{
  "2024-11-26": {
    "source": "https://www.malware-traffic-analysis.net/2024/11/26/page2.html",
    "hosts": [
      {
        "ip": "10.11.26.183",
        "mac": "d0:57:7b:ce:fc:8b",
        "hostname": "DESKTOP-B8TQK49",
        "account": "oboomwald",
        "family": "NetSupport"
      }
    ],
    "iocs": [
      "194.180.191.64",
      "modandcrackedapk.com",
      "classicgrand.com"
    ],
    "publisher_conflicts": [
      {
        "field": "c2_ip",
        "published": "194.180.191.164",
        "packet_value": "194.180.191.64",
        "reason": "Summary IOC conflicts with its own walkthrough and the packet destinations."
      }
    ],
    "comparison": "Native NetSupport User-Agent, cleartext port 443 and periodic callbacks support the tool identification. The delivery-chain explanation and malicious authorization context require the publisher or endpoint evidence. Shared site visits alone do not prove causation."
  },
  "2024-09-04": {
    "source": "https://www.malware-traffic-analysis.net/2024/09/04/page2.html",
    "hosts": [
      {
        "ip": "172.17.0.99",
        "mac": "18:3d:a2:b6:8d:c4",
        "hostname": "DESKTOP-RNVO9AT",
        "account": "afletcher",
        "family": "Koi Stealer"
      }
    ],
    "iocs": [
      "79.124.78.197"
    ],
    "comparison": "The engine retains the three PHP request paths and repeated POST activity, but does not independently identify Koi Stealer. The publisher bases that label on supplied ETPRO alerts, which were not fed to this PCAP-only run."
  },
  "2024-08-15": {
    "source": "https://www.malware-traffic-analysis.net/2024/08/15/page2.html",
    "hosts": [
      {
        "ip": "10.8.15.133",
        "mac": "00:1c:bf:03:54:82",
        "hostname": "DESKTOP-H8ALZBV",
        "account": "plucero",
        "family": "WarmCookie"
      }
    ],
    "iocs": [
      "104.21.55.70",
      "172.67.170.159",
      "72.5.43.29",
      "quote.checkfedexexp.com",
      "business.checkfedexexp.com",
      "798563fcf7600f7ef1a35996291a9dfb5f9902733404dd499e2e736ea1dc6fc5",
      "dab98819d1d7677a60f5d06be210d45b74ae5fd8cf0c24ec1b3766e25ce6dc2c",
      "b7aec5f73d2a6bbd8cd920edb4760e2edadc98c3a45bf4fa994d47ca9cbd02f6"
    ],
    "publisher_conflicts": [
      {
        "field": "followup_ip",
        "published": "172.67.170.169",
        "packet_value": "172.67.170.159",
        "reason": "Packet TLS/flow evidence uses .159. The published full HTTPS path is not visible from encrypted PCAP metadata."
      }
    ],
    "comparison": "The downloaded ZIP/DLL hashes and callback evidence are available, but the JavaScript child hash requires safe archive extraction outside this decoder's no-unpacking profile. The encrypted follow-up URL path and WarmCookie classification are publisher context, not independent packet conclusions."
  },
  "2024-07-30": {
    "source": "https://www.malware-traffic-analysis.net/2024/07/30/page2.html",
    "hosts": [
      {
        "ip": "172.16.1.66",
        "mac": "00:1e:64:ec:f3:08",
        "hostname": "DESKTOP-SKBR25F",
        "account": "ccollier",
        "family": "STRRAT"
      }
    ],
    "iocs": [
      "141.98.10.79",
      "github.com",
      "objects.githubusercontent.com",
      "repo1.maven.org",
      "ip-api.com"
    ],
    "publisher_conflicts": [
      {
        "field": "c2_ip",
        "published": "141.98.10.69",
        "packet_value": "141.98.10.79",
        "reason": "Actual TCP/12132 endpoint is .79; frame 9119 includes the literal STRRAT software label."
      }
    ],
    "comparison": "V2 missed meaningful non-web behavior. V3 reports the literal structured software/host/account announcement and sustained custom TCP flow. STRRAT is directly visible as a self-reported label, not cryptographically authenticated attribution. File-sharing domains and public-IP services are not inherently malicious."
