Add Android forensics, IOC threat-intel DB, Compose companion; scrub secrets from configs

This commit is contained in:
SsSnake
2026-07-13 15:45:47 -07:00
parent 925216290f
commit e48d577bd5
387 changed files with 211976 additions and 921 deletions

View File

@@ -0,0 +1,22 @@
uuid,event_id,category,type,value,comment,to_ids,date
3f6407bd-cfd7-4bb6-9338-34132bdc3c62,9,Network activity,ip-dst,"88.198.222.163","C2 for malware dropped",1,20161108
47690aa0-910d-478d-b0ea-fff1f40631ee,9,Payload delivery,md5,"8ebeb3f91cda8e985a9c61beb8cdde9d","adobe_flash_player.apk Droid Jack",1,20161108
4bf52b9f-f004-4793-a0ba-bf1e211c089d,9,Payload delivery,md5,"76f8142b4e52c671871b3df87f10c30c","Assadcrimes.ppsx",1,20161108
58223ba8-5da0-4111-8b1b-69fe8e96ca05,9,Payload delivery,email-src,"office@assadcrimes.info","email used for targeted phishing",1,20161108
58223cbc-ec7c-43f6-a95a-69fe8e96ca05,9,Network activity,domain,"assadcrimes.info","Fake activist website used as a watering hole",1,20161108
58223d3d-5864-453a-8c70-69fe8e96ca05,9,Payload delivery,vulnerability,"CVE-2014-4114","",0,20161108
58223dcd-63c0-45f1-9516-69fe8e96ca05,9,Payload type,text,"njRat","",0,20161108
58223dd5-ca58-4ad4-98d6-69fe8e96ca05,9,Payload type,text,"NanoCore RAT","",0,20161108
58223e40-64f4-47ca-b56b-69fe8e96ca05,9,Payload type,text,"DroidJack","",0,20161108
58223f8a-1820-476b-823c-497a8e96ca05,9,Network activity,ip-dst,"212.7.195.171","IP hosting assadcrimes.info website",0,20161108
588e5189-3408-4430-b4de-7f3a04c1107b,9,Payload delivery,md5,"a4f1f4921bb11ff9d22fad89b19b155d","Doc Dropper 1 Crypter",1,20161108
593c7165-8933-46ba-8b6b-36db6e65c1b3,9,External analysis,link,"https://citizenlab.org/2016/08/group5-syria/","",0,20161108
7aa1122f-33ee-422b-acae-8820e0664fdb,9,Payload delivery,md5,"7d898530d2e77f15f5badce8d7df215e","second stage executable, saved to disk as %temp%\dwm.exe",1,20161108
7af948f4-01b5-43f9-b9be-3746a9ce0fcf,9,Payload delivery,md5,"6161083021b695814434450c1882f9f3","Doc Dropper 3 Crypter",1,20161108
87004645-e8b6-4b7e-a79b-ca643e1446ec,9,Payload delivery,md5,"494bab7fd0b42b0b14051ed9abbd651f","dvm.exe [dropped by decoy app]",1,20161108
b02858c1-6bfb-4097-a00e-98182b0ec121,9,Payload delivery,md5,"b4121c3a1892332402000ef0d587c0ee","njRat binary",1,20161108
b98003bc-640e-442e-99ec-8ab90190bd4c,9,Payload delivery,md5,"366908f6c5c4f4329478d60586eca5bc","putty.exe [stage1 downloader]",0,20161108
dc028130-bdaf-462a-acd8-81f8ea0eec51,9,Payload delivery,md5,"f1f84ea3229dca0ccacb7381a2f49f99","Assadcrimes1.ppsx",1,20161108
dd6a607c-1ffb-4f02-bf84-3cc3292f66b7,9,Payload delivery,md5,"2fc276e1c06c3c78c6d7b66a141213be","alshohadaa alatfal.exe",1,20161108
e03c93a5-5b27-4242-8725-e82079d84a02,9,Payload delivery,md5,"30bb678db3ad0140fc33acd9803385c3","Assadcrimes.info.ppsx",1,20161108
