misp-circl-feed/feeds/circl/misp/57ceb5e1-bd08-4fbb-9967-4b68950d210f.json

441 lines
No EOL
13 KiB
JSON

{
"Event": {
"analysis": "0",
"date": "2016-09-06",
"extends_uuid": "",
"info": "Malspam 2016-09-06 (.wsf in .zip) - campaign: \"Invoice INV[x]\"",
"publish_timestamp": "1473164859",
"published": true,
"threat_level_id": "3",
"timestamp": "1473164823",
"uuid": "57ceb5e1-bd08-4fbb-9967-4b68950d210f",
"Orgc": {
"name": "CIRCL",
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
},
"Tag": [
{
"colour": "#ffffff",
"local": false,
"name": "tlp:white",
"relationship_type": ""
},
{
"colour": "#3a7300",
"local": false,
"name": "circl:incident-classification=\"malware\"",
"relationship_type": ""
},
{
"colour": "#770095",
"local": false,
"name": "ms-caro-malware:malware-platform=\"Win32\"",
"relationship_type": ""
},
{
"colour": "#790097",
"local": false,
"name": "ms-caro-malware:malware-platform=\"Win64\"",
"relationship_type": ""
}
],
"Attribute": [
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164816",
"to_ids": true,
"type": "ip-dst",
"uuid": "57ceb610-ec44-40f5-8c67-4f63950d210f",
"value": "186.202.126.199"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164816",
"to_ids": true,
"type": "ip-dst",
"uuid": "57ceb610-f20c-4a23-baf7-4825950d210f",
"value": "188.120.235.214"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164817",
"to_ids": true,
"type": "ip-dst",
"uuid": "57ceb611-b710-446f-b4fd-4c77950d210f",
"value": "200.83.4.62"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164817",
"to_ids": true,
"type": "ip-dst",
"uuid": "57ceb611-91c0-4229-8a0b-41bb950d210f",
"value": "208.71.106.48"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164817",
"to_ids": true,
"type": "ip-dst",
"uuid": "57ceb611-78c0-411e-a024-4d59950d210f",
"value": "213.205.40.169"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164817",
"to_ids": true,
"type": "ip-dst",
"uuid": "57ceb611-3274-44c0-8312-48f3950d210f",
"value": "23.95.106.213"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164817",
"to_ids": true,
"type": "ip-dst",
"uuid": "57ceb611-6384-4017-9ce2-43b9950d210f",
"value": "81.196.20.134"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164818",
"to_ids": true,
"type": "ip-dst",
"uuid": "57ceb612-bce4-47e1-a20b-4cca950d210f",
"value": "81.24.34.9"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164818",
"to_ids": true,
"type": "ip-dst",
"uuid": "57ceb612-16a8-4b48-870e-4547950d210f",
"value": "85.12.197.61"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164818",
"to_ids": true,
"type": "ip-dst",
"uuid": "57ceb612-8ebc-4ee3-9a5f-4648950d210f",
"value": "88.156.222.94"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164818",
"to_ids": true,
"type": "domain",
"uuid": "57ceb612-dad0-4848-8744-4289950d210f",
"value": "alians-ekb.ru"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164818",
"to_ids": true,
"type": "domain",
"uuid": "57ceb612-03f4-40cb-b002-4bc8950d210f",
"value": "bostoncittyregenerww.com"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164819",
"to_ids": true,
"type": "url",
"uuid": "57ceb613-b7b8-4435-8acd-40af950d210f",
"value": "http://alians-ekb.ru/j8fn3rg3"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164819",
"to_ids": true,
"type": "url",
"uuid": "57ceb613-0ffc-4189-bf42-4080950d210f",
"value": "http://bostoncittyregenerww.com/js/j8fn3rg3"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164819",
"to_ids": true,
"type": "url",
"uuid": "57ceb613-9704-406e-ac22-4672950d210f",
"value": "http://mixup0813.web.fc2.com/j8fn3rg3"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164819",
"to_ids": true,
"type": "url",
"uuid": "57ceb613-7818-4e29-93ff-4146950d210f",
"value": "http://portadeenrolar.ind.br/j8fn3rg3"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164819",
"to_ids": true,
"type": "url",
"uuid": "57ceb613-6f50-4e67-a568-4b24950d210f",
"value": "http://sitio655.vtrbandaancha.net/j8fn3rg3"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164820",
"to_ids": true,
"type": "url",
"uuid": "57ceb614-7010-4e98-9212-47f3950d210f",
"value": "http://sp-moto.ru/j8fn3rg3"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164820",
"to_ids": true,
"type": "url",
"uuid": "57ceb614-b024-45b6-85a7-40ca950d210f",
"value": "http://tst-technik.de/j8fn3rg3"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164820",
"to_ids": true,
"type": "url",
"uuid": "57ceb614-0070-4ca5-b5a1-43a8950d210f",
"value": "http://www.cmg-ingegneria.it/j8fn3rg3"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164820",
"to_ids": true,
"type": "url",
"uuid": "57ceb614-b140-45ce-b6a8-4f57950d210f",
"value": "http://www.lnowak.tkdami.net/j8fn3rg3"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164820",
"to_ids": true,
"type": "url",
"uuid": "57ceb614-9fec-4d66-bc7a-4c23950d210f",
"value": "http://www.montegelato.it/j8fn3rg3"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164820",
"to_ids": true,
"type": "url",
"uuid": "57ceb614-8a54-4e7c-84c7-4ddf950d210f",
"value": "http://www.oltransservice.org/j8fn3rg3"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164821",
"to_ids": true,
"type": "url",
"uuid": "57ceb615-d070-46f8-9427-43f4950d210f",
"value": "http://www.vanetti.it/j8fn3rg3"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164821",
"to_ids": true,
"type": "url",
"uuid": "57ceb615-edf8-4752-aa7a-4198950d210f",
"value": "http://www.vilastefania.go.ro/j8fn3rg3"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164821",
"to_ids": true,
"type": "hostname",
"uuid": "57ceb615-4af4-47de-9253-437c950d210f",
"value": "mixup0813.web.fc2.com"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164821",
"to_ids": true,
"type": "hostname",
"uuid": "57ceb615-6c8c-4657-b5ac-409d950d210f",
"value": "portadeenrolar.ind.br"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164821",
"to_ids": true,
"type": "hostname",
"uuid": "57ceb615-f238-4400-ab64-4461950d210f",
"value": "sitio655.vtrbandaancha.net"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164822",
"to_ids": true,
"type": "domain",
"uuid": "57ceb616-19ec-4cb4-a889-4e0c950d210f",
"value": "sp-moto.ru"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164822",
"to_ids": true,
"type": "domain",
"uuid": "57ceb616-cad8-4768-8590-420a950d210f",
"value": "tst-technik.de"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164822",
"to_ids": true,
"type": "hostname",
"uuid": "57ceb616-4cdc-477e-9412-44d2950d210f",
"value": "www.cmg-ingegneria.it"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164822",
"to_ids": true,
"type": "hostname",
"uuid": "57ceb616-c78c-44de-a815-442d950d210f",
"value": "www.lnowak.tkdami.net"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164822",
"to_ids": true,
"type": "hostname",
"uuid": "57ceb616-a1d0-4811-83ea-458c950d210f",
"value": "www.montegelato.it"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164823",
"to_ids": true,
"type": "hostname",
"uuid": "57ceb617-ebac-4bca-b107-4f94950d210f",
"value": "www.oltransservice.org"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164823",
"to_ids": true,
"type": "hostname",
"uuid": "57ceb617-d470-4f66-a6b1-4bfc950d210f",
"value": "www.vanetti.it"
},
{
"category": "Network activity",
"comment": "download location",
"deleted": false,
"disable_correlation": false,
"timestamp": "1473164823",
"to_ids": true,
"type": "hostname",
"uuid": "57ceb617-2c08-4f2b-91f1-4dda950d210f",
"value": "www.vilastefania.go.ro"
}
]
}
}