2019-11-19 10:56:30 +01:00
{
"namespace" : "mwdb" ,
"description" : "Malware Database (mwdb) Taxonomy - Tags used across the platform" ,
2019-11-21 08:09:20 +01:00
"version" : 2 ,
2019-11-19 10:56:30 +01:00
"predicates" : [
{
"value" : "location_type" ,
"expanded" : "Location Type" ,
"description" : "Type of malicious URL."
} ,
{
"value" : "family" ,
"expanded" : "Malware Family"
}
] ,
"values" : [
{
"predicate" : "location_type" ,
"entry" : [
{
"value" : "cnc" ,
"expanded" : "CNC" ,
"description" : "C&C server, usually administrated by criminals. Malware connects to it (usually with a custom protocol) to get new commands and updates."
} ,
{
"value" : "download_url" ,
"expanded" : "Download URL" ,
"description" : "Download url. Used to download more malware samples. Sometimes just a hacked legitimate website."
} ,
{
"value" : "panel" ,
"expanded" : "Panel" ,
"description" : "Malware panel. HTTP service used by criminals to manage the botnet."
} ,
{
"value" : "peer" ,
"expanded" : "Peer" ,
"description" : "Peer. IP/port of infected machine of a legitimate computer user."
} ,
{
"value" : "other" ,
"expanded" : "Other" ,
"description" : "Other kind of URL found in the malware."
}
]
} ,
{
"predicate" : "family" ,
"entry" : [
{
2019-11-21 08:09:20 +01:00
"value" : "agenttesla" ,
"expanded" : "agenttesla"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "andromeda" ,
"expanded" : "andromeda"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "anubis" ,
"expanded" : "anubis"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "avemaria" ,
"expanded" : "avemaria"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "azorult" ,
"expanded" : "azorult"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "brushaloader" ,
"expanded" : "brushaloader"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "bublik" ,
"expanded" : "bublik"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "bunitu" ,
"expanded" : "bunitu"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "cerber" ,
"expanded" : "cerber"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "chthonic" ,
"expanded" : "chthonic"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "citadel" ,
"expanded" : "citadel"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "corebot" ,
"expanded" : "corebot"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "cryptomix" ,
"expanded" : "cryptomix"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "cryptoshield" ,
"expanded" : "cryptoshield"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "cryptowall" ,
"expanded" : "cryptowall"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "danabot" ,
"expanded" : "danabot"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "danaloader" ,
"expanded" : "danaloader"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "dridex" ,
"expanded" : "dridex"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "dridex-worker" ,
"expanded" : "dridex-worker"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "dyre" ,
"expanded" : "dyre"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "emotet" ,
"expanded" : "emotet"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "emotet5_upnp" ,
"expanded" : "emotet5_upnp"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "emotet_doc" ,
"expanded" : "emotet_doc"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "emotet_spam" ,
"expanded" : "emotet_spam"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "emotet_upnp" ,
"expanded" : "emotet_upnp"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "evil-pony" ,
"expanded" : "evil-pony"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "flokibot" ,
"expanded" : "flokibot"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "formbook" ,
"expanded" : "formbook"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "gandcrab" ,
"expanded" : "gandcrab"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "get2" ,
"expanded" : "get2"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "globeimposter" ,
"expanded" : "globeimposter"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "gluedropper" ,
"expanded" : "gluedropper"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "gootkit" ,
"expanded" : "gootkit"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "h1n1" ,
"expanded" : "h1n1"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "hancitor" ,
"expanded" : "hancitor"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "hawkeye" ,
"expanded" : "hawkeye"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "icedid" ,
"expanded" : "icedid"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "iceid" ,
"expanded" : "iceid"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "iceix" ,
"expanded" : "iceix"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "isfb" ,
"expanded" : "isfb"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "jaff" ,
"expanded" : "jaff"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "kbot" ,
"expanded" : "kbot"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "kegotip" ,
"expanded" : "kegotip"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "kins" ,
"expanded" : "kins"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "kovter" ,
"expanded" : "kovter"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "kpot" ,
"expanded" : "kpot"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "kronos" ,
"expanded" : "kronos"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "locky" ,
"expanded" : "locky"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "lokibot" ,
"expanded" : "lokibot"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "madlocker" ,
"expanded" : "madlocker"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "madness_pro" ,
"expanded" : "madness_pro"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "maoloa" ,
"expanded" : "maoloa"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "mirai" ,
"expanded" : "mirai"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "mmbb" ,
"expanded" : "mmbb"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "nanocore" ,
"expanded" : "nanocore"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "necurs" ,
"expanded" : "necurs"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "netwire" ,
"expanded" : "netwire"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "neutrino" ,
"expanded" : "neutrino"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "njrat" ,
"expanded" : "njrat"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "nymaim" ,
"expanded" : "nymaim"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "odinaff" ,
"expanded" : "odinaff"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "onliner" ,
"expanded" : "onliner"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "ostap" ,
"expanded" : "ostap"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "panda" ,
"expanded" : "panda"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "phorpiex" ,
"expanded" : "phorpiex"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "pony" ,
"expanded" : "pony"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "pushdo" ,
"expanded" : "pushdo"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "qadars" ,
"expanded" : "qadars"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "qakbot" ,
"expanded" : "qakbot"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "quantloader" ,
"expanded" : "quantloader"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "quasarrat" ,
"expanded" : "quasarrat"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "ramnit" ,
"expanded" : "ramnit"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "remcos" ,
"expanded" : "remcos"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "retefe" ,
"expanded" : "retefe"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "ruckguv" ,
"expanded" : "ruckguv"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "sage" ,
"expanded" : "sage"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "sendsafe" ,
"expanded" : "sendsafe"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "shifu" ,
"expanded" : "shifu"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "slave" ,
"expanded" : "slave"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "smokeloader" ,
"expanded" : "smokeloader"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "systembc" ,
"expanded" : "systembc"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "teslacrypt" ,
"expanded" : "teslacrypt"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "test" ,
"expanded" : "test"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "testmod" ,
"expanded" : "testmod"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "tinba" ,
"expanded" : "tinba"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "tinba_dga" ,
"expanded" : "tinba_dga"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "tinynuke" ,
"expanded" : "tinynuke"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "tofsee" ,
"expanded" : "tofsee"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "torment" ,
"expanded" : "torment"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "torrentlocker" ,
"expanded" : "torrentlocker"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "trickbot" ,
"expanded" : "trickbot"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "troldesh" ,
"expanded" : "troldesh"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "unknown" ,
"expanded" : "unknown"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "vawtrak" ,
"expanded" : "vawtrak"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "vjworm" ,
"expanded" : "vjworm"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "vmzeus" ,
"expanded" : "vmzeus"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "vmzeus2" ,
"expanded" : "vmzeus2"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "wannacry" ,
"expanded" : "wannacry"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "xagent" ,
"expanded" : "xagent"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "zeus" ,
"expanded" : "zeus"
2019-11-19 10:56:30 +01:00
} ,
{
2019-11-21 08:09:20 +01:00
"value" : "zloader" ,
"expanded" : "zloader"
2019-11-19 10:56:30 +01:00
}
]
}
]
}