e900b943-c875-4125-b4a7-f53de2620468,9,Payload delivery,md5,"dd5bedd915967c5efe00733cf7478cb4","",1,20161108
1 uuid event_id category type value comment to_ids date
2 3f6407bd-cfd7-4bb6-9338-34132bdc3c62 9 Network activity ip-dst 88.198.222.163 C2 for malware dropped 1 20161108
3 47690aa0-910d-478d-b0ea-fff1f40631ee 9 Payload delivery md5 8ebeb3f91cda8e985a9c61beb8cdde9d adobe_flash_player.apk Droid Jack 1 20161108
4 4bf52b9f-f004-4793-a0ba-bf1e211c089d 9 Payload delivery md5 76f8142b4e52c671871b3df87f10c30c Assadcrimes.ppsx 1 20161108
5 58223ba8-5da0-4111-8b1b-69fe8e96ca05 9 Payload delivery email-src office@assadcrimes.info email used for targeted phishing 1 20161108
6 58223cbc-ec7c-43f6-a95a-69fe8e96ca05 9 Network activity domain assadcrimes.info Fake activist website used as a watering hole 1 20161108
7 58223d3d-5864-453a-8c70-69fe8e96ca05 9 Payload delivery vulnerability CVE-2014-4114 0 20161108
8 58223dcd-63c0-45f1-9516-69fe8e96ca05 9 Payload type text njRat 0 20161108
9 58223dd5-ca58-4ad4-98d6-69fe8e96ca05 9 Payload type text NanoCore RAT 0 20161108
10 58223e40-64f4-47ca-b56b-69fe8e96ca05 9 Payload type text DroidJack 0 20161108
11 58223f8a-1820-476b-823c-497a8e96ca05 9 Network activity ip-dst 212.7.195.171 IP hosting assadcrimes.info website 0 20161108
12 588e5189-3408-4430-b4de-7f3a04c1107b 9 Payload delivery md5 a4f1f4921bb11ff9d22fad89b19b155d Doc Dropper 1 Crypter 1 20161108
13 593c7165-8933-46ba-8b6b-36db6e65c1b3 9 External analysis link https://citizenlab.org/2016/08/group5-syria/ 0 20161108
14 7aa1122f-33ee-422b-acae-8820e0664fdb 9 Payload delivery md5 7d898530d2e77f15f5badce8d7df215e second stage executable, saved to disk as %temp%\dwm.exe 1 20161108
15 7af948f4-01b5-43f9-b9be-3746a9ce0fcf 9 Payload delivery md5 6161083021b695814434450c1882f9f3 Doc Dropper 3 Crypter 1 20161108
16 87004645-e8b6-4b7e-a79b-ca643e1446ec 9 Payload delivery md5 494bab7fd0b42b0b14051ed9abbd651f dvm.exe [dropped by decoy app] 1 20161108
17 b02858c1-6bfb-4097-a00e-98182b0ec121 9 Payload delivery md5 b4121c3a1892332402000ef0d587c0ee njRat binary 1 20161108
18 b98003bc-640e-442e-99ec-8ab90190bd4c 9 Payload delivery md5 366908f6c5c4f4329478d60586eca5bc putty.exe [stage1 downloader] 0 20161108
19 dc028130-bdaf-462a-acd8-81f8ea0eec51 9 Payload delivery md5 f1f84ea3229dca0ccacb7381a2f49f99 Assadcrimes1.ppsx 1 20161108
20 dd6a607c-1ffb-4f02-bf84-3cc3292f66b7 9 Payload delivery md5 2fc276e1c06c3c78c6d7b66a141213be alshohadaa alatfal.exe 1 20161108
21 e03c93a5-5b27-4242-8725-e82079d84a02 9 Payload delivery md5 30bb678db3ad0140fc33acd9803385c3 Assadcrimes.info.ppsx 1 20161108
22 e900b943-c875-4125-b4a7-f53de2620468 9 Payload delivery md5 dd5bedd915967c5efe00733cf7478cb4 1 20161108