4596 lines
No EOL
164 KiB
JSON
4596 lines
No EOL
164 KiB
JSON
{
|
|
"Event": {
|
|
"analysis": "2",
|
|
"date": "2019-04-09",
|
|
"extends_uuid": "",
|
|
"info": "OSINT - Mirai Compiled for New Processors Surfaces in the Wild",
|
|
"publish_timestamp": "1554821644",
|
|
"published": true,
|
|
"threat_level_id": "3",
|
|
"timestamp": "1554821614",
|
|
"uuid": "5cacb081-1854-4035-acbc-4096950d210f",
|
|
"Orgc": {
|
|
"name": "CIRCL",
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
},
|
|
"Tag": [
|
|
{
|
|
"colour": "#004646",
|
|
"local": "0",
|
|
"name": "type:OSINT",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#0071c3",
|
|
"local": "0",
|
|
"name": "osint:lifetime=\"perpetual\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#0087e8",
|
|
"local": "0",
|
|
"name": "osint:certainty=\"50\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#ffffff",
|
|
"local": "0",
|
|
"name": "tlp:white",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#0088cc",
|
|
"local": "0",
|
|
"name": "misp-galaxy:botnet=\"Mirai\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#0088cc",
|
|
"local": "0",
|
|
"name": "misp-galaxy:malpedia=\"Mirai\"",
|
|
"relationship_type": ""
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb092-2ab0-4c03-9b7e-427d950d210f",
|
|
"value": "0c35f2902d92ef4f46e4643d11c46bde57027bb14e2b75c027a50fe7efc4f358"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb092-eae8-477b-8bfd-44eb950d210f",
|
|
"value": "3446c2ed11a6a5e02702afd5f7082eb435b2922096443cabd45d54b5b7582cc1"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb092-8b44-4727-a24b-4f37950d210f",
|
|
"value": "48c760ba6b6a29e2a90bdb88bf96486c158f2b47ee9e1c560a47071e39bb5e87"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb092-dfd8-4b5d-a111-4cb6950d210f",
|
|
"value": "5876c9ac609ece0e051c57b380489490bc78e40c796b637af1e80adbdb9f70dc"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb092-5308-44b2-b3d7-4fce950d210f",
|
|
"value": "a457090fb6df8cb93c91ec6b5d89927f7a6f9e247389d945d44731351a367b4e"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb092-e640-44c3-8a4c-4d74950d210f",
|
|
"value": "ed5e313821bf3a20d226c1b5f2b0ba7f1897d0778c27620017b852579e3e1894"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb092-0e8c-47c6-9c76-43ae950d210f",
|
|
"value": "fae498477388c53c8c623fd8ddb710cc286584200767907b104d55f916d37c05"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0a0-da90-4388-8e3a-4629950d210f",
|
|
"value": "006436f282f46f49eb97c2e119622ac61086a908623ca741eb29caeca22c797a"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0a0-55e4-459d-b37f-49d8950d210f",
|
|
"value": "28bb80c687cb0aeea0b2d53dd5bf34f21f7292e5708b0aefeea25aebe2ff93af"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0a0-0004-4e31-ad5f-4829950d210f",
|
|
"value": "5647168f9818dc40599d057c426424709bde5722c62088ecff64b97d3acfc4a7"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0a0-d83c-414d-b500-4ccc950d210f",
|
|
"value": "57cc6875ae0c571ef1edaae72d82b0da6e60331ad4b3ad34c922b9e4612b8779"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0a0-0580-43b0-9646-4723950d210f",
|
|
"value": "61893583675935ac7a4857542f13d513ffbb176b302a72d26d7ec39fd931decb"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0a0-5dbc-4d80-b9a3-48b5950d210f",
|
|
"value": "ac4a00bfe1031e19eb9a101d61ef5267627ebaeb2aca4b962c7bb1b5a59e337c"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0a0-461c-4f4b-8908-4ec1950d210f",
|
|
"value": "b0cef399ea8ec2244aebb3506a2bb60c64c3921e816c0fc9752caf84c6cf196d"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0a0-00c8-43ec-af2e-4022950d210f",
|
|
"value": "b5da0b6070d9cf3a3d628864e0f0860c8fc967ce692c0142f5a6dafee64079f6"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0af-3dec-451d-a56a-4c90950d210f",
|
|
"value": "09f8885872bc47e03608d6725f8735074c8b915ca08540e367921223058c108a"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0af-f534-484b-b714-4072950d210f",
|
|
"value": "199f1976cb5fb39a9c395a28e2178476b6eaec0f3499a5a11912f103dcd64d00"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0af-3384-4735-beef-4d84950d210f",
|
|
"value": "1efdfc79d0c4b779966dfcae7d4f0a1f17f043e098ec0f90ff12a7ebc3c3f1f1"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0af-823c-4fa5-b5c3-4637950d210f",
|
|
"value": "24b4c838dd41c0d812f747e48cf24be4f2265bce8f1e4d0d8ca6a7fc5649019b"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0af-3518-4f11-b865-4fae950d210f",
|
|
"value": "59b7a7baf4c239786fdf5ceca9084d829c6f6fc0603a524df313b2ef4958e4c2"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0af-daec-4e16-b566-445c950d210f",
|
|
"value": "6183c7c87ff7cc3721c000af73714be27884a22057c4dc69bccd34571353f327"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0af-fd54-474b-b2a5-486a950d210f",
|
|
"value": "74a45ff17678e0bddf383b5229785dda04c515e778bc9421d9396168f1cf3c3d"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0af-89b4-47cd-81b9-4180950d210f",
|
|
"value": "76c9e543a0386994031b4905533eccd05400b3bb12fefc94f1eb65af5debe986"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0af-7854-48cf-a3ce-4d00950d210f",
|
|
"value": "b6359a84bd36a3ce8a13f1306ad74d757c384a772691c228c9a00a5246d828fa"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0af-233c-4797-b963-4c10950d210f",
|
|
"value": "b758405fd18c4518878868163472bcb4e988e4ecbc3312b9756d231b80646816"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0af-569c-4e62-8740-4833950d210f",
|
|
"value": "b89196b9773c6c809a2547434ce3e9de8a494ed7b338e013fd3f2818b4b54fd1"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0af-a4f0-4040-ba9c-4816950d210f",
|
|
"value": "c33080bea85616fd1251f877cd9ff570dd6a2e2f24cc20254754cb2c74a2375e"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0af-729c-4027-818f-4c88950d210f",
|
|
"value": "d21880f4f919c410d0f2ee447716a2f7288dbaa21ec7de8601f0fc999b4d3d45"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0af-16a0-4006-bfac-4e6e950d210f",
|
|
"value": "f646c45feb0ccab4caf61bdb4aa45b0295614b2e881ad9c594ccaec2ea886671"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-cc98-4ca4-a94f-484a950d210f",
|
|
"value": "006b73c03760f168a5d71c0edd50e9a437aca7b3db1dbecac75ea2ef9e74f54f"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-cbc0-473c-a8ba-4c37950d210f",
|
|
"value": "233790b3a74245c4660cadec23145246484154abd01edd45836c31598f96b13d"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-dc38-4436-9c13-42e7950d210f",
|
|
"value": "26298ff73035ef2dc92cda118d476933d3014b39ac478865bd86d28aa5457459"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-9148-4f8d-a324-4aae950d210f",
|
|
"value": "2d7ed9ccd1b94f58aff30f7a7d798dd03b6a0f5bed2a529e1e13d8d78e9ae289"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-5274-4f59-86ea-4bba950d210f",
|
|
"value": "3891a82075bd173bb1e052c27f1be946559aaeb65e6a4c761ba8bbd2cbccd3fb"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-a2e0-4e05-9f43-46eb950d210f",
|
|
"value": "43c5efda1875fd809f97b49d296f34e1292ed86e5a4197460764fe67b98294ef"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-bed0-4c8e-a3b5-4fe7950d210f",
|
|
"value": "44f1d6144df90adea1b7b482c84946257c9fb70a9c195a6846f416de80b5e6fd"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-0dac-42be-bc13-410f950d210f",
|
|
"value": "4cb4c5cbf7eb646bdc08640f4f9e9a4383a9c7ac4e26be0caeb9dc904670c5bf"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-7ee8-418b-92fb-4304950d210f",
|
|
"value": "4d8a4841a2f4a61ed6df2be79dd7ea1eb2052cee6eba4d8de30add7908ebb779"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-1928-474d-ad59-40d2950d210f",
|
|
"value": "537c2d136a805fe1b703709b0794e25f91f2136027287fa4817080330c7989ce"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-84ec-47d4-9eec-4c10950d210f",
|
|
"value": "683b6f8209725ae0e715cda5a1cd35bcaacb5d45ae8e487c98dce2c01c91c887"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-c5b8-4b62-bd40-43de950d210f",
|
|
"value": "9b1eab0283fd6948a9a181abaa2f6b3c26f2b0077c8a8b32e763790dd64d2a22"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-9e54-45a4-a8ce-49be950d210f",
