diff --git a/objects.html b/objects.html index 16a9359..9582cf2 100755 --- a/objects.html +++ b/objects.html @@ -475,6 +475,7 @@ body.book #toc,body.book #preamble,body.book h1.sect0,body.book .sect1>h2{page-b
original-date
-datetime
origin
text
When the information available in the leak was created. It’s usually before the first-seen.
+The link where the leak is (or was) accessible at first-seen.
+
text
duplicate
text
A description of the leak which could include the potential victim(s) or description of the leak.
--
raw-data
attachment
Raw data as received by the AIL sensor compressed and encoded in Base64.
--
type
text
Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
+Duplicate of the existing leaks.
@@ -623,23 +604,33 @@ ail-leak is a MISP object available in JSON format at
origin
type
text
The link where the leak is (or was) accessible at first-seen.
+Type of information leak as discovered and classified by an AIL module. ['Credential', 'CreditCards', 'Mail', 'Onion', 'Phone', 'Keys']
duplicate_number
counter
text
text
Number of known duplicates.
+A description of the leak which could include the potential victim(s) or description of the leak.
+
+
original-date
datetime
When the information available in the leak was created. It’s usually before the first-seen.
+
duplicate
-text
duplicate_number
counter
Duplicate of the existing leaks.
+Number of known duplicates.
raw-data
attachment
Raw data as received by the AIL sensor compressed and encoded in Base64.
++
permission
-text
comment
comment
Android permission ['ACCESS_CHECKIN_PROPERTIES', 'ACCESS_COARSE_LOCATION', 'ACCESS_FINE_LOCATION', 'ACCESS_LOCATION_EXTRA_COMMANDS', 'ACCESS_NETWORK_STATE', 'ACCESS_NOTIFICATION_POLICY', 'ACCESS_WIFI_STATE', 'ACCOUNT_MANAGER', 'ADD_VOICEMAIL', 'ANSWER_PHONE_CALLS', 'BATTERY_STATS', 'BIND_ACCESSIBILITY_SERVICE', 'BIND_APPWIDGET', 'BIND_AUTOFILL_SERVICE', 'BIND_CARRIER_MESSAGING_SERVICE', 'BIND_CHOOSER_TARGET_SERVICE', 'BIND_CONDITION_PROVIDER_SERVICE', 'BIND_DEVICE_ADMIN', 'BIND_DREAM_SERVICE', 'BIND_INCALL_SERVICE', 'BIND_INPUT_METHOD', 'BIND_MIDI_DEVICE_SERVICE', 'BIND_NFC_SERVICE', 'BIND_NOTIFICATION_LISTENER_SERVICE', 'BIND_PRINT_SERVICE', 'BIND_QUICK_SETTINGS_TILE', 'BIND_REMOTEVIEWS', 'BIND_SCREENING_SERVICE', 'BIND_TELECOM_CONNECTION_SERVICE', 'BIND_TEXT_SERVICE', 'BIND_TV_INPUT', 'BIND_VISUAL_VOICEMAIL_SERVICE', 'BIND_VOICE_INTERACTION', 'BIND_VPN_SERVICE', 'BIND_VR_LISTENER_SERVICE', 'BIND_WALLPAPER', 'BLUETOOTH', 'BLUETOOTH_ADMIN', 'BLUETOOTH_PRIVILEGED', 'BODY_SENSORS', 'BROADCAST_PACKAGE_REMOVED', 'BROADCAST_SMS', 'BROADCAST_STICKY', 'BROADCAST_WAP_PUSH', 'CALL_PHONE', 'CALL_PRIVILEGED', 'CAMERA', 'CAPTURE_AUDIO_OUTPUT', 'CAPTURE_SECURE_VIDEO_OUTPUT', 'CAPTURE_VIDEO_OUTPUT', 'CHANGE_COMPONENT_ENABLED_STATE', 'CHANGE_CONFIGURATION', 'CHANGE_NETWORK_STATE', 'CHANGE_WIFI_MULTICAST_STATE', 'CHANGE_WIFI_STATE', 'CLEAR_APP_CACHE', 'CONTROL_LOCATION_UPDATES', 'DELETE_CACHE_FILES', 'DELETE_PACKAGES', 'DIAGNOSTIC', 'DISABLE_KEYGUARD', 'DUMP', 'EXPAND_STATUS_BAR', 'FACTORY_TEST', 'GET_ACCOUNTS', 'GET_ACCOUNTS_PRIVILEGED', 'GET_PACKAGE_SIZE', 'GET_TASKS', 'GLOBAL_SEARCH', 'INSTALL_LOCATION_PROVIDER', 'INSTALL_PACKAGES', 'INSTALL_SHORTCUT', 'INSTANT_APP_FOREGROUND_SERVICE', 'INTERNET', 'KILL_BACKGROUND_PROCESSES', 'LOCATION_HARDWARE', 'MANAGE_DOCUMENTS', 'MANAGE_OWN_CALLS', 'MASTER_CLEAR', 'MEDIA_CONTENT_CONTROL', 'MODIFY_AUDIO_SETTINGS', 'MODIFY_PHONE_STATE', 'MOUNT_FORMAT_FILESYSTEMS', 'MOUNT_UNMOUNT_FILESYSTEMS', 'NFC', 'PACKAGE_USAGE_STATS', 'PERSISTENT_ACTIVITY', 'PROCESS_OUTGOING_CALLS', 'READ_CALENDAR', 'READ_CALL_LOG', 'READ_CONTACTS', 'READ_EXTERNAL_STORAGE', 'READ_FRAME_BUFFER', 'READ_INPUT_STATE', 'READ_LOGS', 'READ_PHONE_NUMBERS', 'READ_PHONE_STATE', 'READ_SMS', 'READ_SYNC_SETTINGS', 'READ_SYNC_STATS', 'READ_VOICEMAIL', 'REBOOT', 'RECEIVE_BOOT_COMPLETED', 'RECEIVE_MMS', 'RECEIVE_SMS', 'RECEIVE_WAP_PUSH', 'RECORD_AUDIO', 'REORDER_TASKS', 'REQUEST_COMPANION_RUN_IN_BACKGROUND', 'REQUEST_COMPANION_USE_DATA_IN_BACKGROUND', 'REQUEST_DELETE_PACKAGES', 'REQUEST_IGNORE_BATTERY_OPTIMIZATIONS', 'REQUEST_INSTALL_PACKAGES', 'RESTART_PACKAGES', 'SEND_RESPOND_VIA_MESSAGE', 'SEND_SMS', 'SET_ALARM', 'SET_ALWAYS_FINISH', 'SET_ANIMATION_SCALE', 'SET_DEBUG_APP', 'SET_PREFERRED_APPLICATIONS', 'SET_PROCESS_LIMIT', 'SET_TIME', 'SET_TIME_ZONE', 'SET_WALLPAPER', 'SET_WALLPAPER_HINTS', 'SIGNAL_PERSISTENT_PROCESSES', 'STATUS_BAR', 'SYSTEM_ALERT_WINDOW', 'TRANSMIT_IR', 'UNINSTALL_SHORTCUT', 'UPDATE_DEVICE_STATS', 'USE_FINGERPRINT', 'USE_SIP', 'VIBRATE', 'WAKE_LOCK', 'WRITE_APN_SETTINGS', 'WRITE_CALENDAR', 'WRITE_CALL_LOG', 'WRITE_CONTACTS', 'WRITE_EXTERNAL_STORAGE', 'WRITE_GSERVICES', 'WRITE_SECURE_SETTINGS', 'WRITE_SETTINGS', 'WRITE_SYNC_SETTINGS', 'WRITE_VOICEMAIL']
+Comment about the set of android permission(s)
comment
comment
permission
text
Comment about the set of android permission(s)
