1200KM · ANDREY PAUTOV
Home · Article · Ten reports · Screenshot gallery · Publication boundaries

Measured 19 September 2026 · Public derivative · Historical training evidence, not approved threat intelligence.

2022-02-23: AdversaryGraph live-instance PCAP report

Actual deployment: [local-workspace], HTTP [local-instance]. This is a regression validation, not an independent blind trial. No malware was executed and no malicious endpoint was contacted.

Executive assessment

Decoded 30023 packets across 143 IP endpoints and 809 transport flows. Observed 499 DNS events, 43 HTTP requests, 111 TLS ClientHello events, and 500 exported HTTP object(s). Deterministic rules produced 57 finding(s): 0 high, 39 medium, and 18 low. Findings are evidence-bound candidates and require analyst review; encrypted payload contents remain unavailable.

These findings identify observations and review priorities, not a proven malware family, actor, or causal infection chain. Source-frame evidence takes precedence over exercise answer typos.

Capture and execution evidence

Capture window: 2022-02-23T18:22:24.405139+00:00 to 2022-02-23T19:07:05.141800+00:00 UTC. Capture SHA-256: eefc7e61b50e7846f5a3282d7645539d7b2b4b85aa08a09d0b823896c9449d1f. Analysis ID: 43bc93eb-d6db-4400-b983-b0dd404c8ca4; review session: bfa8693a-227f-4f5d-8e70-aff8c425ac42. First real HTTP upload/analysis: 14.594 seconds. Fresh uncached decoder repeat: 16.462 seconds. Prior isolated upload: 12.500 seconds. The fresh repeat ran while builds/tests were active; these timings are not a controlled performance comparison. Native packet analysis used zero LLM calls and zero LLM tokens. Coding-agent token usage was not instrumented.

Packet result equals prior isolated result: True; fresh repeat exact: True; retained capture checksum valid: True; API retrieval identical: True; idempotent upload: True.

Internal host identities

Address MAC addresses Frame-backed identities
172.16.0.1 00:09:12:96:5d:c9
172.16.0.131 2c:27:d7:d2:06:f5 account: desktop-vd151o7$; account: tricia.becker; domain: SUNNYSTATION; full-name: Tricia Becker; hostname: DESKTOP-VD151O7
172.16.0.149 00:1b:fc:7b:d1:c0 account: desktop-kpq9fdb$; account: nick.montgomery; full-name: Nick Montgomery; hostname: DESKTOP-KPQ9FDB
172.16.0.170 00:12:f0:64:d1:d9 account: desktop-w5tftqy$; account: everett.french; full-name: Everett French; hostname: DESKTOP-W5TFTQY
172.16.0.255 ff:ff:ff:ff:ff:ff
172.16.0.52 00:1e:4f:0e:a8:74
172.16.0.53 18:66:da:6f:2e:f0

Evidence timeline

UTC Frame Candidate observation
2022-02-23T18:22:25.845892+00:00 100 low: Directory-service protocol activity
2022-02-23T18:22:25.846208+00:00 102 low: Directory-service protocol activity
2022-02-23T18:22:26.177209+00:00 178 low: Directory-service protocol activity
2022-02-23T18:22:26.177462+00:00 179 low: Directory-service protocol activity
2022-02-23T18:22:46.798957+00:00 577 low: Directory-service protocol activity
2022-02-23T18:22:46.799387+00:00 579 low: Directory-service protocol activity
2022-02-23T18:22:47.543288+00:00 746 low: Directory-service protocol activity
2022-02-23T18:22:47.543562+00:00 747 low: Directory-service protocol activity
2022-02-23T18:23:08.974536+00:00 1424 low: Directory-service protocol activity
2022-02-23T18:23:08.975010+00:00 1427 low: Directory-service protocol activity
2022-02-23T18:23:18.091368+00:00 1785 low: Directory-service protocol activity
2022-02-23T18:23:18.091725+00:00 1786 low: Directory-service protocol activity
2022-02-23T18:23:34.754258+00:00 1944 low: Directory-service protocol activity
2022-02-23T18:23:34.754498+00:00 1946 low: Directory-service protocol activity
2022-02-23T18:23:36.235912+00:00 2143 low: Directory-service protocol activity
2022-02-23T18:23:36.236065+00:00 2147 low: Directory-service protocol activity
2022-02-23T18:23:49.296865+00:00 2867 low: Directory-service protocol activity
2022-02-23T18:23:49.297222+00:00 2868 low: Directory-service protocol activity
2022-02-23T18:24:34.594654+00:00 3995 medium: Script, archive, or executable transfer candidate
2022-02-23T18:24:43.773918+00:00 4679 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:24:46.046147+00:00 4802 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:25:36.619127+00:00 5068 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:25:53.128039+00:00 6688 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:25:59.066759+00:00 6805 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:26:53.133526+00:00 7688 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:27:12.307679+00:00 7719 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:27:49.244491+00:00 7792 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:28:52.482644+00:00 8729 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:28:57.604581+00:00 9146 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:29:08.764198+00:00 9331 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:30:12.302161+00:00 10803 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:30:15.920950+00:00 10835 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:30:17.459389+00:00 10946 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:31:17.205749+00:00 11650 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:31:18.346228+00:00 11743 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:31:18.933946+00:00 12139 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:32:10.331071+00:00 13103 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:32:13.501484+00:00 13119 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:32:53.408930+00:00 13219 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:32:57.113862+00:00 13452 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:32:58.480852+00:00 13684 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:33:32.927267+00:00 14063 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:34:28.349874+00:00 14528 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:35:31.632906+00:00 14623 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:37:33.832013+00:00 16159 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:38:06.643664+00:00 17066 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:48:55.363262+00:00 18531 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:48:57.105876+00:00 18949 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:49:46.878850+00:00 19849 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:51:10.288195+00:00 20080 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:58:23.769347+00:00 20948 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:58:36.711457+00:00 21069 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T18:59:24.595545+00:00 21121 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T19:00:30.182090+00:00 21759 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T19:02:42.805401+00:00 23259 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T19:03:18.865202+00:00 23301 medium: Sustained external TCP conversation outside decoded application coverage
2022-02-23T19:06:08.280407+00:00 24437 medium: Sustained external TCP conversation outside decoded application coverage

Highest-volume conversations

Wire volume includes overhead/retransmissions. A large or periodic flow is not automatically exfiltration or C2.

Initiator Responder Stream Wire bytes First frame
172.16.0.149:49838 135.148.121.246:8080 tcp 471 1,576,264 26585
172.16.0.149:49837 135.148.121.246:8080 tcp 470 1,562,738 24751
172.16.0.170:54074 178.211.56.194:443 tcp 199 1,215,548 5088
172.16.0.170:54147 185.184.25.78:8080 tcp 390 1,155,759 21759
172.16.0.170:54158 198.199.98.78:8080 tcp 417 789,030 23301
172.16.0.131:49200 156.96.154.210:80 tcp 228 760,206 9571
172.16.0.149:49747 64.34.171.228:80 tcp 186 630,805 3992
172.16.0.149:49839 134.209.156.68:443 tcp 472 588,137 26586
172.16.0.149:49803 144.217.88.125:443 tcp 327 572,707 18990
172.16.0.149:49783 144.217.88.125:443 tcp 254 571,538 12208
172.16.0.170:54119 128.199.93.156:8080 tcp 311 546,358 17066
172.16.0.170:54115 162.144.76.184:8080 tcp 306 545,561 16159
172.16.0.170:54114 180.250.21.2:443 tcp 303 545,128 15324
172.16.0.149:49766 135.148.121.246:8080 tcp 217 537,491 7804
172.16.0.170:54094 168.197.250.14:80 tcp 244 532,475 11074
172.16.0.149:49761 135.148.121.246:8080 tcp 210 499,520 6963
172.16.0.170:54088 168.197.250.14:80 tcp 227 492,888 9331
172.16.0.170:54143 139.196.72.155:8080 tcp 369 356,002 21121
172.16.0.149:49800 135.148.121.246:8080 tcp 324 342,682 18531
172.16.0.170:54110 59.148.253.194:443 tcp 299 341,845 14833

Native packet findings, artifacts and limitations

AdversaryGraph Deterministic PCAP Analysis

Source: 2022-02-23-traffic-analysis-exercise.pcap Capture SHA-256: eefc7e61b50e7846f5a3282d7645539d7b2b4b85aa08a09d0b823896c9449d1f Semantic result SHA-256: 8a329890ed01eedca67808c92bdfa492463b036b435540749e5ff2e599d7deee Analyzer manifest SHA-256: ee952aeb7cdc6958f4ae5178c54c274a1e4f0aec4d42f3bdb95baaff063b3dde

Executive summary

Decoded 30023 packets across 143 IP endpoints and 809 transport flows. Observed 499 DNS events, 43 HTTP requests, 111 TLS ClientHello events, and 500 exported HTTP object(s). Deterministic rules produced 57 finding(s): 0 high, 39 medium, and 18 low. Findings are evidence-bound candidates and require analyst review; encrypted payload contents remain unavailable.

Capture facts

Deterministic findings

MEDIUM — Script, archive, or executable transfer candidate

HTTP metadata names a script, archive, or executable. This is a transfer candidate, not proof of file type, execution, or malicious intent; legitimate updates use the same formats.

Rule: script-or-executable-transfer@pcap-rules-v3; confidence: 0.86; evidence: frame 3995 / TCP stream 186, frame 4675 / TCP stream 186.

Metrics: {"content_type":"application/x-msdownload","declared_body_bytes":593920,"destination":"172.16.0.149","response_count":1,"source":"64.34.171.228","uri":"/c7g8t/zbBYgukXYxzAF2hZc/"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 178 / TCP stream 8, frame 180 / TCP stream 8, frame 182 / TCP stream 8, frame 184 / TCP stream 8, frame 1710 / TCP stream 8.

Metrics: {"destination":"172.16.0.52","event_count":8,"operation_numbers":["0","1","12"],"protocol":"drsuapi","source":"172.16.0.131"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 100 / TCP stream 5, frame 117 / TCP stream 5, frame 120 / TCP stream 5, frame 212 / TCP stream 13, frame 229 / TCP stream 13.

Metrics: {"destination":"172.16.0.52","event_count":41,"operation_numbers":["","0","2","3"],"protocol":"ldap","source":"172.16.0.131"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1785 / TCP stream 87, frame 1787 / TCP stream 87, frame 1790 / TCP stream 87, frame 1793 / TCP stream 87, frame 1795 / TCP stream 87.

Metrics: {"destination":"172.16.0.52","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"172.16.0.131"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 2143 / TCP stream 101, frame 2159 / TCP stream 101, frame 2162 / TCP stream 101, frame 2168 / TCP stream 101, frame 2214 / TCP stream 111.