|
|
"value": "a736d6ebf9596872f3c92ac486be2588ccf0c53cf15a3897a97c83ca1525ff8d"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-3704-471e-99fe-43aa950d210f",
|
|
"value": "a9dbcc2681d427f9820ca9c5ec120b9bf3e83c9856e89736884ee4dc26712e50"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-a3f4-4e70-bc39-4db1950d210f",
|
|
"value": "bdd19fa8a7c0e3a5ebbb14d5885cb09a863122ad2c78f53361db0c194045d491"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-9b08-4cf0-ad80-4144950d210f",
|
|
"value": "c0f18a5113b341faacb9f647cee954a237925cc62d5daff559a8a880702273c1"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-63a8-4643-bbc1-4a91950d210f",
|
|
"value": "c75b3c52c0f5eebfd4c44c3069a393e824d455c7405d57ee99fd7613b8211b31"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-1af4-4984-aa83-4b10950d210f",
|
|
"value": "d28d05477ddbb1e3de330e98a2cb199ed76df0d1c942c467c977c9b70771477a"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-d36c-4c49-9f3b-4300950d210f",
|
|
"value": "de6a0d2b8b4323bc06a6cd02b0042fc92c36319696dafafd057e905d359f60ea"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5cacb0c0-2d9c-43cb-91cf-429b950d210f",
|
|
"value": "e740f780f2b91a41c5024115bbed607b0a75e52fcf4f96b86d0f8adda0c97ddf"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821356",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "5cacb0e1-0414-411b-b1ac-4c92950d210f",
|
|
"value": "178.62.227.13/wrgjwrgjwrg246356356356/hmicroblazebe"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821368",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "5cacb0e1-85bc-4131-95e0-4779950d210f",
|
|
"value": "178.62.227.13/wrgjwrgjwrg246356356356/hmicroblazeel"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821368",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "5cacb0e1-786c-4147-b142-4bef950d210f",
|
|
"value": "178.62.227.13/wrgjwrgjwrg246356356356/hnios2"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821368",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "5cacb0e1-6158-48f4-8fa7-4af9950d210f",
|
|
"value": "178.62.227.13/wrgjwrgjwrg246356356356/hopenrisc"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821368",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "5cacb0e1-31a8-4b18-b798-489b950d210f",
|
|
"value": "178.62.227.13/wrgjwrgjwrg246356356356/hxtensa"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821395",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "5cacb113-90c0-483e-ad66-449a950d210f",
|
|
"value": "https://unit42.paloaltonetworks.com/mirai-compiled-for-new-processor-surfaces/"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821411",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "5cacb123-ac18-4214-86b8-48ca950d210f",
|
|
"value": "In late February 2019, Unit 42 discovered Mirai samples compiled for new processors/architectures not previously seen before. Despite the source code being publicly released In October of 2016, the malware has, until now, only been found targeting a fixed set of processors/architectures.\r\n\r\nUnit 42 has found the newly discovered samples are compiled for Altera Nios II, OpenRISC, Tensilica Xtensa, and Xilinx MicroBlaze processors. This is not the first time Mirai has been expanded for new processor architectures, samples targeting ARC CPUs were discovered in January 2018. Yet this development shows that Mirai developers continue to actively innovate, targeting a growing array of IoT devices. The malware gained notoriety in 2016 for its use in massive denial of service attacks on Dyn and the website of security blogger Brian Krebs. If the latest innovations lead to an increase in the number of infected devices, that means that Mirai attackers would have access to additional firepower for use in denial of service attacks.\r\n\r\nIn this blog, we show the new features we\u00e2\u20ac\u2122ve found in these new samples, discuss the infrastructure we observed, show how other Mirai samples using known exploits were hosted on the same infrastructure as the new samples, and give indicators of compromise (IoCs) for these new samples.\r\n\r\nTo protect against Mirai and other threats, organizations should make securing their IoT devices with the latest updates and non-default passwords a priority."
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821500",
|
|
"to_ids": false,
|
|
"type": "vulnerability",
|
|
"uuid": "5cacb17c-a0f0-4063-b721-1fd6950d210f",
|
|
"value": "CVE-2014-8361"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821500",
|
|
"to_ids": false,
|
|
"type": "vulnerability",
|
|
"uuid": "5cacb17c-8378-43b1-a6dd-1fd6950d210f",
|
|
"value": "CVE-2017-17215"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1554821531",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "5cacb19b-aa84-4b1e-a70d-44a6950d210f",
|
|
"value": "178.62.227.13"
|
|
}
|
|
],
|
|
"Object": [
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821605",
|
|
"uuid": "4d6e3fee-7c21-49c4-ae5f-9cc8c2a51e0f",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "4d6e3fee-7c21-49c4-ae5f-9cc8c2a51e0f",
|
|
"referenced_uuid": "3c8f723c-33a7-49c2-93ba-1e85d049c50c",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821614",
|
|
"uuid": "5cacb1ee-8068-43fb-94d5-48ee950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "6cd4a58c-faf4-4de7-91e1-19c35dc05ff7",
|
|
"value": "faa296969c2a02bcb4d810a13eb5c851"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "7ddb634d-ea05-46a8-8234-1a8b88e5605d",
|
|
"value": "0e19b991b88c8c53384fb3a0ac04653db8e6c29b"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "e7b85416-d508-4f01-a677-f4ecf2dd1640",
|
|
"value": "44f1d6144df90adea1b7b482c84946257c9fb70a9c195a6846f416de80b5e6fd"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821606",
|
|
"uuid": "3c8f723c-33a7-49c2-93ba-1e85d049c50c",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "73fbcfe8-b315-424c-8f13-3ebebd0d29da",
|
|
"value": "2019-04-09T14:38:43"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "cef990fb-ed10-4ac1-8de5-f3dd99be4d7a",
|
|
"value": "https://www.virustotal.com/file/44f1d6144df90adea1b7b482c84946257c9fb70a9c195a6846f416de80b5e6fd/analysis/1554820723/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "06fc83ee-7be8-490d-9d49-79f16c3d18ba",
|
|
"value": "27/57"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821606",
|
|
"uuid": "f7d995da-6b74-46bd-a3bd-b216173f7ecd",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "f7d995da-6b74-46bd-a3bd-b216173f7ecd",
|
|
"referenced_uuid": "08d445db-073c-4725-b822-4dc12152dc6d",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821614",
|
|
"uuid": "5cacb1ee-2958-460c-ac84-4261950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "ec41169c-7031-491e-864f-18b3822c68a4",
|
|
"value": "db7d0b0918d8918a28ada67f2dc28d7e"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "0af3b581-473b-4afd-b144-a062e94199a0",
|
|
"value": "a5583a253c1a2441439d93762563500e6a145e08"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "4e43e8c2-93ec-4a85-94ab-8afe4f6a593f",
|
|
"value": "537c2d136a805fe1b703709b0794e25f91f2136027287fa4817080330c7989ce"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821606",
|
|
"uuid": "08d445db-073c-4725-b822-4dc12152dc6d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "11a6886f-371b-4c90-a19b-36ae205b473d",
|
|
"value": "2019-04-09T14:38:43"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "968baca9-1027-4316-bb45-b9c041a78ada",
|
|
"value": "https://www.virustotal.com/file/537c2d136a805fe1b703709b0794e25f91f2136027287fa4817080330c7989ce/analysis/1554820723/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "52b9e278-211e-4527-b57d-1c2df1246fa3",
|
|
"value": "27/56"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821606",
|
|
"uuid": "30d18426-8b6c-4bd7-9dbe-fe48578c0858",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "30d18426-8b6c-4bd7-9dbe-fe48578c0858",
|
|
"referenced_uuid": "b65f158d-86b3-46ea-8e90-5aff73b83607",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821614",
