{"response": [{"Event":{"id":"420","orgc_id":"12","org_id":"1","date":"2019-05-16","threat_level_id":"3","info":"Targeted phishing - PDF documents / phishkit","published":false,"uuid":"5cdd3938-7134-4908-9552-173cc0a8016e","attribute_count":"115","analysis":"1","timestamp":"1645624567","distribution":"3","proposal_email_lock":false,"locked":false,"publish_timestamp":"1623682639","sharing_group_id":"0","disable_correlation":false,"extends_uuid":"","protected":null,"Org":{"id":"1","name":"Training","uuid":"5d6d3b30-9db0-44b9-8869-7f56a5e38e14","local":true},"Orgc":{"id":"12","name":"EUROLEA","uuid":"5cdc2cdd-bca4-4a76-8955-03cdc0a8016e","local":false},"Attribute":[{"id":"74806","type":"yara","category":"Artifacts dropped","to_ids":false,"uuid":"5cdd3a39-84f0-4179-b3ea-173cc0a8016e","event_id":"420","distribution":"5","timestamp":"1558002233","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"0","object_relation":null,"first_seen":null,"last_seen":null,"value":"rule PDF_LIFT {\r\nstrings:\r\n\t$a = \"Rect[ 195.05 428.59 411.79 489.67]\"\r\ncondition:\r\n\tall of them\r\n}","Galaxy":[],"ShadowAttribute":[]},{"id":"74807","type":"yara","category":"Artifacts dropped","to_ids":true,"uuid":"5cdd3a5b-3448-49d1-b35e-12a4c0a8016e","event_id":"420","distribution":"5","timestamp":"1558012404","comment":"Generic yara rule to find the common JAT author.","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"0","object_relation":null,"first_seen":null,"last_seen":null,"value":"rule PDF_JAT_AUTHOR {\r\nstrings:\r\n$a = \"<","Galaxy":[],"ShadowAttribute":[]},{"id":"74897","type":"text","category":"Other","to_ids":false,"uuid":"5cdd62fc-e698-486a-b877-4563950d210f","event_id":"420","distribution":"5","timestamp":"1558012668","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":true,"object_id":"2458","object_relation":"language","first_seen":null,"last_seen":null,"value":"PHP","Galaxy":[],"ShadowAttribute":[]},{"id":"74898","type":"filename","category":"Payload delivery","to_ids":true,"uuid":"5cdd62fc-8010-4377-97b3-46ae950d210f","event_id":"420","distribution":"5","timestamp":"1558012668","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":true,"object_id":"2458","object_relation":"filename","first_seen":null,"last_seen":null,"value":"sendmail.php","Galaxy":[],"ShadowAttribute":[]},{"id":"74899","type":"text","category":"Other","to_ids":false,"uuid":"5cdd62fc-0494-426e-96d5-4de9950d210f","event_id":"420","distribution":"5","timestamp":"1558012668","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":true,"object_id":"2458","object_relation":"state","first_seen":null,"last_seen":null,"value":"Malicious","Galaxy":[],"ShadowAttribute":[]}]},{"id":"2459","name":"virustotal-report","meta-category":"misc","description":"VirusTotal report","template_uuid":"d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4","template_version":"2","event_id":"420","uuid":"d9bdc42c-191f-49a2-8cbe-2604f5462df6","timestamp":"1558013351","distribution":"5","sharing_group_id":"0","comment":"","deleted":false,"first_seen":null,"last_seen":null,"ObjectReference":[],"Attribute":[{"id":"74900","type":"datetime","category":"Other","to_ids":false,"uuid":"f1c90675-0c32-40f1-af8f-f90a06993120","event_id":"420","distribution":"5","timestamp":"1558002051","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"2459","object_relation":"last-submission","first_seen":null,"last_seen":null,"value":"2019-05-16 08:54:33","Galaxy":[],"ShadowAttribute":[]},{"id":"74901","type":"link","category":"Payload delivery","to_ids":false,"uuid":"f8eb37d5-1ef7-4e7c-b97c-7fcab9d7e00e","event_id":"420","distribution":"5","timestamp":"1558002051","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"2459","object_relation":"permalink","first_seen":null,"last_seen":null,"value":"https://www.virustotal.com/file/f2676b94952018c220ee352b9857bc5ad62195b2d15cdfaf54fa5c5985d6934a/analysis/1557996873/","Galaxy":[],"ShadowAttribute":[]},{"id":"74902","type":"text","category":"Payload