misp-circl-feed/feeds/circl/misp/5472f4a5-eafc-43c4-91b1-4bfe950d210b.json

792 lines
No EOL
23 KiB
JSON

{
"Event": {
"analysis": "2",
"date": "2014-11-20",
"extends_uuid": "",
"info": "OSINT Evil Bunny: Suspect #4",
"publish_timestamp": "1456152009",
"published": true,
"threat_level_id": "2",
"timestamp": "1416822111",
"uuid": "5472f4a5-eafc-43c4-91b1-4bfe950d210b",
"Orgc": {
"name": "CthulhuSPRL.be",
"uuid": "55f6ea5f-fd34-43b8-ac1d-40cb950d210f"
},
"Tag": [
{
"colour": "#004646",
"local": false,
"name": "type:OSINT",
"relationship_type": ""
},
{
"colour": "#33FF00",
"local": false,
"name": "tlp:green",
"relationship_type": ""
}
],
"Attribute": [
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416819896",
"to_ids": false,
"type": "link",
"uuid": "5472f4b8-77a4-4381-a8a8-4a48950d210b",
"value": "http://0x1338.blogspot.be/2014/11/hunting-bunnies.html"
},
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416819896",
"to_ids": false,
"type": "link",
"uuid": "5472f4b8-591c-4c5e-bf23-4bff950d210b",
"value": "https://drive.google.com/file/d/0B9Mrr-en8FX4M2lXN1B4eElHcE0/view"
},
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416819913",
"to_ids": false,
"type": "text",
"uuid": "5472f4c9-f368-401a-aba8-4082950d210b",
"value": "Evil Bunny"
},
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416819913",
"to_ids": false,
"type": "text",
"uuid": "5472f4c9-f624-4cd5-8b4e-4fd8950d210b",
"value": "EvilBunny"
},
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416819928",
"to_ids": false,
"type": "comment",
"uuid": "5472f4d8-7c24-4e07-9341-4740950d210b",
"value": "Data entered by David Andr\u00c3\u00a9"
},
{
"category": "Payload delivery",
"comment": "Imported via the freetext import.",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416820000",
"to_ids": true,
"type": "md5",
"uuid": "5472f520-2764-4016-941c-4228950d210b",
"value": "c40e3ee23cf95d992b7cd0b7c01b8599"
},
{
"category": "Payload delivery",
"comment": "Imported via the freetext import.",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416820000",
"to_ids": true,
"type": "sha1",
"uuid": "5472f520-257c-4e79-a281-469e950d210b",
"value": "1e8b4c374db03dcca026c5feba0a5c117f740233"
},
{
"category": "Payload delivery",
"comment": "Imported via the freetext import.",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416820000",
"to_ids": true,
"type": "md5",
"uuid": "5472f520-f474-4069-9e81-4514950d210b",
"value": "3bbb59afdf9bda4ffdc644d9d51c53e7"
},
{
"category": "Payload delivery",
"comment": "Imported via the freetext import.",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416820000",
"to_ids": true,
"type": "sha1",
"uuid": "5472f520-fcf0-41d6-92bb-42e9950d210b",
"value": "1798985f4cc2398a482f2232e72e5817562530de"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821332",
"to_ids": false,
"type": "vulnerability",
"uuid": "5472fa54-180c-48d3-b8d6-4605950d210b",
"value": "CVE-2011-4369"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821407",
"to_ids": true,
"type": "url",
"uuid": "5472fa9f-8678-49bd-886f-47a2950d210b",
"value": "http://le-progres.net/images/php/test.php?rec=11206-01"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821407",
"to_ids": true,
"type": "url",
"uuid": "5472fa9f-d3dc-47b0-83c3-4d04950d210b",
"value": "http://ghatreh.com/skins/php/test.php?rec=11206-01"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821407",
"to_ids": true,
"type": "url",
"uuid": "5472fa9f-3598-4f6a-961b-45f9950d210b",
"value": "http://www.usthb-dz.org/includes/php/test.php?rec=11206-01"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821884",
"to_ids": true,
"type": "domain",
"uuid": "5472fb13-2854-4a94-952b-41e6950d210b",
"value": "le-progres.net"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821879",
"to_ids": true,
"type": "domain",
"uuid": "5472fb13-acb8-4ee2-842f-4293950d210b",
"value": "ghatreh.com"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821871",
"to_ids": true,
"type": "domain",
"uuid": "5472fb13-53c4-452f-81de-4d51950d210b",
"value": "usthb-dz.org"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821577",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fb49-2884-43f1-b5be-4455950d210b",
"value": "69.90.160.65"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821577",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fb49-5c20-4d2d-89ad-48be950d210b",
"value": "70.38.107.13"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821578",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fb4a-ebb0-49ed-888f-4803950d210b",
"value": "70.38.12.10"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821588",