|
|
"uuid": "5cacb1ee-cb70-4600-9992-4d37950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "7b22d12e-4ef6-4761-b787-2d9162804889",
|
|
"value": "28e21fc1cd115a22e461b66614e76726"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "c463520b-a978-4511-85a3-369958ea6ec5",
|
|
"value": "2db0b72452e9e676c03cb580c0bd8f128fa16349"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "ed24df5a-dd32-464f-afd4-37bb8ce5264a",
|
|
"value": "e740f780f2b91a41c5024115bbed607b0a75e52fcf4f96b86d0f8adda0c97ddf"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821606",
|
|
"uuid": "b65f158d-86b3-46ea-8e90-5aff73b83607",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "2b7bdcc5-8354-4034-b97b-f609c0c8ec8d",
|
|
"value": "2019-04-09T14:38:48"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "9d9ec46e-dfa0-4131-ac1c-e1a7ef6aab57",
|
|
"value": "https://www.virustotal.com/file/e740f780f2b91a41c5024115bbed607b0a75e52fcf4f96b86d0f8adda0c97ddf/analysis/1554820728/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "f7f7b737-92a0-425a-8076-d821dae9fdf8",
|
|
"value": "26/55"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821606",
|
|
"uuid": "b193159a-ffa2-487b-95c4-0d8243f8ad9c",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "b193159a-ffa2-487b-95c4-0d8243f8ad9c",
|
|
"referenced_uuid": "032474ca-6510-4dde-8ed2-b9da5050112e",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821614",
|
|
"uuid": "5cacb1ee-4164-4439-9f79-43af950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "e89bbe47-41ec-450a-8bd8-86e6e904e356",
|
|
"value": "5e687ed6f3887cabe76df9ff3bb55544"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "95316f15-9cd4-4a65-8864-b40c9a09748e",
|
|
"value": "3c8e5a63687573e83ef36ad36b1ed11ded782670"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "18690281-3f2a-471d-9ebe-598b0c5e0db4",
|
|
"value": "a736d6ebf9596872f3c92ac486be2588ccf0c53cf15a3897a97c83ca1525ff8d"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821606",
|
|
"uuid": "032474ca-6510-4dde-8ed2-b9da5050112e",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "be28fdd4-91ce-4d89-86d8-41277d44fa1d",
|
|
"value": "2019-04-09T14:38:47"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "b63dd06c-915d-45b5-8b8e-6c969f111e54",
|
|
"value": "https://www.virustotal.com/file/a736d6ebf9596872f3c92ac486be2588ccf0c53cf15a3897a97c83ca1525ff8d/analysis/1554820727/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "921ca717-b58f-419d-bfc6-f502d1a089ef",
|
|
"value": "26/55"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821606",
|
|
"uuid": "71263d1f-4ce5-4dfd-8b98-22edc46918aa",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "71263d1f-4ce5-4dfd-8b98-22edc46918aa",
|
|
"referenced_uuid": "5d7e98f1-3719-4c81-9fa8-0e8c5d58cc7a",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821614",
|
|
"uuid": "5cacb1ee-9068-4032-ba1c-451b950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "75e73d32-31ca-465d-8e36-310300538fcf",
|
|
"value": "d88dae330b75ea78e773e2467b07a449"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "40274090-2267-4334-b68f-fd6275d41337",
|
|
"value": "5a405e547f0070c65bec869f8e42c19277100c44"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "e3808033-3969-4145-933c-ae9c3e1e37d2",
|
|
"value": "28bb80c687cb0aeea0b2d53dd5bf34f21f7292e5708b0aefeea25aebe2ff93af"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821607",
|
|
"uuid": "5d7e98f1-3719-4c81-9fa8-0e8c5d58cc7a",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "ede52e54-04d2-4758-9540-c1f45d09b35e",
|
|
"value": "2019-04-09T14:38:44"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "05ebcbf9-2914-40c1-b083-7b70f091e9a5",
|
|
"value": "https://www.virustotal.com/file/28bb80c687cb0aeea0b2d53dd5bf34f21f7292e5708b0aefeea25aebe2ff93af/analysis/1554820724/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "d3b485ad-00f0-477d-a050-78707dc34a74",
|
|
"value": "26/55"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821607",
|
|
"uuid": "f520e3f7-1da0-4457-8f67-3515a31174bc",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "f520e3f7-1da0-4457-8f67-3515a31174bc",
|
|
"referenced_uuid": "7fd6de13-43fb-46d7-a71c-3d7df2cb0667",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821614",
|
|
"uuid": "5cacb1ee-36ac-44c8-8226-4195950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "175328a9-8b52-46fa-9aa7-f0a01aa81c91",
|
|
"value": "68474973ee4e95a5316e2c038b4f1b76"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "c1342a0f-9133-45bd-8b01-0d727b8863bc",
|
|
"value": "4f25dd20f320f4737369535e18a1ddd6b144f582"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "95032837-78f7-4db9-b2a3-4f8f22aefe28",
|
|
"value": "5647168f9818dc40599d057c426424709bde5722c62088ecff64b97d3acfc4a7"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821607",
|
|
"uuid": "7fd6de13-43fb-46d7-a71c-3d7df2cb0667",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "ee7b9358-d974-438b-a2db-0aa98329a899",
|
|
"value": "2019-04-09T14:38:44"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "06e4ca20-4ec3-4452-a467-0beb1719f2c9",
|
|
"value": "https://www.virustotal.com/file/5647168f9818dc40599d057c426424709bde5722c62088ecff64b97d3acfc4a7/analysis/1554820724/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "7a607e73-86da-45da-8032-7f318678583b",
|
|
"value": "25/56"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821607",
|
|
"uuid": "6a5f7378-218c-4ea3-a54d-c5767472ddb1",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "6a5f7378-218c-4ea3-a54d-c5767472ddb1",
|
|
"referenced_uuid": "b8d2d6ad-e5e3-42a5-b950-1046b821f68f",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821614",
|
|
"uuid": "5cacb1ee-0b04-43b1-bebd-4abe950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "71c89e68-7f25-422b-a56e-36c4b3564489",
|
|
"value": "b93e64100d422a1e1bd2c857d04d16d9"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "fedf886f-ee0e-4486-b095-e9617d3f4e51",
|
|
"value": "9f54db846bff49c5467ed03c583a851d882f930a"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "eeb02934-f8bf-4451-82e8-0aa51ecab70a",
|
|
"value": "b5da0b6070d9cf3a3d628864e0f0860c8fc967ce692c0142f5a6dafee64079f6"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821607",
|
|
"uuid": "b8d2d6ad-e5e3-42a5-b950-1046b821f68f",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "7c7097dc-7c52-48be-8ef6-3e430f924a3a",
|
|
"value": "2019-04-09T14:38:45"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "ef14212c-5ae7-4d28-8f08-7ad47b711b5d",
|
|
"value": "https://www.virustotal.com/file/b5da0b6070d9cf3a3d628864e0f0860c8fc967ce692c0142f5a6dafee64079f6/analysis/1554820725/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "5acef96f-3e25-4bd6-a96f-f35eb4498f48",
|
|
"value": "26/57"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821607",
|
|
"uuid": "ccaa3b0c-b5e6-4536-9606-b56b08602015",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "ccaa3b0c-b5e6-4536-9606-b56b08602015",
|
|
"referenced_uuid": "298cf9d4-5927-4a83-abf4-b195c0b926a7",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-118c-4845-a32e-475a950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "ba50a7b5-dff0-4c8d-bbec-a186e3ed4d3a",
|
|
"value": "9c691e5f7d2a0f99b0e9bce04e9f89f9"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "a94c269c-00b2-4c0c-a67e-04612d15e656",
|
|
"value": "2f63f5e91a43b3377ec703ee71b686f738fd3075"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "719ce2fc-98fd-4fa1-8f7a-e9601e86f6a5",
|
|
"value": "f646c45feb0ccab4caf61bdb4aa45b0295614b2e881ad9c594ccaec2ea886671"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821607",
|
|
"uuid": "298cf9d4-5927-4a83-abf4-b195c0b926a7",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "2269aa19-cffa-476b-9500-10099866f819",
|
|
"value": "2019-04-09T14:38:49"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "25cd2265-baed-432e-b1dc-9e388a86dc73",
|
|
"value": "https://www.virustotal.com/file/f646c45feb0ccab4caf61bdb4aa45b0295614b2e881ad9c594ccaec2ea886671/analysis/1554820729/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "d42b4f59-5a9e-413a-afdf-194dcc3b6d3a",
