1200KM · ANDREY PAUTOV
Home · Article · Ten reports · Screenshot gallery · Publication boundaries

Measured 19 September 2026 · Public derivative · Historical training evidence, not approved threat intelligence.

2021-12-08: AdversaryGraph live-instance PCAP report

Actual deployment: [local-workspace], HTTP [local-instance]. This is a regression validation, not an independent blind trial. No malware was executed and no malicious endpoint was contacted.

Executive assessment

Decoded 55390 packets across 756 IP endpoints and 2044 transport flows. Observed 1726 DNS events, 17 HTTP requests, 191 TLS ClientHello events, and 500 exported HTTP object(s). Deterministic rules produced 18 finding(s): 0 high, 12 medium, and 6 low. Findings are evidence-bound candidates and require analyst review; encrypted payload contents remain unavailable.

These findings identify observations and review priorities, not a proven malware family, actor, or causal infection chain. Source-frame evidence takes precedence over exercise answer typos.

Capture and execution evidence

Capture window: 2021-12-03T19:41:50.282150+00:00 to 2021-12-03T20:15:46.320562+00:00 UTC. Capture SHA-256: 91e547acc39e8ef27d7ec549404157fe527e090bd5caf6fe189c2bae6d4a57ef. Analysis ID: 96e0e828-93ae-49d5-8104-9f14cb584c3e; review session: 69fc74e8-a685-4c8b-bde3-5ee0bb1190f6. First real HTTP upload/analysis: 21.972 seconds. Fresh uncached decoder repeat: 27.496 seconds. Prior isolated upload: 20.329 seconds. The fresh repeat ran while builds/tests were active; these timings are not a controlled performance comparison. Native packet analysis used zero LLM calls and zero LLM tokens. Coding-agent token usage was not instrumented.

Packet result equals prior isolated result: True; fresh repeat exact: True; retained capture checksum valid: True; API retrieval identical: True; idempotent upload: True.

Internal host identities

Address MAC addresses Frame-backed identities
10.12.3.1 00:30:b6:89:08:49
10.12.3.255 ff:ff:ff:ff:ff:ff
10.12.3.3 10:98:36:b9:41:7c
10.12.3.35 00:4f:49:f9:3a:6f
10.12.3.38 00:4f:49:c8:4e:37
10.12.3.66 00:4f:49:e7:81:3d account: darin.figueroa; domain: FARGREENTECH; full-name: Darin Figueroa; hostname: DESKTOP-LUOABV1; hostname: FARGREENTECH
192.168.201.133 00:30:b6:89:08:49

Evidence timeline

UTC Frame Candidate observation
2021-12-03T19:41:50.675316+00:00 43 low: Directory-service protocol activity
2021-12-03T19:41:50.676125+00:00 46 low: Directory-service protocol activity
2021-12-03T19:42:09.027599+00:00 290 low: Directory-service protocol activity
2021-12-03T19:42:09.027946+00:00 291 low: Directory-service protocol activity
2021-12-03T19:42:09.117621+00:00 352 low: Directory-service protocol activity
2021-12-03T19:42:09.117762+00:00 353 low: Directory-service protocol activity
2021-12-03T19:42:47.664570+00:00 1743 medium: HTTP client claiming a PowerShell User-Agent
2021-12-03T19:42:48.410086+00:00 1771 medium: HTTP client claiming a PowerShell User-Agent
2021-12-03T20:09:49.711447+00:00 11092 medium: Sustained external TCP conversation outside decoded application coverage
2021-12-03T20:09:52.632698+00:00 11301 medium: Sustained external TCP conversation outside decoded application coverage
2021-12-03T20:10:20.118295+00:00 13057 medium: Sustained external TCP conversation outside decoded application coverage
2021-12-03T20:11:23.142675+00:00 18188 medium: Sustained external TCP conversation outside decoded application coverage
2021-12-03T20:11:56.538087+00:00 21451 medium: Sustained external TCP conversation outside decoded application coverage
2021-12-03T20:12:02.890489+00:00 23295 medium: Sustained external TCP conversation outside decoded application coverage
2021-12-03T20:12:33.057066+00:00 28378 medium: Sustained external TCP conversation outside decoded application coverage
2021-12-03T20:13:27.885993+00:00 43910 medium: Sustained external TCP conversation outside decoded application coverage
2021-12-03T20:13:53.220600+00:00 46108 medium: Sustained external TCP conversation outside decoded application coverage
2021-12-03T20:14:17.368790+00:00 47842 medium: Sustained external TCP conversation outside decoded application coverage

