Skip to content
Permalink
master
Switch branches/tags

Name already in use

A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?
Go to file
 
 
Cannot retrieve contributors at this time
uuid event_id category type value comment to_ids date object_relation attribute_tag object_uuid object_name object_meta_category event_info event_member_org event_source_org event_distribution event_threat_level_id event_analysis event_date event_tag event_timestamp
5ca87b9f-9e20-4777-84ff-113768f8e8cf 289 Network activity url 193.29.57.193:443 Dridex Config 1 1554545572 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87b9f-dc7c-48e5-aab7-113768f8e8cf 289 Network activity url 109.94.110.82:443 Dridex Config 1 1554545573 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87b9f-d80c-428b-aa6d-113768f8e8cf 289 Network activity url 185.243.114.241:443 Dridex Config 1 1554545575 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87b9f-c2d0-4023-9e25-113768f8e8cf 289 Network activity url 5.149.254.28:443 Dridex Config 1 1554545578 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87d9f-30ac-49b9-bcd6-112e68f8e8cf 289 Network activity url t97uoquintengbnia.company Gozi ISFB v2 Config 1 1554546079 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87d9f-7de0-45f5-a3d0-112e68f8e8cf 289 Network activity url koo89iiignatius.com Gozi ISFB v2 Config 1 1554546079 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87d9f-7e84-42a7-ad74-112e68f8e8cf 289 Network activity url s45ooallison.com Gozi ISFB v2 Config 1 1554546079 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bbb-c0f4-4713-b1ef-1fec68f8e8cf 289 Payload delivery malware-sample 2019-04-06-dridex-loader-packed-vk.exe|f2c14db5471d3c3a46945ee43b1d1486 1 1554545595 malware-sample 5ca87bbb-6f4c-42c8-ba10-1fec68f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bbb-b34c-4c7e-8056-1fec68f8e8cf 289 Payload delivery filename 2019-04-06-dridex-loader-packed-vk.exe 0 1554545595 filename 5ca87bbb-6f4c-42c8-ba10-1fec68f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bbb-1074-4a17-8e03-1fec68f8e8cf 289 Payload delivery md5 f2c14db5471d3c3a46945ee43b1d1486 1 1554545595 md5 5ca87bbb-6f4c-42c8-ba10-1fec68f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bbb-0424-4c7b-a784-1fec68f8e8cf 289 Payload delivery sha1 7d61769a1272fe4f03fce8e93240be52218c309b 1 1554545595 sha1 5ca87bbb-6f4c-42c8-ba10-1fec68f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bbb-68b8-4bb1-bc64-1fec68f8e8cf 289 Payload delivery sha256 45e054568cb4a2ce48d5f0d185488872810080f00e8d371b8d4648ece3916061 1 1554545595 sha256 5ca87bbb-6f4c-42c8-ba10-1fec68f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bbb-c3ec-4b41-b79f-1fec68f8e8cf 289 Other size-in-bytes 290816 0 1554545595 size-in-bytes 5ca87bbb-6f4c-42c8-ba10-1fec68f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bcd-ef84-4ecb-b312-113268f8e8cf 289 Payload delivery malware-sample 2019-04-06-dridex-loader-unpacked-vk.exe.dll|4d12225a7384758438d62628c77e4263 1 1554545613 malware-sample 5ca87bcd-1370-4cab-9957-113268f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bcd-1760-4a16-bfd7-113268f8e8cf 289 Payload delivery filename 2019-04-06-dridex-loader-unpacked-vk.exe.dll 0 1554545613 filename 5ca87bcd-1370-4cab-9957-113268f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bcd-5a38-4b1c-81f1-113268f8e8cf 289 Payload delivery md5 4d12225a7384758438d62628c77e4263 1 1554545613 md5 5ca87bcd-1370-4cab-9957-113268f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bcd-0024-4be2-9b71-113268f8e8cf 289 Payload delivery sha1 2ca546af0875d0a3b3c9feb4caac569e28c70ab3 1 1554545613 sha1 5ca87bcd-1370-4cab-9957-113268f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bcd-2d1c-46f9-83f9-113268f8e8cf 289 Payload delivery sha256 22adbbe64e25aff75358403153ac6e9151cf8fe72a86bbcebf1afc4562dfd6e9 1 1554545613 sha256 5ca87bcd-1370-4cab-9957-113268f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bcd-8b0c-4ed4-a212-113268f8e8cf 289 Other size-in-bytes 88576 0 1554545613 size-in-bytes 5ca87bcd-1370-4cab-9957-113268f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bde-7e38-4260-964d-113068f8e8cf 289 Payload delivery malware-sample 2019-04-06-isfb-gozi-loader-unpacked-vk.exe.exe|7c6dc428e9ea0270b4291302b725f331 1 1554545630 malware-sample 5ca87bde-82c0-4f94-828e-113068f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bde-474c-4c2f-b489-113068f8e8cf 289 Payload delivery filename 2019-04-06-isfb-gozi-loader-unpacked-vk.exe.exe 0 1554545630 filename 5ca87bde-82c0-4f94-828e-113068f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bde-dd6c-4fee-ac4c-113068f8e8cf 289 Payload delivery md5 7c6dc428e9ea0270b4291302b725f331 1 1554545630 md5 5ca87bde-82c0-4f94-828e-113068f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bde-6b18-4d23-832b-113068f8e8cf 289 Payload delivery sha1 6963370f6033eb58d7cbb731af22fcb32a6240b7 1 1554545630 sha1 5ca87bde-82c0-4f94-828e-113068f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bde-2a8c-4f1d-9bbd-113068f8e8cf 289 Payload delivery sha256 d2fc86b566d50e85f9081c13e3e62afabc17b2036ef0a8dd7f5d49667f26b6f3 1 1554545630 sha256 5ca87bde-82c0-4f94-828e-113068f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172
5ca87bde-1d50-4ccf-bc4f-113068f8e8cf 289 Other size-in-bytes 44032 0 1554545630 size-in-bytes 5ca87bde-82c0-4f94-828e-113068f8e8cf file file 2019-04-06: Gozi ISFB v2 -> Dridex Banker "301" VK-Intel VK-Intel 3 Medium 0 2019-04-06 Banker: Gozi ISFB v2,10291029JSJUYNHG,Banker: Dridex,Dridex ID: "301",ISFB Version: 217173,ISFB Group: 3268 1554547172