|
|
"value": "26/57"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821607",
|
|
"uuid": "e431dfa4-ace9-4c86-8348-47f0c41d5424",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "e431dfa4-ace9-4c86-8348-47f0c41d5424",
|
|
"referenced_uuid": "36cb190d-e9c4-4a68-a628-a79c96323f5a",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-ca34-47b0-b82a-419f950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "eec7be4b-99af-4183-b15c-d32f57fded60",
|
|
"value": "96bcf6a954e4a09013aafcfd1613d3c1"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "2fdd0c66-dfe5-4154-b4f7-cbc9b6ea289a",
|
|
"value": "f745cabbabe6bc0b94edb282f23ceae43687ac9d"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "fb99eed2-dd4f-4cb4-beea-eb12627ded7a",
|
|
"value": "43c5efda1875fd809f97b49d296f34e1292ed86e5a4197460764fe67b98294ef"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821607",
|
|
"uuid": "36cb190d-e9c4-4a68-a628-a79c96323f5a",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "5f5f84bf-3939-4436-b488-895e354ed150",
|
|
"value": "2019-04-09T14:38:42"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "2143807d-9289-4f40-a9b7-eee165f261e9",
|
|
"value": "https://www.virustotal.com/file/43c5efda1875fd809f97b49d296f34e1292ed86e5a4197460764fe67b98294ef/analysis/1554820722/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "f3981f91-a741-4363-83f5-67372127ee89",
|
|
"value": "23/56"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821607",
|
|
"uuid": "eaa5e596-0f6d-4ce1-aa4f-602720bd37ea",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "eaa5e596-0f6d-4ce1-aa4f-602720bd37ea",
|
|
"referenced_uuid": "fe27f62d-2cb0-4d56-a1ea-30eebcf27b8a",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-4898-45ab-b275-4600950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "640e4eaf-05dc-420d-9943-9ebf0b7d12c1",
|
|
"value": "030d0ed66c1976cbfebe1f2f77e185b9"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "ef387eac-8583-424f-81a4-116fb11dde96",
|
|
"value": "62e043ab97411660ead3ab107d31cf36e7f7cc6a"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "9c3fcff5-3778-4eb2-803c-96a8a3492ef3",
|
|
"value": "26298ff73035ef2dc92cda118d476933d3014b39ac478865bd86d28aa5457459"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821607",
|
|
"uuid": "fe27f62d-2cb0-4d56-a1ea-30eebcf27b8a",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "6a26bbe5-6e2a-4c57-9caf-1d9e2bcf49c7",
|
|
"value": "2019-04-09T14:38:44"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "8649496d-2958-4073-95d3-2c6775e46e3c",
|
|
"value": "https://www.virustotal.com/file/26298ff73035ef2dc92cda118d476933d3014b39ac478865bd86d28aa5457459/analysis/1554820724/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "393098d7-6be0-4396-b020-8c93d6484d00",
|
|
"value": "28/58"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821608",
|
|
"uuid": "6d039067-955e-4e72-a631-e049cf35a77f",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "6d039067-955e-4e72-a631-e049cf35a77f",
|
|
"referenced_uuid": "5349f3ce-b5d8-47d3-b28a-f01f5ca628d8",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-a51c-474b-b9d9-49a4950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "6c669201-2d26-4c0b-b0f9-009767e4c533",
|
|
"value": "070923d033e0f0df5a346f95ef213603"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "93dfd644-3596-41ee-b4e0-22fe4f2d451f",
|
|
"value": "dc1a187834113a8282bb508ecc491b3a5228df87"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "8257b3b3-deac-4248-83d6-e6387b956fc1",
|
|
"value": "b6359a84bd36a3ce8a13f1306ad74d757c384a772691c228c9a00a5246d828fa"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821608",
|
|
"uuid": "5349f3ce-b5d8-47d3-b28a-f01f5ca628d8",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "ca07c1a1-7a95-482b-ad31-1b9039796701",
|
|
"value": "2019-04-09T14:38:45"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "5b8cd520-b5c5-4a44-b5f2-92d4e7409f2e",
|
|
"value": "https://www.virustotal.com/file/b6359a84bd36a3ce8a13f1306ad74d757c384a772691c228c9a00a5246d828fa/analysis/1554820725/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "41d7af15-4288-4e2b-8b30-4c451551dd26",
|
|
"value": "24/58"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821608",
|
|
"uuid": "906f4543-dd5e-40cb-83f5-6a30ad65a3bb",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "906f4543-dd5e-40cb-83f5-6a30ad65a3bb",
|
|
"referenced_uuid": "57817aa5-8715-40b2-9f08-795fff3f197c",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-0b70-4e9d-b4c3-4a09950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "bdf479b5-5a77-4c06-b27d-b14f166ebe1e",
|
|
"value": "1b31128247d016ce5607b05c0f834d37"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "91908e0f-e7de-41f6-89b2-c0b72a36467d",
|
|
"value": "7f39e85c750bc6a04295c8edec05d279ae7abf4a"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "627462f6-608a-4720-b86f-96db3107a2a2",
|
|
"value": "d28d05477ddbb1e3de330e98a2cb199ed76df0d1c942c467c977c9b70771477a"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821608",
|
|
"uuid": "57817aa5-8715-40b2-9f08-795fff3f197c",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "f3e27b5a-2196-4609-8ad4-a028d15ead31",
|
|
"value": "2019-04-09T14:38:47"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "086c032d-d09e-4d40-a384-da1bbb3b1d3f",
|
|
"value": "https://www.virustotal.com/file/d28d05477ddbb1e3de330e98a2cb199ed76df0d1c942c467c977c9b70771477a/analysis/1554820727/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "2215e1c4-0b33-4ed6-9dfb-1568fd71528a",
|
|
"value": "24/56"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821608",
|
|
"uuid": "6e8a1137-4eeb-42f5-8b5b-30d6b8f325ef",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "6e8a1137-4eeb-42f5-8b5b-30d6b8f325ef",
|
|
"referenced_uuid": "b002923b-f027-4427-a79e-2802833d564d",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-3000-4fba-9d16-40f0950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "565ed369-9faa-44ed-b819-76a73cfd6ede",
|
|
"value": "c0736037b15f55e27bbdbd5ec15d1546"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "7d688253-aca8-4b9b-be4b-a1b6beccdb4a",
|
|
"value": "541adaf3c110d45eb40c7856ed08c134eb22de38"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5d93e62f-13b6-41c9-9718-1c274761260a",
|
|
"value": "199f1976cb5fb39a9c395a28e2178476b6eaec0f3499a5a11912f103dcd64d00"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821608",
|
|
"uuid": "b002923b-f027-4427-a79e-2802833d564d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "6c5d257d-be36-426d-9928-f6db85734d39",
|
|
"value": "2019-04-09T14:38:43"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "387ad1df-153a-4def-a115-56aacc343a51",
|
|
"value": "https://www.virustotal.com/file/199f1976cb5fb39a9c395a28e2178476b6eaec0f3499a5a11912f103dcd64d00/analysis/1554820723/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "2ebba7ee-205c-4153-8b88-b928f3803e5e",
|
|
"value": "22/57"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821608",
|
|
"uuid": "ba07517c-15ac-49e5-b2b6-c6bcc1573288",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "ba07517c-15ac-49e5-b2b6-c6bcc1573288",
|
|
"referenced_uuid": "bd8d81c1-a0c1-46cc-b8e0-d6742f9b5bbb",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-a6e0-45f5-94a0-42a5950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "118a4f99-0f8a-476a-aaf1-b37153553a47",
|
|
"value": "19a44645ccdfefb3e0476209127e5df0"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "d3f09b56-f40f-4b9b-be42-e32b721d4da9",
|
|
"value": "7ad84ff53ad50d6c440c29f5fe0dc3cf68ac6fca"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "ab238c1c-5553-452f-8334-52414d5ec454",
|
|
"value": "4cb4c5cbf7eb646bdc08640f4f9e9a4383a9c7ac4e26be0caeb9dc904670c5bf"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821608",
|
|
"uuid": "bd8d81c1-a0c1-46cc-b8e0-d6742f9b5bbb",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "6524b670-33b8-45f4-9235-7a3f8d9db7b3",
