Skip to content

Instantly share code, notes, and snippets.

@coolacid
Created April 20, 2015 14:59
Show Gist options
  • Save coolacid/a6ab2e481ae50900c703 to your computer and use it in GitHub Desktop.
Save coolacid/a6ab2e481ae50900c703 to your computer and use it in GitHub Desktop.
{
"_shard": 0,
"_node": "fan7MZSvSUS6LS3XcwQFfA",
"_index": "cif.observables-2015.04.20",
"_type": "observables",
"_id": "bafb0b47000be58fb6c4f08f29af81704531965b0bd907e57c7f99c69ae194b8",
"_score": 1,
"fields": {
"tags": [
"suspicious"
],
"protocol": [
6
],
"application": [
"http",
"https"
],
"provider": [
"spamhaus.org"
],
"confidence": [
95
],
"tlp": [
"green"
],
"@version": [
2
],
"lang": [
"EN"
],
"firsttime": [
"2015-04-20T04:06:26Z"
],
"related": [
"8a8647dfd6b80bda02878afe106735bb15c9c513cfa4b49f5d09df333080771b"
],
"id": [
"bafb0b47000be58fb6c4f08f29af81704531965b0bd907e57c7f99c69ae194b8"
],
"@timestamp": [
"2015-04-20T04:06:26.651Z"
],
"altid": [
"http://www.spamhaus.org/query/dbl?domain=anonymz.com"
],
"reporttime": [
"2015-04-20T04:06:26Z"
],
"lasttime": [
"2015-04-20T04:06:26Z"
],
"altid_tlp": [
"green"
],
"otype": [
"fqdn"
],
"group": [
"everyone"
],
"observable": [
"anonymz.com"
]
},
"sort": [
1
],
"_explanation": {
"value": 1,
"description": "sum of:",
"details": [
{
"value": 1,
"description": "ConstantScore(*:*), product of:",
"details": [
{
"value": 1,
"description": "boost"
},
{
"value": 1,
"description": "queryNorm"
}
]
}
]
}
}
{
"_shard": 0,
"_node": "fan7MZSvSUS6LS3XcwQFfA",
"_index": "cif.observables-2015.04.20",
"_type": "observables",
"_id": "d208dd7cb399f2d85cd870a528f9abc259d45315ee249b0c549c2ae7b1ae2e1d",
"_score": 1,
"fields": {
"portlist": [
"22"
],
"@version": [
2
],
"lang": [
"EN"
],
"firsttime": [
"2015-04-19T20:23:27Z"
],
"id": [
"d208dd7cb399f2d85cd870a528f9abc259d45315ee249b0c549c2ae7b1ae2e1d"
],
"timezone": [
"Europe/Dublin"
],
"geolocation": [
"53.3478,-6.2597"
],
"lasttime": [
"2015-04-19T20:23:27Z"
],
"longitude": [
"-6.2597"
],
"tags": [
"scanner"
],
"rir": [
"ripencc"
],
"protocol": [
6
],
"application": [
"ssh"
],
"asn_desc": [
"BLACKNIGHT-AS Blacknight Internet Solutions Ltd,IE"
],
"provider": [
"danger.rulez.sk"
],
"confidence": [
85
],
"tlp": [
"green"
],
"@timestamp": [
"2015-04-20T04:52:03.811Z"
],
"altid": [
"http://danger.rulez.sk/projects/bruteforceblocker/blist.php"
],
"reporttime": [
"2015-04-20T04:50:59Z"
],
"prefix": [
"78.153.192.0/19"
],
"asn": [
"39122"
],
"latitude": [
"53.3478"
],
"otype": [
"ipv4"
],
"group": [
"everyone"
],
"observable": [
"78.153.211.146"
],
"cc": [
"IE"
]
},
"sort": [
1
],
"_explanation": {
"value": 1,
"description": "sum of:",
"details": [
{
"value": 1,
"description": "ConstantScore(*:*), product of:",
"details": [
{
"value": 1,
"description": "boost"
},
{
"value": 1,
"description": "queryNorm"
}
]
}
]
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment