187 lines
No EOL
5.4 KiB
JSON
187 lines
No EOL
5.4 KiB
JSON
{
|
|
"Event": {
|
|
"analysis": "0",
|
|
"date": "2016-09-14",
|
|
"extends_uuid": "",
|
|
"info": "Malspam 2016-09-14 (.wsf in .zip) - campaign: \"Tax invoice\"",
|
|
"publish_timestamp": "1473847988",
|
|
"published": true,
|
|
"threat_level_id": "3",
|
|
"timestamp": "1473847978",
|
|
"uuid": "57d9227b-d318-4c5a-9045-4fc3950d210f",
|
|
"Orgc": {
|
|
"name": "CIRCL",
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
},
|
|
"Tag": [
|
|
{
|
|
"colour": "#ffffff",
|
|
"local": "0",
|
|
"name": "tlp:white",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#3a7300",
|
|
"local": "0",
|
|
"name": "circl:incident-classification=\"malware\"",
|
|
"relationship_type": ""
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473847975",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "57d922a7-7a00-478b-b085-4c4b950d210f",
|
|
"value": "103.208.86.164"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473847975",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "57d922a7-b548-43b8-8b49-48c9950d210f",
|
|
"value": "178.212.131.10"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473847976",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "57d922a8-5590-47c8-830b-4e24950d210f",
|
|
"value": "192.3.7.44"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473847976",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "57d922a8-4778-4ef5-9e52-4d56950d210f",
|
|
"value": "37.200.70.6"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473847976",
|
|
"to_ids": true,
|
|
"type": "domain",
|
|
"uuid": "57d922a8-aa90-42c6-b9d4-479d950d210f",
|
|
"value": "adzebury.com"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473847976",
|
|
"to_ids": true,
|
|
"type": "domain",
|
|
"uuid": "57d922a8-7ed4-4e7e-80f5-4479950d210f",
|
|
"value": "duelrid.com"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473847976",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "57d922a8-8cf8-47e4-8f05-45e9950d210f",
|
|
"value": "http://adzebury.com/dsd7gk"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473847977",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "57d922a9-6bac-44de-9084-4717950d210f",
|
|
"value": "http://duelrid.com/b9m1t"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473847977",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "57d922a9-0b4c-41b4-a949-47cd950d210f",
|
|
"value": "http://maydayen.net/e3ib4f"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473847977",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "57d922a9-6a14-4688-b631-49df950d210f",
|
|
"value": "http://morningaamu.com/6wdyivzv"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473847977",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "57d922a9-2dcc-4ec1-8bd3-404a950d210f",
|
|
"value": "http://smilehymy.com/f72gngb"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473847978",
|
|
"to_ids": true,
|
|
"type": "domain",
|
|
"uuid": "57d922aa-2538-4e3e-b563-44e3950d210f",
|
|
"value": "maydayen.net"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473847978",
|
|
"to_ids": true,
|
|
"type": "domain",
|
|
"uuid": "57d922aa-cd08-4703-8509-4cb5950d210f",
|
|
"value": "morningaamu.com"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473847978",
|
|
"to_ids": true,
|
|
"type": "domain",
|
|
"uuid": "57d922aa-edec-48e7-ba2d-49f6950d210f",
|
|
"value": "smilehymy.com"
|
|
}
|
|
]
|
|
}
|
|
} |