STIX2 json for 2026-07-20

STIX2 json for all bruteforce attempts for 2026-07-20

Last Updated: 11:07 UTC

Download STIX2 json File

']", "pattern_type": "stix", "valid_from": "2026-07-20T00:00:00.000Z", "valid_until": "2026-08-19T23:59:59.000Z", "kill_chain_phases": [{"kill_chain_name": "lockheed-martin-cyber-kill-chain", "phase_name": "exploitation"}], "external_references": [{"source_name": "jamesbrine.com.au Threat Intelligence", "description": "Daily threat feed", "url": "https://jamesbrine.com.au/2026-07-20-stix2-json-feed/"}], "labels": ["sensor:digitaloceanlondon", "protocol:ftp", "protocol:git", "protocol:mssql", "protocol:mysql", "protocol:ntp", "protocol:portscan", "protocol:redis", "protocol:sip", "protocol:snmp", "protocol:ssh", "protocol:telnet", "protocol:web"], "created_by_ref": "identity--8f46cf6a-622e-4127-bbdd-968d59ea87e0", "created": "2026-07-21T11:00:02.171Z", "modified": "2026-07-21T11:00:02.171Z", "object_marking_refs": ["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"]}, {"type": "indicator", "spec_version": "2.1", "id": "indicator--c4972861-7cf8-447d-9980-78eff1c66ee8", "name": "Malicious Host", "description": "Observed: FTP, GIT, MSSQL, MYSQL, NTP, PORTSCAN, REDIS, SIP, SNMP, SSH, TELNET, WEB activity. Sensors: digitaloceanlondon", "indicator_types": ["malicious-activity"], "pattern": "[ipv4-addr:value = '']", "pattern_type": "stix", "valid_from": "2026-07-20T00:00:00.000Z", "valid_until": "2026-08-19T23:59:59.000Z", "kill_chain_phases": [{"kill_chain_name": "lockheed-martin-cyber-kill-chain", "phase_name": "exploitation"}], "external_references": [{"source_name": "jamesbrine.com.au Threat Intelligence", "description": "Daily threat feed", "url": "https://jamesbrine.com.au/2026-07-20-stix2-json-feed/"}], "labels": ["sensor:digitaloceanlondon", "protocol:ftp", "protocol:git", "protocol:mssql", "protocol:mysql", "protocol:ntp", "protocol:portscan", "protocol:redis", "protocol:sip", "protocol:snmp", "protocol:ssh", "protocol:telnet", "protocol:web"], "created_by_ref": "identity--8f46cf6a-622e-4127-bbdd-968d59ea87e0", "created": "2026-07-21T11:00:02.171Z", "modified": "2026-07-21T11:00:02.171Z", "object_marking_refs": ["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"]}, {"type": "indicator", "spec_version": "2.1", "id": "indicator--e0af1514-176c-4f9c-a770-bc092e60b774", "name": "Malicious Host", "description": "Observed: FTP, GIT, MSSQL, MYSQL, NTP, PORTSCAN, REDIS, SIP, SNMP, SSH, TELNET, WEB activity. Sensors: digitaloceanlondon", "indicator_types": ["malicious-activity"], "pattern": "[ipv4-addr:value = '']", "pattern_type": "stix", "valid_from": "2026-07-20T00:00:00.000Z", "valid_until": "2026-08-19T23:59:59.000Z", "kill_chain_phases": [{"kill_chain_name": "lockheed-martin-cyber-kill-chain", "phase_name": "exploitation"}], "external_references": [{"source_name": "jamesbrine.com.au Threat Intelligence", "description": "Daily threat feed", "url": "https://jamesbrine.com.au/2026-07-20-stix2-json-feed/"}], "labels": ["sensor:digitaloceanlondon", "protocol:ftp", "protocol:git", "protocol:mssql", "protocol:mysql", "protocol:ntp", "protocol:portscan", "protocol:redis", "protocol:sip", "protocol:snmp", "protocol:ssh", "protocol:telnet", "protocol:web"], "created_by_ref": "identity--8f46cf6a-622e-4127-bbdd-968d59ea87e0", "created": "2026-07-21T11:00:02.171Z", "modified": "2026-07-21T11:00:02.171Z", "object_marking_refs": ["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"]}, {"type": "indicator", "spec_version": "2.1", "id": "indicator--882d0e6c-38c5-4a2f-a2be-64d3c69a8ec9", "name": "Malicious Host", "description": "Observed: FTP, GIT, MSSQL, MYSQL, NTP, PORTSCAN, REDIS, SIP, SNMP, SSH, TELNET, WEB activity. Sensors: digitaloceanlondon", "indicator_types": ["malicious-activity"], "pattern": "[ipv4-addr:value = '']", "pattern_type": "stix", "valid_from": "2026-07-20T00:00:00.000Z", "valid_until": "2026-08-19T23:59:59.000Z", "kill_chain_phases": [{"kill_chain_name": "lockheed-martin-cyber-kill-chain", "phase_name": "exploitation"}], "external_references": [{"source_name": "jamesbrine.com.au Threat Intelligence", "description": "Daily threat feed", "url": "https://jamesbrine.com.au/2026-07-20-stix2-json-feed/"}], "labels": ["sensor:digitaloceanlondon", "protocol:ftp", "protocol:git", "protocol:mssql", "protocol:mysql", "protocol:ntp", "protocol:portscan", "protocol:redis", "protocol:sip", "protocol:snmp", "protocol:ssh", "protocol:telnet", "protocol:web"], "created_by_ref": "identity--8f46cf6a-622e-4127-bbdd-968d59ea87e0", "created": "2026-07-21T11:00:02.171Z", "modified": "2026-07-21T11:00:02.171Z", "object_marking_refs": ["marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"]}, {"type": "indicator", "spec_version": "2.1", "id": "indicator--80625979-9cbb-4643-b70c-d693ded07a97", "name": "Malicious Host", "description": "Observed: FTP, GIT, MSSQL, MYSQL, NTP, PORTSCAN, REDIS, SIP, SNMP, SSH, TELNET, WEB activity. Sensors: digitaloceanlondon", "indicator_types": ["malicious-activity"], "pattern": "[ipv4-addr:value = ';

Share on: