{
  "date": "2020-02-21",
  "affected": "172.17.8.174",
  "family": "Dridex",
  "outcome": "partial",
  "reviewed_story": "Gabriella Ventura’s workstation (172.17.8.174, DESKTOP-TZMKHKC) downloaded the Dridex payload from blueflag[.]xyz and subsequently communicated over TLS with 91.211.88[.]122. The native report finds the initial transfer but misses that follow-on context. The publisher’s persistence details came from additional host artifacts, which were not supplied to this PCAP-only run.",
  "matched": "Correct victim, account, download domain/server and transfer.",
  "gaps": "Misses Dridex and the later suspicious TLS activity. The claim that no post-download malicious behavior is supported is broader than the selected evidence justifies.",
  "caution": "Do not count absent scheduled tasks, registry persistence or host-resident loader files as PCAP extraction failures.",
  "hashes": [
    "03c962ebb541a709b92957e301ea03f1790b6a57d4d0605f618fb0be392c8066"
  ],
  "case_number": 3,
  "name": "One-Hot-Mess",
  "analysis_id": "d9aa0de8-e06d-40b7-bffc-2e1af3c53ea0",
  "capture_sha256": "8b984eca8fb96799a9ad7ec5ee766937e640dc1afcad77101e5aeb0ba6be137d",
  "summary_id": "investigation-summary:abf8dc27-6ce5-4668-a762-9333cb1a9955",
  "native_summary_saved": true,
  "affected_ip_in_short_report": true,
  "affected_reference_boundary": "explicitly stated in reference text",
  "reference_source": {
    "url": "https://www.malware-traffic-analysis.net/2020/02/21/2020-02-21-traffic-analysis-exercise-answers.pdf.zip",
    "retrieved_at": "2026-09-22T19:42:42.683788+00:00",
    "zip_sha256": "9b1b083430a45660d1ac2014a71e0b63ab7e64e1186b6228297ed526787acfa1",
    "pdf_sha256": "2033adaea7f24d64bdc575f2ef52722d0c31004faa5d4c6fd56e69f9d8e32878",
    "archive_member": "2020-02-21-traffic-analysis-exercise-answers.pdf",
    "scope": "Official reference answers, evaluation-only; never supplied to platform or report model."
  },
  "reference_answer_page": "https://www.malware-traffic-analysis.net/2020/02/21/page2.html",
  "reference_hash_checks": [
    {
      "sha256": "03c962ebb541a709b92957e301ea03f1790b6a57d4d0605f618fb0be392c8066",
      "present_in_original_artifacts": true,
      "artifact_id": "artifact-b5a7ebcc669f6e376c5917e8",
      "size_bytes": 208896,
      "completeness": "matches-declared-content-length",
      "transfer_bindings": [
        {
          "url": "http://blueflag.xyz/nCvQOQHCBjZFfiJvyVGA/yrkbdmt.bin",
          "client_ip": "172.17.8.174",
          "server_ip": "49.51.172.56",
          "tcp_stream": 60,
          "match_basis": "exact-sha256-of-decoded-http-response-body",
          "status_code": "200",
          "completeness": "matches-declared-content-length",
          "request_frame": 1340,
          "response_frame": 1566
        }
      ],
      "present_in_short_claim_text": false,
      "in_short_ioc_list": false
    }
  ],
  "native_ioc_reviews": [],
  "scope": "Post-freeze reviewer comparison, never supplied to report-writing model. Reference may use alerts, email and endpoint artifacts absent from PCAP-only input."
}
