556 lines
No EOL
17 KiB
JSON
556 lines
No EOL
17 KiB
JSON
{
|
|
"Event": {
|
|
"analysis": "1",
|
|
"date": "2017-09-26",
|
|
"extends_uuid": "",
|
|
"info": "M2M - Locky 2017-09-26 : Affid=3, offline, \".ykcol\":\"INVOICE\" - \"A1234567890.7z\"",
|
|
"publish_timestamp": "1513180991",
|
|
"published": true,
|
|
"threat_level_id": "3",
|
|
"timestamp": "1513180979",
|
|
"uuid": "59ca3ba5-b2b0-4473-b296-ff74950d210f",
|
|
"Orgc": {
|
|
"name": "CIRCL",
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
},
|
|
"Tag": [
|
|
{
|
|
"colour": "#ffffff",
|
|
"local": "0",
|
|
"name": "tlp:white",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#006c6c",
|
|
"local": "0",
|
|
"name": "ecsirt:malicious-code=\"ransomware\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#0088cc",
|
|
"local": "0",
|
|
"name": "misp-galaxy:ransomware=\"Locky\"",
|
|
"relationship_type": ""
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Artifacts dropped",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1506425765",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "59ca3ba5-5094-4e1b-8af0-4037950d210f",
|
|
"value": "da9e78d691e18dfa299c805cbf497118"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180940",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "59ca3ba6-1624-4fd4-be1e-4ac0950d210f",
|
|
"value": "http://bodywork-sf.net/dg6rerg"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180940",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "59ca3ba6-fc90-421f-88a8-41b6950d210f",
|
|
"value": "bodywork-sf.net"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "bodywork-sf.net",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180940",
|
|
"to_ids": false,
|
|
"type": "ip-dst",
|
|
"uuid": "59ca3ba6-cdc4-43ec-b29f-4e26950d210f",
|
|
"value": "98.124.251.167"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180940",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "59ca3ba6-b1f4-4ad9-9818-4f2e950d210f",
|
|
"value": "http://boetsebiltong.co.za/dg6rerg"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180940",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "59ca3ba7-2514-48e0-8122-4da1950d210f",
|
|
"value": "boetsebiltong.co.za"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "boetsebiltong.co.za",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180940",
|
|
"to_ids": false,
|
|
"type": "ip-dst",
|
|
"uuid": "59ca3ba7-7bd4-41bd-8f91-4461950d210f",
|
|
"value": "41.72.154.153"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180940",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "59ca3ba7-9528-498e-a37a-4eb2950d210f",
|
|
"value": "http://bouwpartnerzaagenschaaf.nl/dg6rerg"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180940",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "59ca3ba7-0cc4-44a2-8270-498f950d210f",
|
|
"value": "bouwpartnerzaagenschaaf.nl"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "bouwpartnerzaagenschaaf.nl",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180940",
|
|
"to_ids": false,
|
|
"type": "ip-dst",
|
|
"uuid": "59ca3ba8-f01c-43f6-bacb-499a950d210f",
|
|
"value": "84.38.226.161"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180940",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "59ca3ba8-32bc-4c4b-9b9f-4fa3950d210f",
|
|
"value": "http://brand-online.eu/dg6rerg"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180940",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "59ca3ba8-dbec-47eb-81c8-4e19950d210f",
|
|
"value": "brand-online.eu"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "brand-online.eu",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180940",
|
|
"to_ids": false,
|
|
"type": "ip-dst",
|
|
"uuid": "59ca3ba8-af3c-4d69-b69d-4460950d210f",
|
|
"value": "85.214.253.117"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180940",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "59ca3ba8-2484-4b0d-affb-46fa950d210f",
|
|
"value": "http://brascopperchile.cl/dg6rerg"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "59ca3ba9-03f8-49f6-af33-46c0950d210f",
|
|
"value": "brascopperchile.cl"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "brascopperchile.cl",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": false,
|
|
"type": "ip-dst",
|
|
"uuid": "59ca3ba9-c138-4061-8ef3-48d8950d210f",
|
|
"value": "72.249.104.96"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "59ca3ba9-d438-4c81-8f39-4df7950d210f",
|
|
"value": "http://bredabeckerle.com/dg6rerg"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "59ca3ba9-87e0-4f15-aec1-4c65950d210f",
|
|
"value": "bredabeckerle.com"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "bredabeckerle.com",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": false,
|
|
"type": "ip-dst",
|
|
"uuid": "59ca3ba9-7fcc-43c5-ba9e-491a950d210f",
|
|
"value": "65.44.220.51"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "59ca3baa-bd90-4e10-a342-4f52950d210f",
|
|
