diff --git a/IsItPhishing/Snapshot_IsItPhishing_URL_Malicious.json b/IsItPhishing/Snapshot_IsItPhishing_URL_Malicious.json index 733eb6fa..6e5c675d 100644 --- a/IsItPhishing/Snapshot_IsItPhishing_URL_Malicious.json +++ b/IsItPhishing/Snapshot_IsItPhishing_URL_Malicious.json @@ -1 +1 @@ -{"description": "IsItPhishing", "schema_version": "1.0.19", "type": "investigation", "search-txt": "domain:\"365clientdash.com\"\nurl:\"http://365clientdash.com/zelds/news/\"", "source": "Anastasiia Rozlyvan", "actions": "[{\"created-perf\":1995239999.9965565,\"updated-perf\":1995239999.9965565,\"type\":\"collect\",\"created\":\"2020-11-24T13:56:45.917Z\",\"state\":\"ok\",\"arg\":\"http://365clientdash.com/zelds/news/\",\"result\":[{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"id\":\"collect-e595bf5f\",\"uuid\":\"c462abbc-1181-4ece-8cc7-2369108e7903\"},{\"created-perf\":3853144999.997312,\"updated-perf\":3853144999.997312,\"type\":\"deliberate\",\"created\":\"2020-11-24T13:56:47.775Z\",\"state\":\"ok\",\"arg\":[{\"type\":\"url\",\"value\":\"http://365clientdash.com/zelds/news/\"},{\"type\":\"domain\",\"value\":\"365clientdash.com\"}],\"result\":{\"data\":[{\"module\":\"IsItPhishing\",\"module_instance_id\":\"ec0d130f-2b03-48fa-89de-864549ceff9f\",\"module_type_id\":\"73c4d670-963c-4ecb-82bc-bf747559c3b4\",\"data\":{\"verdicts\":{\"count\":1,\"docs\":[{\"type\":\"verdict\",\"disposition\":2,\"observable\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"disposition_name\":\"Malicious\",\"valid_time\":{\"start_time\":\"2024-03-29T06:00:00.735Z\",\"end_time\":\"2024-01-30T13:56:47.882Z\"}}]}}}]},\"id\":\"deliberate-8dad1f39\",\"uuid\":\"728de767-7c51-434b-8ff5-76a5d5c44fb0\"},{\"created-perf\":7068854999.997711,\"updated-perf\":7068859999.999404,\"type\":\"investigate\",\"created\":\"2020-11-24T13:56:50.990Z\",\"state\":\"ok\",\"arg\":{\"type\":\"domain\",\"value\":\"365clientdash.com\"},\"result\":{\"data\":[{\"module\":\"urlscan. URL and website sandbox\",\"module_instance_id\":\"b158950e-9754-4e01-bc9c-4b66d241874d\",\"module_type_id\":\"a0d1f3ca-bc86-4b87-b6de-496d3c4b4d63\",\"data\":{\"indicators\":{\"count\":1,\"docs\":[{\"description\":\"\u0421lassified as phishing\",\"tags\":[\"phishing\"],\"valid_time\":{},\"producer\":\"urlscan.io\",\"schema_version\":\"1.0.17\",\"type\":\"indicator\",\"short_description\":\"\u0421lassified as phishing\",\"title\":\"phishing\",\"id\":\"transient:indicator-344f10f2-89cc-5bbb-9176-726345d25538\",\"confidence\":\"High\"}]},\"relationships\":{\"count\":6,\"docs\":[{\"schema_version\":\"1.0.17\",\"target_ref\":\"transient:sighting-966c1071-7ad9-4e7a-8304-7f000db63218\",\"type\":\"relationship\",\"source_ref\":\"transient:indicator-344f10f2-89cc-5bbb-9176-726345d25538\",\"id\":\"transient:relationship-1809c18e-31e7-4a7f-99c5-ab81bb6c214b\",\"relationship_type\":\"indicates\"},{\"schema_version\":\"1.0.17\",\"target_ref\":\"transient:sighting-7a04db98-6e00-4329-801e-8144ff598d17\",\"type\":\"relationship\",\"source_ref\":\"transient:indicator-344f10f2-89cc-5bbb-9176-726345d25538\",\"id\":\"transient:relationship-50c6cf06-983e-4911-9ccc-823d64b41d9f\",\"relationship_type\":\"indicates\"},{\"schema_version\":\"1.0.17\",\"target_ref\":\"transient:sighting-4b2b9586-1e83-458c-9c5e-69a47cf33f83\",\"type\":\"relationship\",\"source_ref\":\"transient:indicator-344f10f2-89cc-5bbb-9176-726345d25538\",\"id\":\"transient:relationship-26dd8940-bf8c-4b63-a8ee-190566362d77\",\"relationship_type\":\"indicates\"},{\"schema_version\":\"1.0.17\",\"target_ref\":\"transient:sighting-08a47db2-1ae6-4ed3-be7b-ad9d8927038e\",\"type\":\"relationship\",\"source_ref\":\"transient:indicator-344f10f2-89cc-5bbb-9176-726345d25538\",\"id\":\"transient:relationship-6041adff-3f0e-4c48-9e9e-541012f66f81\",\"relationship_type\":\"indicates\"},{\"schema_version\":\"1.0.17\",\"target_ref\":\"transient:sighting-1ebc89ba-c395-498c-9813-1c60b0d6b7b4\",\"type\":\"relationship\",\"source_ref\":\"transient:indicator-344f10f2-89cc-5bbb-9176-726345d25538\",\"id\":\"transient:relationship-6fa7e0bd-f5c2-462c-b972-71b2f8bece01\",\"relationship_type\":\"indicates\"},{\"schema_version\":\"1.0.17\",\"target_ref\":\"transient:sighting-abf138d6-50ef-44a1-86be-f03d81fd45f6\",\"type\":\"relationship\",\"source_ref\":\"transient:indicator-344f10f2-89cc-5bbb-9176-726345d25538\",\"id\":\"transient:relationship-1b8c3fd9-5f34-44c5-bde4-fd51325f0cba\",\"relationship_type\":\"indicates\"}]}, \"sightings\":{\"count\":13,\"docs\":[{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"62513ff2-9071-442f-86b0-fb015f7de0c6\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/62513ff2-9071-442f-86b0-fb015f7de0c6\",\"id\":\"transient:sighting-abf138d6-50ef-44a1-86be-f03d81fd45f6\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-20T10:06:03.959Z\",\"end_time\":\"2023-09-20T10:06:03.959Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[13,3,4,2560188,766090,55]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://reports