|
"uuid": "95a0fb67-eb73-4da5-b3f7-f99deb3634d3",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223488",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "636dc4c4-5012-4915-9e99-2bb1726f8b78",
|
|
"value": "46.29.183.211"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223488",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "8edf992c-6c53-4db2-9113-36fe761e2ead",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223489",
|
|
"uuid": "42d44845-7f54-4efa-9422-881f5352bbf5",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223489",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "4e3dfbc9-1b22-49c3-962c-67b8ce9421ea",
|
|
"value": "183.87.87.73"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223489",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "30277941-2c0f-4417-ba2b-160d56e54c43",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223489",
|
|
"uuid": "851159a2-aa5f-45fb-a2d6-e49fc48c653e",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223489",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "e909d2dd-3748-46a2-bc66-385c1903f9b5",
|
|
"value": "212.71.237.140"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223490",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "88b12fdf-e9d7-4c20-9bc2-7c5590da1072",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223490",
|
|
"uuid": "f807f094-1401-4f8f-8a42-9d690cf8a6cc",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223490",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "7e4f6ade-e904-4fea-bd67-f9cae7dc8531",
|
|
"value": "62.75.143.100"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223490",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "10b534ee-fb32-492b-b47d-9668089f8e20",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223490",
|
|
"uuid": "d79e72e1-27bc-46d8-9eaa-914867541d59",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223491",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "967dacd0-044c-42bf-8a7c-893ad713f744",
|
|
"value": "185.86.148.222"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223491",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "c5ce777b-cd7e-439d-ae57-e2e69a924150",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223491",
|
|
"uuid": "44279a38-8352-45d7-b135-2d528da34463",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223492",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "be8190c2-522b-4778-a8e0-46fe953e03ab",
|
|
"value": "77.245.101.134"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223492",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "7e37d64f-8ef5-4585-8ee6-ca96a1e01a1e",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223492",
|
|
"uuid": "181bd9f1-5ede-466d-bfcb-721d18ae8e2d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223492",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "27fe7045-2955-4da5-b3c8-206e9193b5b6",
|
|
"value": "79.127.57.42"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223492",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "58eb7afa-51e3-4e7b-b060-c8c684e980a9",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223493",
|
|
"uuid": "e421c073-f433-463b-abcd-fab84f6fa2d6",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223493",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "7963f57b-64e0-4485-b4a7-962154d13321",
|
|
"value": "159.203.204.126"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223493",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "e260d5e6-cec3-4d03-afa4-cdd9fc50f507",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223494",
|
|
"uuid": "387fcd00-d2ac-4ac0-8611-f407d23fd692",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223494",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "e9dca7ad-0ea5-4616-8b4d-9d462ee7f79d",
|
|
"value": "190.230.60.129"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223494",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "3b35c381-c6b7-43a3-b8f7-6598241d4a92",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223494",
|
|
"uuid": "6e8ab55f-363b-4174-9a5b-780029816016",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223494",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "de3792e1-2a0e-43cf-8a15-6f5d472b3c5d",
|
|
"value": "201.184.65.229"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223495",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "d604f81e-9693-4ea6-bded-6bf70bbc8769",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223495",
|
|
"uuid": "e779d83c-59bd-40fd-a3a4-8675f0df175e",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223495",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "d6a7cbc0-bd86-4fd2-8469-fe268d2773e0",
|
|
"value": "181.188.149.134"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223495",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "da3be1fa-d65a-4cfb-aece-73802f17a103",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223495",
|
|
"uuid": "eda5e617-cf9a-495a-b245-292611d47280",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223496",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "fabc70e2-490b-4c4b-bb10-3153cf3ea182",
|
|
"value": "181.36.42.205"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223496",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "0341429f-2337-4e40-872e-97729d437b66",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223496",
|
|
"uuid": "011719d0-96f3-41e0-805a-ac09ecb5a6ef",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223496",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "48d11780-951f-4e42-b466-cd90636aacd5",
|
|
"value": "80.85.87.122"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223496",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "4f14047a-8ae5-4927-8da8-170986257de0",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223497",
|
|
"uuid": "07bfc0e0-a95e-42d0-bb59-27fed01ceae9",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223497",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "488b25aa-7598-4e04-92c1-5de86d5b6fb3",
|
|
"value": "77.55.211.77"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223497",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "95b0131a-2ce0-41e8-a03e-e60808d8356c",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223497",
|
|
"uuid": "e26f5920-6575-43fe-9519-ea440de7ded0",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223497",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "b1832ce6-9d50-4565-a9fe-4593f1ce0693",
|
|
"value": "186.83.133.253"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223497",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "9c0a6526-15f5-4131-a0bf-c9016289c6dc",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223498",
|
|
"uuid": "56fb672c-7c99-4171-ba3b-6ebdc944e9e8",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223498",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "80675efd-9571-41b8-a946-30e78020d28b",
|
|
"value": "50.28.51.143"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223498",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "a0088108-0e6d-422b-b4ee-28e0b582c0f5",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223499",
|
|
"uuid": "d84b60c8-f300-43c5-be7e-c064a7f61e1a",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223499",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "ef214de1-5828-4c45-80d0-7001c9f009bb",
|
|
"value": "200.58.171.51"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223499",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "a975ccb7-b17c-4a6f-ab9a-16fffd449c1f",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223499",
|
|