"value": "http://brendo.biz/dg6rerg"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "59ca3baa-da48-4758-a542-4233950d210f",
|
|
"value": "brendo.biz"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "brendo.biz",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": false,
|
|
"type": "ip-dst",
|
|
"uuid": "59ca3baa-3988-43a7-b6db-4a36950d210f",
|
|
"value": "103.53.172.3"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "59ca3baa-4688-40f3-914c-45e6950d210f",
|
|
"value": "http://broadcastaudiodevices.com/dg6rerg"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "59ca3baa-c624-4af0-b200-4038950d210f",
|
|
"value": "broadcastaudiodevices.com"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "broadcastaudiodevices.com",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": false,
|
|
"type": "ip-dst",
|
|
"uuid": "59ca3bab-31e8-40cd-b2a1-48ed950d210f",
|
|
"value": "87.106.187.207"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "59ca3bab-99fc-41e8-a12c-492f950d210f",
|
|
"value": "http://bsfotodesign.com/dg6rerg"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "59ca3bab-da08-43ae-8498-4502950d210f",
|
|
"value": "bsfotodesign.com"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "bsfotodesign.com",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": false,
|
|
"type": "ip-dst",
|
|
"uuid": "59ca3bab-73a0-48dc-80ad-4a05950d210f",
|
|
"value": "80.172.241.44"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "59ca3bab-dcec-4031-a8d6-493c950d210f",
|
|
"value": "http://cadsangiorgio.com/dg6rerg"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "59ca3bac-e6cc-4a1b-9c27-ff74950d210f",
|
|
"value": "cadsangiorgio.com"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "cadsangiorgio.com",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": false,
|
|
"type": "ip-dst",
|
|
"uuid": "59ca3bac-46cc-4534-8dd1-4cbc950d210f",
|
|
"value": "94.23.218.112"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "59ca3bac-8c90-434b-8efd-4ae6950d210f",
|
|
"value": "http://caldas-cca.com/dg6rerg"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "59ca3bac-4c60-4e26-88de-4db7950d210f",
|
|
"value": "caldas-cca.com"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "caldas-cca.com",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": false,
|
|
"type": "ip-dst",
|
|
"uuid": "59ca3bad-7010-44e6-b0b4-43f0950d210f",
|
|
"value": "31.47.73.147"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "59ca3bad-1e34-4a8d-a62f-418c950d210f",
|
|
"value": "http://playbrief.info/p66/dg6rerg"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "59ca3bad-c788-4860-bc9f-4325950d210f",
|
|
"value": "playbrief.info"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "payment url",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1513180939",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "59ca3c3e-1afc-4177-8a36-4012950d210f",
|
|
"value": "g46mbrrzpfszonuk.onion"
|
|
}
|
|
],
|
|
"Object": [
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "7",
|
|
"timestamp": "1513180943",
|
|
"uuid": "d6a29259-b755-4577-8e9e-aa469b450d09",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "d6a29259-b755-4577-8e9e-aa469b450d09",
|
|
"referenced_uuid": "3d7a6ad5-2ce1-4c80-a7e1-5320084a5c18",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1513180940",
|
|
"uuid": "5a314f0c-f378-49c3-baf8-41f602de0b81"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1513180940",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "5a314f0c-c5f0-45fc-8a59-4f2e02de0b81",
|
|
"value": "da9e78d691e18dfa299c805cbf497118"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1513180940",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5a314f0c-fea4-4f85-8998-42b402de0b81",
|
|
"value": "6a90cce461369432d65ec7a8ba9c79eec9884660b02de5bef6b1d02e31553f15"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1513180940",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "5a314f0c-07b0-45a4-a51e-43f902de0b81",
|
|
"value": "ef03943f1a90a11dbc87ad2d99d4644e452643c4"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "1",
|
|
"timestamp": "1513180940",
|
|
"uuid": "3d7a6ad5-2ce1-4c80-a7e1-5320084a5c18",
|
|
"Attribute": [
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1513180940",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "5a314f0c-3ab4-41e6-aa82-454002de0b81",
|
|
"value": "https://www.virustotal.com/file/6a90cce461369432d65ec7a8ba9c79eec9884660b02de5bef6b1d02e31553f15/analysis/1512655657/"
|
|
},
|
|
{
|
|
"category": "Other",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1513180940",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "5a314f0c-ea20-4830-a510-4d3302de0b81",
|
|
"value": "56/68"
|
|
},
|
|
{
|
|
"category": "Other",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1513180940",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "5a314f0c-8a00-46cc-a003-42a302de0b81",
|
|
"value": "2017-12-07T14:07:37"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
} |