{
  "date": "2019-12-25",
  "affected": "10.12.25.101",
  "family": null,
  "outcome": "missed",
  "reviewed_story": "This capture shows web-server reconnaissance, not an established malware callback. The scanner 139.199.184[.]166 probed the server exposed as 128.199.64[.]235, with internal address 10.12.25.101, including activity against ports 80, 8080 and 8983. The native summary reverses the investigative emphasis by describing possible beaconing or data transfer.",
  "matched": "Contains the external scanner and server addresses, but does not explain their correct security roles.",
  "gaps": "Wrong core scenario; omits the internal victim. Targeted server URLs are presented as beaconing-review indicators. It also suggests contacted URLs received reputation checks, although full-URL enrichment was not performed.",
  "caution": "The PDF’s notes contain 139.119.184.166, while its main answer and capture use 139.199.184.166; this is treated as a reference inconsistency.",
  "hashes": [],
  "case_number": 5,
  "name": "It happened on Christmas day",
  "analysis_id": "389d8086-ac21-4e6d-9270-fdd62ee6d5b0",
  "capture_sha256": "a86c6a31ed04ed05571f997d296f8e7c7be7f262f6e602bd72d9e5de656945c5",
  "summary_id": "investigation-summary:c94b3ca0-893a-444b-ba41-36eae0216030",
  "native_summary_saved": true,
  "affected_ip_in_short_report": false,
  "affected_reference_boundary": "explicitly stated in reference text",
  "reference_source": {
    "url": "https://www.malware-traffic-analysis.net/2019/12/25/2019-12-25-traffic-analysis-exercise-answers.pdf.zip",
    "retrieved_at": "2026-09-22T19:42:43.234898+00:00",
    "zip_sha256": "73a8286e8840590ca22c1186191287d2f2e2b830d004675697c67004153d9131",
    "pdf_sha256": "5d710b4c238f949a08ccc31324cd52ecabb5a248f571f2acc03fd30b76835608",
    "archive_member": "2019-12-25-traffic-analysis-exercise-answers.pdf",
    "scope": "Official reference answers, evaluation-only; never supplied to platform or report model."
  },
  "reference_answer_page": "https://www.malware-traffic-analysis.net/2019/12/25/page2.html",
  "reference_hash_checks": [],
  "native_ioc_reviews": [
    {
      "value": "http://128.199.64.235/1.php",
      "kind": "url",
      "native_explanation": "http://128.199.64.235/1.php received suspicious repeated POST requests from 139.199.184.166; flagged for potential beaconing or data transfer review.",
      "review": "incorrect_security_role_target_not_c2"
    },
    {
      "value": "http://128.199.64.235/qq.php",
      "kind": "url",
      "native_explanation": "http://128.199.64.235/qq.php was targeted by repeated outbound POST requests from 139.199.184.166, suggesting suspicious interaction.",
      "review": "incorrect_security_role_target_not_c2"
    }
  ],
  "scope": "Post-freeze reviewer comparison, never supplied to report-writing model. Reference may use alerts, email and endpoint artifacts absent from PCAP-only input."
}