delivery","to_ids":false,"uuid":"fb7fe45e-a16c-44c4-9a4b-7b6b0018fd43","event_id":"420","distribution":"5","timestamp":"1558002051","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":true,"object_id":"2459","object_relation":"detection-ratio","first_seen":null,"last_seen":null,"value":"1/56","Galaxy":[],"ShadowAttribute":[]}]},{"id":"2460","name":"virustotal-report","meta-category":"misc","description":"VirusTotal report","template_uuid":"d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4","template_version":"2","event_id":"420","uuid":"dcd9ca51-3194-44ee-86a2-5f0cf9b923f8","timestamp":"1558013351","distribution":"5","sharing_group_id":"0","comment":"","deleted":false,"first_seen":null,"last_seen":null,"ObjectReference":[],"Attribute":[{"id":"74903","type":"datetime","category":"Other","to_ids":false,"uuid":"ac5c453a-e980-47a2-9a84-5d37cf392471","event_id":"420","distribution":"5","timestamp":"1558002047","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"2460","object_relation":"last-submission","first_seen":null,"last_seen":null,"value":"2019-05-13 02:37:30","Galaxy":[],"ShadowAttribute":[]},{"id":"74904","type":"link","category":"Payload delivery","to_ids":false,"uuid":"2b1914f7-d429-496f-b76b-dd9ea4ae34f2","event_id":"420","distribution":"5","timestamp":"1558002047","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"2460","object_relation":"permalink","first_seen":null,"last_seen":null,"value":"https://www.virustotal.com/file/56a73192c75130550294b327b36c051841d3780bd3732b410e0c190db6f9d936/analysis/1557715050/","Galaxy":[],"ShadowAttribute":[]},{"id":"74905","type":"text","category":"Payload delivery","to_ids":false,"uuid":"c092edd1-d209-4fc1-8b59-cc68ea535499","event_id":"420","distribution":"5","timestamp":"1558002047","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":true,"object_id":"2460","object_relation":"detection-ratio","first_seen":null,"last_seen":null,"value":"0/58","Galaxy":[],"ShadowAttribute":[]}]},{"id":"2461","name":"virustotal-report","meta-category":"misc","description":"VirusTotal report","template_uuid":"d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4","template_version":"2","event_id":"420","uuid":"76f9b382-c58e-46f8-b174-42275f764d3e","timestamp":"1558013351","distribution":"5","sharing_group_id":"0","comment":"","deleted":false,"first_seen":null,"last_seen":null,"ObjectReference":[],"Attribute":[{"id":"74906","type":"datetime","category":"Other","to_ids":false,"uuid":"15b0df6f-7808-4a07-a743-33883c247a54","event_id":"420","distribution":"5","timestamp":"1558002045","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"2461","object_relation":"last-submission","first_seen":null,"last_seen":null,"value":"2019-05-13 02:37:43","Galaxy":[],"ShadowAttribute":[]},{"id":"74907","type":"link","category":"Payload delivery","to_ids":false,"uuid":"15db416c-93ca-4af3-bc7e-aa8af7ad332e","event_id":"420","distribution":"5","timestamp":"1558002045","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"2461","object_relation":"permalink","first_seen":null,"last_seen":null,"value":"https://www.virustotal.com/file/28f73ae365bde8c03d0f93ef73f71c086a026ac58f72b82bb2384c3a5ab42d02/analysis/1557715063/","Galaxy":[],"ShadowAttribute":[]},{"id":"74908","type":"text","category":"Payload delivery","to_ids":false,"uuid":"0c2fc5a0-15f4-432a-90c6-c3a49b54266e","event_id":"420","distribution":"5","timestamp":"1558002045","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":true,"object_id":"2461","object_relation":"detection-ratio","first_seen":null,"last_seen":null,"value":"2/59","Galaxy":[],"ShadowAttribute":[]}]},{"id":"2462","name":"virustotal-report","meta-category":"misc","description":"VirusTotal report","template_uuid":"d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4","template_version":"2","event_id":"420","uuid":"c22ccebe-e72f-4b92-9c63-a196b4959c43","timestamp":"1558013352","distribution":"5","sharing_group_id":"0","comment":"","deleted":false,"first_seen":null,"last_seen":null,"ObjectReference":[],"Attribute":[{"id":"74909","type":"datetime","category":"Other","to_ids":false,"uuid":"829ba8b8-a820-487f-9199-96b13a032e7b","event_id":"420","distribution":"5","timestamp":"1558002049","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"2462","object_relation":"last-submission","first_seen":null,"last_seen":null,"value":"2019-05-15 