Skip to content
Permalink
master
Switch branches/tags

Name already in use

A tag already exists with the provided branch name. Many Git commands accept both tag and branch names, so creating this branch may cause unexpected behavior. Are you sure you want to create this branch?
Go to file
 
 
Cannot retrieve contributors at this time
uuid event_id category type value comment to_ids date object_relation attribute_tag object_uuid object_name object_meta_category
5cce2392-14c4-4733-b375-6aac68f8e8cf 300 Network activity url http://ghostru.biz/glora.exe Download & Execute Command 1 1557013394
5cce23b4-4e48-470b-8928-6aae68f8e8cf 300 Internal reference comment DGA domain: ndjlctodpepuxb.com, Resolved IP: 92.242.140.21 DGA domain: pqmnskgnprfcdbs.com, Resolved IP: 92.242.140.21 DGA domain: hjcojqxtrphkemwcgha.com, Resolved IP: 92.242.140.21 DGA domain: nkrdbolq.com, Resolved IP: 92.242.140.21 DGA domain: nitqaqudex.com, Resolved IP: 92.242.140.21 DGA domain: fdiaetxekbcvwx.com, Resolved IP: 92.242.140.21 DGA domain: kuenkvhyrd.com, Resolved IP: 92.242.140.21 DGA domain: lqmrogrmglfsnoj.com, Resolved IP: 92.242.140.21 DGA domain: tgxcyyvketgddxgu.com, Resolved IP: 92.242.140.21 DGA domain: uskfsurgk.com, Resolved IP: 92.242.140.21 DGA domain: qpklvinxxyijnihpq.com, Resolved IP: 92.242.140.21 DGA domain: lyboqylrtxyvn.com, Resolved IP: 92.242.140.21 DGA domain: hbvjtkjnts.com, Resolved IP: 92.242.140.21 DGA domain: aclplxsmerbodlmmx.com, Resolved IP: 92.242.140.21 DGA domain: uklsnpea.com, Resolved IP: 92.242.140.21 DGA domain: jqebchbgcjjaygavihx.com, Resolved IP: 92.242.140.21 DGA domain: jupxsnwsaahajcbcj.com, Resolved IP: 92.242.140.21 DGA domain: qjlqthkkvfcoubwftee.com, Resolved IP: 92.242.140.21 DGA domain: ijnvmfrlfb.com, Resolved IP: 92.242.140.21 DGA domain: ydbssmiwmqybhco.com, Resolved IP: 92.242.140.21 DGA domain: wigiwmmuqx.com, Resolved IP: 92.242.140.21 DGA domain: dvyuqnnudt.com, Resolved IP: 92.242.140.21 DGA domain: shafycxvdtqxidj.com, Resolved IP: 92.242.140.21 DGA domain: llqwdoonpuucdwurben.com, Resolved IP: 92.242.140.21 DGA domain: ilfsdhxxi.com, Resolved IP: 92.242.140.21 DGA domain: cfjxdnjklwhtq.com, Resolved IP: 92.242.140.21 DGA domain: ylndgysnu.com, Resolved IP: 92.242.140.21 DGA domain: wbfgqhsape.com, Resolved IP: 92.242.140.21 DGA domain: ntvjrrayjva.com, Resolved IP: 92.242.140.21 DGA domain: tpevimcvipxhrnq.com, Resolved IP: 92.242.140.21 DGA domain: gjqxrasjseoridl.com, Resolved IP: 92.242.140.21 DGA domain: qqfkbachfxj.com, Resolved IP: 92.242.140.21 DGA Resolved 0 1557013428