"uuid": "29d02595-bd95-4d2c-a225-ca83506bf226",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223499",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "1756164e-a3f5-4740-804d-fc0f23ab00aa",
|
|
"value": "46.41.151.103"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223499",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "80630489-7ef1-4c4e-9209-5cb2edfb16ea",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223500",
|
|
"uuid": "b8c5d4ee-2755-4a98-8e93-f0ccdf0629dc",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223500",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "7bc54630-1198-45fd-ba96-bcbd62bbc6ab",
|
|
"value": "201.163.74.202"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223500",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "9a70fac0-4308-478c-8f3c-499fea5f41ba",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223500",
|
|
"uuid": "cd22a841-3d19-49bb-b3bf-50790a3d5986",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223500",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "08503b3b-1544-443e-85b0-ebd1418c554e",
|
|
"value": "5.77.13.70"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223500",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "f9310872-30f8-431b-a482-d9c3f7febf8d",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223501",
|
|
"uuid": "31674d13-d661-4d69-a2bf-ec7c1f60cc18",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223501",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "a6bb05fe-6b39-48e8-9452-af47e85ad11d",
|
|
"value": "149.167.86.174"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223501",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "1bf5d457-1de0-4a26-9c53-3d10005faa15",
|
|
"value": "990"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223501",
|
|
"uuid": "420f2b40-1d9f-4524-a26a-275a55fd88b8",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223501",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "15599769-01e3-4d7f-884f-c2543f983346",
|
|
"value": "181.164.8.25"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223506",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "a2e9138b-5430-4dcd-b134-98edf24a8e4b",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223507",
|
|
"uuid": "9c74b51d-89b4-4d70-a1e0-6e65b29aec67",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223507",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "c1c208eb-98a0-4cec-86ad-e597522f7256",
|
|
"value": "181.143.194.138"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223507",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "704891df-ce03-477d-b1aa-4beb0abe0b1a",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223507",
|
|
"uuid": "8ed7305f-d9fe-4bc4-b898-bf7948a29357",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223508",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "966b64a9-82c8-4867-bd21-c6e80dcfd2b4",
|
|
"value": "192.241.250.202"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223508",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "a5c4d87b-223b-4d07-8995-2e6accd0b3c7",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223508",
|
|
"uuid": "005b80f7-6714-45bf-bd7c-e10f7f810a52",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223508",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "02bb2a5d-9a0c-41bd-b265-6c14a49f963a",
|
|
"value": "63.142.253.122"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223508",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "8535cf5b-5007-4f75-9c68-8ca9089d5450",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223509",
|
|
"uuid": "8875a80b-4ecc-495f-b335-7bf8169a34a0",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223509",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "5b8601a8-2901-44e9-ba04-a3cdd8eed2ce",
|
|
"value": "178.254.6.27"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223509",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "0f306897-9a17-4779-b632-bb22d90fcc97",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223509",
|
|
"uuid": "8b4e1cee-bbe7-468b-8011-3320696a0fd8",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223510",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "a39b6fa4-7c41-4054-89ee-effb737722fe",
|
|
"value": "92.222.125.16"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223510",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "6c793bea-646a-409f-a750-fce7694a7edc",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223510",
|
|
"uuid": "1eb09c76-4ffe-46e9-bccc-30ff66374a33",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223510",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "f9625e9d-f0c8-4dc5-bc86-4a0cc37f4677",
|
|
"value": "142.44.162.209"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223510",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "b4efef42-69e9-4a29-9328-9fe1ddc44a85",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223511",
|
|
"uuid": "7f991678-2983-45e6-9629-c3bb6d4569b4",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223511",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "8635c95c-d36e-4c4e-9026-f19d314fad50",
|
|
"value": "86.98.25.30"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223511",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "9d70e959-0a67-44d4-b091-7625b7461f44",
|
|
"value": "53"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223511",
|
|
"uuid": "e39e560a-8422-4051-877c-75c0de9bdada",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223511",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "40d14f4f-f82e-43bc-bcf6-442d3120b8dc",
|
|
"value": "31.172.240.91"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223511",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "5abf7046-d1ee-47e6-812f-3e586da89823",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223512",
|
|
"uuid": "e59cb5f9-66f6-4318-b891-1cea6a8cde57",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223512",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "6fc249d1-0cbb-4afa-bc3d-650acfad2628",
|
|
"value": "149.202.153.252"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223512",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "c3c73f10-06af-4216-8fcb-79588534b130",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223512",
|
|
"uuid": "07b7457f-8d3f-4461-95bd-381b1ef263de",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223513",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "732482ab-8201-4b0d-80bf-2b720f3734fd",
|
|
"value": "201.250.11.236"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223513",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "ba18dd48-c819-43b0-970f-597f6dd38db3",
|
|
"value": "50000"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223513",
|
|
"uuid": "0a8d4f83-5817-420c-ad5a-2fb99ecba94b",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223513",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "1fae2c57-4324-4025-87dc-d2e2982209ee",
|
|
"value": "189.129.231.76"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223513",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "faf74002-4375-4b70-9e68-73d97d532068",
|
|
"value": "20"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223514",
|
|
"uuid": "18b4745e-cf5d-4030-b605-31d45f7b0a0d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223514",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "2c247955-5b16-44d3-87ce-e4208d8641cd",
|
|
"value": "182.76.6.2"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223514",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "d3c50f8b-ad7f-45d9-986e-df6a0ab7e571",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223514",
|
|