Metrics: {"destination":"172.16.0.52","event_count":53,"operation_numbers":["0","1","12","13"],"protocol":"drsuapi","source":"172.16.0.149"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1944 / TCP stream 94, frame 2015 / TCP stream 94, frame 2018 / TCP stream 94, frame 2055 / TCP stream 102, frame 2091 / TCP stream 102.

Metrics: {"destination":"172.16.0.52","event_count":103,"operation_numbers":["","0","2","3"],"protocol":"ldap","source":"172.16.0.149"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 2867 / TCP stream 95, frame 2869 / TCP stream 95, frame 2871 / TCP stream 95, frame 2873 / TCP stream 95, frame 2875 / TCP stream 95.

Metrics: {"destination":"172.16.0.52","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"172.16.0.149"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 746 / TCP stream 43, frame 748 / TCP stream 43, frame 750 / TCP stream 43, frame 752 / TCP stream 43, frame 784 / TCP stream 45.

Metrics: {"destination":"172.16.0.52","event_count":53,"operation_numbers":["0","1","12","13"],"protocol":"drsuapi","source":"172.16.0.170"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 577 / TCP stream 32, frame 618 / TCP stream 35, frame 673 / TCP stream 35, frame 682 / TCP stream 35, frame 684 / TCP stream 35.

Metrics: {"destination":"172.16.0.52","event_count":98,"operation_numbers":["","0","2","3"],"protocol":"ldap","source":"172.16.0.170"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1424 / TCP stream 31, frame 1430 / TCP stream 31, frame 1435 / TCP stream 31, frame 1437 / TCP stream 31, frame 1439 / TCP stream 31.

Metrics: {"destination":"172.16.0.52","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"172.16.0.170"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 179 / TCP stream 8, frame 181 / TCP stream 8, frame 183 / TCP stream 8, frame 185 / TCP stream 8, frame 1711 / TCP stream 8.

Metrics: {"destination":"172.16.0.131","event_count":8,"operation_numbers":["0","1","12"],"protocol":"drsuapi","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 102 / TCP stream 5, frame 119 / TCP stream 5, frame 214 / TCP stream 13, frame 231 / TCP stream 13, frame 233 / TCP stream 13.

Metrics: {"destination":"172.16.0.131","event_count":33,"operation_numbers":["","1","4,19,19,19,5","4,5","5"],"protocol":"ldap","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1786 / TCP stream 87, frame 1788 / TCP stream 87, frame 1792 / TCP stream 87, frame 1794 / TCP stream 87, frame 1796 / TCP stream 87.

Metrics: {"destination":"172.16.0.131","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 2147 / TCP stream 101, frame 2161 / TCP stream 101, frame 2164 / TCP stream 101, frame 2169 / TCP stream 101, frame 2215 / TCP stream 111.

Metrics: {"destination":"172.16.0.149","event_count":53,"operation_numbers":["0","1","12","13"],"protocol":"drsuapi","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1946 / TCP stream 94, frame 2017 / TCP stream 94, frame 2057 / TCP stream 102, frame 2093 / TCP stream 102, frame 2099 / TCP stream 102.

Metrics: {"destination":"172.16.0.149","event_count":83,"operation_numbers":["","1","4,19,19,19,5","4,5","5"],"protocol":"ldap","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 2868 / TCP stream 95, frame 2870 / TCP stream 95, frame 2872 / TCP stream 95, frame 2874 / TCP stream 95, frame 2876 / TCP stream 95.

Metrics: {"destination":"172.16.0.149","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 747 / TCP stream 43, frame 749 / TCP stream 43, frame 751 / TCP stream 43, frame 753 / TCP stream 43, frame 785 / TCP stream 45.

Metrics: {"destination":"172.16.0.170","event_count":53,"operation_numbers":["0","1","12","13"],"protocol":"drsuapi","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 579 / TCP stream 32, frame 620 / TCP stream 35, frame 681 / TCP stream 35, frame 683 / TCP stream 35, frame 686 / TCP stream 35.

Metrics: {"destination":"172.16.0.170","event_count":79,"operation_numbers":["","1","4,19,19,19,5","4,5","5"],"protocol":"ldap","source":"172.16.0.52"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 1427 / TCP stream 31, frame 1433 / TCP stream 31, frame 1436 / TCP stream 31, frame 1438 / TCP stream 31, frame 1440 / TCP stream 31.

Metrics: {"destination":"172.16.0.170","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"172.16.0.52"}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 4679 / TCP stream 187.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":52.845,"packets":127,"source":"172.16.0.149","wire_bytes":87055}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 4802 / TCP stream 188.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":96.025,"packets":19,"source":"172.16.0.149","wire_bytes":2721}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 5068 / TCP stream 198.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":47.78,"packets":19,"source":"172.16.0.149","wire_bytes":2517}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 6688 / TCP stream 203.

Metrics: {"destination":"27.254.174.84","destination_port":8080,"duration_seconds":60.005,"packets":117,"source":"172.16.0.170","wire_bytes":86156}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 6805 / TCP stream 204.

Metrics: {"destination":"27.254.174.84","destination_port":8080,"duration_seconds":104.051,"packets":20,"source":"172.16.0.170","wire_bytes":3034}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 7688 / TCP stream 213.

Metrics: {"destination":"27.254.174.84","destination_port":8080,"duration_seconds":49.984,"packets":18,"source":"172.16.0.170","wire_bytes":2793}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 7719 / TCP stream 214.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":46.582,"packets":19,"source":"172.16.0.149","wire_bytes":2755}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 7792 / TCP stream 216.

Metrics: {"destination":"27.254.174.84","destination_port":8080,"duration_seconds":41.718,"packets":76,"source":"172.16.0.170","wire_bytes":54377}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 8729 / TCP stream 221.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":51.375,"packets":412,"source":"172.16.0.149","wire_bytes":320581}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 9146 / TCP stream 222.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":76.16,"packets":19,"source":"172.16.0.149","wire_bytes":3342}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 9331 / TCP stream 227.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":117.001,"packets":559,"source":"172.16.0.170","wire_bytes":492888}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 10803 / TCP stream 236.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":66.043,"packets":21,"source":"172.16.0.170","wire_bytes":3237}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 10835 / TCP stream 237.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":61.284,"packets":117,"source":"172.16.0.149","wire_bytes":89737}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 10946 / TCP stream 238.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":61.474,"packets":21,"source":"172.16.0.149","wire_bytes":3151}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 11650 / TCP stream 247.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":46.562,"packets":412,"source":"172.16.0.149","wire_bytes":340415}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 11743 / TCP stream 249.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":95.062,"packets":19,"source":"172.16.0.170","wire_bytes":2986}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 12139 / TCP stream 251.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":44.834,"packets":19,"source":"172.16.0.149","wire_bytes":3271}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 13103 / TCP stream 261.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":48.149,"packets":19,"source":"172.16.0.149","wire_bytes":2678}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 13119 / TCP stream 262.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":79.426,"packets":19,"source":"172.16.0.170","wire_bytes":3058}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 13219 / TCP stream 268.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":94.94,"packets":398,"source":"172.16.0.170","wire_bytes":319970}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 13452 / TCP stream 272.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":49.955,"packets":132,"source":"172.16.0.149","wire_bytes":101806}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 13684 / TCP stream 274.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":55.29,"packets":19,"source":"172.16.0.149","wire_bytes":2461}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 14063 / TCP stream 281.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":90.205,"packets":19,"source":"172.16.0.170","wire_bytes":2359}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 14528 / TCP stream 293.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":34.782,"packets":21,"source":"172.16.0.170","wire_bytes":4464}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 14623 / TCP stream 298.

Metrics: {"destination":"168.197.250.14","destination_port":80,"duration_seconds":40.858,"packets":201,"source":"172.16.0.170","wire_bytes":159636}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 16159 / TCP stream 306.

Metrics: {"destination":"162.144.76.184","destination_port":8080,"duration_seconds":32.803,"packets":767,"source":"172.16.0.170","wire_bytes":545561}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 17066 / TCP stream 311.

Metrics: {"destination":"128.199.93.156","destination_port":8080,"duration_seconds":36.477,"packets":767,"source":"172.16.0.170","wire_bytes":546358}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 18531 / TCP stream 324.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":51.515,"packets":422,"source":"172.16.0.149","wire_bytes":342682}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 18949 / TCP stream 325.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":83.461,"packets":19,"source":"172.16.0.149","wire_bytes":2922}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 19849 / TCP stream 329.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":35.196,"packets":19,"source":"172.16.0.149","wire_bytes":2531}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 20080 / TCP stream 333.

Metrics: {"destination":"135.148.121.246","destination_port":8080,"duration_seconds":85.095,"packets":19,"source":"172.16.0.149","wire_bytes":3198}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 20948 / TCP stream 367.

Metrics: {"destination":"139.196.72.155","destination_port":8080,"duration_seconds":51.093,"packets":124,"source":"172.16.0.170","wire_bytes":101936}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 21069 / TCP stream 368.

Metrics: {"destination":"139.196.72.155","destination_port":8080,"duration_seconds":38.15,"packets":19,"source":"172.16.0.170","wire_bytes":3125}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 21121 / TCP stream 369.

Metrics: {"destination":"139.196.72.155","destination_port":8080,"duration_seconds":58.283,"packets":413,"source":"172.16.0.170","wire_bytes":356002}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 21759 / TCP stream 390.

Metrics: {"destination":"185.184.25.78","destination_port":8080,"duration_seconds":123.7,"packets":1334,"source":"172.16.0.170","wire_bytes":1155759}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 23259 / TCP stream 411.

Metrics: {"destination":"54.37.106.167","destination_port":8080,"duration_seconds":122.065,"packets":23,"source":"172.16.0.170","wire_bytes":4023}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 23301 / TCP stream 417.

Metrics: {"destination":"198.199.98.78","destination_port":8080,"duration_seconds":95.397,"packets":890,"source":"172.16.0.170","wire_bytes":789030}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 24437 / TCP stream 469.

