Guest User

for Remco

a guest
Feb 28th, 2019
46
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.75 KB | None | 0 0
  1. {
  2. "ip": "168.197.8.233",
  3. "update_time": "2019-02-28T06:07:00.395Z",
  4. "classifications": [
  5. {
  6. "name": "Generic Botnet",
  7. "classified_time": "2019-02-27T09:39:20Z"
  8. }
  9. ],
  10. "source1type": 2,
  11. "source1": {
  12. "update_time": "2019-02-27T09:18:05.565Z",
  13. "@timestamp": "2019-02-27T02:22:56.058Z",
  14. "data": [
  15. {
  16. "attacks": [
  17. {
  18. "@timestamp": "2019-02-27T02:23:03.953Z",
  19. "AttackLog": "login attempt succeed: username:root / password:GLzaoX4uMYFCCcmr0",
  20. "eventid": "login.success"
  21. }
  22. ],
  23. "protocol": "SSH",
  24. "session": "dff46222142b"
  25. },
  26. {
  27. "attacks": [
  28. {
  29. "@timestamp": "2019-02-27T02:22:53.754Z",
  30. "AttackLog": "login attempt succeed: username:root / password:root",
  31. "eventid": "login.success"
  32. },
  33. {
  34. "@timestamp": "2019-02-27T02:22:54.606Z",
  35. "AttackLog": "/ip cloud print",
  36. "eventid": "command.input"
  37. },
  38. {
  39. "@timestamp": "2019-02-27T02:22:56.058Z",
  40. "AttackLog": "ifconfig",
  41. "eventid": "command.input"
  42. },
  43. {
  44. "@timestamp": "2019-02-27T02:22:57.103Z",
  45. "AttackLog": "uname -a",
  46. "eventid": "command.input"
  47. },
  48. {
  49. "@timestamp": "2019-02-27T02:22:58.049Z",
  50. "AttackLog": "cat /proc/cpuinfo",
  51. "eventid": "command.input"
  52. },
  53. {
  54. "@timestamp": "2019-02-27T02:22:59.127Z",
  55. "AttackLog": "ps | grep '[Mm]iner'",
  56. "eventid": "command.input"
  57. },
  58. {
  59. "@timestamp": "2019-02-27T02:23:00.129Z",
  60. "AttackLog": "ps -ef | grep '[Mm]iner'",
  61. "eventid": "command.input"
  62. },
  63. {
  64. "@timestamp": "2019-02-27T02:23:01.19Z",
  65. "AttackLog": "echo Hi | cat -n",
  66. "eventid": "command.input"
  67. }
  68. ],
  69. "protocol": "SSH",
  70. "session": "5a28b1500f37"
  71. }
  72. ]
  73. },
  74. "source2type": 0,
  75. "source2": {
  76. "update_time": "0001-01-01T00:00:00Z",
  77. "@timestamp": "0001-01-01T00:00:00Z",
  78. "data": null
  79. },
  80. "source3type": 0,
  81. "source3": {
  82. "update_time": "0001-01-01T00:00:00Z",
  83. "@timestamp": "0001-01-01T00:00:00Z",
  84. "data": []
  85. }
  86. }
Add Comment
Please, Sign In to add comment