Export from MISP Threat Report TAINTED LEAKS: Disinformation and Phishing With a Russian Nexus (MISP Event #100) Threat Report TAINTED LEAKS: Disinformation and Phishing With a Russian Nexus 100 2017-05-25T00:00:00+00:00 2017-05-25T11:15:50+00:00 Closed Network activity Network activity: id833.ga (MISP Attribute #16046) Malware Artifacts Domain Watchlist Network activity: id833.ga (MISP Attribute #16046) id833.ga High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: id834.ga (MISP Attribute #16047) Malware Artifacts Domain Watchlist Network activity: id834.ga (MISP Attribute #16047) id834.ga High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: id9954.gq (MISP Attribute #16048) Malware Artifacts Domain Watchlist Network activity: id9954.gq (MISP Attribute #16048) id9954.gq High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: id4242.ga (MISP Attribute #16049) Malware Artifacts Domain Watchlist Network activity: id4242.ga (MISP Attribute #16049) id4242.ga High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: mail-google-login.blogspot.com (MISP Attribute #16050) Malware Artifacts Domain Watchlist Network activity: mail-google-login.blogspot.com (MISP Attribute #16050) mail-google-login.blogspot.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: com-securitysettingpage.tk (MISP Attribute #16051) Malware Artifacts Domain Watchlist Network activity: com-securitysettingpage.tk (MISP Attribute #16051) com-securitysettingpage.tk High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 89.40.181.119 (MISP Attribute #16055) Malware Artifacts IP Watchlist Network activity: 89.40.181.119 (MISP Attribute #16055) 89.40.181.119 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 89.32.40.238 (MISP Attribute #16056) Malware Artifacts IP Watchlist Network activity: 89.32.40.238 (MISP Attribute #16056) 89.32.40.238 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 80.255.12.237 (MISP Attribute #16057) Malware Artifacts IP Watchlist Network activity: 80.255.12.237 (MISP Attribute #16057) 80.255.12.237 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: g.mail2017@yandex.com (MISP Attribute #16058) Malware Artifacts Malicious E-mail Payload delivery: g.mail2017@yandex.com (MISP Attribute #16058) g.mail2017@yandex.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: annaablony@mail.com (MISP Attribute #16059) Malware Artifacts Malicious E-mail Payload delivery: annaablony@mail.com (MISP Attribute #16059) annaablony@mail.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: myprimaryreger@gmail.com (MISP Attribute #16060) Malware Artifacts Malicious E-mail Payload delivery: myprimaryreger@gmail.com (MISP Attribute #16060) myprimaryreger@gmail.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none citizenlab ../../../descendant-or-self::node()