5cce22d0-0600-46d6-acab-6f9c68f8e8cf 300 Payload delivery malware-sample ed3be3849ba07eba660fba77fa461b0f1ff71c08599ee3a641e85092b47974ea|b6fe2611258774e53be60cb5d41bbe69 1 1557013200 malware-sample 5cce22d0-ade0-43fc-bde9-6f9c68f8e8cf file file
5cce22d0-51a0-4f47-8bbb-6f9c68f8e8cf 300 Payload delivery filename ed3be3849ba07eba660fba77fa461b0f1ff71c08599ee3a641e85092b47974ea 0 1557013200 filename 5cce22d0-ade0-43fc-bde9-6f9c68f8e8cf file file
5cce22d0-d0c4-420b-a9e2-6f9c68f8e8cf 300 Payload delivery md5 b6fe2611258774e53be60cb5d41bbe69 1 1557013200 md5 5cce22d0-ade0-43fc-bde9-6f9c68f8e8cf file file
5cce22d0-f4a4-4bc6-be81-6f9c68f8e8cf 300 Payload delivery sha1 3b92161d910e1289a0a2a5b72b2082a684335b00 1 1557013200 sha1 5cce22d0-ade0-43fc-bde9-6f9c68f8e8cf file file
5cce22d0-d788-44e3-9744-6f9c68f8e8cf 300 Payload delivery sha256 ed3be3849ba07eba660fba77fa461b0f1ff71c08599ee3a641e85092b47974ea 1 1557013200 sha256 5cce22d0-ade0-43fc-bde9-6f9c68f8e8cf file file
5cce22d0-0b48-4e58-a714-6f9c68f8e8cf 300 Other size-in-bytes 346600 0 1557013200 size-in-bytes 5cce22d0-ade0-43fc-bde9-6f9c68f8e8cf file file
5cce22f5-1a38-47b6-b0c9-04a268f8e8cf 300 Payload delivery malware-sample 20010000.dll|c9f867c621997a435d8de807d6926a57 1 1557013237 malware-sample 5cce22f5-7d6c-45fd-9ef3-04a268f8e8cf file file
5cce22f5-ecac-493f-9432-04a268f8e8cf 300 Payload delivery filename 20010000.dll 0 1557013237 filename 5cce22f5-7d6c-45fd-9ef3-04a268f8e8cf file file
5cce22f5-6870-4cdb-b586-04a268f8e8cf 300 Payload delivery md5 c9f867c621997a435d8de807d6926a57 1 1557013237 md5 5cce22f5-7d6c-45fd-9ef3-04a268f8e8cf file file
5cce22f5-65e4-4818-a4d1-04a268f8e8cf 300 Payload delivery sha1 48ba542ce1401989962d75e4e1549a16e729fb62 1 1557013237 sha1 5cce22f5-7d6c-45fd-9ef3-04a268f8e8cf file file
5cce22f5-e4a4-451b-983b-04a268f8e8cf 300 Payload delivery sha256 8a5e379642d626a20238b9913cc7dc55860ad86a0c0d95ee60758eb2e236a5bc 1 1557013237 sha256 5cce22f5-7d6c-45fd-9ef3-04a268f8e8cf file file
5cce22f5-caa8-4b45-8e2f-04a268f8e8cf 300 Other size-in-bytes 106496 0 1557013237 size-in-bytes 5cce22f5-7d6c-45fd-9ef3-04a268f8e8cf file file
5cce2323-a338-4950-90be-6aae68f8e8cf 300 Payload delivery malware-sample 15190000.dll|1bb2ffb67f5b4809bc446c03114abf11 1 1557013283 malware-sample 5cce2323-52d8-44c8-a67c-6aae68f8e8cf file file
5cce2323-30a4-49a5-b85b-6aae68f8e8cf 300 Payload delivery filename 15190000.dll 0 1557013283 filename 5cce2323-52d8-44c8-a67c-6aae68f8e8cf file file
5cce2323-b414-4904-bb88-6aae68f8e8cf 300 Payload delivery md5 1bb2ffb67f5b4809bc446c03114abf11 1 1557013283 md5 5cce2323-52d8-44c8-a67c-6aae68f8e8cf file file