Highest-volume conversations

Wire volume includes overhead/retransmissions. A large or periodic flow is not automatically exfiltration or C2.

Initiator Responder Stream Wire bytes First frame
10.12.3.66:53013 91.207.181.106:8080 tcp 748 2,960,550 28378
10.12.3.66:53438 91.207.181.106:8080 tcp 1272 1,881,584 51524
10.12.3.66:52457 172.104.227.98:443 tcp 71 1,600,976 8614
10.12.3.66:52456 172.104.227.98:443 tcp 70 1,587,057 6591
10.12.3.66:52415 139.59.6.175:80 tcp 29 1,211,230 1756
10.12.3.66:53129 173.247.253.179:465 tcp 886 1,001,959 36181
10.12.3.66:53001 186.202.161.96:465 tcp 728 987,489 25667
10.12.3.66:53106 108.179.194.17:465 tcp 854 953,894 35188
10.12.3.66:52888 74.220.206.23:465 tcp 595 952,534 21029
10.12.3.66:52989 208.84.244.140:465 tcp 703 951,040 25168
10.12.3.66:53104 108.167.153.167:587 tcp 852 948,727 35168
10.12.3.66:52559 203.211.136.199:587 tcp 206 947,921 12289
10.12.3.66:53244 186.64.117.195:587 tcp 1014 945,771 45476
10.12.3.66:52890 91.207.181.106:8080 tcp 597 805,994 21451
10.12.3.66:52408 204.79.197.200:443 tcp 20 801,226 488
10.12.3.66:53125 199.79.63.117:587 tcp 882 744,297 36087
10.12.3.66:53121 74.220.199.65:587 tcp 877 739,207 35948
10.12.3.66:52978 192.64.117.195:465 tcp 689 544,020 24744
10.12.3.66:52429 172.104.227.98:443 tcp 43 540,063 4112
10.12.3.66:52967 58.80.137.169:587 tcp 678 507,101 24446

Native packet findings, artifacts and limitations

AdversaryGraph Deterministic PCAP Analysis

Source: 2021-12-08-ISC-Forensic-Challenge.pcap Capture SHA-256: 91e547acc39e8ef27d7ec549404157fe527e090bd5caf6fe189c2bae6d4a57ef Semantic result SHA-256: 3343d2811e62c53a10dfd853861eeb3e3316a3080f654a63017c370f005b6af8 Analyzer manifest SHA-256: ee952aeb7cdc6958f4ae5178c54c274a1e4f0aec4d42f3bdb95baaff063b3dde

Executive summary

Decoded 55390 packets across 756 IP endpoints and 2044 transport flows. Observed 1726 DNS events, 17 HTTP requests, 191 TLS ClientHello events, and 500 exported HTTP object(s). Deterministic rules produced 18 finding(s): 0 high, 12 medium, and 6 low. Findings are evidence-bound candidates and require analyst review; encrypted payload contents remain unavailable.

Capture facts

Deterministic findings

MEDIUM — HTTP client claiming a PowerShell User-Agent

The HTTP User-Agent claims Windows PowerShell. User-Agent strings can be spoofed; this alone does not prove interpreter execution or malicious intent.

Rule: powershell-http-client@pcap-rules-v3; confidence: 0.94; evidence: frame 1743 / TCP stream 27.

Metrics: {"destination":"104.21.29.80","request_count":1,"source":"10.12.3.66","user_agent":"Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1320"}

MEDIUM — HTTP client claiming a PowerShell User-Agent

The HTTP User-Agent claims Windows PowerShell. User-Agent strings can be spoofed; this alone does not prove interpreter execution or malicious intent.

