diff --git a/Sample Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv b/Sample Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv index 4b913f8e3f..8ec3f15838 100644 --- a/Sample Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv +++ b/Sample Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv @@ -2,11 +2,11 @@ DateAdded,FirstSeen,Indicator,IndicatorType,TLP 2021-03-10,2021-03-05T10:07:29.0421232Z,8e90ed33c7ee82c0b64078ea36ec95f7420ba435c693b3b3dd728b494abf7dfc,sha256,White 2021-03-10,2021-03-03T10:51:16.7363037Z,2f0bc81c2ea269643cae307239124d1b6479847867b1adfe9ae712a1d5ef135e,sha256,White 2021-03-10,2021-03-05T09:51:58.5865879Z,a291305f181e24fe7194154b4cd355ccb039d5765709c80999e392efec69c90a,sha256,White -2020-03-09,2021-03-04T08:05:00.5878895Z,511df0e2df9bfa5521b588cc4bb5f8c5a321801b803394ebc493db1ef3c78fa1,sha256,White -2020-03-09,2021-01-06T18:38:17.8341434Z,b75f163ca9b9240bf4b37ad92bc7556b40a17e27c2b8ed5c8991385fe07d17d0,sha256,White -2020-03-09,2021-02-09T00:33:52.5232083Z,4edc7770464a14f54d17f36dc9d0fe854f68b346b27b35a6f5839adf1f13f8ea,sha256,White -2020-03-09,2021-02-23T09:14:05.8243534Z,811157f9c7003ba8d17b45eb3cf09bef2cecd2701cedb675274949296a6a183d,sha256,White -2020-03-09,2021-01-24T12:59:40.6969216Z,65149e036fff06026d80ac9ad4d156332822dc93142cf1a122b1841ec8de34b5,sha256,White +2021-03-09,2021-03-04T08:05:00.5878895Z,511df0e2df9bfa5521b588cc4bb5f8c5a321801b803394ebc493db1ef3c78fa1,sha256,White +2021-03-09,2021-01-06T18:38:17.8341434Z,b75f163ca9b9240bf4b37ad92bc7556b40a17e27c2b8ed5c8991385fe07d17d0,sha256,White +2021-03-09,2021-02-09T00:33:52.5232083Z,4edc7770464a14f54d17f36dc9d0fe854f68b346b27b35a6f5839adf1f13f8ea,sha256,White +2021-03-09,2021-02-23T09:14:05.8243534Z,811157f9c7003ba8d17b45eb3cf09bef2cecd2701cedb675274949296a6a183d,sha256,White +2021-03-09,2021-01-24T12:59:40.6969216Z,65149e036fff06026d80ac9ad4d156332822dc93142cf1a122b1841ec8de34b5,sha256,White 2021-03-09,,C:\Program Files\Microsoft\Exchange Server\V15\FrontEnd\HttpProxy\owa\auth\8Lw7tAhF9i1pJnRo.aspx,filepath,White 2021-03-09,,C:\Program Files\Microsoft\Exchange Server\V15\FrontEnd\HttpProxy\owa\auth\OutlookZH.aspx,filepath,White 2021-03-09,,C:\Program Files\Microsoft\Exchange Server\V15\FrontEnd\HttpProxy\owa\auth\authhead.aspx,filepath,White diff --git a/Sample Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.json b/Sample Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.json index 9dbdff005a..eee89aa4d4 100644 --- a/Sample Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.json +++ b/Sample Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.json @@ -1 +1 @@ -[{"DateAdded":"2021-03-10","FirstSeen":"2021-03-05T10:07:29.0421232Z","Indicator":"8e90ed33c7ee82c0b64078ea36ec95f7420ba435c693b3b3dd728b494abf7dfc","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"4ef04cba6bec2c3a164b9b755efbeb1c","FileSha1":"49644cbbb9d234bd4f7a47ed596c8bbfefd39065"}},{"DateAdded":"2021-03-10","FirstSeen":"2021-03-03T10:51:16.7363037Z","Indicator":"2f0bc81c2ea269643cae307239124d1b6479847867b1adfe9ae712a1d5ef135e","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"4cb449474c4d522422e40ecc93ac089b","FileSha1":"40d3e0aa4d4961c184f4c3ae07fb63676357467e"}},{"DateAdded":"2021-03-10","FirstSeen":"2021-03-05T09:51:58.5865879Z","Indicator":"a291305f181e24fe7194154b4cd355ccb039d5765709c80999e392efec69c90a","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"fe15fc6341baad2a111462854f96a2bc","FileSha1":"90cd4f920d48c05fd3cad8275223f596c6388cbd"}},{"DateAdded":"2020-03-09","FirstSeen":"2021-03-04T08:05:00.5878895Z","Indicator":"511df0e2df9bfa5521b588cc4bb5f8c5a321801b803394ebc493db1ef3c78fa1","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"5544ba9ad1b56101b5d52b5270421d4a","FileSha1":"fc6f5ce56166d9b4516ba207f3a653b722e1a8df"}},{"DateAdded":"2020-03-09","FirstSeen":"2021-01-06T18:38:17.8341434Z","Indicator":"b75f163ca9b9240bf4b37ad92bc7556b40a17e27c2b8ed5c8991385fe07d17d0","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"4b3039cf227c611c45d2242d1228a121","FileSha1":"0ba9a76f55aaa495670d74d21850d0155ff5d6a5"}},{"DateAdded":"2020-03-09","FirstSeen":"2021-02-09T00:33:52.5232083Z","Indicator":"4edc7770464a14f54d17f36dc9d0fe854f68b346b27b35a6f5839adf1f13f8ea