  },
  "2022-03-21": {
    "source": "https://www.malware-traffic-analysis.net/2022/03/21/page2.html",
    "hosts": [
      {
        "ip": "10.0.19.14",
        "mac": "00:60:52:b7:33:0f",
        "hostname": "DESKTOP-5QS3D5D",
        "account": "patrick.zimmerman",
        "family": "IcedID / Cobalt Strike"
      }
    ],
    "iocs": [
      "188.166.154.118",
      "157.245.142.66",
      "160.153.32.99",
      "91.193.16.181",
      "23.227.198.203",
      "oceriesfornot.top",
      "antnosience.com",
      "suncoastpinball.com",
      "otectagain.top",
      "seaskysafe.com",
      "dilimoretast.com",
      "filebin.net",
      "situla.bitbit.net",
      "bupdater.com"
    ],
    "publisher_conflicts": [
      {
        "field": "ip",
        "published": "10.0.18.14",
        "packet_value": "10.0.19.14",
        "reason": "The capture and stated 10.0.19.0/24 LAN identify .19.14."
      }
    ],
    "comparison": "The engine retains identity and infrastructure observations, but does not independently classify IcedID or Cobalt Strike. Encrypted sessions and a nonstandard TLS port are insufficient for a definitive malware-family label without dated signature or intelligence support."
  },
  "2022-02-23": {
    "source": "https://www.malware-traffic-analysis.net/2022/02/23/page2.html",
    "hosts": [
      {
        "ip": "172.16.0.131",
        "mac": "2c:27:d7:d2:06:f5",
        "hostname": "DESKTOP-VD151O7",
        "account": "tricia.becker",
        "family": "FormBook / XLoader"
      },
      {
        "ip": "172.16.0.170",
        "mac": "00:12:f0:64:d1:d9",
        "hostname": "DESKTOP-W5TFTQY",
        "account": "everett.french",
        "family": "Emotet"
      },
      {
        "ip": "172.16.0.149",
        "mac": "00:1b:fc:7b:d1:c0",
        "hostname": "DESKTOP-KPQ9FDB",
        "account": "nick.montgomery",
        "family": "Emotet / spambot"
      }
    ],
    "iocs": [
      "156.96.154.210",
      "www.katchybugonsale.com",
      "www.privilegetroissecurity.com",
      "www.hentainftxxx.com",
      "www.moonshot.properties",
      "www.nt-renewable.com",
      "www.elsiepupz.com",
      "www.jogoreviravolta.com",
      "www.seo-python.com",
      "www.db-propertygroup.com",
      "www.xn--pckwb0cye6947ajzku8opzi.com",
      "www.czzhudi.com",
      "www.hydrocheats.com",
      "www.riskprotek.com",
      "www.campdiscount.info",
      "www.mystore.guide",
      "www.theperfecttrainer.com",
      "www.globalsovereignbank.com",
      "www.keysine.com",
      "www.chinadqwx.com",
      "www.awridahmed.com",
      "www.ban-click.com",
      "www.byaliciafryearson.com",
      "www.krpano.pro",
      "www.barrcoplumbingsupply.com",
      "www.32342240.xyz",
      "www.jmtmjz.com",
      "www.freedomteaminc.com",
      "www.centroimprenta.xyz",
      "www.e-scooters.frl",
      "www.klassociates.info",
      "dalgahavuzu.com",
      "www.ajaxmatters.com",
      "135.148.121.246",
      "144.217.88.125",
      "134.209.156.68",
      "14b57211308ac8ad2a63c965783d9ba1c2d1930d0cafd884374d143a481f9bf3"
    ],
    "comparison": "All three clients must remain separate. V2 omitted 2,136 unique hashes from its detailed artifact inventory; V3 retains compact overflow hashes for enrichment. Family-per-host attribution, SMTP email extraction and reversal of a downloaded binary remain outside the native profile. IOC list here is a declared subset of the long publisher list, not an exhaustive recall denominator."