"uuid": "5d3e0edd-cbbc-456c-9c3f-a3eb25e162a8",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223515",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "9207d8e6-3491-4c22-8582-10daa2abf9fb",
|
|
"value": "189.209.217.49"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223515",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "cc246c3f-e012-4daa-ae40-e545c8dbc659",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223515",
|
|
"uuid": "8d10d9be-c5fb-420c-aca8-1cf34c32addf",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223515",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "dc3ff249-7271-41ec-a015-7c916cb341eb",
|
|
"value": "87.106.136.232"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223515",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "8c50dd3d-f6d0-4957-b4d5-c515b2e0e54a",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223516",
|
|
"uuid": "fa17a8a0-c65d-4e9e-b7b8-682d4eddc727",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223516",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "df34ed01-09e2-4b45-b1c7-90e6c28b8f98",
|
|
"value": "91.205.215.66"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223516",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "769c79a6-32be-42c0-a526-0206d5bfc487",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223516",
|
|
"uuid": "5e0cfeb5-db72-4e44-b86a-540e5122a758",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223517",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "f7403620-c32f-41f3-89bd-87a85c5c1db7",
|
|
"value": "212.71.234.16"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223517",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "efa28e29-566c-4f12-824c-710a27fb4f28",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223517",
|
|
"uuid": "dc3c5746-70fa-49ab-86e9-b20f6befbdc7",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223517",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "3e550707-9e49-463a-851c-6d3b6bbc91fc",
|
|
"value": "178.79.161.166"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223520",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "f88c706e-8689-4276-8d2d-6b648a2364aa",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223521",
|
|
"uuid": "a2cba1c3-7f58-44b8-94cd-b71c7709a6a3",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223521",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "6e3444b7-2d62-4c71-a8ee-4faf85f3eb13",
|
|
"value": "162.243.125.212"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223521",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "34578fdd-6115-4201-b915-fda2d2648df0",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223521",
|
|
"uuid": "dff6f9c7-ef3c-42cc-be0f-a33a5903ac99",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223522",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "da2c0523-aa73-47ed-982f-989a41816424",
|
|
"value": "173.212.203.26"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223522",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "7668e0a0-84a0-4c84-8f34-d2b79c981e58",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223522",
|
|
"uuid": "c028d7ef-0d87-4a4c-aec5-aa2b82ebf506",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223522",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "ae6c958d-2a71-4dcd-a947-339346d95f53",
|
|
"value": "85.104.59.244"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223525",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "7c112478-104c-4ae9-8319-dda378f26e90",
|
|
"value": "20"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223525",
|
|
"uuid": "f3f13b74-6ced-491c-b7ec-8cecdcd26dd7",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223526",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "abfd460a-8065-4ba1-8f43-e3c193e2e18e",
|
|
"value": "186.4.172.5"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223526",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "874f7df2-df19-49ea-be93-6ca4f80a99a8",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223526",
|
|
"uuid": "486fcc35-e4ae-4a40-a2e3-b2b3de42b5fc",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223526",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "c1f842d1-1128-4e88-a87d-7bb4cca5ab84",
|
|
"value": "169.239.182.217"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223527",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "940cca89-b817-4759-a0a6-9c882f52609a",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223528",
|
|
"uuid": "86210057-8f30-4344-bd89-c1fcd5a67f78",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223528",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "15b0046f-a48f-46ad-9343-00fbf97a51e4",
|
|
"value": "37.157.194.134"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223528",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "c3b87eb6-1e62-4cfb-b7b6-abc190fda751",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223528",
|
|
"uuid": "96c7ad3e-516d-431c-a0fb-3acbf1578452",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223529",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "ccfe3812-1396-401b-b2ad-c2f7001cf119",
|
|
"value": "190.18.146.70"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223529",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "6452ab58-5b72-43a5-a688-58154ca8188f",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223529",
|
|
"uuid": "629beb78-d4bc-4d7f-83d7-3a3c51b66262",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223530",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "75211016-7a7a-4d7a-a8fa-2cf7eec0a70d",
|
|
"value": "87.230.19.21"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223533",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "bd794047-f310-4468-a0ef-6f69f27d9aa3",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223534",
|
|
"uuid": "852dd915-2b0a-4554-be02-b84c0312aa7f",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223534",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "b7296c8d-de26-4628-a60a-5a3072479563",
|
|
"value": "186.4.172.5"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223534",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "faeaa04b-3005-4a2b-9bbd-22f704677daf",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223534",
|
|
"uuid": "d38d3cd9-af66-42e1-ad6f-3b4952a43fd0",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223535",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "6d638f89-9bc2-43e5-b5ea-3d23157b5754",
|
|
"value": "103.97.95.218"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223539",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "c22d54f9-463e-4187-9890-0605bb51c934",
|
|
"value": "143"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223539",
|
|
"uuid": "54cb6394-2383-4176-a0ad-2aac817e32a2",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223540",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "7e1e2f29-8434-4444-8ca1-38969d529fc7",
|
|
"value": "206.189.98.125"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223540",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "c39fc8f8-03ff-4b74-a168-1e95b6693398",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223540",
|
|
"uuid": "369b7ed3-d5e3-4179-8060-210c8019e3bf",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223540",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "38a7ae4b-abea-4615-a780-1cffac4bbc52",
|
|
"value": "181.143.53.227"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223540",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "3e5d12c5-30e3-4dcf-9c8d-7ab95ce8294d",
|
|
"value": "21"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223541",
|
|
