99 lines
No EOL
2.8 KiB
JSON
99 lines
No EOL
2.8 KiB
JSON
{
|
|
"Event": {
|
|
"analysis": "0",
|
|
"date": "2016-09-12",
|
|
"extends_uuid": "",
|
|
"info": "Malspam 2016-09-12 (.js in .zip) - campaign: \"Budget report\"",
|
|
"publish_timestamp": "1473690285",
|
|
"published": true,
|
|
"threat_level_id": "3",
|
|
"timestamp": "1473690263",
|
|
"uuid": "57d6b9d9-5b3c-4d03-b7a7-4ed2950d210f",
|
|
"Orgc": {
|
|
"name": "CIRCL",
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
},
|
|
"Tag": [
|
|
{
|
|
"colour": "#ffffff",
|
|
"local": false,
|
|
"name": "tlp:white",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#3a7300",
|
|
"local": false,
|
|
"name": "circl:incident-classification=\"malware\"",
|
|
"relationship_type": ""
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473690261",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "57d6ba95-b054-40cb-9951-443d950d210f",
|
|
"value": "23.95.106.223"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473690262",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "57d6ba96-4ca8-47e7-84a9-482f950d210f",
|
|
"value": "http://lookbookinghotels.ws/a9sgrrak"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473690262",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "57d6ba96-57e8-445e-a8e6-4f58950d210f",
|
|
"value": "http://trybttr.ws/h71qizc"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473690262",
|
|
"to_ids": true,
|
|
"type": "domain",
|
|
"uuid": "57d6ba96-e180-4ced-ba82-474a950d210f",
|
|
"value": "lookbookinghotels.ws"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473690262",
|
|
"to_ids": true,
|
|
"type": "domain",
|
|
"uuid": "57d6ba96-d440-450a-80fb-411f950d210f",
|
|
"value": "trybttr.ws"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "download location",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1473690262",
|
|
"to_ids": true,
|
|
"type": "domain",
|
|
"uuid": "57d6ba96-a088-45b3-9315-4c3f950d210f",
|
|
"value": "one4four1.ws"
|
|
}
|
|
]
|
|
}
|
|
} |