1200KM · ANDREY PAUTOV
Home · Article · Ten reports · Screenshot gallery · Publication boundaries

Measured 19 September 2026 · Public derivative · Historical training evidence, not approved threat intelligence.

2021-09-10: AdversaryGraph live-instance PCAP report

Actual deployment: [local-workspace], HTTP [local-instance]. This is a regression validation, not an independent blind trial. No malware was executed and no malicious endpoint was contacted.

Executive assessment

Decoded 9221 packets across 66 IP endpoints and 263 transport flows. Observed 199 DNS events, 58 HTTP requests, 105 TLS ClientHello events, and 45 exported HTTP object(s). Deterministic rules produced 9 finding(s): 0 high, 2 medium, and 7 low. Findings are evidence-bound candidates and require analyst review; encrypted payload contents remain unavailable.

These findings identify observations and review priorities, not a proven malware family, actor, or causal infection chain. Source-frame evidence takes precedence over exercise answer typos.

Capture and execution evidence

Capture window: 2021-09-10T23:15:07.787295+00:00 to 2021-09-11T00:31:57.075695+00:00 UTC. Capture SHA-256: a9576008f7fd634740253a52b2937a205cd214cdde09f6924f0921b8e266dd12. Analysis ID: 9923b3d5-8d06-4f6a-b1f1-810507712be3; review session: 869e7fd1-f976-40e4-affa-f9960f431cf8. First real HTTP upload/analysis: 5.389 seconds. Fresh uncached decoder repeat: 4.922 seconds. Prior isolated upload: 5.742 seconds. The fresh repeat ran while builds/tests were active; these timings are not a controlled performance comparison. Native packet analysis used zero LLM calls and zero LLM tokens. Coding-agent token usage was not instrumented.

Packet result equals prior isolated result: True; fresh repeat exact: True; retained capture checksum valid: True; API retrieval identical: True; idempotent upload: True.

Internal host identities

Address MAC addresses Frame-backed identities
10.9.10.102 00:4f:49:b1:e8:c3 account: hobart.gunnarsson; full-name: Hobart Gunnarsson; hostname: DESKTOP-KKITB6Q
10.9.10.103 20:1a:06:68:23:49
10.9.10.255 ff:ff:ff:ff:ff:ff
10.9.10.9 14:18:77:0f:c6:9e

Evidence timeline

UTC Frame Candidate observation
2021-09-10T23:15:09.539026+00:00 19 low: Repeated unsuccessful DNS resolution
2021-09-10T23:15:14.903567+00:00 80 low: Directory-service protocol activity
2021-09-10T23:15:14.905140+00:00 82 low: Directory-service protocol activity
2021-09-10T23:16:56.202252+00:00 389 low: Directory-service protocol activity
2021-09-10T23:16:56.202503+00:00 391 low: Directory-service protocol activity
2021-09-10T23:16:56.243133+00:00 440 low: Directory-service protocol activity
2021-09-10T23:16:56.243557+00:00 441 low: Directory-service protocol activity
2021-09-10T23:24:48.773365+00:00 4193 medium: Script, archive, or executable transfer candidate
2021-09-10T23:24:48.774253+00:00 4195 medium: Script, archive, or executable transfer candidate

Highest-volume conversations

Wire volume includes overhead/retransmissions. A large or periodic flow is not automatically exfiltration or C2.