+Android permission ['ACCESS_CHECKIN_PROPERTIES', 'ACCESS_COARSE_LOCATION', 'ACCESS_FINE_LOCATION', 'ACCESS_LOCATION_EXTRA_COMMANDS', 'ACCESS_NETWORK_STATE', 'ACCESS_NOTIFICATION_POLICY', 'ACCESS_WIFI_STATE', 'ACCOUNT_MANAGER', 'ADD_VOICEMAIL', 'ANSWER_PHONE_CALLS', 'BATTERY_STATS', 'BIND_ACCESSIBILITY_SERVICE', 'BIND_APPWIDGET', 'BIND_AUTOFILL_SERVICE', 'BIND_CARRIER_MESSAGING_SERVICE', 'BIND_CHOOSER_TARGET_SERVICE', 'BIND_CONDITION_PROVIDER_SERVICE', 'BIND_DEVICE_ADMIN', 'BIND_DREAM_SERVICE', 'BIND_INCALL_SERVICE', 'BIND_INPUT_METHOD', 'BIND_MIDI_DEVICE_SERVICE', 'BIND_NFC_SERVICE', 'BIND_NOTIFICATION_LISTENER_SERVICE', 'BIND_PRINT_SERVICE', 'BIND_QUICK_SETTINGS_TILE', 'BIND_REMOTEVIEWS', 'BIND_SCREENING_SERVICE', 'BIND_TELECOM_CONNECTION_SERVICE', 'BIND_TEXT_SERVICE', 'BIND_TV_INPUT', 'BIND_VISUAL_VOICEMAIL_SERVICE', 'BIND_VOICE_INTERACTION', 'BIND_VPN_SERVICE', 'BIND_VR_LISTENER_SERVICE', 'BIND_WALLPAPER', 'BLUETOOTH', 'BLUETOOTH_ADMIN', 'BLUETOOTH_PRIVILEGED', 'BODY_SENSORS', 'BROADCAST_PACKAGE_REMOVED', 'BROADCAST_SMS', 'BROADCAST_STICKY', 'BROADCAST_WAP_PUSH', 'CALL_PHONE', 'CALL_PRIVILEGED', 'CAMERA', 'CAPTURE_AUDIO_OUTPUT', 'CAPTURE_SECURE_VIDEO_OUTPUT', 'CAPTURE_VIDEO_OUTPUT', 'CHANGE_COMPONENT_ENABLED_STATE', 'CHANGE_CONFIGURATION', 'CHANGE_NETWORK_STATE', 'CHANGE_WIFI_MULTICAST_STATE', 'CHANGE_WIFI_STATE', 'CLEAR_APP_CACHE', 'CONTROL_LOCATION_UPDATES', 'DELETE_CACHE_FILES', 'DELETE_PACKAGES', 'DIAGNOSTIC', 'DISABLE_KEYGUARD', 'DUMP', 'EXPAND_STATUS_BAR', 'FACTORY_TEST', 'GET_ACCOUNTS', 'GET_ACCOUNTS_PRIVILEGED', 'GET_PACKAGE_SIZE', 'GET_TASKS', 'GLOBAL_SEARCH', 'INSTALL_LOCATION_PROVIDER', 'INSTALL_PACKAGES', 'INSTALL_SHORTCUT', 'INSTANT_APP_FOREGROUND_SERVICE', 'INTERNET', 'KILL_BACKGROUND_PROCESSES', 'LOCATION_HARDWARE', 'MANAGE_DOCUMENTS', 'MANAGE_OWN_CALLS', 'MASTER_CLEAR', 'MEDIA_CONTENT_CONTROL', 'MODIFY_AUDIO_SETTINGS', 'MODIFY_PHONE_STATE', 'MOUNT_FORMAT_FILESYSTEMS', 'MOUNT_UNMOUNT_FILESYSTEMS', 'NFC', 'PACKAGE_USAGE_STATS', 'PERSISTENT_ACTIVITY', 'PROCESS_OUTGOING_CALLS', 'READ_CALENDAR', 'READ_CALL_LOG', 'READ_CONTACTS', 'READ_EXTERNAL_STORAGE', 'READ_FRAME_BUFFER', 'READ_INPUT_STATE', 'READ_LOGS', 'READ_PHONE_NUMBERS', 'READ_PHONE_STATE', 'READ_SMS', 'READ_SYNC_SETTINGS', 'READ_SYNC_STATS', 'READ_VOICEMAIL', 'REBOOT', 'RECEIVE_BOOT_COMPLETED', 'RECEIVE_MMS', 'RECEIVE_SMS', 'RECEIVE_WAP_PUSH', 'RECORD_AUDIO', 'REORDER_TASKS', 'REQUEST_COMPANION_RUN_IN_BACKGROUND', 'REQUEST_COMPANION_USE_DATA_IN_BACKGROUND', 'REQUEST_DELETE_PACKAGES', 'REQUEST_IGNORE_BATTERY_OPTIMIZATIONS', 'REQUEST_INSTALL_PACKAGES', 'RESTART_PACKAGES', 'SEND_RESPOND_VIA_MESSAGE', 'SEND_SMS', 'SET_ALARM', 'SET_ALWAYS_FINISH', 'SET_ANIMATION_SCALE', 'SET_DEBUG_APP', 'SET_PREFERRED_APPLICATIONS', 'SET_PROCESS_LIMIT', 'SET_TIME', 'SET_TIME_ZONE', 'SET_WALLPAPER', 'SET_WALLPAPER_HINTS', 'SIGNAL_PERSISTENT_PROCESSES', 'STATUS_BAR', 'SYSTEM_ALERT_WINDOW', 'TRANSMIT_IR', 'UNINSTALL_SHORTCUT', 'UPDATE_DEVICE_STATS', 'USE_FINGERPRINT', 'USE_SIP', 'VIBRATE', 'WAKE_LOCK', 'WRITE_APN_SETTINGS', 'WRITE_CALENDAR', 'WRITE_CALL_LOG', 'WRITE_CONTACTS', 'WRITE_EXTERNAL_STORAGE', 'WRITE_GSERVICES', 'WRITE_SECURE_SETTINGS', 'WRITE_SETTINGS', 'WRITE_SYNC_SETTINGS', 'WRITE_VOICEMAIL']
@@ -759,36 +760,6 @@ annotation is a MISP object available in JSON format at
text
text
Raw text of the annotation
--
creation-date
datetime
Initial creation of the annotation
--
type
text
Type of the annotation ['Annotation', 'Executive Summary', 'Introduction', 'Conclusion', 'Disclaimer', 'Keywords', 'Acknowledgement', 'Other', 'Copyright', 'Authors', 'Logo']
--
format
text
type
text
Type of the annotation ['Annotation', 'Executive Summary', 'Introduction', 'Conclusion', 'Disclaimer', 'Keywords', 'Acknowledgement', 'Other', 'Copyright', 'Authors', 'Logo']
++
text
text
Raw text of the annotation
++
creation-date
datetime
Initial creation of the annotation
++
last-seen
+datetime
Last time the ASN was seen
++
description
text
Description of the autonomous system
++
first-seen
datetime
subnet-announced
ip-src
import
text
Subnet announced
+The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
import
export
text
The inbound IPv4 routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
+The outbound routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
@@ -897,6 +918,16 @@ asn is a MISP object available in JSON format at
subnet-announced
ip-src
Subnet announced
++
country
text
last-seen
datetime
Last time the ASN was seen
--
mp-import
text
description
text
Description of the autonomous system
--
asn
AS
export
text
The outbound routing policy of the AS in RFC 2622 – Routing Policy Specification Language (RPSL) format
--
first-seen
-datetime
First time this payment destination address has been seen
--
symbol
text
text
text
Free text value
--
last-seen
datetime
first-seen
datetime
First time this payment destination address has been seen
++
address
btc
text
text
Free text value
++
text
+text
A description of the cookie.