Metrics: {"destination":"128.199.192.135","destination_port":8080,"duration_seconds":49.124,"packets":302,"source":"172.16.0.170","wire_bytes":248547}

ATT&CK candidates

Identities

IOC and artifact candidates

Actor similarity leads

Local enrichment and correlations

No match means unknown in this corpus. Local CTI may postdate the capture. Matches and shared infrastructure require review; no automatic promotion or attribution. Snapshot: 27cd896e9110b1fda7f2da6c5f4df9153ce2ef635709a10b488145ec018823aa; recorded 2026-09-19T12:09:25.907745+00:00; mode: local-only. Coverage: {"matched_observables":0,"no_exact_match":2994,"observable_limit":5000,"observables_checked":2994,"observables_total":2994,"prior_case_limit_reached":false,"prior_cases_checked":11,"truncated":false}

Coverage and limitations

Live enrichment and correlation validation

The actual IOC library contained 156,125 records. Exact typed matches: 0; source actor assertions: 0. Independent SQL agrees: IOC=True, actors=True. A miss is unknown in this corpus, not evidence of benignness. The earlier isolated corpus included publisher-reference records; its positive matches were not live-provider detections and are not comparable to natural coverage here. ATT&CK catalog candidates: 1; current-version catalog checks passed: True. Detection-strategy joins were checked independently. Cross-case links: 11; independently verified: True. These are shared observations, predominantly common service infrastructure, not common-campaign assertions.

Passive local lookup target Type Local matches
156.96.154.210 ipv4 0
www.katchybugonsale.com domain 0
www.privilegetroissecurity.com domain 0
135.148.121.246 ipv4 0
14b57211308ac8ad2a63c965783d9ba1c2d1930d0cafd884374d143a481f9bf3 sha256 0
abca26cf70ef57ef879c81a3b45d9fc5ce4437f54bda65d0170f3f5bae8a54f5 sha256 0

Approved external passive enrichment

Completed 6/6 planned case indicators. Shared indicators reuse one saved lookup rather than consume provider quota repeatedly.

These lookups used the actual local application and were explicitly authorized. No PCAP or payload was uploaded, no private address was disclosed, no target was scanned, and no AI provider was invoked. Tier-two/three pivots query the local corpus only.

Provider intelligence was retrieved after the captures: current reputation, hosting and service observations do not establish historical causality. not_found means absent from that provider, not benign. Family labels and ATT&CK/actor leads remain source assertions awaiting review.

Historical coverage caveat: ThreatFox documents a six-month IOC expiration policy for its API since May 2025. That can limit these older exercises; it does not prove why any particular lookup missed. ThreatFox API policy.

156.96.154.210

Type: ip; request: 6.574 seconds; completed: 2026-09-19T14:07:35.528619+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 22/100 (needs review); a heuristic priority, not calibrated probability. Graph: 2 nodes, 1 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok 3 engines marked malicious and 1 suspicious; 51 harmless, 34 undetected.
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar skipped MalwareBazaar is hash-focused; input is not a hash.
otx ok OTX returned 0 pulse(s).
urlscan ok urlscan returned 0 scan result(s). urlscan activity analysis found no obvious suspicious pattern.
greynoise not_found GreyNoise classification: unknown. Query status: not_found
abuseipdb ok AbuseIPDB confidence score: 0/100.
shodan not_found Shodan returned 0 open port(s). Query status: not_found
censys ok Censys host lookup returned 0 service(s).

No actor lead returned. This does not establish absence of an actor.

www.katchybugonsale.com

Type: domain; request: 2.250 seconds; completed: 2026-09-19T14:07:51.198863+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 6/100 (low signal); a heuristic priority, not calibrated probability. Graph: 2 nodes, 2 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok 1 engines marked malicious and 0 suspicious; 52 harmless, 36 undetected.
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar skipped MalwareBazaar is hash-focused; input is not a hash.
otx ok OTX returned 0 pulse(s).
urlscan ok urlscan returned 0 scan result(s). urlscan activity analysis found no obvious suspicious pattern.
greynoise skipped GreyNoise is IP-focused; input is not an IP.
abuseipdb skipped AbuseIPDB is IP-focused; input is not an IP.
shodan skipped Shodan host lookup is IP-focused; input is not an IP.
censys ok Censys web property lookup returned 2 record(s) for www.katchybugonsale.com. Broader Censys search requires an organization-enabled account and API role.

No actor lead returned. This does not establish absence of an actor.

www.privilegetroissecurity.com

Type: domain; request: 6.268 seconds; completed: 2026-09-19T14:08:15.218784+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 21/100 (needs review); a heuristic priority, not calibrated probability. Graph: 15 nodes, 18 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok No malicious detections in last analysis; 56 harmless, 33 undetected.
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar skipped MalwareBazaar is hash-focused; input is not a hash.
otx ok OTX returned 0 pulse(s).
urlscan ok urlscan returned 3 scan result(s). urlscan activity analysis found 2 suspicious pattern(s).
greynoise skipped GreyNoise is IP-focused; input is not an IP.
abuseipdb skipped AbuseIPDB is IP-focused; input is not an IP.
shodan skipped Shodan host lookup is IP-focused; input is not an IP.
censys ok Censys web property lookup returned 2 record(s) for www.privilegetroissecurity.com. Broader Censys search requires an organization-enabled account and API role.

No actor lead returned. This does not establish absence of an actor.

135.148.121.246

Type: ip; request: 11.964 seconds; completed: 2026-09-19T14:08:40.923184+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 100/100 (highly suspicious); a heuristic priority, not calibrated probability. Graph: 29 nodes, 34 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok 2 engines marked malicious and 1 suspicious; 53 harmless, 33 undetected.
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar skipped MalwareBazaar is hash-focused; input is not a hash.
otx ok OTX returned 50 pulse(s).
urlscan ok urlscan returned 10 scan result(s). urlscan activity analysis found 3 suspicious pattern(s).
greynoise not_found GreyNoise classification: unknown. Query status: not_found
abuseipdb ok AbuseIPDB confidence score: 0/100.
shodan ok Shodan returned 3 open port(s).
censys ok Censys host lookup returned 3 service(s).