","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"548f4cb8f60a986ebcc62a61fc612a19","FileSha1":"3ea3154878c384f8392503b2e61b00ffd0c343ed"}},{"DateAdded":"2020-03-09","FirstSeen":"2021-02-23T09:14:05.8243534Z","Indicator":"811157f9c7003ba8d17b45eb3cf09bef2cecd2701cedb675274949296a6a183d","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"f2ca0ee8528bd942faab8aa5f940b17b","FileSha1":"7d67fa8af286fd949d4665439a13e91b83f1fafe"}},{"DateAdded":"2020-03-09","FirstSeen":"2021-01-24T12:59:40.6969216Z","Indicator":"65149e036fff06026d80ac9ad4d156332822dc93142cf1a122b1841ec8de34b5","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"502f6c0f3d5e982157e7d687bed04eeb","FileSha1":"6263f899fe23fbf04e6c833b2f19008b6208305a"}},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\8Lw7tAhF9i1pJnRo.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\OutlookZH.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\authhead.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\bob.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\current\\one1.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\errorPage.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\errorPages.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\fatal-erro.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\log.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\logg.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\logout.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\one.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\one1.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\shel.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\shel2.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\shel90.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\a.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\default.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\shell.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\Server.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\aspnet_client.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\aspnet_iisstart.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\aspnet_pages.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\aspnet_www.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\default1.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\errorcheck.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\iispage.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\s.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\session.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\shell.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\system_web\\log.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\xclkmcfldfi948398430fdjkfdkj.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\xx.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\Server.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\discover.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\HttpProxy.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\OutlookEN.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\supp0rt.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\OAB\\log.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\log.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\logg.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\logout.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-11","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\Current\\google.log","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-11","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\google.log","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-11","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\google.log","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-11","FirstSeen":"","Indicator":"C:\\users\\public\\opera\\opera_browser.exe","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-11","FirstSeen":"2021-03-08T20:16:39.0784849Z","Indicator":"e044d9f2d0f1260c3f4a543a1e67f33fcac265be114a1b135fd575b860d2b8c6","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"cdda3913408c4c46a6c575421485fa5b","FileSha1":"56eec7392297e7301159094d7e461a696fe5b90f"}},{"DateAdded