"uuid": "7f9430a2-5c64-4618-8b3d-b82fcba8a129",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223541",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "47253f77-ea57-4481-a3ca-672cdd8f9b49",
|
|
"value": "185.94.252.13"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223541",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "6a119183-a54b-4220-a22d-6b9e3d1e2114",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223541",
|
|
"uuid": "29aa845a-23e6-4515-a3b1-33e0c3477a8a",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223541",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "15f162e7-28f2-4e67-ab53-ef1820e553d6",
|
|
"value": "190.145.67.134"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223541",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "85111fb9-f3c5-488d-8dfc-b96ba690028b",
|
|
"value": "8090"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223542",
|
|
"uuid": "93323000-96fa-4f52-8a94-6265f055c65c",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223542",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "4b902e48-94dc-4bc1-905a-2539fd18ee62",
|
|
"value": "136.243.177.26"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223542",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "73bfe3eb-0416-4633-9124-a5153bb00abf",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223542",
|
|
"uuid": "d80cdb63-5236-4c5e-b20e-925e5d13ce15",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223543",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "a1c235ae-0b40-4cb2-8c3f-6f5f316f7b78",
|
|
"value": "94.205.247.10"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223543",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "74a8b481-9a6d-4d32-ab98-2f65ba64a0f2",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223543",
|
|
"uuid": "89a1fcfd-542f-4e0b-a34b-fc1d07b7b931",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223543",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "9f751312-6f08-4653-b574-512221ed1a67",
|
|
"value": "95.128.43.213"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223543",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "91e2db68-b071-42a7-826e-9ce47e3f25ab",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223544",
|
|
"uuid": "bf3bb988-0b92-4dbc-9117-2579a6379a60",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223544",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "88ef5744-6305-4470-82f1-16e5c6535964",
|
|
"value": "159.65.25.128"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223544",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "c42994b7-8d70-44c1-ac1e-e74397db0327",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223544",
|
|
"uuid": "a8195ebb-5aea-4e9f-ae0e-a27d812999c6",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223545",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "3475b965-81bc-41b7-a897-bd36a28fa352",
|
|
"value": "222.214.218.192"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223546",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "5cf32c20-f90c-4f96-a746-1b67d4f0b415",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223546",
|
|
"uuid": "38d1baf7-2b90-45f0-ad42-578e8463e27b",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223547",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "92199351-25f3-4352-b941-39947837929f",
|
|
"value": "104.236.246.93"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223547",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "81cca7cd-7348-4fe1-93ea-6726a3a04732",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223547",
|
|
"uuid": "f74b85b8-bbe8-4208-8e3e-7f2bb9680bc6",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223547",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "2aacde3c-ece9-42bf-8ac0-aa2788b6a2b5",
|
|
"value": "217.160.182.191"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223547",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "846093bd-b588-488d-8b5d-543714158740",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223548",
|
|
"uuid": "c73f7671-308d-46cf-9f96-69ccf7e223bf",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223548",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "cc30ed79-e21f-41f9-a66e-cdcbc45409b9",
|
|
"value": "59.152.93.46"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223548",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "bf4cc74a-3e29-4441-bd0d-916bd7364e97",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223548",
|
|
"uuid": "f4abdebd-025d-4202-a0c1-7c0663ca3b7d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223549",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "7fe7b7dd-fa09-42e9-bf7f-9b8ee50c9643",
|
|
"value": "138.201.140.110"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223549",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "503b6cc6-80e7-4a72-859e-dbcdd802fdc7",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223549",
|
|
"uuid": "691698c6-b092-42dd-9c5f-21ec4d6e8103",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223550",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "f337d81c-3885-4b0b-8ba8-4d2e34c0a7d6",
|
|
"value": "45.33.49.124"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223550",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "a2a330e6-a94d-4485-94bd-7a4f4eafe24d",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223550",
|
|
"uuid": "7af18c76-a904-4dbb-a7f2-143186a31a41",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223550",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "5e6ac9b4-48d7-4f2b-9d1a-1cf75df8beb1",
|
|
"value": "78.188.105.159"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223551",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "209afe77-fee6-4559-810e-76e949d226a5",
|
|
"value": "21"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223551",
|
|
"uuid": "05a98bc9-cb4b-41dc-ae3b-bf14e267d2cd",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223551",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "20db9f9b-7486-47e5-a8c0-158572fe3101",
|
|
"value": "92.222.216.44"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223551",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "54897b2f-baa0-4605-9088-347e62cdd386",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223551",
|
|
"uuid": "b576ffd9-dd61-43a8-bfd0-e108b0785608",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223552",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "69052222-c996-4a69-9b16-95e5d5917be1",
|
|
"value": "185.129.92.210"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223552",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "6770af81-7cc9-454c-bad8-654f813bb596",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223552",
|
|
"uuid": "22fe7635-5a40-4144-a70c-e17d1d5975b9",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223552",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "72ef0a8e-6efe-453c-81b4-2a3f9689ba4b",
|
|
"value": "47.41.213.2"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223552",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "84e2d521-80fa-4ab6-acda-e50d6237ff51",
|
|
"value": "22"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223553",
|
|
"uuid": "5e188cf1-b6b9-450b-8f78-aa29ef99e3a7",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223553",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "e88dfe0e-7511-4e3b-8cb1-39d6f77919d8",
|
|
"value": "144.139.247.220"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223553",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "642a203e-226f-448f-b327-0feb6baa9ebe",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223553",
|
|