Rule: powershell-http-client@pcap-rules-v3; confidence: 0.94; evidence: frame 1771 / TCP stream 29.

Metrics: {"destination":"139.59.6.175","request_count":1,"source":"10.12.3.66","user_agent":"Mozilla/5.0 (Windows NT; Windows NT 10.0; en-US) WindowsPowerShell/5.1.19041.1320"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 353 / TCP stream 11, frame 355 / TCP stream 11, frame 357 / TCP stream 11, frame 359 / TCP stream 11, frame 3126 / TCP stream 32.

Metrics: {"destination":"10.12.3.66","event_count":16,"operation_numbers":["0","1","12"],"protocol":"drsuapi","source":"10.12.3.3"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 46 / TCP stream 0, frame 52 / TCP stream 0, frame 428 / TCP stream 17, frame 433 / TCP stream 17, frame 435 / TCP stream 17.

Metrics: {"destination":"10.12.3.66","event_count":25,"operation_numbers":["1","4,19,19,19,5","4,5","5"],"protocol":"ldap","source":"10.12.3.3"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 291 / TCP stream 8, frame 293 / TCP stream 8, frame 295 / TCP stream 8, frame 297 / TCP stream 8, frame 299 / TCP stream 8.

Metrics: {"destination":"10.12.3.66","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"10.12.3.3"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 352 / TCP stream 11, frame 354 / TCP stream 11, frame 356 / TCP stream 11, frame 358 / TCP stream 11, frame 3125 / TCP stream 32.

Metrics: {"destination":"10.12.3.3","event_count":16,"operation_numbers":["0","1","12"],"protocol":"drsuapi","source":"10.12.3.66"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 43 / TCP stream 0, frame 50 / TCP stream 0, frame 53 / TCP stream 0, frame 426 / TCP stream 17, frame 431 / TCP stream 17.

Metrics: {"destination":"10.12.3.3","event_count":32,"operation_numbers":["0","2","3"],"protocol":"ldap","source":"10.12.3.66"}

LOW — Directory-service protocol activity

Directory protocol operations were decoded. Normal Windows logon uses these protocols; activity alone does not establish discovery, credential theft, or DCSync.

Rule: directory-service-activity@pcap-rules-v3; confidence: 0.95; evidence: frame 290 / TCP stream 8, frame 292 / TCP stream 8, frame 294 / TCP stream 8, frame 296 / TCP stream 8, frame 298 / TCP stream 8.

Metrics: {"destination":"10.12.3.3","event_count":15,"operation_numbers":["1","16","17","3","34","36","39","5","6","64","7"],"protocol":"samr","source":"10.12.3.66"}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 11092 / TCP stream 92.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":30.685,"packets":107,"source":"10.12.3.66","wire_bytes":73616}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 11301 / TCP stream 113.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":57.532,"packets":147,"source":"10.12.3.66","wire_bytes":105748}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 13057 / TCP stream 241.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":42.498,"packets":168,"source":"10.12.3.66","wire_bytes":125939}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 18188 / TCP stream 443.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":33.66,"packets":583,"source":"10.12.3.66","wire_bytes":454912}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 21451 / TCP stream 597.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":36.785,"packets":1049,"source":"10.12.3.66","wire_bytes":805994}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 23295 / TCP stream 598.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":59.968,"packets":108,"source":"10.12.3.66","wire_bytes":73622}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 28378 / TCP stream 748.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":34.519,"packets":3721,"source":"10.12.3.66","wire_bytes":2960550}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 43910 / TCP stream 895.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":49.751,"packets":111,"source":"10.12.3.66","wire_bytes":74055}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 46108 / TCP stream 1057.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":54.922,"packets":353,"source":"10.12.3.66","wire_bytes":265548}

MEDIUM — Sustained external TCP conversation outside decoded application coverage

The flow exchanges traffic with a public endpoint but has no HTTP/TLS/identity event in this profile. Inspect the stream for a custom protocol or a missing handshake. This is a coverage/investigation lead, not a malware verdict.