Initiator Responder Stream Wire bytes First frame
10.9.10.102:58182 23.1.237.225:80 tcp 101 2,087,602 4189
10.9.10.102:58181 23.1.237.216:80 tcp 100 1,112,368 4188
10.9.10.102:58171 52.238.248.6:443 tcp 90 456,652 3051
10.9.10.102:58174 23.1.237.200:80 tcp 93 317,223 3234
10.9.10.102:58132 167.172.37.9:443 tcp 51 311,988 1479
10.9.10.102:58131 194.62.42.206:80 tcp 50 301,789 1183
10.9.10.102:58238 10.9.10.9:445 tcp 157 46,539 8941
10.9.10.102:58100 10.9.10.9:445 tcp 19 41,170 359
10.9.10.102:58161 10.9.10.9:445 tcp 80 37,417 2666
10.9.10.102:58145 23.3.86.10:443 tcp 65 34,890 1954
10.9.10.102:58144 23.3.86.10:443 tcp 62 33,452 1951
10.9.10.102:58142 23.3.86.10:443 tcp 60 33,177 1949
10.9.10.102:58146 23.3.86.10:443 tcp 64 27,539 1953
10.9.10.102:58122 20.190.151.131:443 tcp 41 27,457 710
10.9.10.102:58152 23.3.85.202:80 tcp 72 27,040 2309
10.9.10.102:58172 20.190.154.138:443 tcp 91 24,811 3074
10.9.10.102:58217 40.126.26.135:443 tcp 136 24,796 8400
10.9.10.102:58175 40.125.122.151:443 tcp 94 22,424 4025
10.9.10.102:58153 23.3.85.202:80 tcp 71 21,713 2308
10.9.10.102:58154 23.3.85.202:80 tcp 74 20,215 2311

Native packet findings, artifacts and limitations

AdversaryGraph Deterministic PCAP Analysis

Source: 2021-09-10-traffic-analysis-exercise.pcap Capture SHA-256: a9576008f7fd634740253a52b2937a205cd214cdde09f6924f0921b8e266dd12 Semantic result SHA-256: ce8b10a4ba7a6615d2c58f5895ecb69dca768d904402026068da26b4ef7db5ed Analyzer manifest SHA-256: ee952aeb7cdc6958f4ae5178c54c274a1e4f0aec4d42f3bdb95baaff063b3dde

Executive summary

Decoded 9221 packets across 66 IP endpoints and 263 transport flows. Observed 199 DNS events, 58 HTTP requests, 105 TLS ClientHello events, and 45 exported HTTP object(s). Deterministic rules produced 9 finding(s): 0 high, 2 medium, and 7 low. Findings are evidence-bound candidates and require analyst review; encrypted payload contents remain unavailable.

Capture facts

Deterministic findings

MEDIUM — Script, archive, or executable transfer candidate

HTTP metadata names a script, archive, or executable. This is a transfer candidate, not proof of file type, execution, or malicious intent; legitimate updates use the same formats.

Rule: script-or-executable-transfer@pcap-rules-v3; confidence: 0.86; evidence: frame 4193 / TCP stream 100, frame 4198 / TCP stream 100, frame 4200 / TCP stream 100, frame 6404 / TCP stream 100.

Metrics: {"content_type":"application/octet-stream","declared_body_bytes":1048578,"destination":"10.9.10.102","response_count":2,"source":"23.1.237.216","uri":"/d/msdownload/update/software/defu/2021/09/am_delta_patch_1.349.439.0_dcf977cccce1b58289d270f71f8151b3acc1566b.exe"}

MEDIUM — Script, archive, or executable transfer candidate

HTTP metadata names a script, archive, or executable. This is a transfer candidate, not proof of file type, execution, or malicious intent; legitimate updates use the same formats.

Rule: script-or-executable-transfer@pcap-rules-v3; confidence: 0.86; evidence: frame 4195 / TCP stream 101, frame 4199 / TCP stream 101, frame 4201 / TCP stream 101, frame 6356 / TCP stream 101, frame 6371 / TCP stream 101.

Metrics: {"content_type":"application/octet-stream","declared_body_bytes":1970634,"destination":"10.9.10.102","response_count":3,"source":"23.1.237.225","uri":"/d/msdownload/update/software/defu/2021/09/am_delta_patch_1.349.439.0_dcf977cccce1b58289d270f71f8151b3acc1566b.exe"}

LOW — Repeated unsuccessful DNS resolution

Repeated NXDOMAIN responses may indicate a dead domain, misconfiguration, retrying software, or malicious fallback. They do not establish a domain-generation algorithm.