"uuid": "dcb9a38e-4045-454e-9bb1-be822ebfacc3",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223553",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "2c8e189d-08a5-48ce-9581-a1cc897eeb27",
|
|
"value": "46.105.131.87"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223554",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "720195bf-81e0-4695-856d-de3f9aa6314f",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223554",
|
|
"uuid": "9f6f6e53-46dd-47ac-ac0f-26acb70b3364",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223554",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "17e5eeed-d3f4-4464-ad86-5b52147db18f",
|
|
"value": "62.75.187.192"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223554",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "4e04a8e0-c0d5-4d22-bc46-f5198d758783",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223554",
|
|
"uuid": "30a99db6-4aa3-451d-a605-dd6453aeeb59",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223554",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "3af5b3ba-277d-44fb-86a4-3d4ce7abac3c",
|
|
"value": "88.156.97.210"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223555",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "fd153f46-4872-4454-ac00-ddd7cac6cd8b",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223556",
|
|
"uuid": "ba9ce618-662f-4ca4-9d4f-964b00ee11d2",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223556",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "2084f874-cb90-44e6-872d-5628f23c0568",
|
|
"value": "177.246.193.139"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223556",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "99649388-0e32-4157-999a-86028192678e",
|
|
"value": "20"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223556",
|
|
"uuid": "c2199a8c-3f81-4aa3-8207-a228a92c7d37",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223557",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "a18f9df7-d1cf-4143-8b18-8007e6405899",
|
|
"value": "188.166.253.46"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223557",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "914be338-6cab-4a8f-b02a-55d3042b818e",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223557",
|
|
"uuid": "2d124a9d-ca65-4917-b5b8-e878f0160b5b",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223557",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "bb3a8ff6-14f1-490c-b1d2-cac50fb6d2f8",
|
|
"value": "80.11.163.139"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223557",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "08cf4685-dd15-4608-bc6e-31373c6fb95c",
|
|
"value": "21"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223558",
|
|
"uuid": "22c1513a-4c2e-4b60-b60d-5892f50b3ae1",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223558",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "438a3dec-29ae-4ac3-9771-3b50542feda2",
|
|
"value": "41.220.119.246"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223558",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "76fa362f-9c56-40f7-aeb8-05383efc05fa",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223559",
|
|
"uuid": "02cadccd-f890-432a-a755-89f7dee50a67",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223559",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "0b698684-b4ca-4b96-bed4-6344ced9bf61",
|
|
"value": "31.12.67.62"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223559",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "70dae41f-5950-4e3b-a2ec-dc65591a7520",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223559",
|
|
"uuid": "31657079-b070-4572-99ee-deb3ece8cf36",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223559",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "aa5ff09f-ec60-4242-93bc-156d66bd4cba",
|
|
"value": "45.123.3.54"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223560",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "cb935d85-6581-49d2-93e1-ae76eef67316",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223560",
|
|
"uuid": "4d678bd1-04c6-4e97-adc1-08e1de518145",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223560",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "69e804e3-5835-4554-a637-b2c62b15b3c8",
|
|
"value": "179.32.19.219"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223560",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "feb7bca9-25d2-41a1-8e72-fc808ac59e71",
|
|
"value": "22"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223560",
|
|
"uuid": "5e397c06-f14d-4a23-bfc2-dd0ee76952fc",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223561",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "8a2a35ae-9b62-4aac-908d-724cf82235d0",
|
|
"value": "190.226.44.20"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223561",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "abf1db35-7cbb-4b50-a9c1-501157894d9c",
|
|
"value": "21"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223561",
|
|
"uuid": "5bb5d6a4-0c77-412e-a50f-89e892a393ac",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223561",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "5a6866b6-b883-4eb6-be56-18ff16a0b0d1",
|
|
"value": "87.106.139.101"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223561",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "da052ffb-252b-4cdf-939e-161e28c3aac3",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223562",
|
|
"uuid": "ebedbe7a-c2e3-4648-8c12-f723e3557dfb",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223562",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "3f66f7ff-33c1-4463-ab4b-444c4d0c46b8",
|
|
"value": "182.176.132.213"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223562",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "22c8b71f-465f-43f3-a8f7-537fa9ff6a7a",
|
|
"value": "8090"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223562",
|
|
"uuid": "13a0f5d7-8594-4dc0-ada4-ef84c3be24eb",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223562",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "46ee076a-fb4c-4b2d-bf5b-4475e9807b1d",
|
|
"value": "190.201.164.223"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223562",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "a856ea94-6442-491d-af6d-53e85cda02f8",
|
|
"value": "53"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223563",
|
|
"uuid": "a385944f-cbcd-42b0-bd62-859a57883ca9",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223563",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "95e4b999-7b4e-405f-bf3c-de9f4aaf2c6d",
|
|
"value": "190.53.135.159"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223563",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "fbe886ad-8cd0-43d4-a5b2-6b6446594d8c",
|
|
"value": "21"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223563",
|
|
"uuid": "43e73629-4016-4c0a-a586-002afdbbcc0e",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223563",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "1c603252-9267-4aa2-85b0-32c583b485c4",
|
|
"value": "78.24.219.147"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223563",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "e51e5e85-d3d4-43bd-bfcb-3e248a32f955",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223564",
|
|
"uuid": "93c3a34d-c0e7-45dd-9c9b-a2ecd63b3df4",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223564",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "db55819a-f8e3-4201-9433-903b79534d9b",
|
|
"value": "5.196.74.210"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223564",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "f007bdb4-f5a3-4fbb-b540-569fde29bad3",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223564",
|
|
