diff --git a/STIX_for_digital_forensics/Email_Harassment/email_harassment.svg b/STIX_for_digital_forensics/Email_Harassment/email_harassment.svg new file mode 100644 index 0000000..55ac393 --- /dev/null +++ b/STIX_for_digital_forensics/Email_Harassment/email_harassment.svg @@ -0,0 +1,797 @@ + + + + + + + + + + + + + + + + + + + + + + + + + Page-1 + + + + Rectangle.1002 + x-crime-case: Email Harassment + + + + + + + x-crime-case:Email Harassment + + Rectangle.1021 + x-action: Access willselfdestruct.com + + + + + + + x-action:Access willselfdestruct.com + + Dynamic connector.1024 + action_refs + + + + + action_refs + + Rectangle.1006 + x-timeline + + + + + + + x-timeline + + Dynamic connector.1192 + reconstructed_from_ref + + + + + reconstructed_from_ref + + Rectangle.1001 + indicator: accessed the website + + + + + + + indicator:accessed the website + + Rectangle.1027 + observed-data + + + + + + + observed-data + + Dynamic connector.1028 + indicated-by + + + + + indicated-by + + Dynamic connector.1032 + based-on + + + + + based-on + + Rectangle.1075 + network-traffic + + + + + + + network-traffic + + Dynamic connector.1035 + object_refs + + + + + object_refs + + Rectangle.1016 + ip4-addr + + + + + + + ip4-addr + + Rectangle.1017 + domain-name + + + + + + + domain-name + + Dynamic connector.1018 + src_ref + + + + + src_ref + + Dynamic connector.1019 + dst_ref + + + + + dst_ref + + Rectangle.1020 + indicator: submitted a form that forms a harassment email + + + + + + + indicator:submitted a form that forms a harassment email + + Dynamic connector.1021 + indicated-by + + + + + indicated-by + + Rectangle.1024 + observed-data + + + + + + + observed-data + + Dynamic connector.1025 + based-on + + + + + based-on + + Dynamic connector.1026 + object_refs + + + + + object_refs + + Rectangle.1027 + threat-actor + + + + + + + threat-actor + + Rectangle.1028 + x-computer + + + + + + + x-computer + + Dynamic connector.1029 + has + + + + + has + + Dynamic connector.1031 + used-by + + + + + used-by + + Rectangle.1033 + network-traffic + + + + + + + network-traffic + + Rectangle.1034 + mac-add + + + + + + + mac-add + + Dynamic connector.1035 + resolves-to + + + + + resolves-to + + Dynamic connector.1036 + has + + + + + has + + Rectangle.1037 + infrastructure + + + + + + + infrastructure + + Dynamic connector.1038 + indicates + + + + + indicates + + Dynamic connector.1039 + indicates + + + + + indicates + + Dynamic connector.1040 + consists-of + + + + + consists-of + + Dynamic connector.1041 + ues + + + + + ues + + Rectangle.1042 + x-action: submitted a harassment form + + + + + + + x-action:submitted a harassment form + + Dynamic connector.1043 + action_refs + + + + + action_refs + + Dynamic connector.1044 + dst_ref + + + + + dst_ref + + Dynamic connector.1045 + src_ref + + + + + src_ref + + Rectangle.1046 + email-message + + + + + + + email-message + + Rectangle.1047 + email-addr + + + + + + + email-addr + + Dynamic connector.1048 + to_refs + + + + + to_refs + + Rectangle.1049 + email-addr + + + + + + + email-addr + + Dynamic connector.1050 + from_refs + + + + + from_refs + + Rectangle.1051 + url + + + + + + + url + + Dynamic connector.1052 + consists-of + + + + + consists-of + + Rectangle.1054 + indicator: An email contains a harassment link to the website + + + + + + + indicator:An email contains a harassment link to the website + + Rectangle.1055 + observed-data + + + + + + + observed-data + + Dynamic connector.1056 + based-on + + + + + based-on + + Dynamic connector.1057 + object_refs + + + + + object_refs + + Dynamic connector.1058 + object_refs + + + + + object_refs + + Rectangle.1061 + indicator: A link leads to a harassment message + + + + + + + indicator:A link leads to a harassment message + + Rectangle.1062 + observed-data + + + + + + + observed-data + + Dynamic connector.1063 + based-on + + + + + based-on + + Rectangle.1066 + x-webpage + + + + + + + x-webpage + + Dynamic connector.1067 + url_ref + + + + + url_ref + + Dynamic connector.1068 + object_refs + + + + + object_refs + + Rectangle.1069 + x-investigation-tool + + + + + + + x-investigation-tool + + Rectangle.1070 + file + + + + + + + file + + Dynamic connector.1108 + inputs_refs + + + + + inputs_refs + + Dynamic connector.1104 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1073 + outputs_refs + + + + + outputs_refs + + Dynamic connector.1074 + case_file_refs + + + + + case_file_refs + + + + + + + + + + + + + + + + + Note.1193 + [network-traffic:src_ref.value='192.168.15.4' AND network-tra... + + + + + + + [network-traffic:src_ref.value='192.168.15.4' AND network-traffic:dst_ref.value='www.willselfdestruct.com' ANDinfrastrcture:consists-of.value='www.willselfdestruct.com' ] + + Sheet.1013 + + + + + + + + + + + + + + + + + + + + + + + Note.1022 + [network-traffic:extensions.http-request-ext.request_method='... + + + + + + + [network-traffic:extensions.http-request-ext.request_method='POST' ANDnetwork-traffic:extensions.http-request-ext.request_header.host='www.willselfdestruct.com'' ANDnetwork-traffic:extensions.http-request-ext.request_header.Content-Type. application/x-www-form-urlencoded.to='lilytruckrige@yahoo.com' ANDnetwork-traffic:extensions.http-request-ext.request_header.Content-Type. application/x-www-form-urlencoded.subject='you can't find us' ANDnetwork-traffic:extensions.http-request-ext.request_header.Content-Type. application/x-www-form-urlencoded.message='and you can't hide from us. Stop teaching.' ANDinfrastrcture:consists-of.value='www.willselfdestruct.com' ] + + Sheet.1023 + + + + + + + + + + + + + + + + + + + + + + + Note.1059 + [url:value='www.willselfdestruct.com' AND email-message:body ... + + + + + + + [url:value='www.willselfdestruct.com' AND email-message:body MATCHES 'www.willselfdestruct.com'] + + Sheet.1060 + + + + + + + + + + + + + + + + + + + + + + + Note.1064 + [webpage:url_ref:value='www.willselfdestruct.com' AND webpage... + + + + + + + [webpage:url_ref:value='www.willselfdestruct.com' AND webpage:content MATCHES 'you can't find us' AND webpage:content MATCHES 'and you can't hide from us. Stop teaching.'] + + Sheet.1065 + + + + + + + + diff --git a/STIX_for_digital_forensics/Email_Harassment/email_harassment.vsdx b/STIX_for_digital_forensics/Email_Harassment/email_harassment.vsdx new file mode 100644 index 0000000..9029262 Binary files /dev/null and b/STIX_for_digital_forensics/Email_Harassment/email_harassment.vsdx differ