chg: Add FP risk tags to bambenekconsulting feeds

pull/12/head
Raphaël Vinot 2018-07-10 13:27:31 +02:00
parent 17819e3d15
commit 77c62cd937
104 changed files with 223 additions and 63 deletions

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Bamital\"" "misp-galaxy:botnet=\"Bamital\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Bamital\"" "misp-galaxy:botnet=\"Bamital\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:banker=\"Banjori\"" "misp-galaxy:banker=\"Banjori\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:banker=\"Banjori\"" "misp-galaxy:banker=\"Banjori\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Bebloh\"" "misp-galaxy:banker=\"Bebloh\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Bebloh\"" "misp-galaxy:banker=\"Bebloh\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Bedep\"" "misp-galaxy:tool=\"Bedep\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Bedep\"" "misp-galaxy:tool=\"Bedep\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Beebone\"" "misp-galaxy:botnet=\"Beebone\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Beebone\"" "misp-galaxy:botnet=\"Beebone\""
] ]
} }

View File

@ -3,5 +3,8 @@
"name": "Chinad", "name": "Chinad",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Chinad_NS", "name": "Chinad_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Corebot\"" "misp-galaxy:banker=\"Corebot\""
] ]
} }

View File

@ -5,14 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"misp-galaxy:ransomware=\"CryptoLocker by NTK Ransomware\"", "false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"MSN CryptoLocker Ransomware\"",
"misp-galaxy:ransomware=\"CryptoLocker 5.1\"",
"misp-galaxy:ransomware=\"FakeCryptoLocker\"",
"misp-galaxy:ransomware=\"PClock3 Ransomware\"",
"misp-galaxy:ransomware=\"CryptoLocker3 Ransomware\"",
"misp-galaxy:ransomware=\"CryptoLocker 1.0.0\"",
"misp-galaxy:ransomware=\"DynA-Crypt Ransomware\"",
"misp-galaxy:ransomware=\"CryptoLocker\"" "misp-galaxy:ransomware=\"CryptoLocker\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"CryptoLocker\"" "misp-galaxy:ransomware=\"CryptoLocker\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"DirCrypt\"" "misp-galaxy:ransomware=\"DirCrypt\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"DirCrypt\"" "misp-galaxy:ransomware=\"DirCrypt\""
] ]
} }

View File

@ -3,5 +3,8 @@
"name": "Dromedan", "name": "Dromedan",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Dromedan_NS", "name": "Dromedan_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Dyre\"" "misp-galaxy:banker=\"Dyre\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Dyre\"" "misp-galaxy:banker=\"Dyre\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Fobber\"" "misp-galaxy:banker=\"Fobber\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Fobber\"" "misp-galaxy:banker=\"Fobber\""
] ]
} }

View File

@ -3,5 +3,8 @@
"name": "G01", "name": "G01",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "G01_NS", "name": "G01_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -5,7 +5,8 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"misp-galaxy:tool=\"Emotet\"", "false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Geodo\"" "misp-galaxy:banker=\"Geodo\"",
"misp-galaxy:tool=\"Emotet\""
] ]
} }

View File

@ -5,7 +5,8 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"misp-galaxy:tool=\"Emotet\"", "false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Geodo\"" "misp-galaxy:banker=\"Geodo\"",
"misp-galaxy:tool=\"Emotet\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Gozi\"" "misp-galaxy:banker=\"Gozi\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Gozi\"" "misp-galaxy:banker=\"Gozi\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:android=\"Hesperbot\"" "misp-galaxy:android=\"Hesperbot\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:android=\"Hesperbot\"" "misp-galaxy:android=\"Hesperbot\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Kraken\"" "misp-galaxy:botnet=\"Kraken\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Kraken\"" "misp-galaxy:botnet=\"Kraken\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"Locky\"" "misp-galaxy:ransomware=\"Locky\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"Locky\"" "misp-galaxy:ransomware=\"Locky\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Madmax\"" "misp-galaxy:botnet=\"Madmax\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Madmax\"" "misp-galaxy:botnet=\"Madmax\""
] ]
} }

View File

@ -3,5 +3,8 @@
"name": "Matsnu", "name": "Matsnu",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"high\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Matsnu_NS", "name": "Matsnu_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"high\""
]
} }

View File

@ -5,7 +5,8 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"misp-galaxy:botnet=\"Mirai\"", "false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Mirai\"" "misp-galaxy:tool=\"Mirai\"",
"misp-galaxy:botnet=\"Mirai\""
] ]
} }

View File

@ -5,7 +5,8 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"misp-galaxy:botnet=\"Mirai\"", "false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Mirai\"" "misp-galaxy:tool=\"Mirai\"",
"misp-galaxy:botnet=\"Mirai\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Licat\"" "misp-galaxy:banker=\"Licat\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Licat\"" "misp-galaxy:banker=\"Licat\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Necurs\"" "misp-galaxy:tool=\"Necurs\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Necurs\"" "misp-galaxy:tool=\"Necurs\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:tool=\"Nymaim\"" "misp-galaxy:tool=\"Nymaim\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:tool=\"Nymaim\"" "misp-galaxy:tool=\"Nymaim\""
] ]
} }