++
cookie-name
text
Name of the cookie (if splitted)
++
type
text
Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
++
cookie
cookie
type
text
Type of cookie and how it’s used in this specific object. ['Session management', 'Personalization', 'Tracking', 'Exfiltration', 'Malicious Payload', 'Beaconing']
--
cookie-name
text
Name of the cookie (if splitted)
--
text
text
A description of the cookie.
--
username
+text
Username related to the password(s)
++
origin
text
Origin of the credential(s) ['bruteforce-scanning', 'malware-analysis', 'memory-analysis', 'network-analysis', 'leak', 'unknown']
++
format
text
Format of the password(s) ['clear-text', 'hashed', 'encrypted', 'unknown']
++
type
text
Type of password(s) ['password', 'api-key', 'encryption-key', 'unknown']
++
text
text
format
text
Format of the password(s) ['clear-text', 'hashed', 'encrypted', 'unknown']
--
origin
text
Origin of the credential(s) ['bruteforce-scanning', 'malware-analysis', 'memory-analysis', 'network-analysis', 'leak', 'unknown']
--
notification
text
username
text
Username related to the password(s)
--
type
text
Type of password(s) ['password', 'api-key', 'encryption-key', 'unknown']
--
cc-number
-cc-number
expiration
datetime
credit-card number as encoded on the card.
+Maximum date of validity
@@ -1377,20 +1378,30 @@ credit-card is a MISP object available in JSON format at
name
card-security-code
text
Name of the card owner.
+Card security code (CSC, CVD, CVV, CVC and SPC) as embossed or printed on the card.
issued
datetime
cc-number
cc-number
Initial date of validity or issued date.
+credit-card number as encoded on the card.
++
name
text
Name of the card owner.
@@ -1407,20 +1418,10 @@ credit-card is a MISP object available in JSON format at
card-security-code
text
Card security code (CSC, CVD, CVV, CVC and SPC) as embossed or printed on the card.
--
expiration
issued
datetime
Maximum date of validity
+Initial date of validity or issued date.
@@ -1465,10 +1466,40 @@ ddos is a MISP object available in JSON format at
ip-src
ip-src
ip-dst
ip-dst
IP address originating the attack
+Destination IP (victim)
++
protocol
text
Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
++
domain-dst
domain
Destination domain (victim)
++
src-port
port
Port originating the attack
@@ -1485,36 +1516,6 @@ ddos is a MISP object available in JSON format at
total-pps
counter
Packets per second
--
dst-port
port
Destination port of the attack
--
ip-dst
ip-dst
Destination IP (victim)
--
total-bps
counter
total-pps
counter
Packets per second
++
last-seen
datetime
protocol
text
Protocol used for the attack ['TCP', 'UDP', 'ICMP', 'IP']
--
src-port
dst-port
port
Port originating the attack
+Destination port of the attack
domain-dst
domain
ip-src
ip-src
Destination domain (victim)
+IP address originating the attack
@@ -1613,6 +1614,26 @@ diameter-attack is a MISP object available in JSON format at
CmdCode
text
A decimal representation of the diameter Command Code.
++
SessionId
text
Session-ID.
++
ApplicationId
text
Origin-Realm
Username
text
Origin-Realm.
--
first-seen
datetime
When the attack has been seen for the first time.
--
Origin-Host
text
Origin-Host.
+Username (in this case, usually the IMSI).
@@ -1663,16 +1664,36 @@ diameter-attack is a MISP object available in JSON format at
SessionId
Origin-Host
text
Session-ID.
+Origin-Host.
first-seen
datetime
When the attack has been seen for the first time.
++
category
text
Category. ['Cat0', 'Cat1', 'Cat2', 'Cat3', 'CatSMS']
++
text
text
CmdCode
text
A decimal representation of the diameter Command Code.
--
Username
text
Username (in this case, usually the IMSI).
--
IdrFlags
text
category
Origin-Realm
text
Category. ['Cat0', 'Cat1', 'Cat2', 'Cat3', 'CatSMS']
+Origin-Realm.
