Files

2.6 KiB

1uuidevent_idcategorytypevaluecommentto_idsdate
23f6407bd-cfd7-4bb6-9338-34132bdc3c629Network activityip-dst88.198.222.163C2 for malware dropped120161108
347690aa0-910d-478d-b0ea-fff1f40631ee9Payload deliverymd58ebeb3f91cda8e985a9c61beb8cdde9dadobe_flash_player.apk Droid Jack120161108
44bf52b9f-f004-4793-a0ba-bf1e211c089d9Payload deliverymd576f8142b4e52c671871b3df87f10c30cAssadcrimes.ppsx120161108
558223ba8-5da0-4111-8b1b-69fe8e96ca059Payload deliveryemail-srcoffice@assadcrimes.infoemail used for targeted phishing120161108
658223cbc-ec7c-43f6-a95a-69fe8e96ca059Network activitydomainassadcrimes.infoFake activist website used as a watering hole120161108
758223d3d-5864-453a-8c70-69fe8e96ca059Payload deliveryvulnerabilityCVE-2014-4114020161108
858223dcd-63c0-45f1-9516-69fe8e96ca059Payload typetextnjRat020161108
958223dd5-ca58-4ad4-98d6-69fe8e96ca059Payload typetextNanoCore RAT020161108
1058223e40-64f4-47ca-b56b-69fe8e96ca059Payload typetextDroidJack020161108
1158223f8a-1820-476b-823c-497a8e96ca059Network activityip-dst212.7.195.171IP hosting assadcrimes.info website020161108
12588e5189-3408-4430-b4de-7f3a04c1107b9Payload deliverymd5a4f1f4921bb11ff9d22fad89b19b155dDoc Dropper 1 Crypter120161108
13593c7165-8933-46ba-8b6b-36db6e65c1b39External analysislinkhttps://citizenlab.org/2016/08/group5-syria/020161108
147aa1122f-33ee-422b-acae-8820e0664fdb9Payload deliverymd57d898530d2e77f15f5badce8d7df215esecond stage executable, saved to disk as %temp%\dwm.exe120161108
157af948f4-01b5-43f9-b9be-3746a9ce0fcf9Payload deliverymd56161083021b695814434450c1882f9f3Doc Dropper 3 Crypter120161108
1687004645-e8b6-4b7e-a79b-ca643e1446ec9Payload deliverymd5494bab7fd0b42b0b14051ed9abbd651fdvm.exe [dropped by decoy app]120161108
17b02858c1-6bfb-4097-a00e-98182b0ec1219Payload deliverymd5b4121c3a1892332402000ef0d587c0eenjRat binary120161108
18b98003bc-640e-442e-99ec-8ab90190bd4c9Payload deliverymd5366908f6c5c4f4329478d60586eca5bcputty.exe [stage1 downloader]020161108
19dc028130-bdaf-462a-acd8-81f8ea0eec519Payload deliverymd5f1f84ea3229dca0ccacb7381a2f49f99Assadcrimes1.ppsx120161108
20dd6a607c-1ffb-4f02-bf84-3cc3292f66b79Payload deliverymd52fc276e1c06c3c78c6d7b66a141213bealshohadaa alatfal.exe120161108
21e03c93a5-5b27-4242-8725-e82079d84a029Payload deliverymd530bb678db3ad0140fc33acd9803385c3Assadcrimes.info.ppsx120161108
22e900b943-c875-4125-b4a7-f53de26204689Payload deliverymd5dd5bedd915967c5efe00733cf7478cb4120161108