17:45:13","Galaxy":[],"ShadowAttribute":[]},{"id":"74910","type":"link","category":"Payload delivery","to_ids":false,"uuid":"77e038db-79c1-487f-8193-f857970cfd08","event_id":"420","distribution":"5","timestamp":"1558002049","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"2462","object_relation":"permalink","first_seen":null,"last_seen":null,"value":"https://www.virustotal.com/file/0fb825db2262d98e29846fa67171e3450666af9c0a6c31eaf8d7c84539be9132/analysis/1557942313/","Galaxy":[],"ShadowAttribute":[]},{"id":"74911","type":"text","category":"Payload delivery","to_ids":false,"uuid":"17e94734-ed26-449a-b1fe-768b881c6f83","event_id":"420","distribution":"5","timestamp":"1558002049","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":true,"object_id":"2462","object_relation":"detection-ratio","first_seen":null,"last_seen":null,"value":"1/54","Galaxy":[],"ShadowAttribute":[]}]},{"id":"2463","name":"virustotal-report","meta-category":"misc","description":"VirusTotal report","template_uuid":"d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4","template_version":"2","event_id":"420","uuid":"c3b36005-d35f-4540-bf78-cd09e2ac5e3d","timestamp":"1558013352","distribution":"5","sharing_group_id":"0","comment":"","deleted":false,"first_seen":null,"last_seen":null,"ObjectReference":[],"Attribute":[{"id":"74912","type":"datetime","category":"Other","to_ids":false,"uuid":"823fdaca-bb79-49fd-b865-e3e9d8dd86e3","event_id":"420","distribution":"5","timestamp":"1558011890","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"2463","object_relation":"last-submission","first_seen":null,"last_seen":null,"value":"2019-05-16 09:42:04","Galaxy":[],"ShadowAttribute":[]},{"id":"74913","type":"link","category":"Payload delivery","to_ids":false,"uuid":"3f1e2085-c793-4bb9-8022-5d037641c73e","event_id":"420","distribution":"5","timestamp":"1558011890","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"2463","object_relation":"permalink","first_seen":null,"last_seen":null,"value":"https://www.virustotal.com/file/9c4f9755fc183f6ad4ad4d600a0a3ed9230900152245f924b9106202ce543c58/analysis/1557999724/","Galaxy":[],"ShadowAttribute":[]},{"id":"74914","type":"text","category":"Payload delivery","to_ids":false,"uuid":"2c1f9f4d-f9bb-442e-84f8-0f06c1b28d5f","event_id":"420","distribution":"5","timestamp":"1558011890","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":true,"object_id":"2463","object_relation":"detection-ratio","first_seen":null,"last_seen":null,"value":"10/61","Galaxy":[],"ShadowAttribute":[]}]},{"id":"2464","name":"virustotal-report","meta-category":"misc","description":"VirusTotal report","template_uuid":"d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4","template_version":"2","event_id":"420","uuid":"f5647ba0-86e7-40fa-92a2-7d0fe024a7c2","timestamp":"1558013352","distribution":"5","sharing_group_id":"0","comment":"","deleted":false,"first_seen":null,"last_seen":null,"ObjectReference":[],"Attribute":[{"id":"74915","type":"datetime","category":"Other","to_ids":false,"uuid":"e2e51a40-0e8a-41df-a238-3176befa0d6d","event_id":"420","distribution":"5","timestamp":"1558002050","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"2464","object_relation":"last-submission","first_seen":null,"last_seen":null,"value":"2019-05-15 20:41:35","Galaxy":[],"ShadowAttribute":[]},{"id":"74916","type":"link","category":"Payload delivery","to_ids":false,"uuid":"2e637413-a76f-4b89-a5f1-1fb99c942c20","event_id":"420","distribution":"5","timestamp":"1558002050","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"2464","object_relation":"permalink","first_seen":null,"last_seen":null,"value":"https://www.virustotal.com/file/c052025b442995f04a68b1b6b2007c36dbf47448c08dc249219a7f3eebd369c2/analysis/1557952895/","Galaxy":[],"ShadowAttribute":[]},{"id":"74917","type":"text","category":"Payload