{
  "date": "2020-04-24",
  "affected": "10.0.0.167",
  "family": "Qakbot / Qbot",
  "outcome": "partial",
  "reviewed_story": "Elmer Obrien’s workstation (10.0.0.167, DESKTOP-GRIONXA) received a Windows executable disguised as a PNG from alphapioneer[.]com. Its recovered SHA-256 matches the publisher’s Qakbot sample. The packet transfer and identity are established; the family identification comes from the published investigation, not a successful live reputation lookup in this run.",
  "matched": "Correct affected workstation, user, download server, disguised payload and exact SHA-256.",
  "gaps": "The native report does not identify Qakbot or reconstruct its later activity. It spends space on another ZIP transfer whose relevance is unresolved.",
  "caution": "The reference explicitly does not enumerate all Qakbot indicators. An unlisted transfer is not automatically benign or a false positive.",
  "hashes": [
    "f6210da7865e00351c0e79464a1ba14a8ecc59dd79f650f2ff76f1697f6807b1"
  ],
  "case_number": 1,
  "name": "Steelcoffee",
  "analysis_id": "c66676ab-7276-4989-8c27-65017a63c2ba",
  "capture_sha256": "498ffc6e11fa8b38c07202a6fcb44da2a1064e9f89f6f8516b2985b08532f5e7",
  "summary_id": "investigation-summary:c2b79478-9161-4da8-b3eb-4afa38d5843d",
  "native_summary_saved": true,
  "affected_ip_in_short_report": true,
  "affected_reference_boundary": "explicitly stated in reference text",
  "reference_source": {
    "url": "https://www.malware-traffic-analysis.net/2020/04/24/2020-04-24-traffic-analysis-exercise-answers.pdf.zip",
    "retrieved_at": "2026-09-22T19:42:42.127798+00:00",
    "zip_sha256": "feeea1a752285bc3565625bd247cc69c5299e5632b4b2094c9a12598350393e0",
    "pdf_sha256": "7581b2cf8ed9af0d759e702bdb5992e0924da50b53a7f7eba007e8d1998a3c96",
    "archive_member": "2020-04-24-traffic-analysis-exercise-answers.pdf",
    "scope": "Official reference answers, evaluation-only; never supplied to platform or report model."
  },
  "reference_answer_page": "https://www.malware-traffic-analysis.net/2020/04/24/page2.html",
  "reference_hash_checks": [
    {
      "sha256": "f6210da7865e00351c0e79464a1ba14a8ecc59dd79f650f2ff76f1697f6807b1",
      "present_in_original_artifacts": true,
      "artifact_id": "artifact-f0534328830e4534e66f10ca",
      "size_bytes": 1950208,
      "completeness": "matches-declared-content-length",
      "transfer_bindings": [
        {
          "url": "http://alphapioneer.com/spool/8888.png?uid=VwBpAG4AZABvAHcAcwAgAEQAZQBmAGUAbgBkAGUAcgAgAC0AIAA2ACwAMgAxACwAMAB8AE0AaQBjAHIAbwBzAG8AZgB0ACAAVwBpAG4AZABvAHcAcwAgADEAMAAgAFAAcgBvAA==",
          "client_ip": "10.0.0.167",
          "server_ip": "119.31.234.40",
          "tcp_stream": 136,
          "match_basis": "exact-sha256-of-decoded-http-response-body",
          "status_code": "200",
          "completeness": "matches-declared-content-length",
          "request_frame": 5518,
          "response_frame": 7388
        }
      ],
      "present_in_short_claim_text": true,
      "in_short_ioc_list": true
    }
  ],
  "native_ioc_reviews": [
    {
      "value": "f6210da7865e00351c0e79464a1ba14a8ecc59dd79f650f2ff76f1697f6807b1",
      "kind": "sha256",
      "native_explanation": "SHA-256 hash f6210da7865e00351c0e79464a1ba14a8ecc59dd79f650f2ff76f1697f6807b1 identifies the downloaded PE file and should be reviewed to determine maliciousness; no threat intelligence verdict is returned at this time.",
      "review": "corroborated_exact_payload"
    }
  ],
  "scope": "Post-freeze reviewer comparison, never supplied to report-writing model. Reference may use alerts, email and endpoint artifacts absent from PCAP-only input."
}