View File

@ -3,5 +3,8 @@
"name": "P2P_GOZ", "name": "P2P_GOZ",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "P2P_GOZ_NS", "name": "P2P_GOZ_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "PT_GOZ_/_New_GOZ_NS", "name": "PT_GOZ_/_New_GOZ_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"PadCrypt\"" "misp-galaxy:ransomware=\"PadCrypt\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"PadCrypt\"" "misp-galaxy:ransomware=\"PadCrypt\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Panda Banker\"" "misp-galaxy:banker=\"Panda Banker\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Panda Banker\"" "misp-galaxy:banker=\"Panda Banker\""
] ]
} }

View File

@ -3,5 +3,8 @@
"name": "Pizd", "name": "Pizd",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"high\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Pizd_NS", "name": "Pizd_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"high\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Proslikefan", "name": "Proslikefan",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Proslikefan_NS", "name": "Proslikefan_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Pushdo\"" "misp-galaxy:botnet=\"Pushdo\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Pushdo\"" "misp-galaxy:botnet=\"Pushdo\""
] ]
} }

View File

@ -3,5 +3,8 @@
"name": "Pykspa", "name": "Pykspa",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Pykspa_NS", "name": "Pykspa_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\""
]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Qadars\"" "misp-galaxy:banker=\"Qadars\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Qadars\"" "misp-galaxy:banker=\"Qadars\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Akbot\"", "misp-galaxy:tool=\"Akbot\"",
"misp-galaxy:banker=\"Qakbot\"" "misp-galaxy:banker=\"Qakbot\""
] ]

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Akbot\"", "misp-galaxy:tool=\"Akbot\"",
"misp-galaxy:banker=\"Qakbot\"" "misp-galaxy:banker=\"Qakbot\""
] ]

View File

@ -3,5 +3,8 @@
"name": "Ramdo", "name": "Ramdo",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Ramdo_NS", "name": "Ramdo_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Ramnit\"", "misp-galaxy:botnet=\"Ramnit\"",
"misp-galaxy:banker=\"Ramnit\"" "misp-galaxy:banker=\"Ramnit\""
] ]

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Ramnit\"", "misp-galaxy:botnet=\"Ramnit\"",
"misp-galaxy:banker=\"Ramnit\"" "misp-galaxy:banker=\"Ramnit\""
] ]

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Ranbyus\"" "misp-galaxy:banker=\"Ranbyus\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Ranbyus\"" "misp-galaxy:banker=\"Ranbyus\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:tool=\"Shifu\"" "misp-galaxy:tool=\"Shifu\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:tool=\"Shifu\"" "misp-galaxy:tool=\"Shifu\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:botnet=\"Simda\"" "misp-galaxy:botnet=\"Simda\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:botnet=\"Simda\"" "misp-galaxy:botnet=\"Simda\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Sisron\"" "misp-galaxy:banker=\"Sisron\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Sisron\"" "misp-galaxy:banker=\"Sisron\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Zeus Sphinx\"" "misp-galaxy:banker=\"Zeus Sphinx\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Zeus Sphinx\"" "misp-galaxy:banker=\"Zeus Sphinx\""
] ]
} }

View File

@ -3,5 +3,8 @@
"name": "Suppobox", "name": "Suppobox",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"high\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Suppobox_NS", "name": "Suppobox_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"high\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Symmi", "name": "Symmi",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Tempedreve", "name": "Tempedreve",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Tempedreve_NS", "name": "Tempedreve_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -5,7 +5,8 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"misp-galaxy:banker=\"Tinba\"", "false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Tinba\"" "misp-galaxy:tool=\"Tinba\"",
"misp-galaxy:banker=\"Tinba\""
] ]
} }

View File

@ -5,7 +5,8 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"misp-galaxy:banker=\"Tinba\"", "false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Tinba\"" "misp-galaxy:tool=\"Tinba\"",
"misp-galaxy:banker=\"Tinba\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"TinyNuke\"" "misp-galaxy:banker=\"TinyNuke\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"TinyNuke\"" "misp-galaxy:banker=\"TinyNuke\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:botnet=\"Gheg\"" "misp-galaxy:botnet=\"Gheg\""
] ]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:botnet=\"Gheg\"" "misp-galaxy:botnet=\"Gheg\""
] ]
} }

View File

@ -3,5 +3,8 @@
"name": "Unknowndropper", "name": "Unknowndropper",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Unknowndropper_NS", "name": "Unknowndropper_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Unknownjs", "name": "Unknownjs",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Unknownjs_NS", "name": "Unknownjs_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -5,7 +5,8 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"misp-galaxy:tool=\"Vawtrak\"", "false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Vawtrak\"" "misp-galaxy:banker=\"Vawtrak\"",
"misp-galaxy:tool=\"Vawtrak\""
] ]
} }

View File

@ -5,7 +5,8 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"misp-galaxy:tool=\"Vawtrak\"", "false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Vawtrak\"" "misp-galaxy:banker=\"Vawtrak\"",
"misp-galaxy:tool=\"Vawtrak\""
] ]
} }

View File

@ -3,5 +3,8 @@
"name": "Vidro", "name": "Vidro",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -3,5 +3,8 @@
"name": "Vidro_NS", "name": "Vidro_NS",
"vendor": "bambenekconsulting", "vendor": "bambenekconsulting",
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting" "parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
} }

View File

@ -5,6 +5,7 @@
"impact": 3, "impact": 3,
"parser": ".parsers.bambenekconsulting", "parser": ".parsers.bambenekconsulting",
"tags": [ "tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:botnet=\"Virut\"" "misp-galaxy:botnet=\"Virut\""
] ]
} }

Some files were not shown because too many files have changed in this diff Show More