Rule: repeated-nxdomain@pcap-rules-v3; confidence: 0.5; evidence: frame 19, frame 64, frame 134, frame 168, frame 7624.

Metrics: {"domain":"wpad.angrypoutine.com","response_count":12,"source":"10.9.10.102"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 389 / TCP stream 15, frame 398 / TCP stream 15, frame 404 / TCP stream 15, frame 417 / TCP stream 15, frame 2059 / TCP stream 67.

Metrics: {"destination":"10.9.10.9","event_count":25,"operation_numbers":["0","1","12"],"protocol":"drsuapi","source":"10.9.10.102"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 80 / TCP stream 1, frame 83 / TCP stream 1, frame 478 / TCP stream 22, frame 483 / TCP stream 22, frame 486 / TCP stream 22.

Metrics: {"destination":"10.9.10.9","event_count":50,"operation_numbers":["0","2","3"],"protocol":"ldap","source":"10.9.10.102"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 440 / TCP stream 19, frame 442 / TCP stream 19, frame 444 / TCP stream 19, frame 446 / TCP stream 19, frame 448 / TCP stream 19.

Metrics: {"destination":"10.9.10.9","event_count":57,"operation_numbers":["1","16","17","18","19","20","25","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"10.9.10.102"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 391 / TCP stream 15, frame 401 / TCP stream 15, frame 406 / TCP stream 15, frame 418 / TCP stream 15, frame 2060 / TCP stream 67.

Metrics: {"destination":"10.9.10.102","event_count":25,"operation_numbers":["0","1","12"],"protocol":"drsuapi","source":"10.9.10.9"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 82 / TCP stream 1, frame 480 / TCP stream 22, frame 485 / TCP stream 22, frame 487 / TCP stream 22, frame 495 / TCP stream 23.

Metrics: {"destination":"10.9.10.102","event_count":39,"operation_numbers":["1","4,19,19,19,5","4,5","5"],"protocol":"ldap","source":"10.9.10.9"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 441 / TCP stream 19, frame 443 / TCP stream 19, frame 445 / TCP stream 19, frame 447 / TCP stream 19, frame 449 / TCP stream 19.

Metrics: {"destination":"10.9.10.102","event_count":57,"operation_numbers":["1","16","17","18","19","20","25","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"10.9.10.9"}

ATT&CK candidates

Identities

IOC and artifact candidates

Actor similarity leads

Local enrichment and correlations

No match means unknown in this corpus. Local CTI may postdate the capture. Matches and shared infrastructure require review; no automatic promotion or attribution. Snapshot: fd1ef8f35792013eb051dd90b6a512f313f5655d99849d97a044c7dc6beb785f; recorded 2026-09-19T12:10:32.214995+00:00; mode: local-only. Coverage: {"matched_observables":0,"no_exact_match":248,"observable_limit":5000,"observables_checked":248,"observables_total":248,"prior_case_limit_reached":false,"prior_cases_checked":15,"truncated":false}

Coverage and limitations

Live enrichment and correlation validation

The actual IOC library contained 156,125 records. Exact typed matches: 0; source actor assertions: 0. Independent SQL agrees: IOC=True, actors=True. A miss is unknown in this corpus, not evidence of benignness. The earlier isolated corpus included publisher-reference records; its positive matches were not live-provider detections and are not comparable to natural coverage here. ATT&CK catalog candidates: 1; current-version catalog checks passed: True. Detection-strategy joins were checked independently. Cross-case links: 15; independently verified: True. These are shared observations, predominantly common service infrastructure, not common-campaign assertions.

Passive local lookup target Type Local matches
194.62.42.206 ipv4 0
simpsonsavingss.com domain 0
167.172.37.9 ipv4 0
eed363fc4af7a9070d69340592dcab7c78db4f90710357de29e3b624aa957cf8 sha256 0
1d48d9166408d8b8bf39f9557e4f8a57133c353567c55966ec2831a7bc230431 sha256 0
au.download.windowsupdate.com domain 0

Approved external passive enrichment

Completed 6/6 planned case indicators. Shared indicators reuse one saved lookup rather than consume provider quota repeatedly.