.365clientdash.com/\",\"type\":\"url\"},\"related\":{\"value\":\"reports.365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"reports.365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"3.213.94.123\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://reports.365clientdash.com/\",\"type\":\"url\"},\"related\":{\"value\":\"3.213.94.123\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"51f175e3-fc96-4deb-90a0-7af441825ee9\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/51f175e3-fc96-4deb-90a0-7af441825ee9\",\"id\":\"transient:sighting-00e33851-3c6b-441f-a4e5-9c3cef785c09\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-05-14T11:13:13.639Z\",\"end_time\":\"2023-05-14T11:13:13.639Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[16,11,5,201655630,41286965,472]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"3067289e-b4fa-41a9-b0e2-76f5190f4916\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/3067289e-b4fa-41a9-b0e2-76f5190f4916\",\"id\":\"transient:sighting-966c1071-7ad9-4e7a-8304-7f000db63218\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-28T11:15:25.891Z\",\"end_time\":\"2023-09-28T11:15:25.891Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[3,0,3,579755,522522,8]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://www.365clientdash.com/\",\"type\":\"url\"},\"related\":{\"value\":\"www.365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"www.365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"52.202.107.58\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://www.365clientdash.com/\",\"type\":\"url\"},\"related\":{\"value\":\"52.202.107.58\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"dd6041be-d448-44a6-8513-e6e9e6f1e301\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/dd6041be-d448-44a6-8513-e6e9e6f1e301\",\"id\":\"transient:sighting-20131650-634d-4544-8bef-dc99ff3fa378\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2024-03-29T06:00:00.735Z\",\"end_time\":\"2023-05-19T19:46:32.249Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[17,22,5,387355600,80816348,884]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://app.365clientdash.com/\",\"type\":\"url\"},\"related\":{\"value\":\"app.365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"app.365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"35.242.150.168\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://app.365clientdash.com/\",\"type\":\"url\"},\"related\":{\"value\":\"35.242.150.168\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"20522121-4eab-40a8-8fcf-1afe3a12c67f\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/20522121-4eab-40a8-8fcf-1afe3a12c67f\",\"id\":\"transient:sighting-107ea90c-474f-4962-b970-f20e4aa6a33b\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-05-20T23:09:32.080Z\",\"end_time\":\"2023-05-20T23:09:32.080Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[9,1,4,4809199,1233626,15]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"02715de4-6cfd-4ace-ae17-20d259873aa4\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/02715de4-6cfd-4ace-ae17-20d259873aa4\",\"id\":\"transient:sighting-4b2b9586-1e83-458c-9c5e-69a47cf33f83\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-28T11:15:24.714Z\",\"end_time\":\"2023-09-28T11:15:24.714Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[3,0,3,579755,522531,8]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"ab5fdbbe-bc2d-4f4e-b239-85279f8f6ba9\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/ab5fdbbe-bc2d-4f4e-b239-85279f8f6ba9\",\"id\":\"transient:sighting-7ecb9c43-4818-4592-b125-8d9d13fa705b\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-21T17:17:18.883Z\",\"end_time\":\"2023-09-21T17:17:18.883Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[1,0,1,315,516,1]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"ca83937a-d424-4221-9142-be03019dc518\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/ca83937a-d424-4221-9142-be03019dc518\",\"id\":\"transient:sighting-d343ed48-99bd-48f2-a2e7-97c35bc800eb\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-21T21:27:53.136Z\",\"end_time\":\"2023-09-21T21:27:53.136Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[1,0,1,315,516,1]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"32597256-3921-4319-9b4a-849b4670ba6f\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/32597256-3921-4319-9b4a-849b4670ba6f\",\"id\":\"transient:sighting-a6202ee3-f186-4eb8-9994-3460a2d4137e\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-22T11:56:09.200Z\",\"end_time\":\"2023-09-22T11:56:09.200Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[1,0,1,315,516,1]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://365clientdash.com/upload/big-pond.php?email=abuse@example.com\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://365clientdash.com/upload/big-pond.php?email=abuse@example.com\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"84f5ba18-1f34-413a-917f-b33c414783f8\