Skip to content

The Malware object describes the classification of known malicious software, which is intentionally designed to cause damage to a computer, server, client, or computer network.

  • Extends: _entity

classification_ids

  • Type: integer_t
  • Requirement: required
  • Values:
    • 0 - Unknown
    • 1 - Adware
    • 2 - Backdoor
    • 3 - Bot
    • 4 - Bootkit
    • 5 - DDOS
    • 6 - Downloader
    • 7 - Dropper
    • 8 - Exploit-Kit
    • 9 - Keylogger
    • 10 - Ransomware
    • 11 - Remote-Access-Trojan
    • 13 - Resource-Exploitation
    • 14 - Rogue-Security-Software
    • 15 - Rootkit
    • 16 - Screen-Capture
    • 17 - Spyware
    • 18 - Trojan
    • 19 - Virus
    • 20 - Webshell
    • 21 - Wiper
    • 22 - Worm
    • 99 - Other

The list of normalized identifiers of the malware classifications. Reference: STIX Malware Types

name

  • Type: string_t
  • Requirement: recommended

The malware name, as reported by the detection engine.

path

  • Type: string_t
  • Requirement: recommended

The filesystem path of the malware that was observed.

provider

  • Type: string_t
  • Requirement: recommended

The provider of the malware information.

uid

  • Type: string_t
  • Requirement: recommended

The malware unique identifier, as reported by the detection engine. For example a virus id or an IPS signature id.

classifications

  • Type: string_t
  • Requirement: optional

The list of malware classifications, normalized to the captions of the classification_id values. In the case of ‘Other’, they are defined by the event source.

cves

  • Type: cve
  • Requirement: optional

List of Common Vulnerabilities and Exposures (CVE).

At least one of: name, uid