5cce2323-5cc4-475d-8875-6aae68f8e8cf 300 Payload delivery sha1 23193abcf46a62c6d76a710cf86f3807fab04a42 1 1557013283 sha1 5cce2323-52d8-44c8-a67c-6aae68f8e8cf file file
5cce2323-400c-42c1-b2d8-6aae68f8e8cf 300 Payload delivery sha256 ba00d19866096d38d0386aa718abaa1d65c01a53452b69d303af7de79b681496 1 1557013283 sha256 5cce2323-52d8-44c8-a67c-6aae68f8e8cf file file
5cce2323-3208-4205-9c33-6aae68f8e8cf 300 Other size-in-bytes 94208 0 1557013283 size-in-bytes 5cce2323-52d8-44c8-a67c-6aae68f8e8cf file file
5cce236b-6d7c-4a29-b7d3-6f7568f8e8cf 300 Payload delivery malware-sample 230000.dll|c48d90da35de03e1e77c1367dca83080 1 1557013355 malware-sample 5cce236b-790c-42f3-92d2-6f7568f8e8cf file file
5cce236b-7da8-4bdd-89aa-6f7568f8e8cf 300 Payload delivery filename 230000.dll 0 1557013355 filename 5cce236b-790c-42f3-92d2-6f7568f8e8cf file file
5cce236b-702c-454e-8fd4-6f7568f8e8cf 300 Payload delivery md5 c48d90da35de03e1e77c1367dca83080 1 1557013355 md5 5cce236b-790c-42f3-92d2-6f7568f8e8cf file file
5cce236b-a8c0-46e0-b0fc-6f7568f8e8cf 300 Payload delivery sha1 0aaca38fd6819518ed2bd532806e24533068588c 1 1557013355 sha1 5cce236b-790c-42f3-92d2-6f7568f8e8cf file file
5cce236b-ab6c-4268-a082-6f7568f8e8cf 300 Payload delivery sha256 2d2674aa1faa4cbc531368a79d92d7162c9fcbe1736564ae2b5232cef47af604 1 1557013355 sha256 5cce236b-790c-42f3-92d2-6f7568f8e8cf file file
5cce236b-5bec-4c93-a884-6f7568f8e8cf 300 Other size-in-bytes 175104 0 1557013355 size-in-bytes 5cce236b-790c-42f3-92d2-6f7568f8e8cf file file
5cce237d-53a4-4be3-862f-6ab068f8e8cf 300 Payload delivery malware-sample glora.exe|6096b02f0376e084af8e441163a7b378 1 1557013373 malware-sample 5cce237d-4ae4-42bc-98f6-6ab068f8e8cf file file
5cce237d-435c-444b-8b77-6ab068f8e8cf 300 Payload delivery filename glora.exe 0 1557013373 filename 5cce237d-4ae4-42bc-98f6-6ab068f8e8cf file file
5cce237d-5e80-4211-a86a-6ab068f8e8cf 300 Payload delivery md5 6096b02f0376e084af8e441163a7b378 1 1557013373 md5 5cce237d-4ae4-42bc-98f6-6ab068f8e8cf file file
5cce237d-0b7c-4b10-860f-6ab068f8e8cf 300 Payload delivery sha1 819590f176b0b5c19b55e521837c382380cfb729 1 1557013373 sha1 5cce237d-4ae4-42bc-98f6-6ab068f8e8cf file file
5cce237d-1518-4777-98f9-6ab068f8e8cf 300 Payload delivery sha256 c376d0704f9f702d5186f457f49acb93c6c63ff1c5558478265f488cc8b36fbd 1 1557013373 sha256 5cce237d-4ae4-42bc-98f6-6ab068f8e8cf file file
5cce237d-0f38-494a-8e00-6ab068f8e8cf 300 Other size-in-bytes 688128 0 1557013373 size-in-bytes 5cce237d-4ae4-42bc-98f6-6ab068f8e8cf file file