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/84f5ba18-1f34-413a-917f-b33c414783f8\",\"id\":\"transient:sighting-08a47db2-1ae6-4ed3-be7b-ad9d8927038e\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-21T03:50:19.811Z\",\"end_time\":\"2023-09-21T03:50:19.811Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[13,3,4,2560006,768680,54]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"de074142-3a5a-46f9-9f47-e6a870c3ad4e\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/de074142-3a5a-46f9-9f47-e6a870c3ad4e\",\"id\":\"transient:sighting-1ebc89ba-c395-498c-9813-1c60b0d6b7b4\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-27T13:33:18.698Z\",\"end_time\":\"2023-09-27T13:33:18.698Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[3,0,3,579755,522531,8]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"bd89d843-28a5-4b27-978a-e61f7676d9b3\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/bd89d843-28a5-4b27-978a-e61f7676d9b3\",\"id\":\"transient:sighting-7a04db98-6e00-4329-801e-8144ff598d17\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-27T15:00:29.334Z\",\"end_time\":\"2023-09-27T15:00:29.334Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[3,0,3,579755,522441,8]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"4ae453a4-6c85-40e8-af51-3e0d79e4ab82\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/4ae453a4-6c85-40e8-af51-3e0d79e4ab82\",\"id\":\"transient:sighting-503b068a-ce99-4f28-b911-e829553d64af\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-21T20:40:12.011Z\",\"end_time\":\"2023-09-21T20:40:12.011Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[1,0,1,315,516,1]]}}]}}},{\"module\":\"IsItPhishing\",\"module_instance_id\":\"ec0d130f-2b03-48fa-89de-864549ceff9f\",\"module_type_id\":\"73c4d670-963c-4ecb-82bc-bf747559c3b4\",\"data\":{}}]},\"id\":\"investigate-a187ddc4\",\"uuid\":\"92e6aefb-5d4d-4427-b214-94ac0e9b8a88\"},{\"created-perf\":10583789999.996952,\"updated-perf\":10583789999.996952,\"type\":\"investigate\",\"created\":\"2020-11-24T13:56:54.505Z\",\"state\":\"ok\",\"arg\":{\"type\":\"url\",\"value\":\"http://365clientdash.com/zelds/news/\"},\"result\":{\"data\":[{\"module\":\"IsItPhishing\",\"module_instance_id\":\"ec0d130f-2b03-48fa-89de-864549ceff9f\",\"module_type_id\":\"73c4d670-963c-4ecb-82bc-bf747559c3b4\",\"data\":{\"verdicts\":{\"count\":1,\"docs\":[{\"type\":\"verdict\",\"disposition\":2,\"observable\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"disposition_name\":\"Malicious\",\"valid_time\":{\"start_time\":\"2024-03-29T06:00:00.735Z\",\"end_time\":\"2024-04-05T06:00:00.735Z\"}}]},\"judgements\":{\"count\":1,\"docs\":[{\"valid_time\":{\"start_time\":\"2024-03-29T06:00:00.735Z\",\"end_time\":\"2024-04-05T06:00:00.735Z\"},\"schema_version\":\"1.0.22\",\"observable\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"type\":\"judgement\",\"source\":\"IsItPhishing\",\"disposition\":2,\"disposition_name\":\"Malicious\",\"priority\":85,\"id\":\"transient:judgement-53592350-2382-4d9b-a0d4-6c13c7ff847a\",\"severity\":\"High\",\"confidence\":\"High\"}]}}}]},\"id\":\"investigate-92b0c6ff\",\"uuid\":\"7f94168d-8d02-491e-ab3f-a47ecf34c1fb\"},{\"created-perf\":13709274999.997433,\"updated-perf\":13709279999.999126,\"type\":\"deliberate\",\"created\":\"2020-11-24T13:56:57.631Z\",\"state\":\"ok\",\"arg\":[{\"type\":\"ip\",\"value\":\"35.242.150.168\"},{\"type\":\"url\",\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\"},{\"type\":\"url\",\"value\":\"https://app.365clientdash.com/\"},{\"type\":\"ip\",\"value\":\"3.213.94.123\"},{\"type\":\"domain\",\"value\":\"www.365clientdash.com\"},{\"type\":\"url\",\"value\":\"https://365clientdash.com/upload/big-pond.php?email=abuse@example.com\"},{\"type\":\"url\",\"value\":\"https://reports.365clientdash.com/\"},{\"type\":\"ip\",\"value\":\"198.54.113.32\"},{\"type\":\"domain\",\"value\":\"app.365clientdash.com\"},{\"type\":\"ip\",\"value\":\"52.202.107.58\"},{\"type\":\"domain\",\"value\":\"reports.365clientdash.com\"},{\"type\":\"url\",\"value\":\"https://www.365clientdash.com/\"}],\"result\":{\"data\":[{\"module\":\"IsItPhishing\",\"module_instance_id\":\"ec0d130f-2b03-48fa-89de-864549ceff9f\",\"module_type_id\":\"73c4d670-963c-4ecb-82bc-bf747559c3b4\",\"data\":{\"verdicts\":{\"count\":5,\"docs\":[{\"type\":\"verdict\",\"disposition\":2,\"observable\":{\"value\":\"https://365clientdash.com/upload/big-pond.php?email=abuse@example.com\",\"type\":\"url\"},\"disposition_name\":\"Malicious\",\"valid_time\":{\"start_time\":\"2024-03-29T06:00:00.735Z\",\"end_time\":\"2024-04-05T06:00:00.735Z\"}},{\"type\":\"verdict\",\"disposition\":2,\"observable\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"disposition_name\":\"Malicious\",\"valid_time\":{\"start_time\":\"2024-03-29T06:00:00.735Z\",\"end_time\":\"2024-04-05T06:00:00.735Z\"}},{\"type\":\"verdict\",\"disposition\":5,\"observable\":{\"value\":\"https://app.365clientdash.com/\",\"type\":\"url\"},\"disposition_name\":\"Unknown\",\"valid_time\":{\"start_time\":\"2024-03-29T06:00:00.735Z\",\"end_time\":\"2024-04-05T06:00:00.735Z\"}},{\"type\":\"verdict\",\"disposition\":5,\"observable\":{\"value\":\"https://reports.365clientdash.com/\",\"type\":\"url\"},\"disposition_name\":\"Unknown\",\"valid_time\":{\"start_time\":\"2024-03-29T06:00:00.735Z\",\"end_time\":\"2024-04-05T06:00:00.735Z\"}},{\"type\":\"verdict\",\"disposition\":5,\"observable\":{\"value\":\"https://www.365clientdash.com/\",\"type\":\"url\"},\"disposition_name\":\"Unknown\",\"valid_time\":{\"start_time\":\"2024-03-29T06:00:00.735Z\",\"end_time\":\"2024-04-05T06:00:00.735Z\"}}]}}}]},\"id\":\"deliberate-73713e63\",\"uuid\":\"79f4f4c9-4522-422b-ad0f-56b18ad1504b\"}]", "short_description": "Snapshot @ 20201124 13:59:22", "id": "https://private.intel.amp.cisco.com:443/ctia/investigation/investigation-50e65f1e-881c-46a0-b0cd-d856c9f0d525", "tlp": "amber", "groups": ["32e22c6d-7624-477e-8bbd-989c979b552e"], "timestamp": "2020-11-24T13:59:39.337Z", "owner": "9d64bbce-2e7c-43f0-b9d7-0e2fa3c2d88d"} \ No newline at end of file +{"description": "IsItPhishing", "schema_version": "1.0.19", "type": "investigation", "search-txt": "domain:\"365clientdash.com\"\nurl:\"http://365clientdash.com/zelds/news/\"", "source": "Anastasiia Rozlyvan", "actions": "[{\"created-perf\":1995239999.9965565,\"updated-perf\":1995239999.9965565,\"type\":\"collect\",\"created\":\"2020-11-24T13:56:45.917Z\",\"state\":\"ok\",\"arg\":\"http://365clientdash.com/zelds/news/\",\"result\":[{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"id\":\"collect-e595bf5f\",\"uuid\":\"c462abbc-1181-4ece-8cc7-2369108e7903\"},{\"created-perf\":3853144999.997312,\"updated-perf\":3853144999.997312,\"type\":\"deliberate\",\"created\":\"2020-11-24T13:56:47.775Z\",\"state\":\"ok\",\"arg\":[{\"type\":\"url\",\"value\":\"http://365clientdash.com/zelds/news/\"},{\"type\":\"domain\",\"value\":\"365clientdash.com\"}],\"result\":{\"data\":[{\"module\":\"IsItPhishing\",\"module_instance_id\":\"ec0d130f-2b03-48fa-89de-864549ceff9f\",\"module_type_id\":\"73c4d670-963c-4ecb-82bc-bf747559c3b4\",\"data\":{\"verdicts\":{\"count\":1,\"docs\":[{\"type\":\"verdict\",\"disposition\":2,\"observable\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"disposition_name\":\"Malicious\",\"valid_time\":{\"start_time\":\"2024-04-05T06:00:00.735Z\",\"end_time\":\"2024-02-06T13:56:47.882Z\"}}]}}}]},\"id\":\"deliberate-8dad1f39\",\"uuid\":\"728de767-7c51-434b-8ff5-76a5d5c44fb0\"},{\"created-perf\":7068854999.997711,\"updated-perf\":7068859999.999404,\"type\":\"investigate\",\"created\":\"2020-11-24T13:56:50.990Z\",\"state\":\"ok\",\"arg\":{\"type\":\"domain\",\"value\":\"365clientdash.com\"},\"result\":{\"data\":[{\"module\":\"urlscan. URL and website sandbox\",\"module_instance_id\":\"b158950e-9754-4e01-bc9c-4b66d241874d\",\"module_type_id\":\"a0d1f3ca-bc86-4b87-b6de-496d3c4b4d63\",\"data\":{\"indicators\":{\"count\":1,\"docs\":[{\"description\":\"\u0421lassified as phishing\",\"tags\":[\"phishing\"],\"valid_time\":{},\"producer\":\"urlscan.io\",\"schema_version\":\"1.0.17\",\"type\":\"indicator\",\"short_description\":\"\u0421lassified as phishing\",\"title\":\"phishing\",\"id\":\"transient:indicator-344f10f2-89cc-5bbb-9176-726345d25538\",\"confidence\":\"High\"}]},\"relationships\":{\"count\":6,\"docs\":[{\"schema_version\":\"1.0.17\",\"target_ref\":\"transient:sighting-966c1071-7ad9-4e7a-8304-7f000db63218\",\"type\":\"relationship\",\"source_ref\":\"transient:indicator-344f10f2-89cc-5bbb-9176-726345d25538\",\"id\":\"transient:relationship-1809c18e-31e7-4a7f-99c5-ab81bb6c214b\",\"relationship_type\":\"indicates\"},{\"schema_version\":\"1.0.17\",\"target_ref\":\"transient:sighting-7a04db98-6e00-4329-801e-8144ff598d17\",\"type\":\"relationship\",\"source_ref\":\"transient:indicator-344f10f2-89cc-5bbb-9176-726345d25538\",\"id\":\"transient:relationship-50c6cf06-983e-4911-9ccc-823d64b41d9f\",\"relationship_type\":\"indicates\"},{\"schema_version\":\"1.0.17\",\"target_ref\":\"transient:sighting-4b2b9586-1e83-458c-9c5e-69a47cf33f83\",\"type\":\"relationship\",\"source_ref\":\"transient:indicator-344f10f2-89cc-5bbb-9176-726345d25538\",\"id\":\"transient:relationship-26dd8940-bf8c-4b63-a8ee-190566362d77\",\"relationship_type\":\"indicates\"},{\"schema_version\":\"1.0.17\",\"target_ref\":\"transient:sighting-08a47db2-1ae6-4ed3-be7b-ad9d8927038e\",\"type\":\"relationship\",\"source_ref\":\"transient:indicator-344f10f2-89cc-5bbb-9176-726345d25538\",\"id\":\"transient:relationship-6041adff-3f0e-4c48-9e9e-541012f66f81\",\"relationship_type\":\"indicates\"},{\"schema_version\":\"1.0.17\",\"target_ref\":\"transient:sighting-1ebc89ba-c395-498c-9813-1c60b0d6b7b4\",\"type\":\"relationship\",\"source_ref\":\"transient:indicator-344f10f2-89cc-5bbb-9176-726345d25538\",\"id\":\"transient:relationship-6fa7e0bd-f5c2-462c-b972-71b2f8bece01\",\"relationship_type\":\"indicates\"},{\"schema_version\":\"1.0.17\",\"target_ref\":\"transient:sighting-abf