+
text
-text
domain
domain
A description of the tuple
--
ip
ip-dst
IP Address
+Domain name
@@ -1801,20 +1792,30 @@ domain-ip is a MISP object available in JSON format at
domain
domain
first-seen
datetime
Domain name
+First time the tuple has been seen
++
ip
ip-dst
IP Address
first-seen
datetime
text
text
First time the tuple has been seen
+A description of the tuple
@@ -1859,13 +1860,13 @@ elf is a MISP object available in JSON format at
os_abi
type
text
Header operating system application binary interface (ABI) ['AIX', 'ARM', 'AROS', 'C6000_ELFABI', 'C6000_LINUX', 'CLOUDABI', 'FENIXOS', 'FREEBSD', 'GNU', 'HPUX', 'HURD', 'IRIX', 'MODESTO', 'NETBSD', 'NSK', 'OPENBSD', 'OPENVMS', 'SOLARIS', 'STANDALONE', 'SYSTEMV', 'TRU64']
+Type of ELF ['CORE', 'DYNAMIC', 'EXECUTABLE', 'HIPROC', 'LOPROC', 'NONE', 'RELOCATABLE']
+
entrypoint-address
+text
Address of the entry point
++
number-sections
counter
type
os_abi
text
Type of ELF ['CORE', 'DYNAMIC', 'EXECUTABLE', 'HIPROC', 'LOPROC', 'NONE', 'RELOCATABLE']
+Header operating system application binary interface (ABI) ['AIX', 'ARM', 'AROS', 'C6000_ELFABI', 'C6000_LINUX', 'CLOUDABI', 'FENIXOS', 'FREEBSD', 'GNU', 'HPUX', 'HURD', 'IRIX', 'MODESTO', 'NETBSD', 'NSK', 'OPENBSD', 'OPENVMS', 'SOLARIS', 'STANDALONE', 'SYSTEMV', 'TRU64']
+
entrypoint-address
text
Address of the entry point
--
ssdeep
-ssdeep
sha256
sha256
Fuzzy hash using context triggered piecewise hashes (CTPH)
+Secure Hash Algorithm 2 (256 bits)
++
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
type
text
Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
++
flag
text
Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
++
name
text
Name of the section
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
@@ -1987,26 +2048,6 @@ elf-section is a MISP object available in JSON format at
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
size-in-bytes
size-in-bytes
sha224
sha224
ssdeep
ssdeep
Secure Hash Algorithm 2 (224 bits)
+Fuzzy hash using context triggered piecewise hashes (CTPH)
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
type
text
Type of the section ['NULL', 'PROGBITS', 'SYMTAB', 'STRTAB', 'RELA', 'HASH', 'DYNAMIC', 'NOTE', 'NOBITS', 'REL', 'SHLIB', 'DYNSYM', 'INIT_ARRAY', 'FINI_ARRAY', 'PREINIT_ARRAY', 'GROUP', 'SYMTAB_SHNDX', 'LOOS', 'GNU_ATTRIBUTES', 'GNU_HASH', 'GNU_VERDEF', 'GNU_VERNEED', 'GNU_VERSYM', 'HIOS', 'LOPROC', 'ARM_EXIDX', 'ARM_PREEMPTMAP', 'HEX_ORDERED', 'X86_64_UNWIND', 'MIPS_REGINFO', 'MIPS_OPTIONS', 'MIPS_ABIFLAGS', 'HIPROC', 'LOUSER', 'HIUSER']
--
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
md5
md5
[Insecure] MD5 hash (128 bits)
--
name
text
Name of the section
--
text
text
flag
text
md5
md5
Flag of the section ['ALLOC', 'EXCLUDE', 'EXECINSTR', 'GROUP', 'HEX_GPREL', 'INFO_LINK', 'LINK_ORDER', 'MASKOS', 'MASKPROC', 'MERGE', 'MIPS_ADDR', 'MIPS_LOCAL', 'MIPS_MERGE', 'MIPS_NAMES', 'MIPS_NODUPES', 'MIPS_NOSTRIP', 'NONE', 'OS_NONCONFORMING', 'STRINGS', 'TLS', 'WRITE', 'XCORE_SHF_CP_SECTION']
+[Insecure] MD5 hash (128 bits)
+
+
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
++
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
+
subject
-email-subject
from-display-name
email-src-display-name
Subject
--
thread-index
email-thread-index
Identifies a particular conversation thread
+Display name of the sender
@@ -2175,10 +2166,10 @@ email is a MISP object available in JSON format at
header
email-header
to
email-dst
Full headers
+Destination email address
@@ -2195,36 +2186,6 @@ email is a MISP object available in JSON format at
from-display-name
email-src-display-name
Display name of the sender
--
send-date
datetime
Date the email has been sent
--
x-mailer
email-x-mailer
X-Mailer generally tells the program that was used to draft and send the original email
--
message-id
email-message-id
reply-to
email-reply-to
Email address the reply will be sent to
--
screenshot
attachment
Screenshot of email
--
to-display-name
email-dst-display-name
Display name of the receiver
--
cc
email-dst
Carbon copy
--
from
email-src
Sender email address
--
mime-boundary
email-mime-boundary
to
cc
email-dst
Destination email address
+Carbon copy
++
reply-to
email-reply-to
Email address the reply will be sent to
++
from
email-src
Sender email address
++
to-display-name
email-dst-display-name
Display name of the receiver
++
thread-index
email-thread-index
Identifies a particular conversation thread
++
send-date
datetime
Date the email has been sent
++
header
email-header
Full headers
++
x-mailer
email-x-mailer
X-Mailer generally tells the program that was used to draft and send the original email
++
screenshot
attachment
Screenshot of email
++
subject
email-subject
Subject
@@ -2343,16 +2344,86 @@ file is a MISP object available in JSON format at
ssdeep
ssdeep
sha256
sha256
Fuzzy hash using context triggered piecewise hashes (CTPH)
+Secure Hash Algorithm 2 (256 bits)
certificate
x509-fingerprint-sha1
Certificate value if the binary is signed with another authentication scheme than authenticode
++
filename
filename
Filename on disk
++
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
++
text
text
Free text value to attach to the file
++
sha1
sha1
sha512
sha512
size-in-bytes
size-in-bytes
Secure Hash Algorithm 2 (512 bits)
+Size of the file, in bytes
++
ssdeep
ssdeep
Fuzzy hash using context triggered piecewise hashes (CTPH)
@@ -2393,40 +2474,10 @@ file is a MISP object available in JSON format at
sha512/256
sha512/256
pattern-in-file
pattern-in-file
Secure Hash Algorithm 2 (256 bits)
--
size-in-bytes
size-in-bytes
Size of the file, in bytes
--
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
--
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
+Pattern that can be found in the file
@@ -2443,36 +2494,6 @@ file is a MISP object available in JSON format at
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
tlsh
tlsh
Fuzzy hash by Trend Micro: Locality Sensitive Hash
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
--
md5
md5
filename
filename
sha512
sha512
Filename on disk
--
text
text
Free text value to attach to the file
--
pattern-in-file
pattern-in-file
Pattern that can be found in the file
--
malware-sample
malware-sample
The file itself (binary)
--
certificate
x509-fingerprint-sha1
Certificate value if the binary is signed with another authentication scheme than authenticode
+Secure Hash Algorithm 2 (512 bits)
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
++
malware-sample
malware-sample
The file itself (binary)
++
last-seen
+datetime
When the location was seen for the last time.
++
altitude
float
The altitude is the decimal value of the altitude in the World Geodetic System 84 (WGS84) reference.
++
first-seen
datetime
When the location was seen for the first time.
++
longitude
float
region
text
Region.
--
latitude
float
first-seen
datetime
When the location was seen for the first time.
--
city
region
text
City.
+Region.
altitude
float
The altitude is the decimal value of the altitude in the World Geodetic System 84 (WGS84) reference.
--
last-seen
datetime
When the location was seen for the last time.
--
country
text
city
text
City.
++
ipSrc
-ip-src
GtpMsisdn
text
IP source address.
+GTP MSISDN.
text
GtpServingNetwork
text
A description of the GTP attack.
+GTP Serving Network.
ipDest
ip-dst
IP destination address.
++
GtpImsi
text
GtpServingNetwork
GtpInterface
text
GTP Serving Network.
+GTP interface. ['S5', 'S11', 'S10', 'S8', 'Gn', 'Gp']
GtpImei
text
GTP IMEI (International Mobile Equipment Identity).
--
first-seen
datetime
PortSrc
port
Source port.
++
text
text
A description of the GTP attack.
++
ipSrc
ip-src
IP source address.
++
GtpVersion
text
GtpMsisdn
GtpImei
text
GTP MSISDN.
+GTP IMEI (International Mobile Equipment Identity).
GtpInterface
text
GTP interface. ['S5', 'S11', 'S10', 'S8', 'Gn', 'Gp']
--
ipDest
ip-dst
IP destination address.