|
|
"value": "2019-04-09T14:38:43"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "b0b50ff4-fdd4-4a6a-b842-a9c6eb7e6fda",
|
|
"value": "https://www.virustotal.com/file/4cb4c5cbf7eb646bdc08640f4f9e9a4383a9c7ac4e26be0caeb9dc904670c5bf/analysis/1554820723/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "7cd8cfea-f848-4995-85d5-f4124e53e7d5",
|
|
"value": "28/58"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821608",
|
|
"uuid": "6360d4f6-e24c-4cce-869a-24ccd7f9c129",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "6360d4f6-e24c-4cce-869a-24ccd7f9c129",
|
|
"referenced_uuid": "bc7587c2-e369-4c0c-b2d2-b05a4210bcf3",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-9a38-4ac0-b3d2-4e09950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "b6758cb7-ed92-4340-a920-0ac8311d047b",
|
|
"value": "8872577b174b01ddffa596506664b87d"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "aee0a7a9-af78-4a5f-8444-ab196de1775c",
|
|
"value": "814df5ac6c3f29be1f969c9cb4009d6692ac1ee7"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "26c70899-51b2-4bb9-81c2-05b428e7ff09",
|
|
"value": "1efdfc79d0c4b779966dfcae7d4f0a1f17f043e098ec0f90ff12a7ebc3c3f1f1"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821608",
|
|
"uuid": "bc7587c2-e369-4c0c-b2d2-b05a4210bcf3",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "e42d9432-f81f-47db-b20e-e9aead7b58f9",
|
|
"value": "2019-04-09T14:38:43"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "615eace1-018e-46f6-9c7a-cb0eb59da72e",
|
|
"value": "https://www.virustotal.com/file/1efdfc79d0c4b779966dfcae7d4f0a1f17f043e098ec0f90ff12a7ebc3c3f1f1/analysis/1554820723/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "d0fa0cd7-1e9c-4d9a-951f-4a58e20367e1",
|
|
"value": "23/56"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821608",
|
|
"uuid": "4416ae3a-0659-4f4e-bc6e-5cff3da3130d",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "4416ae3a-0659-4f4e-bc6e-5cff3da3130d",
|
|
"referenced_uuid": "8bb6ab5a-d092-4bd3-8039-db1c1610653c",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-1618-4880-b995-4a49950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "41416d74-97a8-43cf-ab63-b5cdd876f582",
|
|
"value": "cf3c7438a29291d9f09d655037552558"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "7da50bdf-732f-470e-afdb-c18b0ac1cc01",
|
|
"value": "fcf643feda4e1d14cffd25cde62dc83a613f67f3"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "a2be0e9e-1c27-4e95-9ebb-8d3e4550dd72",
|
|
"value": "3446c2ed11a6a5e02702afd5f7082eb435b2922096443cabd45d54b5b7582cc1"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821609",
|
|
"uuid": "8bb6ab5a-d092-4bd3-8039-db1c1610653c",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "32190af8-f097-4a30-9b79-b674f20725ce",
|
|
"value": "2019-04-09T14:38:41"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "08bfb991-109b-4bee-8ceb-a3ae0e6115e9",
|
|
"value": "https://www.virustotal.com/file/3446c2ed11a6a5e02702afd5f7082eb435b2922096443cabd45d54b5b7582cc1/analysis/1554820721/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "bf6b88b8-4a51-4bda-a87c-55cced3494f2",
|
|
"value": "23/56"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821609",
|
|
"uuid": "382a6691-5e36-4d86-b0d8-5a04e43342fc",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "382a6691-5e36-4d86-b0d8-5a04e43342fc",
|
|
"referenced_uuid": "6ef3df89-54b3-4737-a303-bfd64e0ace0d",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-67c8-49a0-9b83-4811950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "7413f849-0bbd-43ad-a30b-f8d1e4970cd8",
|
|
"value": "527763edafc92a32f427a75885e8e093"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "62c18884-cdfe-4ace-a2af-3cca616e2176",
|
|
"value": "9eb84bfc2d7f690934db9927b9fffe08eddd61af"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "7bd9a91e-bdde-42d8-82e3-074996e7c026",
|
|
"value": "ed5e313821bf3a20d226c1b5f2b0ba7f1897d0778c27620017b852579e3e1894"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821609",
|
|
"uuid": "6ef3df89-54b3-4737-a303-bfd64e0ace0d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "8560e62f-373b-48e4-bfb7-01885093c8b8",
|
|
"value": "2019-04-09T14:38:49"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "3091c506-d4de-4985-b9a0-0c0146a064b8",
|
|
"value": "https://www.virustotal.com/file/ed5e313821bf3a20d226c1b5f2b0ba7f1897d0778c27620017b852579e3e1894/analysis/1554820729/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "d4641149-8302-4d2f-b1ab-1aca7286924b",
|
|
"value": "21/57"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821609",
|
|
"uuid": "6216369c-87cb-453b-931f-83a18954a135",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "6216369c-87cb-453b-931f-83a18954a135",
|
|
"referenced_uuid": "4ec12cbe-898c-4ccc-8775-28e4e121d5db",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-065c-421f-88b8-4795950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "4e349647-7790-4a9a-8c42-76f23f59f422",
|
|
"value": "ea26a487f8fe99b4e4faecbc258ae98b"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "657e2d03-7db5-4d58-8e7a-cf07244ca342",
|
|
"value": "c6911cd070dc46098b9acffeb834e639ae54fb5f"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "07b8e914-972b-4dd1-95f4-1cafa4ef0b21",
|
|
"value": "ac4a00bfe1031e19eb9a101d61ef5267627ebaeb2aca4b962c7bb1b5a59e337c"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821609",
|
|
"uuid": "4ec12cbe-898c-4ccc-8775-28e4e121d5db",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "6ffa46ce-4e75-438b-a2db-08aeed47304a",
|
|
"value": "2019-04-09T14:38:47"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "1f4bcd4d-b4ae-4c2a-aff6-91c4b5f0e1f4",
|
|
"value": "https://www.virustotal.com/file/ac4a00bfe1031e19eb9a101d61ef5267627ebaeb2aca4b962c7bb1b5a59e337c/analysis/1554820727/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "a1f2cf55-f43b-4ec1-803a-f34a4f4239cc",
|
|
"value": "28/57"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821609",
|
|
"uuid": "d8c1ba83-dbd0-4daa-9a16-4dc2465eab8a",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "d8c1ba83-dbd0-4daa-9a16-4dc2465eab8a",
|
|
"referenced_uuid": "92650226-7b52-4e62-be35-e3127a417cf0",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-2e94-4c3d-841d-49d1950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "5ead5f25-282c-4310-9868-7f4f1e6996af",
|
|
"value": "9c6346e59864c0163d0baa262834e925"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "bfeff236-4e97-48b4-b064-9c6c4522fa56",
|
|
"value": "13ea794313be45e63704c665e61a515c3f7651e3"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "562faff7-9612-4bd1-9d06-280834c145ac",
|
|
"value": "006b73c03760f168a5d71c0edd50e9a437aca7b3db1dbecac75ea2ef9e74f54f"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821609",
|
|
"uuid": "92650226-7b52-4e62-be35-e3127a417cf0",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "13ad6dbb-a89b-4bf3-aa22-ecd56317f930",
|
|
"value": "2019-04-09T14:38:42"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "53db994f-8d24-4a61-9780-cfc1b1aac376",
|
|
"value": "https://www.virustotal.com/file/006b73c03760f168a5d71c0edd50e9a437aca7b3db1dbecac75ea2ef9e74f54f/analysis/1554820722/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "ba4b44ae-999b-44aa-ba37-dbdfd892b0a8",
|
|
"value": "26/59"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821609",
|
|
"uuid": "a4923d2f-c6ba-4228-883c-d93835435f9a",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "a4923d2f-c6ba-4228-883c-d93835435f9a",
|
|
"referenced_uuid": "4ab686a6-fb66-492d-9bb1-487d10f99d09",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-c814-4b37-b8ec-4081950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "4c8ccb27-9f55-4dc9-a79a-406f1fa93d00",
|
|
"value": "cb015741bccea90fa250fed01f694c6e"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "029942eb-0ef8-40ef-aaf3-7305eb85f89f",
|
|
"value": "9b772e05b7e0a8314547530984a50b311e8b7693"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "f1ac1138-6a13-4683-a05e-4307a5263ba6",
|
