132 lines
No EOL
3.8 KiB
JSON
132 lines
No EOL
3.8 KiB
JSON
{
|
|
"Event": {
|
|
"analysis": "0",
|
|
"date": "2016-09-06",
|
|
"extends_uuid": "",
|
|
"info": "Malspam 2016-09-06 (.js in .zip) - campaign: \"copies\"",
|
|
"publish_timestamp": "1473164404",
|
|
"published": true,
|
|
"threat_level_id": "3",
|
|
"timestamp": "1473164373",
|
|
"uuid": "57ceb43f-b180-449b-a0d6-4afe950d210f",
|
|
"Orgc": {
|
|
"name": "CIRCL",
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
},
|
|
"Tag": [
|
|
{
|
|
"colour": "#ffffff",
|
|
"local": "0",
|
|
"name": "tlp:white",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#3a7300",
|
|
"local": "0",
|
|
"name": "circl:incident-classification=\"malware\"",
|
|
"relationship_type": ""
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473164371",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "57ceb453-d430-4f67-b235-4e00950d210f",
|
|
"value": "216.244.68.195"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473164371",
|
|
"to_ids": true,
|
|
"type": "domain",
|
|
"uuid": "57ceb453-19ec-47e5-bfcb-467a950d210f",
|
|
"value": "bookinghotworld.ws"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473164371",
|
|
"to_ids": true,
|
|
"type": "domain",
|
|
"uuid": "57ceb453-7ca4-42ad-aee0-4977950d210f",
|
|
"value": "canonsupervideo4k.ws"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473164371",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "57ceb453-ce18-4c6a-ba72-443a950d210f",
|
|
"value": "darkestzone2.wang"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473164372",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "57ceb454-c2d4-4edd-a1f8-4ddf950d210f",
|
|
"value": "http://bookinghotworld.ws/18p0no4e"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473164372",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "57ceb454-b818-4639-bb5f-4772950d210f",
|
|
"value": "http://canonsupervideo4k.ws/54m7lt3"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473164372",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "57ceb454-84b4-40a3-a520-4430950d210f",
|
|
"value": "http://darkestzone2.wang/7b5hft"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473164372",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "57ceb454-b7a0-4e92-9466-4c99950d210f",
|
|
"value": "http://tradesmartcoin.xyz/ncgpse"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473164372",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "57ceb454-6df0-4491-a206-46c4950d210f",
|
|
"value": "tradesmartcoin.xyz"
|
|
}
|
|
]
|
|
}
|
|
} |