"to_ids": true,
"type": "url",
"uuid": "5472fb54-2da4-4e0e-b3b1-42cb950d210b",
"value": "http://1.9.32.11/bunny/test.php?rec=nvista"
},
{
"category": "Artifacts dropped",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821695",
"to_ids": true,
"type": "md5",
"uuid": "5472fbbf-b7b4-4a69-951e-4234950d210b",
"value": "2a64d331964dbdec8141f16585f392ba"
},
{
"category": "Artifacts dropped",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821695",
"to_ids": true,
"type": "md5",
"uuid": "5472fbbf-a15c-401d-bcd2-4ae0950d210b",
"value": "40e0f0681c79d70ac0329e68a94294cb"
},
{
"category": "Artifacts dropped",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821696",
"to_ids": true,
"type": "md5",
"uuid": "5472fbc0-6508-49b6-8c4b-4536950d210b",
"value": "8132ee00f64856cf10930fd72505cebe"
},
{
"category": "Artifacts dropped",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821696",
"to_ids": true,
"type": "md5",
"uuid": "5472fbc0-1bec-4e1a-a187-4073950d210b",
"value": "e8a333a726481a72b267ec6109939b0d"
},
{
"category": "Artifacts dropped",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821696",
"to_ids": true,
"type": "md5",
"uuid": "5472fbc0-f38c-4c6c-98bd-4479950d210b",
"value": "3bbb59afdf9bda4ffdc644d9d51c53e7"
},
{
"category": "Artifacts dropped",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821696",
"to_ids": true,
"type": "md5",
"uuid": "5472fbc0-db24-42ea-a272-499e950d210b",
"value": "c40e3ee23cf95d992b7cd0b7c01b8599"
},
{
"category": "Artifacts dropped",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821696",
"to_ids": true,
"type": "md5",
"uuid": "5472fbc0-22c4-48bb-abd3-4332950d210b",
"value": "330dc1a7f3930a2234e505ba11da0eea"
},
{
"category": "Artifacts dropped",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821696",
"to_ids": true,
"type": "md5",
"uuid": "5472fbc0-ef78-44a5-b8cb-4402950d210b",
"value": "83b7c532663f11bf994a1b518880557d"
},
{
"category": "Artifacts dropped",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821696",
"to_ids": true,
"type": "md5",
"uuid": "5472fbc0-0fa0-4f7b-adf3-4e63950d210b",
"value": "b8ac16701c3c15b103e61b5a317692bc"
},
{
"category": "Artifacts dropped",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821696",
"to_ids": true,
"type": "md5",
"uuid": "5472fbc0-94bc-421c-8951-45b6950d210b",
"value": "bbf4b1961ff0ce19db748616754da76e"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821717",
"to_ids": true,
"type": "url",
"uuid": "5472fbd5-97a0-4259-b0e9-4521950d210b",
"value": "http://callientefever.info/img/new/n.php"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821717",
"to_ids": true,
"type": "url",
"uuid": "5472fbd5-3a90-4d8e-9179-49e9950d210b",
"value": "http://fullapple.net/pictures/bkp/n.php"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821806",
"to_ids": true,
"type": "domain",
"uuid": "5472fc2e-b068-4c9c-ba01-41a1950d210b",
"value": "callientefever.info"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416821806",
"to_ids": true,
"type": "domain",
"uuid": "5472fc2e-501c-4286-8b25-4f3e950d210b",
"value": "fullapple.net"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822111",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd5f-597c-4984-9d5e-4bb8950d210b",
"value": "184.107.60.97"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822111",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd5f-afe8-4992-a04f-4a63950d210b",
"value": "184.168.221.41"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822111",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd5f-a5e8-47be-8d83-4349950d210b",
"value": "204.13.160.25"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822111",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd5f-c464-4982-9cf6-4d88950d210b",
"value": "204.157.11.208"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822111",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd5f-8b84-4267-be3b-481a950d210b",
"value": "204.93.167.100"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822111",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd5f-9f04-4a96-bcb7-4074950d210b",
"value": "208.73.210.155"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822111",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd5f-0638-45ec-b6d3-45b7950d210b",
"value": "208.87.149.250"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822111",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd5f-7c44-4485-88cc-484e950d210b",
"value": "209.51.136.27"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822111",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd5f-b384-4108-a326-4018950d210b",
"value": "209.62.20.175"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822111",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd5f-5a00-4266-8d5a-4d63950d210b",
"value": "213.186.33.19"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822111",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd5f-8a28-415b-98d2-4801950d210b",
"value": "216.108.239.153"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822111",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd5f-ae74-4b9e-b68e-4df1950d210b",
"value": "216.36.248.128"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-a5f0-413a-ab01-4bd1950d210b",
"value": "216.36.248.134"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-0af0-4609-9b96-43df950d210b",
"value": "64.15.136.137"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-0814-4eb6-8528-4f0f950d210b",
"value": "64.20.43.107"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-abc0-419b-8c7a-4a57950d210b",
"value": "66.45.225.11"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-26bc-4740-b41d-4f24950d210b",
"value": "67.18.209.222"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-e528-4dbc-80b1-46a1950d210b",
"value": "67.19.22.234"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-aeb8-4049-9e06-44f3950d210b",
"value": "67.19.84.46"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-af14-4548-8088-440a950d210b",
"value": "68.178.232.99"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-5f50-4a40-823e-4ae3950d210b",
"value": "69.25.212.153"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-00c0-428e-bf2e-4705950d210b",
"value": "69.46.226.168"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-e8cc-4a3f-bafc-4369950d210b",
"value": "70.38.107.12"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-8ce4-4175-834f-4d01950d210b",
"value": "72.9.244.162"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-a5e4-4342-b941-45f8950d210b",
"value": "74.54.82.222"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-2eb8-497f-b84e-45fd950d210b",
"value": "74.54.82.228"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822112",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd60-4424-4578-8699-4ea1950d210b",
"value": "8.5.1.34"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822113",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd61-8414-43cb-9471-4078950d210b",
"value": "91.121.137.201"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1416822113",
"to_ids": true,
"type": "ip-dst",
"uuid": "5472fd61-b060-4656-acfd-4bfc950d210b",
"value": "91.121.142.185"
},
{
"category": "Artifacts dropped",
"comment": "Automatically added (via b8ac16701c3c15b103e61b5a317692bc)",
"deleted": false,
"disable_correlation": false,
"timestamp": "1455835003",
"to_ids": true,
"type": "sha1",
"uuid": "56c6477b-007c-4e17-a62d-5f51950d210f",
"value": "a4226714f346c7844a9183e01961e7609d6fa241"
},
{
"category": "Artifacts dropped",
"comment": "Automatically added (via 83b7c532663f11bf994a1b518880557d)",
"deleted": false,
"disable_correlation": false,
"timestamp": "1455835006",
"to_ids": true,
"type": "sha1",
"uuid": "56c6477e-2e9c-48f9-b7e0-4efd950d210f",
"value": "c923e15718926bb4a80a29017d5b35bb841bd246"
},
{
"category": "Artifacts dropped",
"comment": "Automatically added (via b8ac16701c3c15b103e61b5a317692bc)",
"deleted": false,
"disable_correlation": false,
"timestamp": "1455835004",
"to_ids": true,
"type": "sha256",
"uuid": "56c6477c-76e4-41d3-94d3-4359950d210f",
"value": "7d1e5c4afb1682087d86e793b3fc5a8371dc7c28e27e7196e3b258934f6bafb5"
},
{
"category": "Artifacts dropped",
"comment": "Automatically added (via 83b7c532663f11bf994a1b518880557d)",
"deleted": false,
"disable_correlation": false,
"timestamp": "1455835006",
"to_ids": true,
"type": "sha256",
"uuid": "56c6477e-2954-44eb-86de-c650950d210f",
"value": "5b54508b69a6d8a7630f9f6b627cba6dc80320f2f762a2cc8ba4dd4519ef500a"
},
{
"category": "Artifacts dropped",
"comment": "Automatically added (via c40e3ee23cf95d992b7cd0b7c01b8599)",
"deleted": false,
"disable_correlation": false,
"timestamp": "1455835007",
"to_ids": true,
"type": "sha256",
"uuid": "56c6477f-4d88-4015-b26e-c651950d210f",
"value": "c6a182f410b4cda0665cd792f00177c56338018fbc31bb34e41b72f8195c20cc"
},
{
"category": "Artifacts dropped",
"comment": "Automatically added (via 3bbb59afdf9bda4ffdc644d9d51c53e7)",
"deleted": false,
"disable_correlation": false,
"timestamp": "1455835008",
"to_ids": true,
"type": "sha256",
"uuid": "56c64780-c934-4188-90fe-59a2950d210f",
"value": "be14d781b85125a6074724964622ab05f89f41e6bacbda398bc7709d1d98a2ef"
}
]
}
}