|
"value": "c33080bea85616fd1251f877cd9ff570dd6a2e2f24cc20254754cb2c74a2375e"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821609",
|
|
"uuid": "4ab686a6-fb66-492d-9bb1-487d10f99d09",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "14e96d42-09ba-4c7d-936d-5c17b1365f4f",
|
|
"value": "2019-04-09T14:38:46"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "75228b11-c8f2-4ad7-b77b-5846519818f8",
|
|
"value": "https://www.virustotal.com/file/c33080bea85616fd1251f877cd9ff570dd6a2e2f24cc20254754cb2c74a2375e/analysis/1554820726/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "ed573984-b2ed-4f13-ae2d-15c11c863f09",
|
|
"value": "26/58"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821609",
|
|
"uuid": "b7a2d065-ed7c-41c8-a2f9-e066c92afe89",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "b7a2d065-ed7c-41c8-a2f9-e066c92afe89",
|
|
"referenced_uuid": "ba0f4453-12d4-492f-90d2-b61e08f8e2d4",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-288c-4374-af3f-4cb9950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "bb4d0a52-0648-4fca-b1cc-74fd4dabf374",
|
|
"value": "573e72820acb518fe1b46b32a012f221"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "cfb48ed6-b059-435b-856b-4654091c63f2",
|
|
"value": "2a9bc043794f45264f9f286f5f5bd5cc1aeffa5c"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "07ba3624-dc89-41f5-98b8-867dfd4b8092",
|
|
"value": "76c9e543a0386994031b4905533eccd05400b3bb12fefc94f1eb65af5debe986"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821610",
|
|
"uuid": "ba0f4453-12d4-492f-90d2-b61e08f8e2d4",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "70ad2cc3-a9d6-4f77-82fe-f528c3211f58",
|
|
"value": "2019-04-09T14:38:44"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "3dccb504-908a-478c-af00-c40d4c69759d",
|
|
"value": "https://www.virustotal.com/file/76c9e543a0386994031b4905533eccd05400b3bb12fefc94f1eb65af5debe986/analysis/1554820724/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "a3bb6ac8-c3b4-4f33-ac97-c846f0cfb115",
|
|
"value": "24/56"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821610",
|
|
"uuid": "b21504d6-8f09-420e-8dd4-4156c9fe6c4c",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "b21504d6-8f09-420e-8dd4-4156c9fe6c4c",
|
|
"referenced_uuid": "02c8cf93-3806-4e09-a801-830a0db3abf6",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-8c24-4fe5-95ed-4884950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "bb94c0a1-def5-4c53-ad9a-83774e9996dc",
|
|
"value": "28799a1fe00f26f9ae1a6392a2654996"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "908cca83-fb00-4cb1-9a79-56331f335843",
|
|
"value": "e1cedd589eb9731d1494c12f90b8e98a352d6d96"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "8d23d14d-ec75-4a5a-9ba3-ccf6d4326c0b",
|
|
"value": "24b4c838dd41c0d812f747e48cf24be4f2265bce8f1e4d0d8ca6a7fc5649019b"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821610",
|
|
"uuid": "02c8cf93-3806-4e09-a801-830a0db3abf6",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "1b14f5ce-e48d-411b-9cca-3b033b21a4b7",
|
|
"value": "2019-04-09T14:38:44"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "225285c5-006e-4e54-8460-28f27b8bc971",
|
|
"value": "https://www.virustotal.com/file/24b4c838dd41c0d812f747e48cf24be4f2265bce8f1e4d0d8ca6a7fc5649019b/analysis/1554820724/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "d275400b-f6ee-4ae6-906d-3fd2be62d323",
|
|
"value": "21/55"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821610",
|
|
"uuid": "37d88da7-8284-4bc6-9a6f-2cd49c1971cd",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "37d88da7-8284-4bc6-9a6f-2cd49c1971cd",
|
|
"referenced_uuid": "21b4521f-74e3-4b6d-90df-c30faad750de",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821615",
|
|
"uuid": "5cacb1ef-ed64-41ef-82fa-47a1950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "14d70e41-1aac-4ea3-9ea8-01a8866c66a2",
|
|
"value": "77899a6d69e23c18af5fc14605721bc1"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "6b888efd-4771-4343-a188-8dadecb4bd6f",
|
|
"value": "0ca2571aba52784af096ee6e5eaeced29b4746de"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "e955810b-54e5-44c1-a38e-da4dd1b3cce4",
|
|
"value": "b0cef399ea8ec2244aebb3506a2bb60c64c3921e816c0fc9752caf84c6cf196d"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821610",
|
|
"uuid": "21b4521f-74e3-4b6d-90df-c30faad750de",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "99d66389-79a1-47db-b88f-fd46b426e489",
|
|
"value": "2019-04-09T14:38:47"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "87480978-ba55-46d2-9b34-25bdafcb1ecb",
|
|
"value": "https://www.virustotal.com/file/b0cef399ea8ec2244aebb3506a2bb60c64c3921e816c0fc9752caf84c6cf196d/analysis/1554820727/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "60a3e7b9-df18-439e-be34-9a82f238e3fc",
|
|
"value": "26/55"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821610",
|
|
"uuid": "ceeb65b8-0b04-4166-b355-252b12391f98",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "ceeb65b8-0b04-4166-b355-252b12391f98",
|
|
"referenced_uuid": "657d45df-b4ba-4dd2-8762-43a8fd4487bf",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821616",
|
|
"uuid": "5cacb1f0-5954-403b-a09c-4930950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "a0d9feeb-526a-4850-9a50-62ea9f413acb",
|
|
"value": "3f7ba91642d882085ff753ffc118681e"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "8861e0f0-6631-4b26-9538-f69fcc620a85",
|
|
"value": "542028b60e014d5ce4f20d63fa47690d2bad6d66"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "5a66f493-5319-4790-8be0-a079bb46697c",
|
|
"value": "5876c9ac609ece0e051c57b380489490bc78e40c796b637af1e80adbdb9f70dc"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821610",
|
|
"uuid": "657d45df-b4ba-4dd2-8762-43a8fd4487bf",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "4a1f7a0a-34a5-4bc4-abeb-ea63d7569649",
|
|
"value": "2019-04-09T14:38:41"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "d1fa976e-5a91-4830-8a93-0eb11de57573",
|
|
"value": "https://www.virustotal.com/file/5876c9ac609ece0e051c57b380489490bc78e40c796b637af1e80adbdb9f70dc/analysis/1554820721/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "35cca4c8-11f1-4b9f-8e23-eb0abb77b398",
|
|
"value": "27/59"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821610",
|
|
"uuid": "98ce3838-810e-49a0-a73c-2255aceb0b23",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "98ce3838-810e-49a0-a73c-2255aceb0b23",
|
|
"referenced_uuid": "4304fa8d-bcc3-4596-b45b-92a1084f6e80",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821616",
|
|
"uuid": "5cacb1f0-2a0c-40ea-8fda-406f950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "fa44a797-fa17-4a89-9d49-a7ad4ef90771",
|
|
"value": "8ffd76166a1c5a3f2c5439716971e226"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "072b8738-2458-413c-8119-572f678b832f",
|
|
"value": "7ea7c61fa70a0526e655ec9893e8df4889b981ee"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "4a7567ea-d426-4618-9ca8-a02b3a57defd",
|
|
"value": "74a45ff17678e0bddf383b5229785dda04c515e778bc9421d9396168f1cf3c3d"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821610",
|
|
"uuid": "4304fa8d-bcc3-4596-b45b-92a1084f6e80",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "3620a9c2-7335-412c-ae00-6fcd135422a9",
|
|
"value": "2019-04-09T14:38:44"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "32b8a7c6-0078-4014-81d1-7927b3625296",
|
|
"value": "https://www.virustotal.com/file/74a45ff17678e0bddf383b5229785dda04c515e778bc9421d9396168f1cf3c3d/analysis/1554820724/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "62dc6312-cb75-47c1-8978-045a7e7342a9",
|
|
"value": "21/57"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821610",
|
|
"uuid": "8f46177b-5fad-4dff-bfe2-a64700c10f7a",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "8f46177b-5fad-4dff-bfe2-a64700c10f7a",
|
|
"referenced_uuid": "6aa42e4d-4b31-4f21-a7c4-c7c2fb0a8c16",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821616",
|
|