delivery","to_ids":false,"uuid":"a84ca298-e8e4-4048-becf-05c209cfaa19","event_id":"420","distribution":"5","timestamp":"1558002050","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":true,"object_id":"2464","object_relation":"detection-ratio","first_seen":null,"last_seen":null,"value":"1/60","Galaxy":[],"ShadowAttribute":[]}]},{"id":"2465","name":"virustotal-report","meta-category":"misc","description":"VirusTotal report","template_uuid":"d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4","template_version":"2","event_id":"420","uuid":"9156df9c-4067-422e-bd38-8c3908e8ea5f","timestamp":"1558013352","distribution":"5","sharing_group_id":"0","comment":"","deleted":false,"first_seen":null,"last_seen":null,"ObjectReference":[],"Attribute":[{"id":"74918","type":"datetime","category":"Other","to_ids":false,"uuid":"f1406b9a-3d0d-4419-96dc-6400f3a9bbb1","event_id":"420","distribution":"5","timestamp":"1558002048","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"2465","object_relation":"last-submission","first_seen":null,"last_seen":null,"value":"2019-05-13 02:37:29","Galaxy":[],"ShadowAttribute":[]},{"id":"74919","type":"link","category":"Payload delivery","to_ids":false,"uuid":"69ee832e-72d0-4b4b-a11c-f57e0452a076","event_id":"420","distribution":"5","timestamp":"1558002048","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":false,"object_id":"2465","object_relation":"permalink","first_seen":null,"last_seen":null,"value":"https://www.virustotal.com/file/ddcf49145d8c78198138a488b7f99bb4f760777be41b293138e4d5b531cebc73/analysis/1557715049/","Galaxy":[],"ShadowAttribute":[]},{"id":"74920","type":"text","category":"Payload delivery","to_ids":false,"uuid":"7d4b7e4e-98b2-4840-92ea-7f22911f5603","event_id":"420","distribution":"5","timestamp":"1558002048","comment":"","sharing_group_id":"0","deleted":false,"disable_correlation":true,"object_id":"2465","object_relation":"detection-ratio","first_seen":null,"last_seen":null,"value":"0/58","Galaxy":[],"ShadowAttribute":[]}]}],"EventReport":[],"CryptographicKey":[],"Tag":[{"id":"865","name":"misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1193\"","colour":"#0088cc","exportable":true,"user_id":"0","hide_tag":false,"numerical_value":null,"is_galaxy":true,"is_custom_galaxy":false,"local_only":false,"local":0},{"id":"1038","name":"misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1192\"","colour":"#0088cc","exportable":true,"user_id":"0","hide_tag":false,"numerical_value":null,"is_galaxy":true,"is_custom_galaxy":false,"local_only":false,"local":0},{"id":"264","name":"enisa:nefarious-activity-abuse=\"spear-phishing-attacks\"","colour":"#3bb800","exportable":true,"user_id":"0","hide_tag":false,"numerical_value":null,"is_galaxy":false,"is_custom_galaxy":false,"local_only":false,"local":0},{"id":"21","name":"type:OSINT","colour":"#004646","exportable":true,"user_id":"0","hide_tag":false,"numerical_value":null,"is_galaxy":false,"is_custom_galaxy":false,"local_only":false,"local":0},{"id":"132","name":"osint:lifetime=\"perpetual\"","colour":"#0071c3","exportable":true,"user_id":"0","hide_tag":false,"numerical_value":null,"is_galaxy":false,"is_custom_galaxy":false,"local_only":false,"local":0},{"id":"467","name":"osint:certainty=\"50\"","colour":"#0087e8","exportable":true,"user_id":"0","hide_tag":false,"numerical_value":"50","is_galaxy":false,"is_custom_galaxy":false,"local_only":false,"local":0},{"id":"9","name":"tlp:green","colour":"#339900","exportable":true,"user_id":"0","hide_tag":false,"numerical_value":null,"is_galaxy":false,"is_custom_galaxy":false,"local_only":false,"local":0},{"id":"2261","name":"misp-galaxy:mitre-ics-techniques=\"Spearphishing Attachment\"","colour":"#0088cc","exportable":true,"user_id":"0","hide_tag":false,"numerical_value":null,"is_galaxy":true,"is_custom_galaxy":false,"local_only":false,"local":1}]}}]}