{ "attributes": { "hijacked-domain": { "categories": [ "Network activity" ], "description": "Domain/hostname hijacked by the the rogue DNS", "misp-attribute": "hostname", "ui-priority": 1 }, "phishing-ip": { "description": "Resource records returns by the rogue DNS", "misp-attribute": "ip-dst", "ui-priority": 1 }, "rogue-dns": { "description": "IP address of the rogue DNS", "misp-attribute": "ip-dst", "ui-priority": 0 }, "status": { "description": "How many authoritative DNS answers were received at the Passive DNS Server's collectors with exactly the given set of values as answers.", "disable_correlation": true, "misp-attribute": "text", "sane_default": [ "ROGUE DNS", "Unknown" ], "ui-priority": 0 }, "timestamp": { "description": "Last time that the rogue DNS value was seen.", "disable_correlation": true, "misp-attribute": "datetime", "ui-priority": 0 } }, "description": "Rogue DNS as defined by CERT.br", "meta-category": "network", "name": "rogue-dns", "required": [ "rogue-dns" ], "uuid": "b7e7859b-6872-4fd2-ac49-f66ccb904505", "version": 1 }