":"2021-03-11","FirstSeen":"2021-03-09T09:23:17.7189583Z","Indicator":"2b9838da7edb0decd32b086e47a31e8f5733b5981ad8247a2f9508e232589bff","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"0e55ead3b8fd305d9a54f78c7b56741a","FileSha1":"f7b084e581a8dcea450c2652f8058d93797413c3"}},{"DateAdded":"2021-03-11","FirstSeen":"2021-03-09T13:14:14.3522438Z","Indicator":"feb3e6d30ba573ba23f3bd1291ca173b7879706d1fe039c34d53a4fdcdf33ede","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"c6eeb14485d93f4e30fb79f3a57518fc","FileSha1":"b7d99521348d319f57d2b2ba7045295fc99cf6a7"}},{"DateAdded":"2021-03-15","FirstSeen":"2021-03-09T08:20:35.6649557Z","Indicator":"dd29e8d47dde124c7d14e614e03ccaab3ecaa50e0a0bef985ed59e98928bc13d","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"f2e22df5e284587dc36f8041129af391","FileSha1":"6c9ec01e105f92727d6acee24a0db0f3ee54b02c"}},{"DateAdded":"2021-03-15","FirstSeen":"2021-03-10T15:25:16.6382191Z","Indicator":"201e4e9910dcdc8c4ffad84b60b328978db8848d265c0b9ba8473cf65dcd0c41","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"aef2ae9b36989bab8818696de5ccd5e7","FileSha1":"f985022d7705d1ec575a1eef4ee32506d8b82871"}}] \ No newline at end of file +[{"DateAdded":"2021-03-10","FirstSeen":"2021-03-05T10:07:29.0421232Z","Indicator":"8e90ed33c7ee82c0b64078ea36ec95f7420ba435c693b3b3dd728b494abf7dfc","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"4ef04cba6bec2c3a164b9b755efbeb1c","FileSha1":"49644cbbb9d234bd4f7a47ed596c8bbfefd39065"}},{"DateAdded":"2021-03-10","FirstSeen":"2021-03-03T10:51:16.7363037Z","Indicator":"2f0bc81c2ea269643cae307239124d1b6479847867b1adfe9ae712a1d5ef135e","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"4cb449474c4d522422e40ecc93ac089b","FileSha1":"40d3e0aa4d4961c184f4c3ae07fb63676357467e"}},{"DateAdded":"2021-03-10","FirstSeen":"2021-03-05T09:51:58.5865879Z","Indicator":"a291305f181e24fe7194154b4cd355ccb039d5765709c80999e392efec69c90a","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"fe15fc6341baad2a111462854f96a2bc","FileSha1":"90cd4f920d48c05fd3cad8275223f596c6388cbd"}},{"DateAdded":"2021-03-09","FirstSeen":"2021-03-04T08:05:00.5878895Z","Indicator":"511df0e2df9bfa5521b588cc4bb5f8c5a321801b803394ebc493db1ef3c78fa1","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"5544ba9ad1b56101b5d52b5270421d4a","FileSha1":"fc6f5ce56166d9b4516ba207f3a653b722e1a8df"}},{"DateAdded":"2021-03-09","FirstSeen":"2021-01-06T18:38:17.8341434Z","Indicator":"b75f163ca9b9240bf4b37ad92bc7556b40a17e27c2b8ed5c8991385fe07d17d0","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"4b3039cf227c611c45d2242d1228a121","FileSha1":"0ba9a76f55aaa495670d74d21850d0155ff5d6a5"}},{"DateAdded":"2021-03-09","FirstSeen":"2021-02-09T00:33:52.5232083Z","Indicator":"4edc7770464a14f54d17f36dc9d0fe854f68b346b27b35a6f5839adf1f13f8ea","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"548f4cb8f60a986ebcc62a61fc612a19","FileSha1":"3ea3154878c384f8392503b2e61b00ffd0c343ed"}},{"DateAdded":"2021-03-09","FirstSeen":"2021-02-23T09:14:05.8243534Z","Indicator":"811157f9c7003ba8d17b45eb3cf09bef2cecd2701cedb675274949296a6a183d","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"f2ca0ee8528bd942faab8aa5f940b17b","FileSha1":"7d67fa8af286fd949d4665439a13e91b83f1fafe"}},{"DateAdded":"2021-03-09","FirstSeen":"2021-01-24T12:59:40.6969216Z","Indicator":"65149e036fff06026d80ac9ad4d156332822dc93142cf1a122b1841ec8de34b5","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"502f6c0f3d5e982157e7d687bed04eeb","FileSha1":"6263f899fe23fbf04e6c833b2f19008b6208305a"}},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\8Lw7tAhF9i1pJnRo.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\OutlookZH.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\authhead.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\bob.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\current\\one1.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\errorPage.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\errorPages.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\fatal-erro.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\log.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\logg.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\logout.