"uuid": "03a4233c-bc52-4d03-a1f8-e5f598897514",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223564",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "1f989ab0-1bac-47b5-9b9e-c1959a0bc1f8",
|
|
"value": "37.208.39.59"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223564",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "f66bd247-2e4d-4641-bb43-870150d897de",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223565",
|
|
"uuid": "14532f41-6e42-4b3c-a4bf-c702235b0789",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223565",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "df3c0b47-cdbd-49a3-a1b8-72f67a0a3a52",
|
|
"value": "187.144.189.58"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223565",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "251c70c2-7be5-4503-9ccc-507ff7ab096d",
|
|
"value": "50000"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223565",
|
|
"uuid": "24c87018-42eb-42b8-add7-44025ba25c79",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223565",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "b35daf7a-eece-4d08-9939-d4d43757fe7b",
|
|
"value": "190.106.97.230"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223566",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "5e7df9d9-839f-48e2-9198-289f87721dc2",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223566",
|
|
"uuid": "30e08e54-c006-4603-9a54-95fe08fa1d3a",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223566",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "21381e5e-6011-4dc2-8e4e-0879729c4bab",
|
|
"value": "186.75.241.230"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223566",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "7c517988-ed48-4f6f-bee0-054dd202dbd2",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223566",
|
|
"uuid": "c648073f-d125-4f4e-9401-6536dc6570ae",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223567",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "0a1c794b-c304-4385-b478-75627d38ea5d",
|
|
"value": "182.176.106.43"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223567",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "e1e45949-93ee-40a3-9bf3-66f494e2d415",
|
|
"value": "995"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223567",
|
|
"uuid": "d481a193-4dc1-48a3-822c-6c52c40258ca",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223567",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "b3714d29-3ccb-42ea-a8ee-b0f15e7375c9",
|
|
"value": "175.100.138.82"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223567",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "91869e40-a539-46d5-8b2e-813c8c3612fa",
|
|
"value": "22"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223568",
|
|
"uuid": "5df7b844-3e02-4393-86dd-709c839710bd",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223568",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "ceb316ba-4613-47e4-8d38-7d18768c734c",
|
|
"value": "190.186.203.55"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223568",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "6f2c87b6-5dad-4813-8dc7-d36f6213ad82",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223569",
|
|
"uuid": "1fa2435f-9fc5-4fcf-bf67-025a542706cc",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223569",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "fbf193ec-713a-4c31-88d1-0b0520dfac46",
|
|
"value": "91.92.191.134"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223569",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "82c76218-61d6-462c-8086-bf44bd68fd13",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223569",
|
|
"uuid": "4ae05217-daa6-4fbf-b240-9bf8b67af071",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223569",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "594aacd9-8d1d-42ea-8475-dcb1884fed9e",
|
|
"value": "211.63.71.72"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223569",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "cf20b326-cbdb-4ddc-9f7c-215139a12c4b",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223570",
|
|
"uuid": "e23a6ed3-d8c9-46a0-a2b2-77541416da6d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223570",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "8121d33a-9af3-4c6c-b465-fa645bbd9f72",
|
|
"value": "104.131.11.150"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223570",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "b9444324-21c2-4f11-a5b4-fdbd83b19d17",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223571",
|
|
"uuid": "def212e2-603c-4f80-a692-020489c90296",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223571",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "8e1ce556-531c-4f82-b339-e5e2a25239e5",
|
|
"value": "186.4.194.153"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223571",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "1e2431c2-f5ef-425d-a0a3-a4d21a21d01d",
|
|
"value": "993"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223571",
|
|
"uuid": "116e192d-a0f3-40b7-b1f8-2afceb7b4eb6",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223572",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "f4013020-f325-4dcc-ac37-c409b87574ca",
|
|
"value": "190.79.251.99"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223572",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "fe383c35-ae4c-421b-ac94-04a31366cb06",
|
|
"value": "21"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223572",
|
|
"uuid": "307d9a75-35c0-41f7-b624-51b671ea6df3",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223572",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "867be9f4-c414-4270-86c6-286d44e8eff3",
|
|
"value": "189.245.216.217"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223572",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "86d57bd3-a0b5-4ca6-a627-a8efd5b94da6",
|
|
"value": "143"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223572",
|
|
"uuid": "8d7d8533-9837-4ef1-a424-8a1d11f4dc24",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223573",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "a9875673-0d8d-422b-be90-304157deaa68",
|
|
"value": "189.189.214.1"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223573",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "6ba816ca-4509-420e-b4ec-778292434350",
|
|
"value": "21"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223573",
|
|
"uuid": "52320b24-c2fd-4785-bc24-9f559b9d68c8",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223573",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "fd37099d-8e53-4941-8ebc-1bc27f10c202",
|
|
"value": "62.75.171.248"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223573",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "a74d0c9f-2b68-45a5-a1d0-de95f8f33026",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223574",
|
|
"uuid": "ea30e0d2-75ca-4391-82e6-b3839815b16f",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223574",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "eca582f7-18dc-4759-b1ac-0b23a5d25dd5",
|
|
"value": "133.130.73.156"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223574",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "78dfbb28-7e2c-46df-8b37-c9d7f331f44e",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223574",
|
|
"uuid": "2ff4b7c6-7e1d-4f76-b204-0919545bfa57",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223574",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "a1e83049-4565-4dba-a285-480f22fda16d",
|
|
"value": "203.150.19.63"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223575",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "a142cb4c-2f42-4ba8-a970-56919ee96a83",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223575",