"uuid": "5cacb1f0-6f3c-44c7-92d6-4310950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "1d76e322-16bd-4015-b7b0-afa8175be9be",
|
|
"value": "fadf704bcfc51bb5b124fe9ea46eec5c"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "752ac3c0-6318-490b-b781-4d5c850b4bd0",
|
|
"value": "1ef3873cd6297568bc3670e86cc78c4ed877e4d9"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "4b1c84f8-1907-4a11-b8b0-beba97fc8266",
|
|
"value": "683b6f8209725ae0e715cda5a1cd35bcaacb5d45ae8e487c98dce2c01c91c887"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821611",
|
|
"uuid": "6aa42e4d-4b31-4f21-a7c4-c7c2fb0a8c16",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "4bdc2e50-a2a8-4867-9d1a-c98f9b552d5f",
|
|
"value": "2019-04-09T14:38:43"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "c82397ad-5b64-4c0f-946a-ffc2b414e736",
|
|
"value": "https://www.virustotal.com/file/683b6f8209725ae0e715cda5a1cd35bcaacb5d45ae8e487c98dce2c01c91c887/analysis/1554820723/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "1435ff7f-0d6e-4e3a-a5a8-da17a7fb2a61",
|
|
"value": "26/55"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821611",
|
|
"uuid": "0a1c567d-90f2-4bc1-b0b8-0f863fbd1a96",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "0a1c567d-90f2-4bc1-b0b8-0f863fbd1a96",
|
|
"referenced_uuid": "8d50aae1-1b2e-40ae-a3ca-c8f5280b0097",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821616",
|
|
"uuid": "5cacb1f0-ce44-40e6-8935-4574950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "9683cca9-7f14-46cd-953d-46d663c39d57",
|
|
"value": "ff4a49b6dce2d03f28fc8f7646139588"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "66ea566e-b9f9-464e-809d-56cbe0624ad1",
|
|
"value": "d3774ca0bf2817ffe1c3fb1781e7836e35488af2"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "f276545c-ca60-414e-9c90-23d3a92067f9",
|
|
"value": "a9dbcc2681d427f9820ca9c5ec120b9bf3e83c9856e89736884ee4dc26712e50"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821611",
|
|
"uuid": "8d50aae1-1b2e-40ae-a3ca-c8f5280b0097",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "c6c7b55e-5ee7-4eed-91f0-8722fc996422",
|
|
"value": "2019-04-09T14:38:47"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "96c1f0bb-004f-4929-b0fb-917be0e536ff",
|
|
"value": "https://www.virustotal.com/file/a9dbcc2681d427f9820ca9c5ec120b9bf3e83c9856e89736884ee4dc26712e50/analysis/1554820727/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "02597b74-98de-4382-a76c-f40c701f0553",
|
|
"value": "22/57"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821611",
|
|
"uuid": "9aa1e457-864e-45d3-8efb-3f767f69c7fe",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "9aa1e457-864e-45d3-8efb-3f767f69c7fe",
|
|
"referenced_uuid": "676eeeaa-4548-47d8-9cb3-d5c7d0662245",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821616",
|
|
"uuid": "5cacb1f0-40f8-4ee0-84e0-4eb2950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "1058297c-d47e-4c04-8a41-1c660bd15abc",
|
|
"value": "b34a5819d7f76c7c2b7402682be2afdf"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "9e62bb83-0c7e-46f4-b12d-b317ce921ae5",
|
|
"value": "223f48a513ec2626941aa92c65f52083b088076c"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821295",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "e725971d-6ea0-4ede-a7c3-7e474eb79808",
|
|
"value": "59b7a7baf4c239786fdf5ceca9084d829c6f6fc0603a524df313b2ef4958e4c2"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821612",
|
|
"uuid": "676eeeaa-4548-47d8-9cb3-d5c7d0662245",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "32e3a138-d2a5-4e4b-9b33-27b4226f4b33",
|
|
"value": "2019-04-09T14:38:41"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "dafa897e-1b70-48f5-a296-d397eb16bf0e",
|
|
"value": "https://www.virustotal.com/file/59b7a7baf4c239786fdf5ceca9084d829c6f6fc0603a524df313b2ef4958e4c2/analysis/1554820721/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "OpenRISC Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821295",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "bdd373da-922c-4555-b705-13554128a922",
|
|
"value": "21/55"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821612",
|
|
"uuid": "5ef45cc5-87ac-40c8-9769-90aeee950b48",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "5ef45cc5-87ac-40c8-9769-90aeee950b48",
|
|
"referenced_uuid": "3c601fd8-25f7-472c-aafb-61246bf050ab",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821616",
|
|
"uuid": "5cacb1f0-2fe4-477c-92de-40b8950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "a219e4e6-9435-41a2-b78d-21bb4d5751e3",
|
|
"value": "fff9efec911c46b6622632a235e21558"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "11a6359d-4476-47e2-aecb-ac0efb8725ba",
|
|
"value": "be257333bab3a8184fe4493fadac018ef6b5cf90"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "aae51dfc-8604-4df0-b240-64325becef7b",
|
|
"value": "0c35f2902d92ef4f46e4643d11c46bde57027bb14e2b75c027a50fe7efc4f358"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821612",
|
|
"uuid": "3c601fd8-25f7-472c-aafb-61246bf050ab",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "74ce3e66-df6d-4cc8-b6b3-2e24778b01f7",
|
|
"value": "2019-04-09T14:38:43"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "3a59df00-0a1f-4438-a214-c23a1b36d7a4",
|
|
"value": "https://www.virustotal.com/file/0c35f2902d92ef4f46e4643d11c46bde57027bb14e2b75c027a50fe7efc4f358/analysis/1554820723/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "250bbb1e-1a82-4b4d-a38d-85bce8f41617",
|
|
"value": "24/55"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821612",
|
|
"uuid": "4bd0f4ab-1dd2-47c1-bc9e-cc984e224ed3",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "4bd0f4ab-1dd2-47c1-bc9e-cc984e224ed3",
|
|
"referenced_uuid": "a14d1157-bb64-44aa-9a5d-4b078c397453",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821616",
|
|
"uuid": "5cacb1f0-2380-47a0-8d2c-400f950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "a1e11af4-b711-4f43-9601-e8db5b272d22",
|
|
"value": "7f706738b1442e0cb68b013f1fa173e4"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "34fa9c23-75a2-42f1-b0bc-4e9a5dc3566e",
|
|
"value": "dea50ca3b6ef8ac547c68f2e5ad973509cb915cc"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "cb40a0f6-3e49-4532-b9bc-30ed42d062ed",
|
|
"value": "57cc6875ae0c571ef1edaae72d82b0da6e60331ad4b3ad34c922b9e4612b8779"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821612",
|
|
"uuid": "a14d1157-bb64-44aa-9a5d-4b078c397453",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "582998a9-3667-487f-ad32-d55e79eca81c",
|
|
"value": "2019-04-09T14:38:44"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "41f5eb00-5b69-4d90-ba46-4fb83f3528fd",
|
|
"value": "https://www.virustotal.com/file/57cc6875ae0c571ef1edaae72d82b0da6e60331ad4b3ad34c922b9e4612b8779/analysis/1554820724/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "8bf83c58-3618-4778-aa56-15d9768b5b51",
|
|
"value": "22/57"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821612",
|
|
"uuid": "7265f4d8-423f-4089-b8bf-61154434bbec",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "7265f4d8-423f-4089-b8bf-61154434bbec",
|
|
"referenced_uuid": "108baa35-aecc-436f-b100-d49c28ba513e",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821616",
|
|
"uuid": "5cacb1f0-dfa4-4ffa-a2f2-4b98950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "72559a25-27dc-4809-a0f3-265f94e532b6",
|
|
"value": "826969c4a4395e2ac077a47c0fad04bf"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "3a934b3d-d595-41bf-a115-6cb10c3e261f",
|
|
"value": "00f9f12d5938af4274dc07a314d63bf079b0cf67"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "2070c980-76cc-4936-8d8e-c01accd99806",
|
|
"value": "4d8a4841a2f4a61ed6df2be79dd7ea1eb2052cee6eba4d8de30add7908ebb779"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821612",
|
|
"uuid": "108baa35-aecc-436f-b100-d49c28ba513e",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "7cad9684-a53e-4065-9a00-b3f4177f6b80",
|
|
"value": "2019-04-09T14:38:43"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "814f5a53-613c-4790-89a3-c6e7ee40f2ad",