138d6-50ef-44a1-86be-f03d81fd45f6\",\"type\":\"relationship\",\"source_ref\":\"transient:indicator-344f10f2-89cc-5bbb-9176-726345d25538\",\"id\":\"transient:relationship-1b8c3fd9-5f34-44c5-bde4-fd51325f0cba\",\"relationship_type\":\"indicates\"}]}, \"sightings\":{\"count\":13,\"docs\":[{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"62513ff2-9071-442f-86b0-fb015f7de0c6\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/62513ff2-9071-442f-86b0-fb015f7de0c6\",\"id\":\"transient:sighting-abf138d6-50ef-44a1-86be-f03d81fd45f6\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-27T10:06:03.959Z\",\"end_time\":\"2023-09-27T10:06:03.959Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[13,3,4,2560188,766090,55]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://reports.365clientdash.com/\",\"type\":\"url\"},\"related\":{\"value\":\"reports.365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"reports.365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"3.213.94.123\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://reports.365clientdash.com/\",\"type\":\"url\"},\"related\":{\"value\":\"3.213.94.123\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"51f175e3-fc96-4deb-90a0-7af441825ee9\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/51f175e3-fc96-4deb-90a0-7af441825ee9\",\"id\":\"transient:sighting-00e33851-3c6b-441f-a4e5-9c3cef785c09\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-05-21T11:13:13.639Z\",\"end_time\":\"2023-05-21T11:13:13.639Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[16,11,5,201655630,41286965,472]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"3067289e-b4fa-41a9-b0e2-76f5190f4916\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/3067289e-b4fa-41a9-b0e2-76f5190f4916\",\"id\":\"transient:sighting-966c1071-7ad9-4e7a-8304-7f000db63218\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-10-05T11:15:25.891Z\",\"end_time\":\"2023-10-05T11:15:25.891Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[3,0,3,579755,522522,8]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://www.365clientdash.com/\",\"type\":\"url\"},\"related\":{\"value\":\"www.365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"www.365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"52.202.107.58\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://www.365clientdash.com/\",\"type\":\"url\"},\"related\":{\"value\":\"52.202.107.58\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"dd6041be-d448-44a6-8513-e6e9e6f1e301\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/dd6041be-d448-44a6-8513-e6e9e6f1e301\",\"id\":\"transient:sighting-20131650-634d-4544-8bef-dc99ff3fa378\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2024-04-05T06:00:00.735Z\",\"end_time\":\"2023-05-26T19:46:32.249Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[17,22,5,387355600,80816348,884]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://app.365clientdash.com/\",\"type\":\"url\"},\"related\":{\"value\":\"app.365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"app.365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"35.242.150.168\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://app.365clientdash.com/\",\"type\":\"url\"},\"related\":{\"value\":\"35.242.150.168\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"20522121-4eab-40a8-8fcf-1afe3a12c67f\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/20522121-4eab-40a8-8fcf-1afe3a12c67f\",\"id\":\"transient:sighting-107ea90c-474f-4962-b970-f20e4aa6a33b\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-05-27T23:09:32.080Z\",\"end_time\":\"2023-05-27T23:09:32.080Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[9,1,4,4809199,1233626,15]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"02715de4-6cfd-4ace-ae17-20d259873aa4\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/02715de4-6cfd-4ace-ae17-20d259873aa4\",\"id\":\"transient:sighting-4b2b9586-1e83-458c-9c5e-69a47cf33f83\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-10-05T11:15:24.714Z\",\"end_time\":\"2023-10-05T11:15:24.714Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[3,0,3,579755,522531,8]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"ab5fdbbe-bc2d-4f4e-b239-85279f8f6ba9\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/ab5fdbbe-bc2d-4f4e-b239-85279f8f6ba9\",\"id\":\"transient:sighting-7ecb9c43-4818-4592-b125-8d9d13fa705b\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-28T17:17:18.883Z\",\"end_time\":\"2023-09-28T17:17:18.883Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[1,0,1,315,516,1]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"ca83937a-d424-4221-9142-be03019dc518\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/ca83937a-d424-4221-9142-be03019dc518\",\"id\":\"transient:sighting-d343ed48-99bd-48f2-a2e7-97c35bc800eb\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-28T21:27:53.136Z\",\"end_time\":\"2023-09-28T21:27:53.136Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