--
PortSrc
port
Source port.
--
host
+hostname
The domain name of the server
++
proxy-user
text
HTTP Proxy Username
++
cookie
text
uri
uri
Request URI
++
url
url
Full HTTP Request URL
++
method
http-method
HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
++
proxy-password
text
url
url
Full HTTP Request URL
--
content-type
other
The MIME type of the body of the request
--
host
hostname
The domain name of the server
--
user-agent
user-agent
The user agent string of the user agent
--
referer
referer
basicauth-password
text
HTTP Basic Authentication Password
--
text
text
proxy-user
basicauth-password
text
HTTP Proxy Username
+HTTP Basic Authentication Password
method
http-method
user-agent
user-agent
HTTP Method invoked (one of GET, POST, PUT, HEAD, DELETE, OPTIONS, CONNECT)
+The user agent string of the user agent
+
uri
uri
content-type
other
Request URI
+The MIME type of the body of the request
@@ -3045,26 +3046,16 @@ ip-port is a MISP object available in JSON format at
text
text
last-seen
datetime
Description of the tuple
+Last time the tuple has been seen
dst-port
port
Destination port
--
first-seen
datetime
src-port
port
Source port
++
text
text
Description of the tuple
++
ip
ip-dst
last-seen
datetime
Last time the tuple has been seen
--
src-port
dst-port
port
Source port
+Destination port
@@ -3143,26 +3144,6 @@ ja3 is a MISP object available in JSON format at
ip-src
ip-src
Source IP Address
--
first-seen
datetime
First seen of the SSL/TLS handshake
--
ip-dst
ip-dst
first-seen
datetime
First seen of the SSL/TLS handshake
++
ja3-fingerprint-md5
md5
Hash identifying source
++
description
text
ja3-fingerprint-md5
md5
ip-src
ip-src
Hash identifying source
+Source IP Address
@@ -3241,16 +3242,6 @@ macho is a MISP object available in JSON format at
text
text
Free text value to attach to the Mach-O file
--
name
text
entrypoint-address
text
Address of the entry point
++
number-sections
counter
entrypoint-address
text
text
Address of the entry point
+Free text value to attach to the Mach-O file
@@ -3329,10 +3330,50 @@ macho-section is a MISP object available in JSON format at
ssdeep
ssdeep
sha256
sha256
Fuzzy hash using context triggered piecewise hashes (CTPH)
+Secure Hash Algorithm 2 (256 bits)
++
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
name
text
Name of the section
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
@@ -3359,26 +3400,6 @@ macho-section is a MISP object available in JSON format at
sha512
sha512
Secure Hash Algorithm 2 (512 bits)
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
--
size-in-bytes
size-in-bytes
sha224
sha224
ssdeep
ssdeep
Secure Hash Algorithm 2 (224 bits)
+Fuzzy hash using context triggered piecewise hashes (CTPH)
sha256
sha256
text
text
Secure Hash Algorithm 2 (256 bits)
+Free text value to attach to the section
-
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
-+
name
-text
sha512
sha512
Name of the section
+Secure Hash Algorithm 2 (512 bits)
+
text
text
sha384
sha384
Free text value to attach to the section
+Secure Hash Algorithm 2 (384 bits)
+
link
-url
username
text
Link into the microblog post
+Username who posted the microblog post
post
text
modification-date
datetime
Raw post
+Last update of the microblog post
@@ -3527,26 +3528,6 @@ microblog is a MISP object available in JSON format at
removal-date
datetime
When the microblog post was removed
--
username
text
Username who posted the microblog post
--
username-quoted
text
link
url
Link into the microblog post
++
creation-date
datetime
modification-date
removal-date
datetime
Last update of the microblog post
+When the microblog post was removed
++
post
text
Raw post
@@ -3625,60 +3626,10 @@ netflow is a MISP object available in JSON format at
icmp-type
text
ip-dst
ip-dst
ICMP type of the flow (if the traffic is ICMP)
--
ip_version
counter
IP version of this flow
--
direction
text
Direction of this flow ['Ingress', 'Egress']
--
dst-port
port
Destination port of the netflow
--
tcp-flags
text
TCP flags of the flow
--
dst-as
AS
Destination AS number for this flow
+IP address destination of the netflow
@@ -3695,26 +3646,6 @@ netflow is a MISP object available in JSON format at
ip-src
ip-src
IP address source of the netflow
--
packet-count
counter
Packets counted in this flow
--
src-port
port
ip-dst
ip-dst
IP address destination of the netflow
--
flow-count
counter
first-packet-seen
datetime
ip-src
ip-src
First packet seen in this flow
+IP address source of the netflow
@@ -3765,10 +3686,70 @@ netflow is a MISP object available in JSON format at
byte-count
src-as
AS
Source AS number for this flow
++
ip_version
counter
Bytes counted in this flow
+IP version of this flow
++
dst-as
AS
Destination AS number for this flow
++
tcp-flags
text
TCP flags of the flow
++
packet-count
counter
Packets counted in this flow
++
icmp-type
text
ICMP type of the flow (if the traffic is ICMP)
++
direction
text
Direction of this flow ['Ingress', 'Egress']
@@ -3785,15 +3766,35 @@ netflow is a MISP object available in JSON format at
src-as
AS
first-packet-seen
datetime
Source AS number for this flow
+First packet seen in this flow
dst-port
port
Destination port of the netflow
++
byte-count
counter
Bytes counted in this flow
++
count
+counter
How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers
++
zone_time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
++
time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
++
time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
++
bailiwick
text
time_last
datetime
origin
text
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen by the passive DNS
+Origin of the Passive DNS response
@@ -3873,26 +3914,6 @@ passive-dns is a MISP object available in JSON format at
zone_time_last
datetime
Last time that the unique tuple (rrname, rrtype, rdata) record has been seen via master file import
--
rrname
text
Resource Record name of the queried resource
--
text
text
origin
text
Origin of the Passive DNS response
--
zone_time_first
datetime
rrname
text
Resource Record name of the queried resource
++
sensor_id
text
time_first
datetime
First time that the unique tuple (rrname, rrtype, rdata) has been seen by the passive DNS
--
count
counter
How many authoritative DNS answers were received at the Passive DNS Server’s collectors with exactly the given set of values as answers
--
first-seen
-datetime
When the paste has been accessible or seen for the first time.
--
title
text
Title of the paste or post.
--
paste
text
first-seen
datetime
When the paste has been accessible or seen for the first time.
++
url
url
title
text
Title of the paste or post.
