139 lines
No EOL
4 KiB
JSON
139 lines
No EOL
4 KiB
JSON
{
|
|
"Event": {
|
|
"analysis": "0",
|
|
"date": "2016-09-05",
|
|
"extends_uuid": "",
|
|
"info": "Malspam 2016-09-05 (.js in .zip) - campaign: \"Credit card receipt\"",
|
|
"publish_timestamp": "1473076239",
|
|
"published": true,
|
|
"threat_level_id": "3",
|
|
"timestamp": "1473076199",
|
|
"uuid": "57cd5a06-59e0-44a8-9200-3306950d210f",
|
|
"Orgc": {
|
|
"name": "CIRCL",
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
},
|
|
"Tag": [
|
|
{
|
|
"colour": "#ffffff",
|
|
"name": "tlp:white"
|
|
},
|
|
{
|
|
"colour": "#3b7500",
|
|
"name": "circl:incident-classification=\"malware\""
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473076151",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "57cd5bb7-b798-4b79-95c3-48a8950d210f",
|
|
"value": "http://canonsupervideo4k.ws/1bcpr7xx"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473076151",
|
|
"to_ids": true,
|
|
"type": "domain",
|
|
"uuid": "57cd5bb7-9e68-48cf-a3eb-4f6e950d210f",
|
|
"value": "canonsupervideo4k.ws"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473076151",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "57cd5bb7-953c-4c3a-8e38-4d26950d210f",
|
|
"value": "107.173.176.4"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473076152",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "57cd5bb8-ae0c-470b-8673-4818950d210f",
|
|
"value": "http://darkestzone2.wang/1i0i75gq"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473076152",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "57cd5bb8-c47c-4071-90c8-445c950d210f",
|
|
"value": "darkestzone2.wang"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473076152",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "57cd5bb8-26bc-4ef9-8ad2-4d45950d210f",
|
|
"value": "http://tradesmartcoin.xyz/3o8pon"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473076152",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "57cd5bb8-783c-4507-815a-4488950d210f",
|
|
"value": "tradesmartcoin.xyz"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473076153",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "57cd5bb9-0d4c-4ee1-accb-418a950d210f",
|
|
"value": "216.126.225.159"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473076199",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "57cd5be7-66c8-476d-bbb9-4c0a950d210f",
|
|
"value": "listofbuyersus.co.in"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473076199",
|
|
"to_ids": true,
|
|
"type": "domain",
|
|
"uuid": "57cd5be7-37f8-4b36-a89a-4af9950d210f",
|
|
"value": "videoconvertermac.in"
|
|
}
|
|
]
|
|
}
|
|
} |