[1,0,1,315,516,1]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"32597256-3921-4319-9b4a-849b4670ba6f\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/32597256-3921-4319-9b4a-849b4670ba6f\",\"id\":\"transient:sighting-a6202ee3-f186-4eb8-9994-3460a2d4137e\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-29T11:56:09.200Z\",\"end_time\":\"2023-09-29T11:56:09.200Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[1,0,1,315,516,1]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://365clientdash.com/upload/big-pond.php?email=abuse@example.com\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://365clientdash.com/upload/big-pond.php?email=abuse@example.com\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"84f5ba18-1f34-413a-917f-b33c414783f8\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/84f5ba18-1f34-413a-917f-b33c414783f8\",\"id\":\"transient:sighting-08a47db2-1ae6-4ed3-be7b-ad9d8927038e\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-28T03:50:19.811Z\",\"end_time\":\"2023-09-28T03:50:19.811Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[13,3,4,2560006,768680,54]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"de074142-3a5a-46f9-9f47-e6a870c3ad4e\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/de074142-3a5a-46f9-9f47-e6a870c3ad4e\",\"id\":\"transient:sighting-1ebc89ba-c395-498c-9813-1c60b0d6b7b4\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-10-04T13:33:18.698Z\",\"end_time\":\"2023-10-04T13:33:18.698Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[3,0,3,579755,522531,8]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"bd89d843-28a5-4b27-978a-e61f7676d9b3\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/bd89d843-28a5-4b27-978a-e61f7676d9b3\",\"id\":\"transient:sighting-7a04db98-6e00-4329-801e-8144ff598d17\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-10-04T15:00:29.334Z\",\"end_time\":\"2023-10-04T15:00:29.334Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[3,0,3,579755,522441,8]]}},{\"description\":\"Scan Result\",\"schema_version\":\"1.0.17\",\"relations\":[{\"origin\":\"urlscan.io Module\",\"relation\":\"Contains\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Resolved_To\",\"source\":{\"value\":\"365clientdash.com\",\"type\":\"domain\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}},{\"origin\":\"urlscan.io Module\",\"relation\":\"Hosted_By\",\"source\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"related\":{\"value\":\"198.54.113.32\",\"type\":\"ip\"}}],\"observables\":[{\"value\":\"365clientdash.com\",\"type\":\"domain\"}],\"type\":\"sighting\",\"source\":\"urlscan.io\",\"external_ids\":[\"4ae453a4-6c85-40e8-af51-3e0d79e4ab82\"],\"internal\":false,\"source_uri\":\"https://urlscan.io/result/4ae453a4-6c85-40e8-af51-3e0d79e4ab82\",\"id\":\"transient:sighting-503b068a-ce99-4f28-b911-e829553d64af\",\"count\":1,\"confidence\":\"High\",\"observed_time\":{\"start_time\":\"2023-09-28T20:40:12.011Z\",\"end_time\":\"2023-09-28T20:40:12.011Z\"},\"data\":{\"columns\":[{\"name\":\"uniqIPs\",\"type\":\"integer\"},{\"name\":\"consoleMsgs\",\"type\":\"integer\"},{\"name\":\"uniqCountries\",\"type\":\"integer\"},{\"name\":\"dataLength\",\"type\":\"integer\"},{\"name\":\"encodedDataLength\",\"type\":\"integer\"},{\"name\":\"requests\",\"type\":\"integer\"}],\"rows\":[[1,0,1,315,516,1]]}}]}}},{\"module\":\"IsItPhishing\",\"module_instance_id\":\"ec0d130f-2b03-48fa-89de-864549ceff9f\",\"module_type_id\":\"73c4d670-963c-4ecb-82bc-bf747559c3b4\",\"data\":{}}]},\"id\":\"investigate-a187ddc4\",\"uuid\":\"92e6aefb-5d4d-4427-b214-94ac0e9b8a88\"},{\"created-perf\":10583789999.996952,\"updated-perf\":10583789999.996952,\"type\":\"investigate\",\"created\":\"2020-11-24T13:56:54.505Z\",\"state\":\"ok\",\"arg\":{\"type\":\"url\",\"value\":\"http://365clientdash.com/zelds/news/\"},\"result\":{\"data\":[{\"module\":\"IsItPhishing\",\"module_instance_id\":\"ec0d130f-2b03-48fa-89de-864549ceff9f\",\"module_type_id\":\"73c4d670-963c-4ecb-82bc-bf747559c3b4\",\"data\":{\"verdicts\":{\"count\":1,\"docs\":[{\"type\":\"verdict\",\"disposition\":2,\"observable\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"disposition_name\":\"Malicious\",\"valid_time\":{\"start_time\":\"2024-04-05T06:00:00.735Z\",\"end_time\":\"2024-04-12T06:00:00.735Z\"}}]},\"judgements\":{\"count\":1,\"docs\":[{\"valid_time\":{\"start_time\":\"2024-04-05T06:00:00.735Z\",\"end_time\":\"2024-04-12T06:00:00.735Z\"},\"schema_version\":\"1.0.22\",\"observable\":{\"value\":\"http://365clientdash.com/zelds/news/\",\"type\":\"url\"},\"type\":\"judgement\",\"source\":\"IsItPhishing\",\"disposition\":2,\"disposition_name\":\"Malicious\",\"priority\":85,\"id\":\"transient:judgement-53592350-2382-4d9b-a0d4-6c13c7ff847a\",\"severity\":\"High\",\"confidence\":\"High\"}]}}}]},\"id\":\"investigate-92b0c6ff\",\"uuid\":\"7f94168d-8d02-491e-ab3f-a47ecf34c1fb\"},{\"created-perf\":13709274999.997433,\"updated-perf\":13709279999.999126,\"type\":