These lookups used the actual local application and were explicitly authorized. No PCAP or payload was uploaded, no private address was disclosed, no target was scanned, and no AI provider was invoked. Tier-two/three pivots query the local corpus only.

Provider intelligence was retrieved after the captures: current reputation, hosting and service observations do not establish historical causality. not_found means absent from that provider, not benign. Family labels and ATT&CK/actor leads remain source assertions awaiting review.

Historical coverage caveat: ThreatFox documents a six-month IOC expiration policy for its API since May 2025. That can limit these older exercises; it does not prove why any particular lookup missed. ThreatFox API policy.

194.62.42.206

Type: ip; request: 8.845 seconds; completed: 2026-09-19T13:49:26.451953+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 15/100 (low signal); a heuristic priority, not calibrated probability. Graph: 16 nodes, 20 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok 1 engines marked malicious and 1 suspicious; 53 harmless, 34 undetected.
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar skipped MalwareBazaar is hash-focused; input is not a hash.
otx ok OTX returned 2 pulse(s).
urlscan ok urlscan returned 7 scan result(s). urlscan activity analysis found no obvious suspicious pattern.
greynoise not_found GreyNoise classification: unknown. Query status: not_found
abuseipdb ok AbuseIPDB confidence score: 0/100.
shodan not_found Shodan returned 0 open port(s). Query status: not_found
censys ok Censys host lookup returned 0 service(s).

No actor lead returned. This does not establish absence of an actor.

simpsonsavingss.com

Type: domain; request: 4.236 seconds; completed: 2026-09-19T13:49:41.831883+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 38/100 (needs review); a heuristic priority, not calibrated probability. Graph: 9 nodes, 12 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok 9 engines marked malicious and 0 suspicious; 46 harmless, 34 undetected.
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar skipped MalwareBazaar is hash-focused; input is not a hash.
otx ok OTX returned 1 pulse(s).
urlscan ok urlscan returned 10 scan result(s). urlscan activity analysis found no obvious suspicious pattern.
greynoise skipped GreyNoise is IP-focused; input is not an IP.
abuseipdb skipped AbuseIPDB is IP-focused; input is not an IP.
shodan skipped Shodan host lookup is IP-focused; input is not an IP.
censys ok Censys web property lookup returned 2 record(s) for simpsonsavingss.com. Broader Censys search requires an organization-enabled account and API role.

No actor lead returned. This does not establish absence of an actor.

167.172.37.9

Type: ip; request: 5.964 seconds; completed: 2026-09-19T13:50:03.549432+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 47/100 (suspicious); a heuristic priority, not calibrated probability. Graph: 9 nodes, 10 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok 4 engines marked malicious and 1 suspicious; 51 harmless, 33 undetected.
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar skipped MalwareBazaar is hash-focused; input is not a hash.
otx ok OTX returned 1 pulse(s).
urlscan ok urlscan returned 1 scan result(s). urlscan activity analysis found 1 suspicious pattern(s).
greynoise not_found GreyNoise classification: unknown. Query status: not_found
abuseipdb ok AbuseIPDB confidence score: 0/100.
shodan ok Shodan returned 3 open port(s).
censys ok Censys host lookup returned 4 service(s).