Provider ATT&CK leads (not packet-observed execution):

ID Name Source / scope
T1036 Masquerading otx (submitted indicator; provider-reported lead, not packet execution proof)
T1090 Proxy otx (submitted indicator; provider-reported lead, not packet execution proof)
T1204 User Execution otx (submitted indicator; provider-reported lead, not packet execution proof)
T1216 System Script Proxy Execution otx (submitted indicator; provider-reported lead, not packet execution proof)
T1218 System Binary Proxy Execution otx (submitted indicator; provider-reported lead, not packet execution proof)
T1566 Phishing otx (submitted indicator; provider-reported lead, not packet execution proof)

No actor lead returned. This does not establish absence of an actor.

14b57211308ac8ad2a63c965783d9ba1c2d1930d0cafd884374d143a481f9bf3

Type: hash; request: 7.589 seconds; completed: 2026-09-19T14:08:56.555583+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 89/100 (highly suspicious); a heuristic priority, not calibrated probability. Graph: 6 nodes, 6 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok 57 engines marked malicious and 0 suspicious; 0 harmless, 11 undetected.
VirusTotal classification/name hints unreviewed; may include benign filenames trojan.emotet/cryp, emotet, cryp, yxcbxz, trojan, banker, spyware, MJAntiVirus.EXE
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar ok MalwareBazaar returned 1 sample record(s). Query status: ok
MalwareBazaar family labels unreviewed source assertion Heodo
otx ok OTX returned 3 pulse(s).
urlscan ok urlscan returned 0 scan result(s). urlscan activity analysis found no obvious suspicious pattern.
greynoise skipped GreyNoise is IP-focused; input is not an IP.
abuseipdb skipped AbuseIPDB is IP-focused; input is not an IP.
shodan skipped Shodan host lookup is IP-focused; input is not an IP.
censys skipped Censys host and search pivots support IP, domain, and URL inputs.

Provider ATT&CK leads (not packet-observed execution):

ID Name Source / scope
T1012 Query Registry virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1016 System Network Configuration Discovery virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1018 Remote System Discovery virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1027 Obfuscated Files or Information virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1027.005 Indicator Removal from Tools virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1036 Masquerading virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1055 Process Injection virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1056 Input Capture virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1056.001 Keylogging virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1057 Process Discovery virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1059 Command and Scripting Interpreter virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1070 Indicator Removal virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1070.004 File Deletion virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1071 Application Layer Protocol virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1082 System Information Discovery virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1083 File and Directory Discovery virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1112 Modify Registry virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1129 Shared Modules virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1134 Access Token Manipulation virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1218 System Binary Proxy Execution virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1218.010 Regsvr32 virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1218.011 Rundll32 virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1497 Virtualization/Sandbox Evasion virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1518 Software Discovery virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1518.001 Security Software Discovery virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1529 System Shutdown/Reboot virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1547 Boot or Logon Autostart Execution virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1547.001 Registry Run Keys / Startup Folder virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1564 Hide Artifacts virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1564.001 Hidden Files and Directories virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1564.003 Hidden Window virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1571 Non-Standard Port virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1573 Encrypted Channel virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1574 Hijack Execution Flow virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1574.002 virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1614 System Location Discovery virustotal (submitted indicator; provider-reported lead, not packet execution proof)

No actor lead returned. This does not establish absence of an actor.

abca26cf70ef57ef879c81a3b45d9fc5ce4437f54bda65d0170f3f5bae8a54f5

Type: hash; request: 2.882 seconds; completed: 2026-09-19T14:09:11.835314+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 0/100 (low signal); a heuristic priority, not calibrated probability. Graph: 1 nodes, 0 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal not_found virustotal has no record for this lookup. Query status: not_found
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar not_found MalwareBazaar returned 0 sample record(s). Query status: hash_not_found
otx ok OTX returned 0 pulse(s).
urlscan ok urlscan returned 0 scan result(s). urlscan activity analysis found no obvious suspicious pattern.
greynoise skipped GreyNoise is IP-focused; input is not an IP.
abuseipdb skipped AbuseIPDB is IP-focused; input is not an IP.
shodan skipped Shodan host lookup is IP-focused; input is not an IP.
censys skipped Censys host and search pivots support IP, domain, and URL inputs.

No actor lead returned. This does not establish absence of an actor.

The live case contains 6 explicitly linked, exact-type/value PCAP observables. 4 retain frame references; remaining exported-object hashes retain native object IDs and capture-export provenance, not an exact packet-frame map. Every link retains the capture checksum, points to a saved provider investigation, and was reread from the real API. Case actor associations remain empty. Verified graph links.

Current ATT&CK catalog and detection-strategy joins

These are read-only joins against the actual database, not generated detections or proof that the victim executed the technique. A valid catalog join cannot validate the original provider assertion.