++
number-sections
-counter
impfuzzy
impfuzzy
Number of sections
--
type
text
Type of PE ['exe', 'dll', 'driver', 'unknown']
--
original-filename
filename
OriginalFilename in the resources
--
pehash
pehash
Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
+Fuzzy Hash (ssdeep) calculated from the import table
file-version
product-name
text
FileVersion in the resources
--
lang-id
text
Lang ID in the resources
--
compilation-timestamp
datetime
Compilation timestamp defined in the PE header
--
entrypoint-address
text
Address of the entry point
--
text
text
Free text value to attach to the PE
+ProductName in the resources
@@ -4189,60 +4120,20 @@ pe is a MISP object available in JSON format at
entrypoint-section-at-position
text
compilation-timestamp
datetime
Name of the section and position of the section in the PE
--
impfuzzy
impfuzzy
Fuzzy Hash (ssdeep) calculated from the import table
+Compilation timestamp defined in the PE header
internal-filename
filename
InternalFilename in the resources
--
legal-copyright
type
text
LegalCopyright in the resources
--
product-version
text
ProductVersion in the resources
--
product-name
text
ProductName in the resources
+Type of PE ['exe', 'dll', 'driver', 'unknown']
@@ -4259,6 +4150,56 @@ pe is a MISP object available in JSON format at
file-version
text
FileVersion in the resources
++
number-sections
counter
Number of sections
++
entrypoint-section-at-position
text
Name of the section and position of the section in the PE
++
original-filename
filename
OriginalFilename in the resources
++
internal-filename
filename
InternalFilename in the resources
++
imphash
imphash
text
text
Free text value to attach to the PE
++
pehash
pehash
Hash of the structural information about a sample. See https://www.usenix.org/legacy/event/leet09/tech/full_papers/wicherski/wicherski_html/
++
product-version
text
ProductVersion in the resources
++
entrypoint-address
text
Address of the entry point
++
lang-id
text
Lang ID in the resources
++
legal-copyright
text
LegalCopyright in the resources
++
ssdeep
-ssdeep
sha256
sha256
Fuzzy hash using context triggered piecewise hashes (CTPH)
+Secure Hash Algorithm 2 (256 bits)
++
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
++
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
++
name
text
Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
++
sha224
sha224
Secure Hash Algorithm 2 (224 bits)
@@ -4337,20 +4378,10 @@ pe-section is a MISP object available in JSON format at
sha512
sha512
characteristic
text
Secure Hash Algorithm 2 (512 bits)
--
sha512/256
sha512/256
Secure Hash Algorithm 2 (256 bits)
+Characteristic of the section ['read', 'write', 'executable']
@@ -4367,53 +4398,23 @@ pe-section is a MISP object available in JSON format at
sha224
sha224
ssdeep
ssdeep
Secure Hash Algorithm 2 (224 bits)
+Fuzzy hash using context triggered piecewise hashes (CTPH)
sha256
sha256
Secure Hash Algorithm 2 (256 bits)
--
characteristic
text
text
Characteristic of the section ['read', 'write', 'executable']
+Free text value to attach to the section
-
sha384
sha384
Secure Hash Algorithm 2 (384 bits)
--
sha512/224
sha512/224
Secure Hash Algorithm 2 (224 bits)
-+
name
-text
sha512
sha512
Name of the section ['.rsrc', '.reloc', '.rdata', '.data', '.text']
+Secure Hash Algorithm 2 (512 bits)
+
text
text
sha384
sha384
Free text value to attach to the section
+Secure Hash Algorithm 2 (384 bits)
+
date-of-birth
-date-of-birth
first-name
first-name
Date of birth of a natural person (in YYYY-MM-DD format).
--
passport-number
passport-number
The passport number of a natural person.
--
passport-country
passport-country
The country in which the passport was issued.
+First name of a natural person.
@@ -4525,10 +4506,10 @@ person is a MISP object available in JSON format at
nationality
nationality
gender
gender
The nationality of a natural person.
+The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
@@ -4545,6 +4526,16 @@ person is a MISP object available in JSON format at
passport-expiration
passport-expiration
The expiration date of a passport.
++
middle-name
middle-name
passport-country
passport-country
The country in which the passport was issued.
++
date-of-birth
date-of-birth
Date of birth of a natural person (in YYYY-MM-DD format).
++
last-name
last-name
Last name of a natural person.
++
passport-number
passport-number
The passport number of a natural person.
++
text
text
passport-expiration
passport-expiration
nationality
nationality
The expiration date of a passport.
--
gender
gender
The gender of a natural person. ['Male', 'Female', 'Other', 'Prefer not to say']
--
first-name
first-name
First name of a natural person.
--
last-name
last-name
Last name of a natural person.
+The nationality of a natural person.
@@ -4643,16 +4644,6 @@ phone is a MISP object available in JSON format at
text
text
A description of the phone.
--
msisdn
text
tmsi
text
Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
--
guti
text
Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
--
last-seen
datetime
first-seen
datetime
When the phone has been accessible or seen for the first time.
--
serial-number
guti
text
Serial Number.
+Globally Unique Temporary UE Identity (GUTI) is a temporary identification to not reveal the phone (user equipment in 3GPP jargon) composed of GUMMEI and the M-TMSI.
gummei
tmsi
text
Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
+Temporary Mobile Subscriber Identities (TMSI) to visiting mobile subscribers can be allocated.
@@ -4733,6 +4694,36 @@ phone is a MISP object available in JSON format at
gummei
text
Globally Unique MME Identifier (GUMMEI) is composed from MCC, MNC and MME Identifier (MMEI).
++
serial-number
text
Serial Number.
++
text
text
A description of the phone.
++
imei
text
first-seen
datetime
When the phone has been accessible or seen for the first time.
++
total-api
-counter
Total amount of API calls
--
dangling-strings
counter
Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
--
callbacks
counter
total-functions
local-references
counter
Total amount of functions in the file.
--
callback-largest
counter
Largest callback
--
ratio-api
float
Ratio: amount of API calls per kilobyte of code section
--
not-referenced-strings
counter
Amount of not referenced strings
--
unknown-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
+Amount of API calls inside a code section
@@ -4871,30 +4812,30 @@ r2graphity is a MISP object available in JSON format at
create-thread
total-api
counter
Amount of calls to CreateThread
+Total amount of API calls
miss-api
memory-allocations
counter
Amount of API call reference that does not resolve to a function offset
+Amount of memory allocations
callback-average
counter
ratio-string
float
Average size of a callback
+Ratio: amount of referenced strings per kilobyte of code section
@@ -4921,20 +4862,60 @@ r2graphity is a MISP object available in JSON format at
ratio-string
float
text
text
Ratio: amount of referenced strings per kilobyte of code section
+Description of the r2graphity object
refsglobalvar
dangling-strings
counter
Amount of API calls outside of code section (glob var, dynamic API)
+Amount of dangling strings (string with a code cross reference, that is not within a function. Radare2 failed to detect that function.)
++
ratio-api
float
Ratio: amount of API calls per kilobyte of code section
++
callback-largest
counter
Largest callback
++
callback-average
counter
Average size of a callback
++
miss-api
counter
Amount of API call reference that does not resolve to a function offset
@@ -4951,10 +4932,50 @@ r2graphity is a MISP object available in JSON format at
text
text
shortest-path-to-create-thread
counter
Description of the r2graphity object
+Shortest path to the first time the binary calls CreateThread
++
not-referenced-strings
counter
Amount of not referenced strings
++
total-functions
counter
Total amount of functions in the file.