\"deliberate\",\"created\":\"2020-11-24T13:56:57.631Z\",\"state\":\"ok\",\"arg\":[{\"type\":\"ip\",\"value\":\"35.242.150.168\"},{\"type\":\"url\",\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\"},{\"type\":\"url\",\"value\":\"https://app.365clientdash.com/\"},{\"type\":\"ip\",\"value\":\"3.213.94.123\"},{\"type\":\"domain\",\"value\":\"www.365clientdash.com\"},{\"type\":\"url\",\"value\":\"https://365clientdash.com/upload/big-pond.php?email=abuse@example.com\"},{\"type\":\"url\",\"value\":\"https://reports.365clientdash.com/\"},{\"type\":\"ip\",\"value\":\"198.54.113.32\"},{\"type\":\"domain\",\"value\":\"app.365clientdash.com\"},{\"type\":\"ip\",\"value\":\"52.202.107.58\"},{\"type\":\"domain\",\"value\":\"reports.365clientdash.com\"},{\"type\":\"url\",\"value\":\"https://www.365clientdash.com/\"}],\"result\":{\"data\":[{\"module\":\"IsItPhishing\",\"module_instance_id\":\"ec0d130f-2b03-48fa-89de-864549ceff9f\",\"module_type_id\":\"73c4d670-963c-4ecb-82bc-bf747559c3b4\",\"data\":{\"verdicts\":{\"count\":5,\"docs\":[{\"type\":\"verdict\",\"disposition\":2,\"observable\":{\"value\":\"https://365clientdash.com/upload/big-pond.php?email=abuse@example.com\",\"type\":\"url\"},\"disposition_name\":\"Malicious\",\"valid_time\":{\"start_time\":\"2024-04-05T06:00:00.735Z\",\"end_time\":\"2024-04-12T06:00:00.735Z\"}},{\"type\":\"verdict\",\"disposition\":2,\"observable\":{\"value\":\"https://365clientdash.com/main/big-pond.php?email=%7B%7Bemail%7D%7D\",\"type\":\"url\"},\"disposition_name\":\"Malicious\",\"valid_time\":{\"start_time\":\"2024-04-05T06:00:00.735Z\",\"end_time\":\"2024-04-12T06:00:00.735Z\"}},{\"type\":\"verdict\",\"disposition\":5,\"observable\":{\"value\":\"https://app.365clientdash.com/\",\"type\":\"url\"},\"disposition_name\":\"Unknown\",\"valid_time\":{\"start_time\":\"2024-04-05T06:00:00.735Z\",\"end_time\":\"2024-04-12T06:00:00.735Z\"}},{\"type\":\"verdict\",\"disposition\":5,\"observable\":{\"value\":\"https://reports.365clientdash.com/\",\"type\":\"url\"},\"disposition_name\":\"Unknown\",\"valid_time\":{\"start_time\":\"2024-04-05T06:00:00.735Z\",\"end_time\":\"2024-04-12T06:00:00.735Z\"}},{\"type\":\"verdict\",\"disposition\":5,\"observable\":{\"value\":\"https://www.365clientdash.com/\",\"type\":\"url\"},\"disposition_name\":\"Unknown\",\"valid_time\":{\"start_time\":\"2024-04-05T06:00:00.735Z\",\"end_time\":\"2024-04-12T06:00:00.735Z\"}}]}}}]},\"id\":\"deliberate-73713e63\",\"uuid\":\"79f4f4c9-4522-422b-ad0f-56b18ad1504b\"}]", "short_description": "Snapshot @ 20201124 13:59:22", "id": "https://private.intel.amp.cisco.com:443/ctia/investigation/investigation-50e65f1e-881c-46a0-b0cd-d856c9f0d525", "tlp": "amber", "groups": ["32e22c6d-7624-477e-8bbd-989c979b552e"], "timestamp": "2020-11-24T13:59:39.337Z", "owner": "9d64bbce-2e7c-43f0-b9d7-0e2fa3c2d88d"} \ No newline at end of file diff --git a/IsItPhishing/Snapshot_IsItPhishing_URL_Suspisious.json b/IsItPhishing/Snapshot_IsItPhishing_URL_Suspisious.json index 6ab9186e..a96f3dd9 100644 --- a/IsItPhishing/Snapshot_IsItPhishing_URL_Suspisious.json +++ b/IsItPhishing/Snapshot_IsItPhishing_URL_Suspisious.json @@ -1 +1 @@ -{"description": "IsItPhishing Suspicious", "schema_version": "1.0.19", "type": "investigation", "search-txt": "url:\"http://freedommms.space/demadel\"", "source": "Anastasiia Rozlyvan", "actions": "[{\"created-perf\":14179879999.999685,\"updated-perf\":14179879999.999685,\"type\":\"collect\",\"created\":\"2020-11-24T14:00:11.607Z\",\"state\":\"ok\",\"arg\":\"url:'http://freedommms.space/demadel'\",\"result\":[{\"value\":\"http://freedommms.space/demadel\",\"type\":\"url\"}],\"id\":\"collect-f45efa18\",\"uuid\":\"d3875f77-5348-4faa-bbad-550b03cbbc8b\"},{\"created-perf\":15183934999.997292,\"updated-perf\":15183934999.997292,\"type\":\"deliberate\",\"created\":\"2020-11-24T14:00:12.611Z\",\"state\":\"ok\",\"arg\":[{\"type\":\"url\",\"value\":\"http://freedommms.space/demadel\"}],\"result\":{\"data\":[{\"module\":\"AMP File Reputation\",\"module_instance_id\":\"ddcf41a2-3ecb-43e8-b5b2-0e36ad2e16f3\",\"module_type_id\":\"1898d0e8-45f7-550d-8ab5-915f064426dd\",\"data\":{\"verdicts\":{\"count\":0,\"docs\":[]}}},{\"module\":\"IsItPhishing\",\"module_instance_id\":\"ec0d130f-2b03-48fa-89de-864549ceff9f\",\"module_type_id\":\"73c4d670-963c-4ecb-82bc-bf747559c3b4\",\"data\":{\"verdicts\":{\"count\":1,\"docs\":[{\"type\":\"verdict\",\"disposition\":3,\"observable\":{\"value\":\"http://freedommms.space/demadel\",\"type\":\"url\"},\"disposition_name\":\"Suspicious\",\"valid_time\":{\"start_time\":\"2024-03-29T06:00:00.735Z\",\"end_time\":\"2024-04-05T06:00:00.735Z\"}}]}}}]},\"id\":\"deliberate-431bf6f1\",\"uuid\":\"bbefe3f7-ea3d-4049-809a-090f200a32fb\"},{\"created-perf\":16190514999.998413,\"updated-perf\":16190514999.998413,\"type\":\"investigate\",\"created\":\"2020-11-24T14:00:13.618Z\",\"state\":\"ok\",\"arg\":{\"type\":\"url\",\"value\":\"http://freedommms.space/demadel\"},\"result\":{\"data\":[{\"module\":\"urlscan. URL