DShield Sensor JSON Log Analysis - SANS Internet Storm Center
Tags
attack-pattern: Ssh - T1021.004
Common Information
Type Value
UUID bd72c7be-b2ea-4d48-909f-654c7eda3b6b
Fingerprint 2be1b1280b220c90
Analysis status DONE
Considered CTI value 0
Text language
Published Jan. 8, 2023, midnight
Added to db Oct. 24, 2023, 1:32 p.m.
Last updated Nov. 17, 2024, 5:57 p.m.
Headline Internet Storm Center
Title DShield Sensor JSON Log Analysis - SANS Internet Storm Center
Detected Hints/Tags/Attributes 8/1/14
Source URLs
Attributes
Details Type #Events CTI Value
Details Domain 7
stedolan.github.io
Details Domain 2
powerbi.microsoft.com
Details Domain 425
isc.sans.edu
Details Domain 3
handlers.sans.edu
Details File 3
cowrie.json
Details File 1
connect.csv
Details File 2
ipinfo.html
Details IPv4 2
193.105.134.95
Details Url 1
https://stedolan.github.io/jq/download
Details Url 2
https://powerbi.microsoft.com/en-us/downloads
Details Url 1
https://isc.sans.edu/diary/29370
Details Url 1
https://isc.sans.edu/diary/28872
Details Url 1
https://isc.sans.edu/ipinfo.html?ip=193.105.134.95
Details Url 2
https://handlers.sans.edu/gbruneau/scripts/process_geoip.sh