  },
  "2022-01-07": {
    "source": "https://www.malware-traffic-analysis.net/2022/01/07/page2.html",
    "hosts": [
      {
        "ip": "192.168.1.216",
        "mac": "9c:5c:8e:32:58:f9",
        "hostname": "DESKTOP-GXMYNO2",
        "account": "steve.smith",
        "family": "OskiStealer"
      }
    ],
    "iocs": [
      "2.56.57.108",
      "16574f51785b0e2fc29c2c61477eb47bb39f714829999511dc8952b43ab17660",
      "a770ecba3b08bbabd0a567fc978e50615f8b346709f8eb3cfacf3faab24090ba",
      "3fe6b1c54b8cf28f571e0c5d6636b4069a8ab00b4f11dd842cfec00691d0c9cd",
      "334e69ac9367f708ce601a6f490ff227d6c20636da5222f148b25831d22e13d4",
      "e2935b5b28550d47dc971f456d6961f20d1633b4892998750140e0eaa9ae9d78"
    ],
    "publisher_conflicts": [
      {
        "field": "mac",
        "published": "95:5c:8e:32:58:f9",
        "packet_value": "9c:5c:8e:32:58:f9",
        "reason": "Ethernet source evidence is 9c, not 95."
      }
    ],
    "comparison": "Library downloads and the external endpoint are retained, but legitimate DLLs are not malware simply because a stealer retrieves them. The engine does not independently label OskiStealer or inspect the uploaded archive contents. Both conflicting observed hostname spellings remain evidence, not silently corrected. Hash list is a declared subset."
  },
  "2021-12-08": {
    "source": "https://isc.sans.edu/diary/28160",
    "hosts": [
      {
        "ip": "10.12.3.66",
        "hostname": "DESKTOP-LUOABV1",
        "account": "darin.figueroa",
        "family": "Emotet"
      }
    ],
    "iocs": [
      "gamaes.shop",
      "newsaarctech.com",
      "172.104.227.98",
      "163.172.50.82"
    ],
    "onset_utc": "2021-12-03T19:42:47+00:00",
    "comparison": "Identity and the listed infrastructure are packet-visible. Native family attribution, an infection-onset conclusion, and extraction/classification of 17 SMTP emails are not implemented. Publisher notes that the Emotet DLL cannot be exported from this capture. Do not interpret HTTP-export completeness as complete malware recovery."
  },
  "2021-10-22": {
    "source": "https://isc.sans.edu/diary/27998",
    "hosts": [
      {
        "ip": "10.10.22.157",
        "hostname": "DESKTOP-NZ875R4",
        "account": "marcus.cobb",
        "family": "NanoCore"
      },
      {
        "ip": "10.10.22.158",
        "hostname": "DESKTOP-87WCE26",
        "account": "kevin.henderson",
        "family": "BazarLoader"
      },
      {
        "ip": "10.10.22.156",
        "hostname": "DESKTOP-CFA3367",
        "account": "agnes.warren",
        "family": "Qakbot"
      }
    ],
    "iocs": [
      "kamuchehddhgfgf.ddns.net",
      "37.0.10.22",
      "sobolpand.top",
      "23.111.114.52",
      "95928b331e9942e4709b41ec8b59eb6f9e068f53ef2eeb15009feafd4ff5138d"
    ],
    "comparison": "Three client identities and infrastructure are retained, but the original task asks for email-to-host mapping. The separate malicious-email archive was not supplied to the PCAP-only engine; those three mappings remain untested, not correct by implication. Family labels require additional evidence. Publisher explicitly notes one missing HTTPS acquisition in the PCAP."
  },
  "2021-09-10": {
    "source": "https://www.malware-traffic-analysis.net/2021/09/10/page2.html",
    "hosts": [
      {
        "ip": "10.9.10.102",
        "mac": "00:4f:49:b1:e8:c3",
        "hostname": "DESKTOP-KKITB6Q",
        "account": "hobart.gunnarsson",
        "family": "BazarLoader / TA551 context"
      }
    ],
    "iocs": [
      "194.62.42.206",
      "simpsonsavingss.com",
      "167.172.37.9",
      "94.158.245.52",
      "eed363fc4af7a9070d69340592dcab7c78db4f90710357de29e3b624aa957cf8"
    ],
    "comparison": "Identity, DLL hash and infrastructure can be compared directly. BazarLoader and TA551 are sourced publisher conclusions, not native actor attribution from the PCAP. A generic transfer finding must not be scored as independent campaign identification."
  }
}