|
|
"uuid": "a3957def-3f37-494c-b2ea-ba4b91753930",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223575",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "823ec187-3faf-4510-aed3-a8151cf60362",
|
|
"value": "216.154.222.52"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223575",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "211f4fbb-53b2-45e4-b9d8-a4d30ec5965d",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223576",
|
|
"uuid": "86ecf564-6937-41ae-bec9-c5875bd21ad8",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223577",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "313c3115-6b37-434e-ae0d-fa77be65e617",
|
|
"value": "149.202.153.251"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223577",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "792dd818-6a94-4932-8093-79831ee37ede",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223577",
|
|
"uuid": "bac2550a-3a22-44db-b581-43120230bdf4",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223577",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "8e564f5a-6fb8-4f84-8258-1abfec19822c",
|
|
"value": "5.189.148.98"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223577",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "8d95279e-3df6-4669-bda6-9fde3a7d2704",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223577",
|
|
"uuid": "b25d8df0-c0d8-49cc-84ab-f5061f44f950",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223578",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "cf9fa5e8-5efb-4a71-a82c-5c328dd0166a",
|
|
"value": "83.110.75.153"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223578",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "d8fa82dd-c73c-4b5f-b541-e4c03e5eb940",
|
|
"value": "8090"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223578",
|
|
"uuid": "bc029328-fc92-493b-9b72-d7ab28ba913e",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223579",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "d114ddcf-2963-47fa-bfb5-e03af5ed7a9c",
|
|
"value": "95.178.241.254"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223579",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "30a657d9-f169-4fb4-a5cd-8e0ea69f3f64",
|
|
"value": "465"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223579",
|
|
"uuid": "32135c50-1fc8-45d4-8e39-4a67c83c2cf7",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223579",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "d20db8c3-8fa7-4cea-83a1-867d952ef6af",
|
|
"value": "190.55.39.215"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223579",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "78fcc4cc-ca67-48f4-84fd-de525d9367c1",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223580",
|
|
"uuid": "18e2c0a2-d6dc-465a-8768-be0b7a811782",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223580",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "c63de2d3-1912-49c5-b175-4a135b9d392a",
|
|
"value": "70.45.30.28"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223580",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "9dab2775-de16-46fa-9d0f-9c266a78e49c",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223580",
|
|
"uuid": "05730afd-8c2e-41b7-a7dc-2359cc2e5d55",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223581",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "b0e61755-3c23-466e-bafd-3dcc55ceebd3",
|
|
"value": "181.230.126.152"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223581",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "96d5a0b2-2b1b-4518-9f1e-e68996221b8d",
|
|
"value": "8090"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223581",
|
|
"uuid": "abbd3315-c87a-4574-8509-ead0168d329d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223582",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "ecb261dc-ab6b-4a67-8d71-eabbf8f6cd83",
|
|
"value": "83.169.33.157"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223582",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "daf9b2d6-21d7-4ef8-a160-a3ded8049bf3",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223582",
|
|
"uuid": "78edbee2-b150-455d-a607-59f3f1fb10ed",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223582",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "c7763517-04cb-4fed-a34d-f41258ba4221",
|
|
"value": "190.55.86.138"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223593",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "540625e3-7935-4ad6-b3a1-5afd0c0a4eef",
|
|
"value": "8443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223594",
|
|
"uuid": "619a2598-24db-4170-aeef-667df7bafb83",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223594",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "3b0bc6cc-daf5-428e-bc7b-ef4d56d9b898",
|
|
"value": "201.113.23.175"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223594",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "bcde0017-9818-4f38-b314-277dfc2d7fa0",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223594",
|
|
"uuid": "61ee3087-4db4-491c-8446-42e78cc8a530",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223594",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "adf471c6-3fab-449f-b6bd-24f453a183ba",
|
|
"value": "113.52.135.33"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223595",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "719e6623-a59d-4ff4-b994-b4a7eecaa351",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223595",
|
|
"uuid": "892b43ce-d155-43c9-bcc2-afd732335dab",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223595",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "ee125d30-c9ab-4e27-a96e-e9047c380fff",
|
|
"value": "139.59.242.76"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223595",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "314464a4-c964-49d0-b92c-6c9b57aad07c",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223595",
|
|
"uuid": "99c28731-cb7b-4fb9-b0b5-1c027b85d19d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223596",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "377306f1-166d-44e6-9927-fa08f8bf72a7",
|
|
"value": "190.171.105.158"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223596",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "2587faa0-0817-47ae-8a6a-3416fd2f31c8",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223596",
|
|
"uuid": "c7fd54a7-895d-426b-ba55-8747c96d61da",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223596",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "b27a152b-5bfd-4446-bfb9-07695bbc223f",
|
|
"value": "176.58.93.123"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223596",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "36e90fe5-b519-484c-a6cf-16123ca5942d",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223597",
|
|
"uuid": "5c09b726-7ed6-485f-be7e-11ce76c697df",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223597",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "069c4764-86f6-42c1-b069-db13ffdc7375",
|
|
"value": "190.13.146.47"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223597",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "789881e1-bccb-48b4-9d4b-71f038913a9b",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223598",
|
|
"uuid": "65c18dcf-8f32-4622-8ad9-16fba085630d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223598",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "22144405-44e1-4e43-875f-5787688879a4",
|
|
"value": "143.95.101.72"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223598",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "3283c40c-f30d-434c-b31b-dde94f3d7d7e",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223598",