Rule: unclassified-external-tcp@pcap-rules-v3; confidence: 0.7; evidence: frame 47842 / TCP stream 1128.

Metrics: {"destination":"91.207.181.106","destination_port":8080,"duration_seconds":40.215,"packets":331,"source":"10.12.3.66","wire_bytes":262342}

ATT&CK candidates

Identities

IOC and artifact candidates

Actor similarity leads

Local enrichment and correlations

No match means unknown in this corpus. Local CTI may postdate the capture. Matches and shared infrastructure require review; no automatic promotion or attribution. Snapshot: 37c4030f9b25335ca7a7a8cd23b5f050fab86309243d1fc8d5d3462e90e2a5a9; recorded 2026-09-19T12:09:53.287759+00:00; mode: local-only. Coverage: {"matched_observables":0,"no_exact_match":3662,"observable_limit":5000,"observables_checked":3662,"observables_total":3662,"prior_case_limit_reached":false,"prior_cases_checked":13,"truncated":false}

Coverage and limitations

Live enrichment and correlation validation

The actual IOC library contained 156,125 records. Exact typed matches: 0; source actor assertions: 0. Independent SQL agrees: IOC=True, actors=True. A miss is unknown in this corpus, not evidence of benignness. The earlier isolated corpus included publisher-reference records; its positive matches were not live-provider detections and are not comparable to natural coverage here. ATT&CK catalog candidates: 1; current-version catalog checks passed: True. Detection-strategy joins were checked independently. Cross-case links: 13; independently verified: True. These are shared observations, predominantly common service infrastructure, not common-campaign assertions.

Passive local lookup target Type Local matches
gamaes.shop domain 0
newsaarctech.com domain 0
172.104.227.98 ipv4 0
163.172.50.82 ipv4 0
0a85cba8c2e6aa44684f15047dcaa4c4d7f86ec356891bc8e0b8ee36bb151f7a sha256 0
2c80de6ffeb0759cb01dd7ad50437ea8dfcb7e4b8582a0129e7e7f700b593e38 sha256 0

Approved external passive enrichment

Completed 6/6 planned case indicators. Shared indicators reuse one saved lookup rather than consume provider quota repeatedly.

These lookups used the actual local application and were explicitly authorized. No PCAP or payload was uploaded, no private address was disclosed, no target was scanned, and no AI provider was invoked. Tier-two/three pivots query the local corpus only.

Provider intelligence was retrieved after the captures: current reputation, hosting and service observations do not establish historical causality. not_found means absent from that provider, not benign. Family labels and ATT&CK/actor leads remain source assertions awaiting review.

Historical coverage caveat: ThreatFox documents a six-month IOC expiration policy for its API since May 2025. That can limit these older exercises; it does not prove why any particular lookup missed. ThreatFox API policy.

gamaes.shop

Type: domain; request: 7.763 seconds; completed: 2026-09-19T14:05:56.714469+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 95/100 (highly suspicious); a heuristic priority, not calibrated probability. Graph: 21 nodes, 26 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok 4 engines marked malicious and 1 suspicious; 49 harmless, 35 undetected.
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar skipped MalwareBazaar is hash-focused; input is not a hash.
otx ok OTX returned 2 pulse(s).
urlscan ok urlscan returned 10 scan result(s). urlscan activity analysis found 4 suspicious pattern(s).
greynoise skipped GreyNoise is IP-focused; input is not an IP.
abuseipdb skipped AbuseIPDB is IP-focused; input is not an IP.
shodan skipped Shodan host lookup is IP-focused; input is not an IP.
censys ok Censys web property lookup returned 2 record(s) for gamaes.shop. Broader Censys search requires an organization-enabled account and API role.