Technique Current catalog match Available detection strategies
T1012 True Detection of Registry Query for Environmental Discovery (x-mitre-detection-strategy--106e32a9-29b7-4ec7-80cf-768662706490)
T1016 True Behavioral Detection of System Network Configuration Discovery (x-mitre-detection-strategy--172cff54-a89b-4207-abc2-8d0c9601025e)
T1018 True Detection Strategy for Remote System Enumeration Behavior (x-mitre-detection-strategy--9ec6dafe-3e93-4ebb-943e-26b84136f6a9)
T1027 True Behavioral Detection of Obfuscated Files or Information (x-mitre-detection-strategy--e3758cbb-5dd9-4aad-b848-0539a8c56307)
T1027.005 True Detection Strategy for Indicator Removal from Tools - Post-AV Evasion Modification (x-mitre-detection-strategy--6ab338c4-9ed3-4f63-9462-b13cea5a68b0)
T1036 True Behavioral Detection of Masquerading Across Platforms via Metadata and Execution Discrepancy (x-mitre-detection-strategy--408aedab-4a23-41ad-809d-fe9c3805b7f6)
T1055 True Behavioral Detection of Process Injection Across Platforms (x-mitre-detection-strategy--9833b57b-4c83-4f58-b4cf-76f041b29273)
T1056 True Behavioral Detection of Input Capture Across Platforms (x-mitre-detection-strategy--c922d994-74bd-4847-a870-c0ae216318c9)
T1056.001 True Behavioral Detection of Keylogging Activity Across Platforms (x-mitre-detection-strategy--fe0d7d82-1575-4685-9a4f-4bf83e0227a0)
T1057 True Detection of Adversarial Process Discovery Behavior (x-mitre-detection-strategy--309ca3cd-d3f0-4aea-8932-558550aa89f4)
T1059 True Behavioral Detection of Command and Scripting Interpreter Abuse (x-mitre-detection-strategy--8582f5e6-44a5-4950-b7e8-a3e1b6d58d63)
T1070 True Behavioral Detection of Indicator Removal Across Platforms (x-mitre-detection-strategy--7225a3bd-f235-4c13-a236-3c6b9a3d445c)
T1070.004 True Behavioral Detection of Malicious File Deletion (x-mitre-detection-strategy--b96fce76-6b29-4e1c-b8b1-741f45a89fdc)
T1071 True Detection of Command and Control Over Application Layer Protocols (x-mitre-detection-strategy--155cab5b-c70b-4cfb-ba52-f62a21836b19)
T1082 True System Discovery via Native and Remote Utilities (x-mitre-detection-strategy--75161d5e-2b6d-4112-ab4d-338f70ea97f0)
T1083 True Recursive Enumeration of Files and Directories Across Privilege Contexts (x-mitre-detection-strategy--33ab9d0c-5671-48e6-8465-f80560909c65)
T1090 True Detection of Proxy Infrastructure Setup and Traffic Bridging (x-mitre-detection-strategy--5c44619a-da36-4bbd-9730-efceacf2409f)
T1112 True Behavior-Based Registry Modification Detection on Windows (x-mitre-detection-strategy--cf6a38ec-4c16-4c7f-8730-6e04f6dd6e67)
T1129 True Behavior-chain, platform-aware detection strategy for T1129 Shared Modules (x-mitre-detection-strategy--928a6ce6-fca0-4d66-aba3-1121431b953e)
T1134 True Behavior-chain detection for T1134 Access Token Manipulation on Windows (x-mitre-detection-strategy--774bbba8-45c2-403d-a445-3a64b3679faf)
T1204 True User Execution – multi-surface behavior chain (documents/links → helper/unpacker → LOLBIN/child → egress) (x-mitre-detection-strategy--70c9f174-2e96-4086-b59c-d2358e434f8e)
T1216 True Detection of Script-Based Proxy Execution via Signed Microsoft Utilities (x-mitre-detection-strategy--8ac2b0d0-a589-4c72-9287-a7d9e47065a9)
T1218 True Detection of Proxy Execution via Trusted Signed Binaries Across Platforms (x-mitre-detection-strategy--ce0b969a-1411-4b6f-a6aa-c31ef6fe6727)
T1218.010 True Detection Strategy for System Binary Proxy Execution: Regsvr32 (x-mitre-detection-strategy--0a931f22-4820-48aa-8051-056da15a6183)
T1218.011 True Detection Strategy for T1218.011 Rundll32 Abuse (x-mitre-detection-strategy--a51d4d34-78fc-49b7-9071-348905dd33c2)
T1497 True Detection Strategy for T1497 Virtualization/Sandbox Evasion (x-mitre-detection-strategy--7f5dde79-7872-48dd-8718-cd2e10d7cbfc)
T1518 True Multi-Platform Software Discovery Behavior Chain (x-mitre-detection-strategy--f18dee58-43be-41e4-85a3-c6820033ac0d)
T1518.001 True Security Software Discovery Across Platforms (x-mitre-detection-strategy--e2409f82-e24c-4bb9-ad44-b20d97fb7a5a)
T1529 True Multi-Platform Shutdown or Reboot Detection via Execution and Host Status Events (x-mitre-detection-strategy--2a464ecb-46ef-41f0-8ab6-a97a99ad0559)
T1547 True Boot or Logon Autostart Execution Detection Strategy (x-mitre-detection-strategy--a9796458-df5d-467f-b037-acad6c261f25)
T1547.001 True Detect Registry and Startup Folder Persistence (Windows) (x-mitre-detection-strategy--8febbfe8-91ae-4625-8fc7-656639b90a11)
T1564 True Detection Strategy for Hidden Artifacts Across Platforms (x-mitre-detection-strategy--bd2348f8-acef-4310-bd03-cf7b866d2592)
T1564.001 True Detection Strategy for Hidden Files and Directories (x-mitre-detection-strategy--3f59957a-2e55-4378-bbe7-090fb1e4f067)
T1564.003 True Detection Strategy for Hidden Windows (x-mitre-detection-strategy--1167a6c8-d735-4d5d-81f5-d81c6eafe239)
T1566 True Detection Strategy for Phishing across platforms. (x-mitre-detection-strategy--7ee73f2e-76b2-4f00-bcc0-7fb79d31d344)
T1571 True Detection Strategy for Non-Standard Ports (x-mitre-detection-strategy--cc8324a7-03d0-47d1-8e2b-3caec44fc129)
T1573 True Detection Strategy for Encrypted Channel across OS Platforms (x-mitre-detection-strategy--08861418-398c-4972-8850-5e11f2d32944)
T1574 True Detection Strategy for Hijack Execution Flow across OS platforms. (x-mitre-detection-strategy--07669925-383b-455b-a3e2-3a79e18eed27)
T1574.002 False None returned
T1614 True Detection Strategy for System Location Discovery (x-mitre-detection-strategy--9daf5067-79c3-477c-bf41-813aada4770d)
Prior analysis Shared count Example observations
6df36b51-4b44-4660-b534-2fa89705e807 31 api.msn.com, checkappexec.microsoft.com, client.wns.windows.com, ctldl.windowsupdate.com, dns.msftncsi.com
29aa3ef8-47c9-4c47-b4cc-1ff3e0708142 24 api.msn.com, client.wns.windows.com, ecs.office.com, login.microsoftonline.com, odc.officeapps.live.com
b79032a8-d69e-4ac1-bdd4-542473fa8e3b 36 api.msn.com, c-ring.msedge.net, client.wns.windows.com, ecs.office.com, fe2cr.update.microsoft.com
faf041c3-70e0-4a01-8780-10917e5e187c 28 api.msn.com, client.wns.windows.com, ctldl.windowsupdate.com, dns.msftncsi.com, ecs.office.com
08324647-35af-4af2-8d82-4387eec03918 26 api.msn.com, checkappexec.microsoft.com, client.wns.windows.com, ctldl.windowsupdate.com, dns.msftncsi.com
616a90fa-f15e-4fcb-8d56-7b8e0eff5785 13 login.live.com, login.microsoftonline.com, odc.officeapps.live.com, settings-win.data.microsoft.com, v10.events.data.microsoft.com
459e119d-191f-49e8-85ea-c78f9de41826 22 api.msn.com, client.wns.windows.com, ctldl.windowsupdate.com, ecs.office.com, fe2cr.update.microsoft.com
7a2cfe72-f48d-4894-8a2d-8889cb3b11b2 43 api.msn.com, client.wns.windows.com, ctldl.windowsupdate.com, ecs.office.com, login.microsoftonline.com
81373b30-6a59-49d1-89b0-bad73ed19eaa 26 api.msn.com, client.wns.windows.com, dns.msftncsi.com, ecs.office.com, login.live.com
38851ad7-b3a0-423d-ae89-3b7be4e4b908 29 api.msn.com, client.wns.windows.com, ctldl.windowsupdate.com, dns.msftncsi.com, ecs.office.com
bfccc426-aa9b-4007-8558-a66d37ecb90c 44 api.msn.com, checkappexec.microsoft.com, client.wns.windows.com, ctldl.windowsupdate.com, dns.msftncsi.com