++
refsglobalvar
counter
Amount of API calls outside of code section (glob var, dynamic API)
++
unknown-references
counter
Amount of API calls not ending in a function (Radare2 bug, probalby)
@@ -4971,30 +4992,10 @@ r2graphity is a MISP object available in JSON format at
local-references
create-thread
counter
Amount of API calls inside a code section
--
shortest-path-to-create-thread
counter
Shortest path to the first time the binary calls CreateThread
--
memory-allocations
counter
Amount of memory allocations
+Amount of calls to CreateThread
@@ -5039,6 +5040,16 @@ regexp is a MISP object available in JSON format at
regexp-type
text
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
++
comment
comment
type
text
Specify which type corresponds to this regex. ['hostname', 'domain', 'email-src', 'email-dst', 'email-subject', 'url', 'user-agent', 'regkey', 'cookie', 'uri', 'filename', 'windows-service-name', 'windows-scheduled-task']
--
regexp
text
regexp-type
type
text
Type of the regular expression syntax. ['PCRE', 'PCRE2', 'POSIX BRE', 'POSIX ERE']
+Specify which type corresponds to this regex. ['hostname', 'domain', 'email-src', 'email-dst', 'email-subject', 'url', 'user-agent', 'regkey', 'cookie', 'uri', 'filename', 'windows-service-name', 'windows-scheduled-task']
+
last-modified
-datetime
key
regkey
Last time the registry key has been modified
+Full key path
data-type
text
Registry value type ['REG_NONE', 'REG_SZ', 'REG_EXPAND_SZ', 'REG_BINARY', 'REG_DWORD', 'REG_DWORD_LITTLE_ENDIAN', 'REG_DWORD_BIG_ENDIAN', 'REG_LINK', 'REG_MULTI_SZ', 'REG_RESOURCE_LIST', 'REG_FULL_RESOURCE_DESCRIPTOR', 'REG_RESOURCE_REQUIREMENTS_LIST', 'REG_QWORD', 'REG_QWORD_LITTLE_ENDIAN']
--
hive
text
key
regkey
Full key path
--
data
text
last-modified
datetime
Last time the registry key has been modified
++
data-type
text
Registry value type ['REG_NONE', 'REG_SZ', 'REG_EXPAND_SZ', 'REG_BINARY', 'REG_DWORD', 'REG_DWORD_LITTLE_ENDIAN', 'REG_DWORD_BIG_ENDIAN', 'REG_LINK', 'REG_MULTI_SZ', 'REG_RESOURCE_LIST', 'REG_FULL_RESOURCE_DESCRIPTOR', 'REG_RESOURCE_REQUIREMENTS_LIST', 'REG_QWORD', 'REG_QWORD_LITTLE_ENDIAN']
++
subject
+classification
text
Subject of the RTIR ticket
+Classification of the RTIR ticket
status
constituency
text
Status of the RTIR ticket ['new', 'open', 'stalled', 'resolved', 'rejected', 'deleted']
+Constituency of the RTIR ticket
@@ -5313,16 +5314,6 @@ rtir is a MISP object available in JSON format at
classification
text
Classification of the RTIR ticket
--
ip
ip-dst
constituency
status
text
Constituency of the RTIR ticket
+Status of the RTIR ticket ['new', 'open', 'stalled', 'resolved', 'rejected', 'deleted']
subject
text
Subject of the RTIR ticket
++
Sandbox report.
++ + | ++sandbox-report is a MISP object available in JSON format at this location The JSON format can be freely reused in your application or automatically enabled in MISP. + | +
Object attribute | +MISP attribute type | +Description | +Disable correlation | +
---|---|---|---|
permalink |
+link |
+
+ Permalink reference + |
+
+ + |
+
score |
+text |
+
+ Score + |
+
+ + |
+
saas-sandbox |
+text |
+
+ A non-on-premise sandbox, also results are not publicly available ['forticloud-sandbox', 'joe-sandbox-cloud', 'symantec-cas-cloud'] + |
+
+ + |
+
results |
+text |
+
+ Freetext result values + |
+
+ + |
+
on-premise-sandbox |
+text |
+
+ The on-premise sandbox used ['cuckoo', 'symantec-cas-on-premise', 'bluecoat-maa', 'trendmicro-deep-discovery-analyzer', 'fireeye-ax', 'vmray', 'joe-sandbox-on-premise'] + |
+
+ + |
+
sandbox-type |
+text |
+
+ The type of sandbox used ['on-premise', 'web', 'saas'] + |
+
+ + |
+
raw-report |
+text |
+
+ Raw report from sandbox + |
+
+ + |
+
web-sandbox |
+text |
+
+ A web sandbox where results are publicly available via an URL ['malwr', 'hybrid-analysis'] + |
+
+ + |
+
SccpCgGT
+MapSmsTypeNumber
text
Signaling Connection Control Part (SCCP) CgGT - Phone number.
--
MapGsmscfGT
text
MAP GSMSCF GT. Phone number.
--
MapImsi
text
MAP IMSI. Phone number starting with MCC/MNC.
--
SccpCdGT
text
Signaling Connection Control Part (SCCP) CdGT - Phone number.
--
first-seen
datetime
When the attack has been seen for the first time.
--
MapOpCode
text
MAP operation codes - Decimal value between 0-99.
+MAP SMS TypeNumber.
@@ -5451,96 +5520,36 @@ ss7-attack is a MISP object available in JSON format at
MapMsisdn
MapSmsTP-DCS
text
MAP MSISDN. Phone number.
+MAP SMS TP-DCS.
++
SccpCdGT
text
Signaling Connection Control Part (SCCP) CdGT - Phone number.
MapUssdCoding
MapImsi
text
MAP USSD Content.
--
SccpCgPC
text
Signaling Connection Control Part (SCCP) CgPC - Phone number.
+MAP IMSI. Phone number starting with MCC/MNC.
SccpCdSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
--
MapVlrGT
text
MAP VLR GT. Phone number.
--
MapMscGT
text
MAP MSC GT. Phone number.
--
MapSmsTypeNumber
text
MAP SMS TypeNumber.
--
SccpCgSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
--
text
text
A description of the attack seen via SS7 logging.
--
MapVersion
text
MapApplicationContext
SccpCgGT
text
MAP application context in OID format.
--
MapGmlc
text
MAP GMLC. Phone number.
+Signaling Connection Control Part (SCCP) CgGT - Phone number.
MapSmsTP-DCS
text
text
MAP SMS TP-DCS.
--
MapSmsTP-PID
text
MAP SMS TP-PID.
+A description of the attack seen via SS7 logging.
@@ -5611,6 +5600,36 @@ ss7-attack is a MISP object available in JSON format at
MapMscGT
text
MAP MSC GT. Phone number.
++
MapVlrGT
text
MAP VLR GT. Phone number.
++
MapGmlc
text
MAP GMLC. Phone number.
++
Category
text
MapGsmscfGT
text
MAP GSMSCF GT. Phone number.
++
MapSmsTP-PID
text
MAP SMS TP-PID.
++
SccpCgPC
text
Signaling Connection Control Part (SCCP) CgPC - Phone number.
++
MapApplicationContext
text
MAP application context in OID format.
++
MapMsisdn
text
MAP MSISDN. Phone number.
++
first-seen
datetime
When the attack has been seen for the first time.
++
MapUssdContent
text
SccpCdSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
++
SccpCgSSN
text
Signaling Connection Control Part (SCCP) - Decimal value between 0-255.
