Azure-Sentinel/Sample Data/Custom/Group IB TIA/GIBTIA_suspicious_ip_socks_...

29 строки
878 B
JSON

{
"dateDetected": "2021-01-19T07:41:11+00:00",
"dateFirstSeen": "2021-01-19T07:41:11+00:00",
"dateLastSeen": "2021-01-21T08:35:46+00:00",
"evaluation": {
"admiraltyCode": "A1",
"credibility": 100,
"reliability": 90,
"severity": "green",
"tlp": "amber",
"ttl": 2
},
"id": "02e385600dfc5bf9b3b3656df8e0e20f5fc5c86e",
"ipv4": {
"asn": "AS60999 Libatech SAL",
"city": null,
"countryCode": "LB",
"countryName": "Lebanon",
"ip": "185.90.169.156",
"provider": "Libatech SAL",
"region": null
},
"isFavourite": false,
"isHidden": false,
"oldId": "395880626",
"portalLink": "https://bt.group-ib.com/suspicious/socks?searchValue=id:02e385600dfc5bf9b3b3656df8e0e20f5fc5c86e",
"seqUpdate": 1614926061941,
"source": "awmproxy.com"
}