|
|
"value": "https://www.virustotal.com/file/4d8a4841a2f4a61ed6df2be79dd7ea1eb2052cee6eba4d8de30add7908ebb779/analysis/1554820723/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "a57a7942-c31f-435c-819e-14bf4bacf46a",
|
|
"value": "20/56"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821612",
|
|
"uuid": "48e16861-6796-4e02-88a7-79c2d7858609",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "48e16861-6796-4e02-88a7-79c2d7858609",
|
|
"referenced_uuid": "0878ecdd-7b9e-44ad-b533-7a494082d77d",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821616",
|
|
"uuid": "5cacb1f0-1054-411c-a54d-4687950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "02c09d47-567b-4523-a86c-87f3c1dd2275",
|
|
"value": "d6530989b7697fbfeb52c7da02606ee6"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "ec0f5fc5-fa6c-4620-9fb3-3450c1517c98",
|
|
"value": "8473e66bfdd122b60b61bd2edcd97742a10e0543"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "f2ab750b-88d0-4a64-9de5-42fb9e8b2668",
|
|
"value": "c75b3c52c0f5eebfd4c44c3069a393e824d455c7405d57ee99fd7613b8211b31"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821613",
|
|
"uuid": "0878ecdd-7b9e-44ad-b533-7a494082d77d",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "bf12de8b-65d0-4cc4-9ab3-083e8622933e",
|
|
"value": "2019-04-09T14:38:46"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "4f23f90d-8c4c-46b2-807e-4ccb5f45e50f",
|
|
"value": "https://www.virustotal.com/file/c75b3c52c0f5eebfd4c44c3069a393e824d455c7405d57ee99fd7613b8211b31/analysis/1554820726/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "b9a49c19-42d7-4105-9f29-b4f6f8eb77a2",
|
|
"value": "27/59"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821613",
|
|
"uuid": "2bc22de4-2a0d-4cb2-a9b3-eb4daec315b0",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "2bc22de4-2a0d-4cb2-a9b3-eb4daec315b0",
|
|
"referenced_uuid": "9c207223-e112-4cf8-8ee7-6a1d559a8423",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821616",
|
|
"uuid": "5cacb1f0-52d8-442c-af3b-4dbb950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "708b7ba7-d880-4d92-b478-7e032f60422e",
|
|
"value": "7f4c596f95d86c5e1843090dd01bf5e3"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "1904f868-51c9-4e26-bac8-9deff1c503c2",
|
|
"value": "50762cbb68321234f92a261a7581c5ca3d4e8ce7"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "02fda874-2ca0-4a59-bc7a-806cf25ee702",
|
|
"value": "a457090fb6df8cb93c91ec6b5d89927f7a6f9e247389d945d44731351a367b4e"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821613",
|
|
"uuid": "9c207223-e112-4cf8-8ee7-6a1d559a8423",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "5a53a2f4-e825-4a43-b172-b597240765e8",
|
|
"value": "2019-04-09T14:38:46"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "006b984c-d154-403a-a4fd-9ed8cd08be6e",
|
|
"value": "https://www.virustotal.com/file/a457090fb6df8cb93c91ec6b5d89927f7a6f9e247389d945d44731351a367b4e/analysis/1554820726/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "e06e7085-4245-4dc0-8362-2751df2857bd",
|
|
"value": "24/56"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821613",
|
|
"uuid": "fa5e7f90-245b-4742-b7d0-2394fec51c85",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "fa5e7f90-245b-4742-b7d0-2394fec51c85",
|
|
"referenced_uuid": "73e039e4-7edb-4e20-a441-91746475ea90",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821616",
|
|
"uuid": "5cacb1f0-d420-4f87-abb0-4e98950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "30337bd7-92f7-4195-ba73-75deac6915c5",
|
|
"value": "0c44d70b35b4daaf693644c524c26752"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "d6ebd185-5551-4427-933e-632364ea078c",
|
|
"value": "618f2cf0181747b7b851ce0aff7639f7e4fa63fb"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821312",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "694dcf48-180a-4f3e-abcd-4073f993e96e",
|
|
"value": "9b1eab0283fd6948a9a181abaa2f6b3c26f2b0077c8a8b32e763790dd64d2a22"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821613",
|
|
"uuid": "73e039e4-7edb-4e20-a441-91746475ea90",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "ad2e9b69-bddb-4e9a-8eac-c32c493b37c1",
|
|
"value": "2019-04-09T14:38:46"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "65fd98a1-9315-4f58-ba58-41bd1aebc944",
|
|
"value": "https://www.virustotal.com/file/9b1eab0283fd6948a9a181abaa2f6b3c26f2b0077c8a8b32e763790dd64d2a22/analysis/1554820726/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Xilinx MicroBlaze Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821312",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "8e59039d-fe6d-4be4-88fe-776945882804",
|
|
"value": "27/59"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821613",
|
|
"uuid": "03c14a71-6d63-4b20-a22d-f00e5edce6c0",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "03c14a71-6d63-4b20-a22d-f00e5edce6c0",
|
|
"referenced_uuid": "6cfcd770-a39a-4100-aa77-114a93d0d742",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821616",
|
|
"uuid": "5cacb1f0-b3f0-43f0-a5d9-4f6e950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "21a4b0d7-7daa-4574-a6bb-4ef6ba65615e",
|
|
"value": "3435076494a390266c3c0075997061b3"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "cf03c370-4b03-476c-9554-ef83d6e93f39",
|
|
"value": "735eb8ae448bfcb2ffb3fc283d2aac68f687f356"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821266",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "a9e75d33-9ad3-48ef-bc83-9b9d158160b3",
|
|
"value": "fae498477388c53c8c623fd8ddb710cc286584200767907b104d55f916d37c05"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821614",
|
|
"uuid": "6cfcd770-a39a-4100-aa77-114a93d0d742",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "bb56ee61-aae8-4c6a-92c3-6bc930d16ab4",
|
|
"value": "2019-04-09T14:38:50"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "c81ac748-2a6b-46e9-adfd-983708fe503b",
|
|
"value": "https://www.virustotal.com/file/fae498477388c53c8c623fd8ddb710cc286584200767907b104d55f916d37c05/analysis/1554820730/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Altera Nios II Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821266",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "38e6b010-35c6-43a3-9241-64efcf5eb198",
|
|
"value": "24/56"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "15",
|
|
"timestamp": "1554821614",
|
|
"uuid": "b4ff969b-0790-4864-a6aa-4ee7b041f432",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "b4ff969b-0790-4864-a6aa-4ee7b041f432",
|
|
"referenced_uuid": "c98512db-97ea-4c11-ad77-ac0cda300412",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1554821616",
|
|
"uuid": "5cacb1f0-6e84-4ebe-8518-44f7950d210f"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "c334d2b4-0431-4da2-882c-2328fcfceae6",
|
|
"value": "c1c7a371b3c3693ce248acad48865731"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "df8df192-c5e4-4e65-a324-ea3fc99df64b",
|
|
"value": "8eedefcfebe110030bcddf42c0ce3ee336fda624"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1554821280",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "ae347e18-4f9c-4a3d-a877-934d02a5365e",
|
|
"value": "61893583675935ac7a4857542f13d513ffbb176b302a72d26d7ec39fd931decb"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1554821614",
|
|
"uuid": "c98512db-97ea-4c11-ad77-ac0cda300412",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "f24c6a63-146f-48fe-bcdd-4fcbac87e608",
|
|
"value": "2019-04-09T14:38:42"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "b85ff7af-7a3f-4120-8a6c-94d97817ad51",
|
|
"value": "https://www.virustotal.com/file/61893583675935ac7a4857542f13d513ffbb176b302a72d26d7ec39fd931decb/analysis/1554820722/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Tensilica Xtensa Samples",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1554821280",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "a8454d86-cb50-4e4a-8741-7b2a7e99d5de",
|
|
"value": "22/57"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
} |