No actor lead returned. This does not establish absence of an actor.

eed363fc4af7a9070d69340592dcab7c78db4f90710357de29e3b624aa957cf8

Type: hash; request: 4.655 seconds; completed: 2026-09-19T13:50:22.243466+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 80/100 (highly suspicious); a heuristic priority, not calibrated probability. Graph: 4 nodes, 4 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok 59 engines marked malicious and 0 suspicious; 0 harmless, 12 undetected.
VirusTotal classification/name hints unreviewed; may include benign filenames trojan.kryplod/quantum, kryplod, quantum, bazar, trojan, ransomware, date1%3fBNLv65=pAAS
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar ok MalwareBazaar returned 1 sample record(s). Query status: ok
otx ok OTX returned 2 pulse(s).
urlscan ok urlscan returned 0 scan result(s). urlscan activity analysis found no obvious suspicious pattern.
greynoise skipped GreyNoise is IP-focused; input is not an IP.
abuseipdb skipped AbuseIPDB is IP-focused; input is not an IP.
shodan skipped Shodan host lookup is IP-focused; input is not an IP.
censys skipped Censys host and search pivots support IP, domain, and URL inputs.

Provider ATT&CK leads (not packet-observed execution):

ID Name Source / scope
T1018 Remote System Discovery virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1036 Masquerading virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1055 Process Injection virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1059 Command and Scripting Interpreter virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1071 Application Layer Protocol virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1082 System Information Discovery virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1083 File and Directory Discovery virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1129 Shared Modules virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1218 System Binary Proxy Execution virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1218.010 Regsvr32 virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1218.011 Rundll32 virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1497 Virtualization/Sandbox Evasion virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1518 Software Discovery virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1518.001 Security Software Discovery virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1573 Encrypted Channel virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1574 Hijack Execution Flow virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1574.002 virustotal (submitted indicator; provider-reported lead, not packet execution proof)

No actor lead returned. This does not establish absence of an actor.

1d48d9166408d8b8bf39f9557e4f8a57133c353567c55966ec2831a7bc230431

Type: hash; request: 5.143 seconds; completed: 2026-09-19T13:50:42.724713+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 0/100 (low signal); a heuristic priority, not calibrated probability. Graph: 1 nodes, 0 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok No malicious detections in last analysis; 0 harmless, 69 undetected.
VirusTotal classification/name hints unreviewed; may include benign filenames am_delta_patch_1.349.439.0_dcf977cccce1b58289d270f71f8151b3acc1566b(3).exe
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar not_found MalwareBazaar returned 0 sample record(s). Query status: hash_not_found
otx ok OTX returned 0 pulse(s).
urlscan ok urlscan returned 0 scan result(s). urlscan activity analysis found no obvious suspicious pattern.
greynoise skipped GreyNoise is IP-focused; input is not an IP.
abuseipdb skipped AbuseIPDB is IP-focused; input is not an IP.
shodan skipped Shodan host lookup is IP-focused; input is not an IP.
censys skipped Censys host and search pivots support IP, domain, and URL inputs.

No actor lead returned. This does not establish absence of an actor.

au.download.windowsupdate.com

Type: domain; request: 8.634 seconds; completed: 2026-09-19T13:51:06.220131+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 34/100 (needs review); a heuristic priority, not calibrated probability. Graph: 32 nodes, 36 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok No malicious detections in last analysis; 60 harmless, 29 undetected.
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar skipped MalwareBazaar is hash-focused; input is not a hash.
otx ok OTX returned 0 pulse(s).
urlscan ok urlscan returned 10 scan result(s). urlscan activity analysis found 2 suspicious pattern(s).
greynoise skipped GreyNoise is IP-focused; input is not an IP.
abuseipdb skipped AbuseIPDB is IP-focused; input is not an IP.
shodan skipped Shodan host lookup is IP-focused; input is not an IP.
censys ok Censys web property lookup returned 2 record(s) for au.download.windowsupdate.com. Broader Censys search requires an organization-enabled account and API role.

No actor lead returned. This does not establish absence of an actor.

Shared-service caution: this is a broadly used legitimate service. A feed/search hit may concern a specific hosted path or unrelated customer; do not classify or block the whole service based on this lookup.

