Skip to content

Instantly share code, notes, and snippets.

@rustybrooks
Created September 14, 2016 13:26
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save rustybrooks/1dea0b5a566c9cf19a0eb73576275e92 to your computer and use it in GitHub Desktop.
Save rustybrooks/1dea0b5a566c9cf19a0eb73576275e92 to your computer and use it in GitHub Desktop.
{
"reputation": {
"as": "11042",
"threat_score": 2,
"counts": {
"Scanning Host": 1,
"Malware Domain": 10
},
"first_seen": "2012-09-28T18:37:52",
"city": null,
"allow_ping": "",
"reputation_rel_checked": 1,
"lon": -97,
"state": -1,
"last_seen": "2013-08-22T23:50:46",
"status": 1,
"activities": [
{
"domain": "cronhosting.com",
"name": "Malware Domain",
"visible": "1",
"url": "http://cronhosting.com/yjioe/isaht/2.js",
"data": {
"url": "http://cronhosting.com/yjioe/isaht/2.js",
"domain": "cronhosting.com",
"vt": {
"F-Secure": "Trojan.Script.187651",
"GData": "Trojan.Script.187651",
"AntiVir": "JS/Dldr.Agent.psyx",
"Norman": "W32/Suspicious_Gen2.SVBPK",
"McAfee-GW-Edition": "Heuristic.BehavesLike.JS.Obfuscated.A",
"Sophos": "JS/RefC-Gen",
"nProtect": "Trojan.Script.187651",
"BitDefender": "Trojan.Script.187651",
"AhnLab-V3": "JS/Downloader",
"Microsoft": "Trojan:JS/Redirector.IT",
"AVG": "HTML/Framer.BW",
"Avast": "JS:Redirector-I [Trj]",
"Comodo": "UnclassifiedMalware"
},
"file": "ASCII text, with very long lines, with no line terminators",
"md5": "54a800b1b53fe3a88f21bdf90704e1b0"
},
"source": "url-system-virustotal",
"vt": "F-Secure: Trojan.Script.187651<br>GData: Trojan.Script.187651<br>AntiVir: JS/Dldr.Agent.psyx<br>Norman: W32/Suspicious_Gen2.SVBPK<br>McAfee-GW-Edition: Heuristic.BehavesLike.JS.Obfuscated.A<br>Sophos: JS/RefC-Gen<br>nProtect: Trojan.Script.187651<br>BitDefender: Trojan.Script.187651<br>AhnLab-V3: JS/Downloader<br>Microsoft: Trojan:JS/Redirector.IT<br>AVG: HTML/Framer.BW<br>Avast: JS:Redirector-I [Trj]<br>Comodo: UnclassifiedMalware",
"file": "ASCII text, with very long lines, with no line terminators",
"data_key": "url-system-http://cronhosting.com/yjioe/isaht/2.js",
"md5": "54a800b1b53fe3a88f21bdf90704e1b0"
},
{
"domain": "cronhosting.com",
"name": "Malware Domain",
"visible": "1",
"url": "http://cronhosting.com/yjioe/isaht/2.js",
"data": {
"url": "http://cronhosting.com/yjioe/isaht/2.js",
"domain": "cronhosting.com",
"vt": {
"F-Secure": "Trojan.Script.187651",
"GData": "Trojan.Script.187651",
"AntiVir": "JS/Dldr.Agent.psyx",
"Norman": "Suspicious_Gen2.SVBPK",
"McAfee-GW-Edition": "Heuristic.BehavesLike.JS.Obfuscated.A",
"Sophos": "JS/RefC-Gen",
"nProtect": "Trojan.Script.187651",
"BitDefender": "Trojan.Script.187651",
"AhnLab-V3": "JS/Downloader",
"Antiy-AVL": "Trojan/win32.agent",
"Microsoft": "Trojan:JS/Redirector.IT",
"AVG": "HTML/Framer.BW",
"Avast": "JS:Redirector-I [Trj]",
"Comodo": "UnclassifiedMalware"
},
"file": "ASCII text, with very long lines, with no line terminators",
"md5": "54a800b1b53fe3a88f21bdf90704e1b0"
},
"source": "url-system-virustotal",
"vt": "F-Secure: Trojan.Script.187651<br>GData: Trojan.Script.187651<br>AntiVir: JS/Dldr.Agent.psyx<br>Norman: Suspicious_Gen2.SVBPK<br>McAfee-GW-Edition: Heuristic.BehavesLike.JS.Obfuscated.A<br>Sophos: JS/RefC-Gen<br>nProtect: Trojan.Script.187651<br>BitDefender: Trojan.Script.187651<br>AhnLab-V3: JS/Downloader<br>Antiy-AVL: Trojan/win32.agent<br>Microsoft: Trojan:JS/Redirector.IT<br>AVG: HTML/Framer.BW<br>Avast: JS:Redirector-I [Trj]<br>Comodo: UnclassifiedMalware",
"file": "ASCII text, with very long lines, with no line terminators",
"data_key": "url-system-http://cronhosting.com/yjioe/isaht/2.js",
"md5": "54a800b1b53fe3a88f21bdf90704e1b0"
},
{
"status": 1,
"domain": "qualityfinserv.com",
"name": "Malware Domain",
"first_date": "2012-09-28T18:37:52",
"data": {
"domain": "qualityfinserv.com"
},
"source": "malware-domains",
"last_date": "2012-09-28T18:37:52",
"data_key": "qualityfinserv.com malware"
},
{
"status": 1,
"domain": "qualityfinserv.com",
"name": "Malware Domain",
"first_date": "2012-10-19T01:56:56",
"data_key": "qualityfinserv.com malware",
"source": "malware-domains",
"last_date": "2012-10-19T01:56:56",
"data": {
"domain": "qualityfinserv.com"
}
}
],
"server_type": "",
"matched_bl": [
"None"
],
"address": "69.73.130.198",
"lat": 38,
"date_added": {
"usec": 308000,
"sec": 1338991650
},
"country": "US (United States)",
"up": 0,
"reputation_rel": "2",
"matched_wl": [
"None"
],
"domains": [
"additon.co.id",
"arsalgroup.com",
"astutesol.com",
"avin.net",
"ayb.am"
],
"reputation_val_checked": 1,
"_id": {
"$id": "4fcf642203b04d42c100028f"
},
"reputation_val": "2"
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment