{
  "date": "2018-08-12",
  "affected": "192.168.1.95",
  "family": "Marap-associated alert; author leaves precise family uncertain",
  "outcome": "partial",
  "reviewed_story": "Mikhail Petrov’s PETROV2018-PC (192.168.1.95) followed a download chain and repeatedly posted to 185.68.93[.]18/dot.php. The publisher links the chain to an IQY email attachment and notes a Marap-associated alert, while retaining family uncertainty. The native summary captures the host and callbacks but does not identify the initiating attachment or clearly explain the executable stage.",
  "matched": "Correct workstation/user and recurring POST destination.",
  "gaps": "Does not explain the IQY-to-download chain. Its selected suspicious file hash is not listed by the answer, so it is not counted as an answer-confirmed payload.",
  "caution": "Email attachments were not model input. The page date is August 12, whereas the packet incident is August 11. Do not turn the publisher’s tentative family discussion into a categorical verdict.",
  "hashes": [],
  "case_number": 20,
  "name": "Sputnik House",
  "analysis_id": "720a1250-ec20-4280-911f-2a97345018f1",
  "capture_sha256": "c9e136e6e53daec4deec416e545d56e3c430dbc2d38374cf7a4dc839a0f4a3ff",
  "summary_id": "investigation-summary:faa2e9a4-9421-475e-b2aa-c3abee8088a2",
  "native_summary_saved": true,
  "affected_ip_in_short_report": true,
  "affected_reference_boundary": "explicitly stated in reference text",
  "reference_source": {
    "url": "https://www.malware-traffic-analysis.net/2018/08/12/2018-08-12-traffic-analysis-exercise-answers.pdf.zip",
    "retrieved_at": "2026-09-22T19:43:11.046922+00:00",
    "zip_sha256": "8fdaa4ad3d8881047476bb572b82567325204272b29fb7f6856b740fe5c32018",
    "pdf_sha256": "887fa632200779537234fa9a109d9e9785186718b807c492c6f873a1a58d0a6f",
    "archive_member": "2018-08-12-traffic-analysis-exercise-answers.pdf",
    "scope": "Official reference answers, evaluation-only; never supplied to platform or report model."
  },
  "reference_answer_page": "https://www.malware-traffic-analysis.net/2018/08/12/page2.html",
  "reference_hash_checks": [],
  "native_ioc_reviews": [
    {
      "value": "b908d9b1001d0a39ba92501c086b1c25b05b171eeda035ae9f3e129d2776a314",
      "kind": "sha256",
      "native_explanation": "SHA-256 b908d9b1001d0a39ba92501c086b1c25b05b171eeda035ae9f3e129d2776a314 is the downloaded suspicious file for review, flagged by static features.",
      "review": "not_explicitly_addressed_by_reference_text"
    },
    {
      "value": "185.68.93.18",
      "kind": "ipv4",
      "native_explanation": "IP 185.68.93.18 is the external host receiving repeated HTTP POST callbacks from the involved host.",
      "review": "corroborated_callback"
    },
    {
      "value": "http://185.68.93.18/dot.php",
      "kind": "url",
      "native_explanation": "http://185.68.93.18/dot.php is the suspicious callback URL for POST activity from the internal host.",
      "review": "corroborated_callback"
    }
  ],
  "scope": "Post-freeze reviewer comparison, never supplied to report-writing model. Reference may use alerts, email and endpoint artifacts absent from PCAP-only input."
}
