<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="4.3.3">Jekyll</generator><link href="/obstracts_demo/feed.xml" rel="self" type="application/atom+xml" /><link href="/obstracts_demo/" rel="alternate" type="text/html" /><updated>2025-10-10T14:24:54+00:00</updated><id>/obstracts_demo/feed.xml</id><title type="html">Obstracts Demo</title><subtitle>Ingest this blog into Obstracts and watch the magic happen.</subtitle><entry><title type="html">[DEMO] A list of IoCs</title><link href="/obstracts_demo/demos/2020/01/02/iocs.html" rel="alternate" type="text/html" title="[DEMO] A list of IoCs" /><published>2020-01-02T08:00:00+00:00</published><updated>2020-01-02T08:00:00+00:00</updated><id>/obstracts_demo/demos/2020/01/02/iocs</id><content type="html" xml:base="/obstracts_demo/demos/2020/01/02/iocs.html"><![CDATA[<p>Here are just some of the extractions Obstracts can perform</p>

<p>1.1.1.1</p>

<p>1.1.1.1/24</p>

<p>1.1.1.1:80</p>

<p>2001:0db8:85a3:0000:0000:8a2e:0370:7334</p>

<p>google.com</p>

<p>igvmwp3544wpnd6u.onion</p>

<p>subdomain.microsoft.com</p>

<p>file.exe</p>

<p>C:\Windows\System64</p>

<p>/a/file/path/file.sh</p>

<p>4ec503be252d765ea37621a629afdaa6</p>

<p>86F7E437FAA5A7FCE15D1DDCB9EAEAEA377667B8</p>

<p>d14a028c2a3a2bc9476102bb288234c415a2b01f828ea62ac5b3e42f</p>

<p>e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855</p>

<p>59e1748777448c69de6b800d7a33bbfb9ff1b463e44354c3553bcdb9c666fa90125a3c79f90397bdf5f6a13de828684f</p>

<p>75d527c368f2efe848ecf6b073a36767800805e9eef2b1857d5f984f036eb6df891d75f72d9b154518c1cd58835286d1da9a38deba3de98b5a53e5ed78a84976</p>

<p>example@example.com</p>

<p>d2:fb:49:24:37:18</p>

<p>00-B0-D0-63-C2-26</p>

<p>HKEY_LOCAL_MACHINE\System\Foo\Bar</p>

<p>Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.6) Gecko/20040113</p>

<p>ASN15139</p>

<p>CVE-2019-4706</p>

<p>cpe:2.3:a:codecabin:wp_go_maps:7.10.58:<em>:</em>:<em>:basic:wordpress:</em>:*</p>

<p>5555555555554444</p>

<p>GB94BARC10201530093459</p>

<p>AU</p>

<p>GB</p>

<p>T1174</p>

<p>TA0006</p>]]></content><author><name></name></author><category term="demos" /><summary type="html"><![CDATA[Here are just some of the extractions Obstracts can perform]]></summary></entry><entry><title type="html">[DEMO] Some information about fakedomain.com</title><link href="/obstracts_demo/demos/2020/01/01/fakedomain.html" rel="alternate" type="text/html" title="[DEMO] Some information about fakedomain.com" /><published>2020-01-01T08:00:00+00:00</published><updated>2020-01-01T08:00:00+00:00</updated><id>/obstracts_demo/demos/2020/01/01/fakedomain</id><content type="html" xml:base="/obstracts_demo/demos/2020/01/01/fakedomain.html"><![CDATA[<p>See the rich relationships Obstracts can generate</p>

<p>fakedomain.com resolves to 1.1.1.1.</p>

<p>fakedomain.com has been known to distribute revil malware sent in  email attachments from the email address fakedomain@email.com</p>

<p>revil is uses the att&amp;ck techniques T1548, T1548.001 and T1650. As well as tools S1061 and S0677.</p>]]></content><author><name></name></author><category term="demos" /><summary type="html"><![CDATA[See the rich relationships Obstracts can generate]]></summary></entry></feed>