{
  "date": "2019-07-19",
  "affected": "172.16.4.205",
  "family": "SocGholish / FakeUpdates delivering NetSupport Manager",
  "outcome": "partial",
  "reviewed_story": "The publisher describes a fake-browser-update infection on ROTTERDAM-PC (172.16.4.205), used by matthijs.devries, followed by NetSupport remote-access traffic and uploaded desktop screenshots. The native summary recognises NetSupport and large POST transfers but does not recover the full fake-update-to-screenshot-theft story. The packet destination is 31.7.62[.]214, despite the answer listing .213.",
  "matched": "Correct host/user, NetSupport-associated traffic and large outbound transfers.",
  "gaps": "Misses SocGholish delivery and identification of the uploaded content as screenshots. The phrase “exceeding one megabyte each” overgeneralises the cited single aggregated finding.",
  "caution": "31.7.62.214 is directly verified in packets; the PDF lists 31.7.62.213. Commercial remote-access software and cleartext HTTP on port 443 require context, not an automatic malware verdict.",
  "hashes": [],
  "case_number": 9,
  "name": "So hot right now",
  "analysis_id": "961bdc9a-7460-440f-a246-f55748149bcc",
  "capture_sha256": "ae759973cbf42e9cd0db35a5450c99f6210fca2c22fb8e689d252e64211bfd36",
  "summary_id": "investigation-summary:60b13529-5cbc-4ec3-af47-296930292eeb",
  "native_summary_saved": true,
  "affected_ip_in_short_report": true,
  "affected_reference_boundary": "explicitly stated in reference text",
  "reference_source": {
    "url": "https://www.malware-traffic-analysis.net/2019/07/19/2019-07-19-traffic-analysis-exercise-answers.pdf.zip",
    "retrieved_at": "2026-09-22T19:42:54.851830+00:00",
    "zip_sha256": "46f35573d8841b633dbe41cc7f635856493735f15a4a2ea740821e01b9b78552",
    "pdf_sha256": "4997aacf214ac649969b4e58598dfd050b053c9fa9805f61173a906acb97cbd2",
    "archive_member": "2019-07-19-traffic-analysis-exercise-answers.pdf",
    "scope": "Official reference answers, evaluation-only; never supplied to platform or report model."
  },
  "reference_answer_page": "https://www.malware-traffic-analysis.net/2019/07/19/page2.html",
  "reference_hash_checks": [],
  "native_ioc_reviews": [
    {
      "value": "31.7.62.214",
      "kind": "ipv4",
      "native_explanation": "The IP 31.7.62.214 received repeated POST requests with a remote-access tool signature from 172.16.4.205.",
      "review": "packet_verified_reference_ip_discrepancy"
    },
    {
      "value": "b5689023.green.mattingsolutions.co",
      "kind": "domain",
      "native_explanation": "The domain b5689023.green.mattingsolutions.co hosted large HTTP POST traffic, which may indicate suspicious outbound data transfer.",
      "review": "not_explicitly_addressed_by_reference_text"
    }
  ],
  "scope": "Post-freeze reviewer comparison, never supplied to report-writing model. Reference may use alerts, email and endpoint artifacts absent from PCAP-only input."
}