and website sandbox\",\"module_instance_id\":\"b158950e-9754-4e01-bc9c-4b66d241874d\",\"module_type_id\":\"a0d1f3ca-bc86-4b87-b6de-496d3c4b4d63\",\"data\":{}},{\"module\":\"IsItPhishing\",\"module_instance_id\":\"ec0d130f-2b03-48fa-89de-864549ceff9f\",\"module_type_id\":\"73c4d670-963c-4ecb-82bc-bf747559c3b4\",\"data\":{\"verdicts\":{\"count\":1,\"docs\":[{\"type\":\"verdict\",\"disposition\":3,\"observable\":{\"value\":\"http://freedommms.space/demadel\",\"type\":\"url\"},\"disposition_name\":\"Suspicious\",\"valid_time\":{\"start_time\":\"2024-03-29T06:00:00.735Z\",\"end_time\":\"2024-04-05T06:00:00.735Z\"}}]},\"judgements\":{\"count\":1,\"docs\":[{\"valid_time\":{\"start_time\":\"2024-03-29T06:00:00.735Z\",\"end_time\":\"2024-04-05T06:00:00.735Z\"},\"schema_version\":\"1.0.22\",\"observable\":{\"value\":\"http://freedommms.space/demadel\",\"type\":\"url\"},\"type\":\"judgement\",\"source\":\"IsItPhishing\",\"disposition\":3,\"disposition_name\":\"Suspicious\",\"priority\":85,\"id\":\"transient:judgement-bcf0e901-2283-4261-b779-60ba57771d6c\",\"severity\":\"Medium\",\"confidence\":\"High\"}]}}}]},\"id\":\"investigate-dbe66399\",\"uuid\":\"0c624382-31f0-48cf-9f5a-7375503a18d0\"}]", "short_description": "Snapshot @ 20201124 14:00:35", "id": "https://private.intel.amp.cisco.com:443/ctia/investigation/investigation-1d5ba36e-6e62-44df-b5c0-20cda3d8664b", "tlp": "amber", "groups": ["32e22c6d-7624-477e-8bbd-989c979b552e"], "timestamp": "2020-11-24T14:01:18.006Z", "owner": "9d64bbce-2e7c-43f0-b9d7-0e2fa3c2d88d"} \ No newline at end of file +{"description": "IsItPhishing Suspicious", "schema_version": "1.0.19", "type": "investigation", "search-txt": "url:\"http://freedommms.space/demadel\"", "source": "Anastasiia Rozlyvan", "actions": "[{\"created-perf\":14179879999.999685,\"updated-perf\":14179879999.999685,\"type\":\"collect\",\"created\":\"2020-11-24T14:00:11.607Z\",\"state\":\"ok\",\"arg\":\"url:'http://freedommms.space/demadel'\",\"result\":[{\"value\":\"http://freedommms.space/demadel\",\"type\":\"url\"}],\"id\":\"collect-f45efa18\",\"uuid\":\"d3875f77-5348-4faa-bbad-550b03cbbc8b\"},{\"created-perf\":15183934999.997292,\"updated-perf\":15183934999.997292,\"type\":\"deliberate\",\"created\":\"2020-11-24T14:00:12.611Z\",\"state\":\"ok\",\"arg\":[{\"type\":\"url\",\"value\":\"http://freedommms.space/demadel\"}],\"result\":{\"data\":[{\"module\":\"AMP File Reputation\",\"module_instance_id\":\"ddcf41a2-3ecb-43e8-b5b2-0e36ad2e16f3\",\"module_type_id\":\"1898d0e8-45f7-550d-8ab5-915f064426dd\",\"data\":{\"verdicts\":{\"count\":0,\"docs\":[]}}},{\"module\":\"IsItPhishing\",\"module_instance_id\":\"ec0d130f-2b03-48fa-89de-864549ceff9f\",\"module_type_id\":\"73c4d670-963c-4ecb-82bc-bf747559c3b4\",\"data\":{\"verdicts\":{\"count\":1,\"docs\":[{\"type\":\"verdict\",\"disposition\":3,\"observable\":{\"value\":\"http://freedommms.space/demadel\",\"type\":\"url\"},\"disposition_name\":\"Suspicious\",\"valid_time\":{\"start_time\":\"2024-04-05T06:00:00.735Z\",\"end_time\":\"2024-04-12T06:00:00.735Z\"}}]}}}]},\"id\":\"deliberate-431bf6f1\",\"uuid\":\"bbefe3f7-ea3d-4049-809a-090f200a32fb\"},{\"created-perf\":16190514999.998413,\"updated-perf\":16190514999.998413,\"type\":\"investigate\",\"created\":\"2020-11-24T14:00:13.618Z\",\"state\":\"ok\",\"arg\":{\"type\":\"url\",\"value\":\"http://freedommms.space/demadel\"},\"result\":{\"data\":[{\"module\":\"urlscan. URL and website sandbox\",\"module_instance_id\":\"b158950e-9754-4e01-bc9c-4b66d241874d\",\"module_type_id\":\"a0d1f3ca-bc86-4b87-b6de-496d3c4b4d63\",\"data\":{}},{\"module\":\"IsItPhishing\",\"module_instance_id\":\"ec0d130f-2b03-48fa-89de-864549ceff9f\",\"module_type_id\":\"73c4d670-963c-4ecb-82bc-bf747559c3b4\",\"data\":{\"verdicts\":{\"count\":1,\"docs\":[{\"type\":\"verdict\",\"disposition\":3,\"observable\":{\"value\":\"http://freedommms.space/demadel\",\"type\":\"url\"},\"disposition_name\":\"Suspicious\",\"valid_time\":{\"start_time\":\"2024-04-05T06:00:00.735Z\",\"end_time\":\"2024-04-12T06:00:00.735Z\"}}]},\"judgements\":{\"count\":1,\"docs\":[{\"valid_time\":{\"start_time\":\"2024-04-05T06:00:00.735Z\",\"end_time\":\"2024-04-12T06:00:00.735Z\"},\"schema_version\":\"1.0.22\",\"observable\":{\"value\":\"http://freedommms.space/demadel\",\"type\":\"url\"},\"type\":\"judgement\",\"source\":\"IsItPhishing\",\"disposition\":3,\"disposition_name\":\"Suspicious\",\"priority\":85,\"id\":\"transient:judgement-bcf0e901-2283-4261-b779-60ba57771d6c\",\"severity\":\"Medium\",\"confidence\":\"High\"}]}}}]},\"id\":\"investigate-dbe66399\",\"uuid\":\"0c624382-31f0-48cf-9f5a-7375503a18d0\"}]", "short_description": "Snapshot @ 20201124 14:00:35", "id": "https://private.intel.amp.cisco.com:443/ctia/investigation/investigation-1d5ba36e-6e62-44df-b5c0-20cda3d8664b", "tlp": "amber", "groups": ["32e22c6d-7624-477e-8bbd-989c979b552e"], "timestamp": "2020-11-24T14:01:18.006Z", "owner": "9d64bbce-2e7c-43f0-b9d7-0e2fa3c2d88d"} \ No newline at end of file