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\one.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\one1.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\shel.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\shel2.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\shel90.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\a.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\default.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\shell.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\Server.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\aspnet_client.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\aspnet_iisstart.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\aspnet_pages.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\aspnet_www.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\default1.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\errorcheck.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\iispage.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\s.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\session.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\shell.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\system_web\\log.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\xclkmcfldfi948398430fdjkfdkj.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\xx.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\Server.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\discover.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\HttpProxy.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\OutlookEN.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\supp0rt.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\OAB\\log.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\log.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\logg.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-09","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\logout.aspx","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-11","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\Current\\google.log","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-11","FirstSeen":"","Indicator":"C:\\inetpub\\wwwroot\\aspnet_client\\google.log","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-11","FirstSeen":"","Indicator":"C:\\Program Files\\Microsoft\\Exchange Server\\V15\\FrontEnd\\HttpProxy\\owa\\auth\\google.log","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-11","FirstSeen":"","Indicator":"C:\\users\\public\\opera\\opera_browser.exe","IndicatorType":"filepath","TLP":"White","ThreatType":"Malware","AdditionalMetadata":""},{"DateAdded":"2021-03-11","FirstSeen":"2021-03-08T20:16:39.0784849Z","Indicator":"e044d9f2d0f1260c3f4a543a1e67f33fcac265be114a1b135fd575b860d2b8c6","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"cdda3913408c4c46a6c575421485fa5b","FileSha1":"56eec7392297e7301159094d7e461a696fe5b90f"}},{"DateAdded":"2021-03-11","FirstSeen":"2021-03-09T09:23:17.7189583Z","Indicator":"2b9838da7edb0decd32b086e47a31e8f5733b5981ad8247a2f9508e232589bff","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"0e55ead3b8fd305d9a54f78c7b56741a","FileSha1":"f7b084e581a8dcea450c2652f8058d93797413c3"}},{"DateAdded":"2021-03-11","FirstSeen":"2021-03-09T13:14:14.3522438Z","Indicator":"feb3e6d30ba573ba23f3bd1291ca173b7879706d1fe039c34d53a4fdcdf33ede","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"c6eeb14485d93f4e30fb79f3a57518fc","FileSha1":"b7d99521348d319f57d2b2ba7045295fc99cf6a7"}},{"DateAdded":"2021-03-15","FirstSeen":"2021-03-09T08:20:35.6649557Z","Indicator":"dd29e8d47dde124c7d14e614e03ccaab3ecaa50e0a0bef985ed59e98928bc13d","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"f2e22df5e284587dc36f8041129af391","FileSha1":"6c9ec01e105f92727d6acee24a0db0f3ee54b02c"}},{"DateAdded":"2021-03-15","FirstSeen":"2021-03-10T15:25:16.6382191Z","Indicator":"201e4e9910dcdc8c4ffad84b60b328978db8848d265c0b9ba8473cf65dcd0c41","IndicatorType":"sha256","TLP":"White","ThreatType":"Malware","AdditionalMetadata":{"FileMd5":"aef2ae9b36989bab8818696de5ccd5e7","FileSha1":"f985022d7705d1ec575a1eef4ee32506d8b82871"}}] \ No newline at end of file