Provider ATT&CK leads (not packet-observed execution):

ID Name Source / scope
T1059 Command and Scripting Interpreter otx (submitted indicator; provider-reported lead, not packet execution proof)
T1137 Office Application Startup otx (submitted indicator; provider-reported lead, not packet execution proof)
T1218 System Binary Proxy Execution otx (submitted indicator; provider-reported lead, not packet execution proof)
T1027 Obfuscated Files or Information otx (submitted indicator; provider-reported lead, not packet execution proof)

No actor lead returned. This does not establish absence of an actor.

newsaarctech.com

Type: domain; request: 18.240 seconds; completed: 2026-09-19T13:57:40.593205+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 83/100 (highly suspicious); a heuristic priority, not calibrated probability. Graph: 23 nodes, 29 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok 2 engines marked malicious and 3 suspicious; 52 harmless, 32 undetected.
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar skipped MalwareBazaar is hash-focused; input is not a hash.
otx ok OTX returned 3 pulse(s).
urlscan ok urlscan returned 10 scan result(s). urlscan activity analysis found 2 suspicious pattern(s).
greynoise skipped GreyNoise is IP-focused; input is not an IP.
abuseipdb skipped AbuseIPDB is IP-focused; input is not an IP.
shodan skipped Shodan host lookup is IP-focused; input is not an IP.
censys ok Censys web property lookup returned 2 record(s) for newsaarctech.com. Broader Censys search requires an organization-enabled account and API role.

Provider ATT&CK leads (not packet-observed execution):

ID Name Source / scope
T1583 Acquire Infrastructure otx (submitted indicator; provider-reported lead, not packet execution proof)
T1584 Compromise Infrastructure otx (submitted indicator; provider-reported lead, not packet execution proof)
T1608 Stage Capabilities otx (submitted indicator; provider-reported lead, not packet execution proof)
T1190 Exploit Public-Facing Application otx (submitted indicator; provider-reported lead, not packet execution proof)
T1078 Valid Accounts otx (submitted indicator; provider-reported lead, not packet execution proof)
T1090 Proxy otx (submitted indicator; provider-reported lead, not packet execution proof)
T1505.003 Web Shell otx (submitted indicator; provider-reported lead, not packet execution proof)
T1573 Encrypted Channel otx (submitted indicator; provider-reported lead, not packet execution proof)
T1539 Steal Web Session Cookie otx (submitted indicator; provider-reported lead, not packet execution proof)
T1071.001 Web Protocols otx (submitted indicator; provider-reported lead, not packet execution proof)
T1567 Exfiltration Over Web Service otx (submitted indicator; provider-reported lead, not packet execution proof)
T1059 Command and Scripting Interpreter otx (submitted indicator; provider-reported lead, not packet execution proof)
T1137 Office Application Startup otx (submitted indicator; provider-reported lead, not packet execution proof)
T1218 System Binary Proxy Execution otx (submitted indicator; provider-reported lead, not packet execution proof)
T1027 Obfuscated Files or Information otx (submitted indicator; provider-reported lead, not packet execution proof)

No actor lead returned. This does not establish absence of an actor.

172.104.227.98

Type: ip; request: 6.358 seconds; completed: 2026-09-19T13:57:48.536759+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 49/100 (suspicious); a heuristic priority, not calibrated probability. Graph: 11 nodes, 14 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok 5 engines marked malicious and 0 suspicious; 51 harmless, 33 undetected.
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar skipped MalwareBazaar is hash-focused; input is not a hash.
otx ok OTX returned 50 pulse(s).
urlscan ok urlscan returned 6 scan result(s). urlscan activity analysis found 1 suspicious pattern(s).
greynoise not_found GreyNoise classification: unknown. Query status: not_found
abuseipdb ok AbuseIPDB confidence score: 0/100.
shodan not_found Shodan returned 0 open port(s). Query status: not_found
censys ok Censys host lookup returned 0 service(s).

No actor lead returned. This does not establish absence of an actor.