The live case contains 6 explicitly linked, exact-type/value PCAP observables. 4 retain frame references; remaining exported-object hashes retain native object IDs and capture-export provenance, not an exact packet-frame map. Every link retains the capture checksum, points to a saved provider investigation, and was reread from the real API. Case actor associations remain empty. Verified graph links.

Current ATT&CK catalog and detection-strategy joins

These are read-only joins against the actual database, not generated detections or proof that the victim executed the technique. A valid catalog join cannot validate the original provider assertion.

Technique Current catalog match Available detection strategies
T1018 True Detection Strategy for Remote System Enumeration Behavior (x-mitre-detection-strategy--9ec6dafe-3e93-4ebb-943e-26b84136f6a9)
T1036 True Behavioral Detection of Masquerading Across Platforms via Metadata and Execution Discrepancy (x-mitre-detection-strategy--408aedab-4a23-41ad-809d-fe9c3805b7f6)
T1055 True Behavioral Detection of Process Injection Across Platforms (x-mitre-detection-strategy--9833b57b-4c83-4f58-b4cf-76f041b29273)
T1059 True Behavioral Detection of Command and Scripting Interpreter Abuse (x-mitre-detection-strategy--8582f5e6-44a5-4950-b7e8-a3e1b6d58d63)
T1071 True Detection of Command and Control Over Application Layer Protocols (x-mitre-detection-strategy--155cab5b-c70b-4cfb-ba52-f62a21836b19)
T1082 True System Discovery via Native and Remote Utilities (x-mitre-detection-strategy--75161d5e-2b6d-4112-ab4d-338f70ea97f0)
T1083 True Recursive Enumeration of Files and Directories Across Privilege Contexts (x-mitre-detection-strategy--33ab9d0c-5671-48e6-8465-f80560909c65)
T1129 True Behavior-chain, platform-aware detection strategy for T1129 Shared Modules (x-mitre-detection-strategy--928a6ce6-fca0-4d66-aba3-1121431b953e)
T1218 True Detection of Proxy Execution via Trusted Signed Binaries Across Platforms (x-mitre-detection-strategy--ce0b969a-1411-4b6f-a6aa-c31ef6fe6727)
T1218.010 True Detection Strategy for System Binary Proxy Execution: Regsvr32 (x-mitre-detection-strategy--0a931f22-4820-48aa-8051-056da15a6183)
T1218.011 True Detection Strategy for T1218.011 Rundll32 Abuse (x-mitre-detection-strategy--a51d4d34-78fc-49b7-9071-348905dd33c2)
T1497 True Detection Strategy for T1497 Virtualization/Sandbox Evasion (x-mitre-detection-strategy--7f5dde79-7872-48dd-8718-cd2e10d7cbfc)
T1518 True Multi-Platform Software Discovery Behavior Chain (x-mitre-detection-strategy--f18dee58-43be-41e4-85a3-c6820033ac0d)
T1518.001 True Security Software Discovery Across Platforms (x-mitre-detection-strategy--e2409f82-e24c-4bb9-ad44-b20d97fb7a5a)
T1573 True Detection Strategy for Encrypted Channel across OS Platforms (x-mitre-detection-strategy--08861418-398c-4972-8850-5e11f2d32944)
T1574 True Detection Strategy for Hijack Execution Flow across OS platforms. (x-mitre-detection-strategy--07669925-383b-455b-a3e2-3a79e18eed27)
T1574.002 False None returned
Prior analysis Shared count Example observations
8f0da1cd-9998-4d41-9fc7-683302a6ee24 51 a-ring.msedge.net, api.msn.com, bing.com, client.wns.windows.com, ctldl.windowsupdate.com
96e0e828-93ae-49d5-8104-9f14cb584c3e 23 api.msn.com, client.wns.windows.com, dns.msftncsi.com, gameplayapi.intel.com, nexus.officeapps.live.com
6e50c68f-5552-400c-9835-15867ddb022d 23 api.msn.com, au.download.windowsupdate.com, client.wns.windows.com, ctldl.windowsupdate.com, dns.msftncsi.com
43bc93eb-d6db-4400-b983-b0dd404c8ca4 35 a-ring.msedge.net, api.msn.com, client.wns.windows.com, ctldl.windowsupdate.com, dns.msftncsi.com
6df36b51-4b44-4660-b534-2fa89705e807 35 api.msn.com, client.wns.windows.com, ctldl.windowsupdate.com, dns.msftncsi.com, fp-vs-nocache.azureedge.net
29aa3ef8-47c9-4c47-b4cc-1ff3e0708142 10 api.msn.com, client.wns.windows.com, settings-win.data.microsoft.com, v10.events.data.microsoft.com, www.bing.com
b79032a8-d69e-4ac1-bdd4-542473fa8e3b 15 api.msn.com, client.wns.windows.com, fe2cr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com, fp.msedge.net
faf041c3-70e0-4a01-8780-10917e5e187c 12 api.msn.com, client.wns.windows.com, ctldl.windowsupdate.com, dns.msftncsi.com, download.windowsupdate.com
08324647-35af-4af2-8d82-4387eec03918 14 api.msn.com, client.wns.windows.com, ctldl.windowsupdate.com, dns.msftncsi.com, fe3cr.delivery.mp.microsoft.com
616a90fa-f15e-4fcb-8d56-7b8e0eff5785 4 login.live.com, settings-win.data.microsoft.com, v10.events.data.microsoft.com, www.bing.com
459e119d-191f-49e8-85ea-c78f9de41826 15 api.msn.com, au.download.windowsupdate.com, client.wns.windows.com, ctldl.windowsupdate.com, download.windowsupdate.com
7a2cfe72-f48d-4894-8a2d-8889cb3b11b2 12 api.msn.com, client.wns.windows.com, ctldl.windowsupdate.com, settings-win.data.microsoft.com, update.googleapis.com
81373b30-6a59-49d1-89b0-bad73ed19eaa 13 api.msn.com, client.wns.windows.com, dns.msftncsi.com, login.live.com, settings-win.data.microsoft.com
38851ad7-b3a0-423d-ae89-3b7be4e4b908 21 api.msn.com, client.wns.windows.com, ctldl.windowsupdate.com, dns.msftncsi.com, fp.msedge.net
bfccc426-aa9b-4007-8558-a66d37ecb90c 18 api.msn.com, au.download.windowsupdate.com, client.wns.windows.com, ctldl.windowsupdate.com, dns.msftncsi.com