++
MapUssdCoding
text
MAP USSD Content.
++
MapOpCode
text
MAP operation codes - Decimal value between 0-99.
++
comment
-comment
stix2-pattern
stix2-pattern
A description of the stix2-pattern.
+STIX 2 pattern
stix2-pattern
stix2-pattern
comment
comment
STIX 2 pattern
+A description of the stix2-pattern.
@@ -5727,6 +5846,16 @@ tor-node is a MISP object available in JSON format at
document
text
Raw document from the consensus.
++
fingerprint
text
first-seen
datetime
description
text
When the Tor node designed by the IP address has been seen for the first time.
+Tor node description.
@@ -5757,13 +5886,13 @@ tor-node is a MISP object available in JSON format at
description
version_line
text
Tor node description.
+versioning information reported by the node.
+
nickname
+text
router’s nickname.
++
last-seen
datetime
When the Tor node designed by the IP address has been seen for the last time.
++
first-seen
datetime
When the Tor node designed by the IP address has been seen for the first time.
++
version
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
++
text
text
nickname
text
router’s nickname.
--
version
text
parsed version of tor, this is None if the relay’s using a new versioning scheme.
--
address
ip-src
document
text
Raw document from the consensus.
--
version_line
text
versioning information reported by the node.
--
last-seen
datetime
When the Tor node designed by the IP address has been seen for the last time.
--
resource_path
+credential
text
Path (between hostname:port and query)
+Credential (username, password)
last-seen
datetime
Last time this URL has been seen
--
port
port
Port number
--
host
hostname
credential
text
Credential (username, password)
--
text
text
Description of the URL
--
domain
domain
Full domain
--
first-seen
datetime
First time this URL has been seen
--
fragment
text
domain_without_tld
resource_path
text
Domain without Top-Level Domain
+Path (between hostname:port and query)
++
url
url
Full URL
@@ -6005,10 +6074,40 @@ url is a MISP object available in JSON format at
url
url
last-seen
datetime
Full URL
+Last time this URL has been seen
++
port
port
Port number
++
first-seen
datetime
First time this URL has been seen
++
domain_without_tld
text
Domain without Top-Level Domain
@@ -6025,6 +6124,26 @@ url is a MISP object available in JSON format at
text
text
Description of the URL
++
domain
domain
Full domain
++
scheme
text
node
target-machine
user
target-user
Name(s) of node that was targeted.
+The username(s) of the user targeted.
target-email
external
target-external
The email address(es) of the user targeted.
+External target organisations affected by this attack.
@@ -6113,16 +6232,6 @@ victim is a MISP object available in JSON format at
name
target-org
The name of the department(s) or organisation(s) targeted.
--
ip-address
ip-dst
user
target-user
name
target-org
The username(s) of the user targeted.
+The name of the department(s) or organisation(s) targeted.
@@ -6153,10 +6262,10 @@ victim is a MISP object available in JSON format at
regions
target-location
node
target-machine
The list of regions or locations from the victim targeted. ISO 3166 should be used.
+Name(s) of node that was targeted.
@@ -6173,10 +6282,20 @@ victim is a MISP object available in JSON format at
external
target-external
target-email
External target organisations affected by this attack.
+The email address(es) of the user targeted.
++
regions
target-location
The list of regions or locations from the victim targeted. ISO 3166 should be used.
@@ -6221,26 +6340,6 @@ virustotal-report is a MISP object available in JSON format at
first-submission
datetime
First Submission
--
last-submission
datetime
Last Submission
--
community-score
text
first-submission
datetime
First Submission
++
detection-ratio
text
last-submission
datetime
Last Submission
++
text
-text
references
link
Description of the vulnerability
+External references
@@ -6339,33 +6458,23 @@ vulnerability is a MISP object available in JSON format at
published
datetime
vulnerable_configuration
text
Initial publication date
--
references
link
External references
+The vulnerable configuration is described in CPE format
created
datetime
text
text
First time when the vulnerability was discovered
+Description of the vulnerability
+
published
+datetime
Initial publication date
++
created
datetime
First time when the vulnerability was discovered
++
summary
text
vulnerable_configuration
text
The vulnerable configuration is described in CPE format
--
expiration-date
-datetime
Expiration of the whois entry
--
text
text
Full whois entry
--
creation-date
datetime
Initial creation of the whois entry
--
registrant-email
whois-registrant-email
Registrant email address
--
registrar
whois-registrar
registrant-org
whois-registrant-org
Registrant organisation
--
registrant-phone
whois-registrant-phone
Registrant phone number
--
nameserver
hostname
Nameserver
--
domain
domain
Domain of the whois entry
--
registrant-name
whois-registrant-name
registrant-phone
whois-registrant-phone
Registrant phone number
++
domain
domain
Domain of the whois entry
++
registrant-email
whois-registrant-email
Registrant email address
++
creation-date
datetime
Initial creation of the whois entry
++
text
text
Full whois entry
++
nameserver
hostname
Nameserver
++
registrant-org
whois-registrant-org
Registrant organisation
++
expiration-date
datetime
Expiration of the whois entry
++
pubkey-info-algorithm
+text
Algorithm of the public key
++
validity-not-before
datetime
Certificate invalid before that date
++
serial-number
text
Serial number of the certificate
++
x509-fingerprint-sha1
x509-fingerprint-sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
++
pubkey-info-modulus
text
Modulus of the public key
++
pubkey-info-exponent
text
Exponent of the public key
++
x509-fingerprint-sha256
x509-fingerprint-sha256
Secure Hash Algorithm 2 (256 bits)
++
pubkey-info-size
text
Length of the public key (in bits)
++
version
text
Version of the certificate
++
text
text
Free text description of hte certificate
++
raw-base64
text
validity-not-before
datetime
Certificate invalid before that date
--
pubkey-info-exponent
text
Exponent of the public key
--
text
text
Free text description of hte certificate
--
issuer
text
pubkey-info-algorithm
text
Algorithm of the public key
--
x509-fingerprint-sha256
x509-fingerprint-sha256
Secure Hash Algorithm 2 (256 bits)
--
pubkey-info-modulus
text
Modulus of the public key
--
version
text
Version of the certificate
--
x509-fingerprint-md5
x509-fingerprint-md5
[Insecure] MD5 hash (128 bits)
--
validity-not-after
datetime
serial-number
text
x509-fingerprint-md5
x509-fingerprint-md5
Serial number of the certificate
--
pubkey-info-size
text
Length of the public key (in bits)
--
x509-fingerprint-sha1
x509-fingerprint-sha1
[Insecure] Secure Hash Algorithm 1 (160 bits)
+[Insecure] MD5 hash (128 bits)
@@ -6773,16 +6892,6 @@ yabin is a MISP object available in JSON format at
comment
comment
A description of Yara rule generated.
--
yara-hunt
yara
whitelist
comment
comment
Whitelist name used to generate the rules.
--
version
comment
yabin.py and regex.txt version used for the generation of the yara rules.
+A description of Yara rule generated.
version
comment
yabin.py and regex.txt version used for the generation of the yara rules.
++
whitelist
comment
Whitelist name used to generate the rules.
++