chg: Add FP risk tags to bambenekconsulting feeds

pull/12/head
Raphaël Vinot 2018-07-10 13:27:31 +02:00
parent 17819e3d15
commit 77c62cd937
104 changed files with 223 additions and 63 deletions

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Bamital\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Bamital\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:banker=\"Banjori\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:banker=\"Banjori\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Bebloh\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Bebloh\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Bedep\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Bedep\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Beebone\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Beebone\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Chinad",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Chinad_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Corebot\""
]
}

View File

@ -5,14 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"misp-galaxy:ransomware=\"CryptoLocker by NTK Ransomware\"",
"misp-galaxy:ransomware=\"MSN CryptoLocker Ransomware\"",
"misp-galaxy:ransomware=\"CryptoLocker 5.1\"",
"misp-galaxy:ransomware=\"FakeCryptoLocker\"",
"misp-galaxy:ransomware=\"PClock3 Ransomware\"",
"misp-galaxy:ransomware=\"CryptoLocker3 Ransomware\"",
"misp-galaxy:ransomware=\"CryptoLocker 1.0.0\"",
"misp-galaxy:ransomware=\"DynA-Crypt Ransomware\"",
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"CryptoLocker\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"CryptoLocker\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"DirCrypt\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"DirCrypt\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Dromedan",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Dromedan_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Dyre\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Dyre\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Fobber\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Fobber\""
]
}

View File

@ -3,5 +3,8 @@
"name": "G01",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -3,5 +3,8 @@
"name": "G01_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -5,7 +5,8 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"misp-galaxy:tool=\"Emotet\"",
"misp-galaxy:banker=\"Geodo\""
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Geodo\"",
"misp-galaxy:tool=\"Emotet\""
]
}

View File

@ -5,7 +5,8 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"misp-galaxy:tool=\"Emotet\"",
"misp-galaxy:banker=\"Geodo\""
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Geodo\"",
"misp-galaxy:tool=\"Emotet\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Gozi\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Gozi\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:android=\"Hesperbot\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:android=\"Hesperbot\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Kraken\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Kraken\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"Locky\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"Locky\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Madmax\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Madmax\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Matsnu",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"high\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Matsnu_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"high\""
]
}

View File

@ -5,7 +5,8 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"misp-galaxy:botnet=\"Mirai\"",
"misp-galaxy:tool=\"Mirai\""
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Mirai\"",
"misp-galaxy:botnet=\"Mirai\""
]
}

View File

@ -5,7 +5,8 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"misp-galaxy:botnet=\"Mirai\"",
"misp-galaxy:tool=\"Mirai\""
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Mirai\"",
"misp-galaxy:botnet=\"Mirai\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Licat\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Licat\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Necurs\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Necurs\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:tool=\"Nymaim\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:tool=\"Nymaim\""
]
}

View File

@ -3,5 +3,8 @@
"name": "P2P_GOZ",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -3,5 +3,8 @@
"name": "P2P_GOZ_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -3,5 +3,8 @@
"name": "PT_GOZ_/_New_GOZ_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"PadCrypt\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:ransomware=\"PadCrypt\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Panda Banker\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Panda Banker\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Pizd",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"high\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Pizd_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"high\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Proslikefan",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Proslikefan_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Pushdo\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Pushdo\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Pykspa",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Pykspa_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Qadars\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Qadars\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Akbot\"",
"misp-galaxy:banker=\"Qakbot\""
]

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Akbot\"",
"misp-galaxy:banker=\"Qakbot\""
]

View File

@ -3,5 +3,8 @@
"name": "Ramdo",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Ramdo_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Ramnit\"",
"misp-galaxy:banker=\"Ramnit\""
]

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:botnet=\"Ramnit\"",
"misp-galaxy:banker=\"Ramnit\""
]

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Ranbyus\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Ranbyus\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:tool=\"Shifu\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:tool=\"Shifu\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:botnet=\"Simda\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:botnet=\"Simda\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Sisron\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Sisron\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Zeus Sphinx\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Zeus Sphinx\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Suppobox",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"high\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Suppobox_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"high\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Symmi",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Tempedreve",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Tempedreve_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -5,7 +5,8 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"misp-galaxy:banker=\"Tinba\"",
"misp-galaxy:tool=\"Tinba\""
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Tinba\"",
"misp-galaxy:banker=\"Tinba\""
]
}

View File

@ -5,7 +5,8 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"misp-galaxy:banker=\"Tinba\"",
"misp-galaxy:tool=\"Tinba\""
"false-positive:risk=\"low\"",
"misp-galaxy:tool=\"Tinba\"",
"misp-galaxy:banker=\"Tinba\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"TinyNuke\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"TinyNuke\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:botnet=\"Gheg\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:botnet=\"Gheg\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Unknowndropper",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Unknowndropper_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Unknownjs",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Unknownjs_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -5,7 +5,8 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"misp-galaxy:tool=\"Vawtrak\"",
"misp-galaxy:banker=\"Vawtrak\""
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Vawtrak\"",
"misp-galaxy:tool=\"Vawtrak\""
]
}

View File

@ -5,7 +5,8 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"misp-galaxy:tool=\"Vawtrak\"",
"misp-galaxy:banker=\"Vawtrak\""
"false-positive:risk=\"low\"",
"misp-galaxy:banker=\"Vawtrak\"",
"misp-galaxy:tool=\"Vawtrak\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Vidro",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -3,5 +3,8 @@
"name": "Vidro_NS",
"vendor": "bambenekconsulting",
"impact": 3,
"parser": ".parsers.bambenekconsulting"
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"low\""
]
}

View File

@ -5,6 +5,7 @@
"impact": 3,
"parser": ".parsers.bambenekconsulting",
"tags": [
"false-positive:risk=\"medium\"",
"misp-galaxy:botnet=\"Virut\""
]
}

Some files were not shown because too many files have changed in this diff Show More