Comparison with publisher answers and earlier runs

The following comparison is separate from native inference. It measures availability of selected facts, not 100% incident-diagnosis accuracy.

Publisher answer.

Identity, DLL hash and infrastructure can be compared directly. BazarLoader and TA551 are sourced publisher conclusions, not native actor attribution from the PCAP. A generic transfer finding must not be scored as independent campaign identification.

Client Field Packet-verified expected value Live
10.9.10.102 ip 10.9.10.102 True
10.9.10.102 mac 00:4f:49:b1:e8:c3 True
10.9.10.102 hostname DESKTOP-KKITB6Q True
10.9.10.102 account hobart.gunnarsson True

Declared IOC subset available: 5/5. Not exhaustive recall.

Browser history/open, Markdown export and investigation transfer: True. Investigation ID: 507c6eec-8119-424e-bada-fcd00ccff4f5. Investigation transfers preserve a bounded preview, total count, source-analysis URL and hashes. Complete evidence remains server-side. TTP-overlap leads are not inserted into actor associations. PDF export: HTTP 200, including an explicitly non-authoritative packet-evidence appendix. STIX export remains HTTP 409 until a human completes review/promotion; this is a successful safety check.

Follow-up priorities

Validate high/medium findings using frame/stream evidence; obtain process and endpoint telemetry for execution, persistence and credential-theft hypotheses. Provider data above is current-time external context, not historical execution evidence. Review shared-CDN matches for specificity. Do not execute exported objects or treat encrypted payload metadata as decrypted evidence.