|
|
"uuid": "0bc0ec79-62fd-4c4d-aea9-43ee08adc4d1",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223598",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "93d7dc88-5bdc-40d1-adec-01b1342292a2",
|
|
"value": "138.197.140.163"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223598",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "47cb62ef-03aa-4384-9f85-dfa36e815b90",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223599",
|
|
"uuid": "139a5e87-4322-4452-a62e-7ac5ccf2bb16",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223599",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "4762e74c-1bb1-4c38-813a-18fcdf24656d",
|
|
"value": "190.10.194.42"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223599",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "b0050f9c-a11a-4eb5-b1f4-10228efa0ff8",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223599",
|
|
"uuid": "3ba85ff4-9653-42e5-bf81-2a733acd93cb",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223600",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "55903d6d-e073-4180-a634-ff24fd5f900e",
|
|
"value": "190.92.103.7"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223600",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "fdf5ab15-c718-45b8-a060-3b2fc1ad240c",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223600",
|
|
"uuid": "fed6e80b-435c-4777-a3ca-d541f83982d9",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223600",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "97ba384a-04b8-491a-9c48-b7af4101fe17",
|
|
"value": "78.109.34.178"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223600",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "ad70e37f-c9c9-437d-85fe-32ea10434b45",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223601",
|
|
"uuid": "1da6d27e-6c9a-4e88-81b6-ef2f1688e29c",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223601",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "f9c767da-dffa-4fcb-bafd-18e39178ae6a",
|
|
"value": "45.33.1.161"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223601",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "17cc1e28-b9d0-4767-85cc-cacaf80cef90",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223601",
|
|
"uuid": "0d7d3724-e303-4945-aaa7-d02bc89aaf93",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223602",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "2f6a8323-2477-4e53-b71b-1233ff2192fe",
|
|
"value": "108.179.216.46"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223602",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "f4986be0-e4dd-44cf-92c3-101a8b6af9bd",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223602",
|
|
"uuid": "f4f9b340-083b-40a6-b179-9cd489a5ef12",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223603",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "4f2ac29b-fd15-4dcd-9eaf-80b22d4e3482",
|
|
"value": "152.168.220.188"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223603",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "ccfb460b-0887-4cf2-b5de-63fd5f0e7c0c",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223603",
|
|
"uuid": "741ca79c-d0b0-41cf-8535-1d7740a21836",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223603",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "1061936b-734b-4ee8-b7d3-7c06f964f039",
|
|
"value": "159.69.211.211"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223603",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "039beb65-1681-4d02-9ad3-4e89840d0615",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223604",
|
|
"uuid": "24e3c669-52ce-4301-ac3f-01b867af7f35",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223604",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "edd4ba92-e7fc-4b02-8579-55d5dc13ab6d",
|
|
"value": "94.177.253.126"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223604",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "ecac2896-80a4-4925-bcc3-5633d03b15e9",
|
|
"value": "80"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223604",
|
|
"uuid": "18c48569-7ebb-4800-862e-3340b2182c63",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223605",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "3a859e54-8f5b-4b16-8473-9ad6418bb833",
|
|
"value": "93.78.205.196"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223605",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "1e45d9aa-5592-4775-86a5-18840e01de2f",
|
|
"value": "443"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223605",
|
|
"uuid": "4431284b-11ff-488b-bcdb-4d043e8f8aa7",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223605",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "2d639cb7-009a-4287-8f7a-d0d6d543e7bc",
|
|
"value": "190.146.81.138"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223605",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "141c5a95-cfb1-4d87-9a63-380e10958852",
|
|
"value": "8090"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223605",
|
|
"uuid": "b301c083-d55e-4928-94cc-8742db88255d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223606",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "22878105-75e1-4afb-bd94-55a66bc1e937",
|
|
"value": "46.32.229.152"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223606",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "d40b0e92-2885-4230-ac1e-cada32646998",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223606",
|
|
"uuid": "200b3fe1-3158-401d-8f28-a37ef1aaafa3",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223606",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "c81759a1-ef05-45b2-af76-4237ddc6d506",
|
|
"value": "181.113.229.139"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223606",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "da9f5195-44cd-4692-b27e-63b057bfa5df",
|
|
"value": "990"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223607",
|
|
"uuid": "ad311c7f-2d41-42d2-a229-9b3011faf234",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223607",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "3d838b38-ca0b-40d3-b0c5-59c5f5cb7ef8",
|
|
"value": "178.249.187.150"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223607",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "c7209ed4-0695-483a-bc53-d3ab12a16a17",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223608",
|
|
"uuid": "7e6436d7-e86e-45cc-a8c0-2c4268f95c0d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223608",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "d442ccdc-3cf0-4402-b6a7-9f525a79fed3",
|
|
"value": "216.70.88.55"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223608",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "187bf1ef-1f61-484e-bb0b-12c5d46e29ae",
|
|
"value": "8080"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "An IP address (or domain or hostname) and a port seen as a tuple (or as a triple) in a specific time frame.",
|
|
"meta-category": "network",
|
|
"name": "ip-port",
|
|
"template_uuid": "9f8cea74-16fe-4968-a2b4-026676949ac6",
|
|
"template_version": "7",
|
|
"timestamp": "1569223608",
|
|
"uuid": "957eff87-41c4-4b83-aa04-ae5594e71a3a",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "ip",
|
|
"timestamp": "1569223609",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "082c9924-ec70-4d99-9474-d210e37492d4",
|
|
"value": "200.82.147.93"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "dst-port",
|
|
"timestamp": "1569223609",
|
|
"to_ids": false,
|
|
"type": "port",
|
|
"uuid": "b3404fdb-c50e-4563-914a-773fb3e6d814",
|
|
"value": "7080"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
} |