163.172.50.82

Type: ip; request: 8.869 seconds; completed: 2026-09-19T13:58:11.047188+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 75/100 (highly suspicious); a heuristic priority, not calibrated probability. Graph: 13 nodes, 17 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok 11 engines marked malicious and 0 suspicious; 46 harmless, 32 undetected.
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar skipped MalwareBazaar is hash-focused; input is not a hash.
otx ok OTX returned 50 pulse(s).
urlscan ok urlscan returned 9 scan result(s). urlscan activity analysis found 1 suspicious pattern(s).
greynoise not_found GreyNoise classification: unknown. Query status: not_found
abuseipdb ok AbuseIPDB confidence score: 0/100.
shodan ok Shodan returned 98 open port(s).
censys ok Censys host lookup returned 48 service(s).

Provider ATT&CK leads (not packet-observed execution):

ID Name Source / scope
T1045 otx (submitted indicator; provider-reported lead, not packet execution proof)
T1055 Process Injection otx (submitted indicator; provider-reported lead, not packet execution proof)
T1129 Shared Modules otx (submitted indicator; provider-reported lead, not packet execution proof)
T1143 otx (submitted indicator; provider-reported lead, not packet execution proof)
T1057 Process Discovery otx (submitted indicator; provider-reported lead, not packet execution proof)
T1105 Ingress Tool Transfer otx (submitted indicator; provider-reported lead, not packet execution proof)
T1071 Application Layer Protocol otx (submitted indicator; provider-reported lead, not packet execution proof)
T1071.001 Web Protocols otx (submitted indicator; provider-reported lead, not packet execution proof)
T1071.004 DNS otx (submitted indicator; provider-reported lead, not packet execution proof)
T1491 Defacement otx (submitted indicator; provider-reported lead, not packet execution proof)
T1491.001 Internal Defacement otx (submitted indicator; provider-reported lead, not packet execution proof)
T1156 otx (submitted indicator; provider-reported lead, not packet execution proof)
T1399 otx (submitted indicator; provider-reported lead, not packet execution proof)
T1027 Obfuscated Files or Information otx (submitted indicator; provider-reported lead, not packet execution proof)
T1053 Scheduled Task/Job otx (submitted indicator; provider-reported lead, not packet execution proof)
T1080 Taint Shared Content otx (submitted indicator; provider-reported lead, not packet execution proof)
T1102 Web Service otx (submitted indicator; provider-reported lead, not packet execution proof)
T1210 Exploitation of Remote Services otx (submitted indicator; provider-reported lead, not packet execution proof)
T1486 Data Encrypted for Impact otx (submitted indicator; provider-reported lead, not packet execution proof)
T1490 Inhibit System Recovery otx (submitted indicator; provider-reported lead, not packet execution proof)
T1566 Phishing otx (submitted indicator; provider-reported lead, not packet execution proof)

No actor lead returned. This does not establish absence of an actor.

0a85cba8c2e6aa44684f15047dcaa4c4d7f86ec356891bc8e0b8ee36bb151f7a

Type: hash; request: 3.095 seconds; completed: 2026-09-19T13:58:25.265449+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 20/100 (needs review); a heuristic priority, not calibrated probability. Graph: 1 nodes, 0 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal ok No malicious detections in last analysis; 0 harmless, 61 undetected.
VirusTotal classification/name hints unreviewed; may include benign filenames sSTToaEwCG5VASw
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar not_found MalwareBazaar returned 0 sample record(s). Query status: hash_not_found
otx ok OTX returned 0 pulse(s).
urlscan ok urlscan returned 0 scan result(s). urlscan activity analysis found no obvious suspicious pattern.
greynoise skipped GreyNoise is IP-focused; input is not an IP.
abuseipdb skipped AbuseIPDB is IP-focused; input is not an IP.
shodan skipped Shodan host lookup is IP-focused; input is not an IP.
censys skipped Censys host and search pivots support IP, domain, and URL inputs.

Provider ATT&CK leads (not packet-observed execution):

ID Name Source / scope
T1036 Masquerading virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1046 Network Service Discovery virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1055 Process Injection virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1055.011 Extra Window Memory Injection virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1071 Application Layer Protocol virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1095 Non-Application Layer Protocol virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1189 Drive-by Compromise virustotal (submitted indicator; provider-reported lead, not packet execution proof)
T1573 Encrypted Channel virustotal (submitted indicator; provider-reported lead, not packet execution proof)

No actor lead returned. This does not establish absence of an actor.

