2.6 KiB
2.6 KiB
| 1 | uuid | event_id | category | type | value | comment | to_ids | date |
|---|---|---|---|---|---|---|---|---|
| 2 | 3f6407bd-cfd7-4bb6-9338-34132bdc3c62 | 9 | Network activity | ip-dst | 88.198.222.163 | C2 for malware dropped | 1 | 20161108 |
| 3 | 47690aa0-910d-478d-b0ea-fff1f40631ee | 9 | Payload delivery | md5 | 8ebeb3f91cda8e985a9c61beb8cdde9d | adobe_flash_player.apk Droid Jack | 1 | 20161108 |
| 4 | 4bf52b9f-f004-4793-a0ba-bf1e211c089d | 9 | Payload delivery | md5 | 76f8142b4e52c671871b3df87f10c30c | Assadcrimes.ppsx | 1 | 20161108 |
| 5 | 58223ba8-5da0-4111-8b1b-69fe8e96ca05 | 9 | Payload delivery | email-src | office@assadcrimes.info | email used for targeted phishing | 1 | 20161108 |
| 6 | 58223cbc-ec7c-43f6-a95a-69fe8e96ca05 | 9 | Network activity | domain | assadcrimes.info | Fake activist website used as a watering hole | 1 | 20161108 |
| 7 | 58223d3d-5864-453a-8c70-69fe8e96ca05 | 9 | Payload delivery | vulnerability | CVE-2014-4114 | 0 | 20161108 | |
| 8 | 58223dcd-63c0-45f1-9516-69fe8e96ca05 | 9 | Payload type | text | njRat | 0 | 20161108 | |
| 9 | 58223dd5-ca58-4ad4-98d6-69fe8e96ca05 | 9 | Payload type | text | NanoCore RAT | 0 | 20161108 | |
| 10 | 58223e40-64f4-47ca-b56b-69fe8e96ca05 | 9 | Payload type | text | DroidJack | 0 | 20161108 | |
| 11 | 58223f8a-1820-476b-823c-497a8e96ca05 | 9 | Network activity | ip-dst | 212.7.195.171 | IP hosting assadcrimes.info website | 0 | 20161108 |
| 12 | 588e5189-3408-4430-b4de-7f3a04c1107b | 9 | Payload delivery | md5 | a4f1f4921bb11ff9d22fad89b19b155d | Doc Dropper 1 Crypter | 1 | 20161108 |
| 13 | 593c7165-8933-46ba-8b6b-36db6e65c1b3 | 9 | External analysis | link | https://citizenlab.org/2016/08/group5-syria/ | 0 | 20161108 | |
| 14 | 7aa1122f-33ee-422b-acae-8820e0664fdb | 9 | Payload delivery | md5 | 7d898530d2e77f15f5badce8d7df215e | second stage executable, saved to disk as %temp%\dwm.exe | 1 | 20161108 |
| 15 | 7af948f4-01b5-43f9-b9be-3746a9ce0fcf | 9 | Payload delivery | md5 | 6161083021b695814434450c1882f9f3 | Doc Dropper 3 Crypter | 1 | 20161108 |
| 16 | 87004645-e8b6-4b7e-a79b-ca643e1446ec | 9 | Payload delivery | md5 | 494bab7fd0b42b0b14051ed9abbd651f | dvm.exe [dropped by decoy app] | 1 | 20161108 |
| 17 | b02858c1-6bfb-4097-a00e-98182b0ec121 | 9 | Payload delivery | md5 | b4121c3a1892332402000ef0d587c0ee | njRat binary | 1 | 20161108 |
| 18 | b98003bc-640e-442e-99ec-8ab90190bd4c | 9 | Payload delivery | md5 | 366908f6c5c4f4329478d60586eca5bc | putty.exe [stage1 downloader] | 0 | 20161108 |
| 19 | dc028130-bdaf-462a-acd8-81f8ea0eec51 | 9 | Payload delivery | md5 | f1f84ea3229dca0ccacb7381a2f49f99 | Assadcrimes1.ppsx | 1 | 20161108 |
| 20 | dd6a607c-1ffb-4f02-bf84-3cc3292f66b7 | 9 | Payload delivery | md5 | 2fc276e1c06c3c78c6d7b66a141213be | alshohadaa alatfal.exe | 1 | 20161108 |
| 21 | e03c93a5-5b27-4242-8725-e82079d84a02 | 9 | Payload delivery | md5 | 30bb678db3ad0140fc33acd9803385c3 | Assadcrimes.info.ppsx | 1 | 20161108 |
| 22 | e900b943-c875-4125-b4a7-f53de2620468 | 9 | Payload delivery | md5 | dd5bedd915967c5efe00733cf7478cb4 | 1 | 20161108 |