Comparison with publisher answers and earlier runs

The following comparison is separate from native inference. It measures availability of selected facts, not 100% incident-diagnosis accuracy.

Publisher answer.

All three clients must remain separate. V2 omitted 2,136 unique hashes from its detailed artifact inventory; V3 retains compact overflow hashes for enrichment. Family-per-host attribution, SMTP email extraction and reversal of a downloaded binary remain outside the native profile. IOC list here is a declared subset of the long publisher list, not an exhaustive recall denominator.

Client Field Packet-verified expected value Live
172.16.0.131 ip 172.16.0.131 True
172.16.0.131 mac 2c:27:d7:d2:06:f5 True
172.16.0.131 hostname DESKTOP-VD151O7 True
172.16.0.131 account tricia.becker True
172.16.0.170 ip 172.16.0.170 True
172.16.0.170 mac 00:12:f0:64:d1:d9 True
172.16.0.170 hostname DESKTOP-W5TFTQY True
172.16.0.170 account everett.french True
172.16.0.149 ip 172.16.0.149 True
172.16.0.149 mac 00:1b:fc:7b:d1:c0 True
172.16.0.149 hostname DESKTOP-KPQ9FDB True
172.16.0.149 account nick.montgomery True

Declared IOC subset available: 37/37. Not exhaustive recall.

Browser history/open, Markdown export and investigation transfer: True. Investigation ID: 7ebcdf06-0ce2-42bb-aa0c-6cd478f63e57. Investigation transfers preserve a bounded preview, total count, source-analysis URL and hashes. Complete evidence remains server-side. TTP-overlap leads are not inserted into actor associations. PDF export: HTTP 200, including an explicitly non-authoritative packet-evidence appendix. STIX export remains HTTP 409 until a human completes review/promotion; this is a successful safety check.

Follow-up priorities

Validate high/medium findings using frame/stream evidence; obtain process and endpoint telemetry for execution, persistence and credential-theft hypotheses. Provider data above is current-time external context, not historical execution evidence. Review shared-CDN matches for specificity. Do not execute exported objects or treat encrypted payload metadata as decrypted evidence.