forked from macar-cm/xarf-schemata
-
Notifications
You must be signed in to change notification settings - Fork 0
/
abuse_malware-attack_0.1.0.json
72 lines (72 loc) · 1.9 KB
/
abuse_malware-attack_0.1.0.json
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
{
"description":"A report for an abusive attack carried out by a malware",
"type":"object",
"properties":{
"Reported-From":{
"type":"string",
"format":"email"
},
"Report-ID":{
"type":"string",
"format":"email"
},
"Category":{
"type":"string",
"enum":["abuse"]
},
"Report-Type":{
"description":"This field follows - in brief - the overall description above",
"type":"string",
"enum":["malware-attack"]
},
"Destination-System":{
"description":"This field describes - more or less exactly - the targeted system which provides the evidence laid down in this report",
"type":"string",
"enum":["real-world","honeypot","spamtrap","honeyd","nepenthes"],
"optional":true
},
"User-Agent":{
"description":"This field describes the software which generated this report email, this is not necessarily software used on the targeted system",
"type":"string"
},
"Date":{
"type":"string",
"format":"date-time"
},
"Source":{
"description":"This field describes the source-ip of the infection, no matter how the attack was carried out",
"type":"string"
},
"Source-Type":{
"type":"string",
"enum":["ipv4","ipv6","ip-address"]
},
"Download-Link":{
"type":"string",
"format":"uri",
"optional":true
},
"Malware-MD5":{
"type":"string",
"optional":true
},
"Antivirus-Result":{
"type":"string",
"optional":true
},
"Antivirus-Vendor":{
"type":"string",
"optional":true,
"requires":"Antivirus-Result"
},
"Attachment":{
"description":"An attachment should provide information about how and from where the malware infection took place if not already evident by the yaml report information",
"type":"string",
"enum":["NO","text/plain", "message/rfc822"]
},
"Schema-URL":{
"type":"string",
"format":"uri"
}
}
}