2c80de6ffeb0759cb01dd7ad50437ea8dfcb7e4b8582a0129e7e7f700b593e38

Type: hash; request: 2.919 seconds; completed: 2026-09-19T14:06:11.868303+00:00. Persistence reread identical: True. Public provider summary. Platform triage score: 0/100 (low signal); a heuristic priority, not calibrated probability. Graph: 1 nodes, 0 edges; local deeper-tier matches: 0/0.

Provider Outcome Returned context / limitation
local-db ok Found 0 local IOC record(s).
virustotal not_found virustotal has no record for this lookup. Query status: not_found
threatfox not_found ThreatFox returned 0 record(s). Query status: no_result
malwarebazaar not_found MalwareBazaar returned 0 sample record(s). Query status: hash_not_found
otx ok OTX returned 0 pulse(s).
urlscan ok urlscan returned 0 scan result(s). urlscan activity analysis found no obvious suspicious pattern.
greynoise skipped GreyNoise is IP-focused; input is not an IP.
abuseipdb skipped AbuseIPDB is IP-focused; input is not an IP.
shodan skipped Shodan host lookup is IP-focused; input is not an IP.
censys skipped Censys host and search pivots support IP, domain, and URL inputs.

No actor lead returned. This does not establish absence of an actor.

The live case contains 6 explicitly linked, exact-type/value PCAP observables. 4 retain frame references; remaining exported-object hashes retain native object IDs and capture-export provenance, not an exact packet-frame map. Every link retains the capture checksum, points to a saved provider investigation, and was reread from the real API. Case actor associations remain empty. Verified graph links.

Current ATT&CK catalog and detection-strategy joins

These are read-only joins against the actual database, not generated detections or proof that the victim executed the technique. A valid catalog join cannot validate the original provider assertion.

Technique Current catalog match Available detection strategies
T1027 True Behavioral Detection of Obfuscated Files or Information (x-mitre-detection-strategy--e3758cbb-5dd9-4aad-b848-0539a8c56307)
T1036 True Behavioral Detection of Masquerading Across Platforms via Metadata and Execution Discrepancy (x-mitre-detection-strategy--408aedab-4a23-41ad-809d-fe9c3805b7f6)
T1045 False None returned
T1046 True Behavioral Detection Strategy for Network Service Discovery Across Platforms (x-mitre-detection-strategy--82e20b1f-300e-43cc-9259-1d506ef5d1f8)
T1053 True Cross-Platform Behavioral Detection of Scheduled Task/Job Abuse (x-mitre-detection-strategy--df11466a-27a2-4cb1-bf73-2a3a4aaee0d9)
T1055 True Behavioral Detection of Process Injection Across Platforms (x-mitre-detection-strategy--9833b57b-4c83-4f58-b4cf-76f041b29273)
T1055.011 True Detection Strategy for Extra Window Memory (EWM) Injection on Windows (x-mitre-detection-strategy--1a8d87f1-48ca-4929-a5cc-2b2a03983f12)
T1057 True Detection of Adversarial Process Discovery Behavior (x-mitre-detection-strategy--309ca3cd-d3f0-4aea-8932-558550aa89f4)
T1059 True Behavioral Detection of Command and Scripting Interpreter Abuse (x-mitre-detection-strategy--8582f5e6-44a5-4950-b7e8-a3e1b6d58d63)
T1071 True Detection of Command and Control Over Application Layer Protocols (x-mitre-detection-strategy--155cab5b-c70b-4cfb-ba52-f62a21836b19)
T1071.001 True Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets (x-mitre-detection-strategy--e6496b9b-2458-4616-9712-a7c0da7fd3bc)
T1071.004 True Behavioral Detection of DNS Tunneling and Application Layer Abuse (x-mitre-detection-strategy--c2721658-fa76-4b6f-9f84-50618de81ae0)
T1078 True Detection of Valid Account Abuse Across Platforms (x-mitre-detection-strategy--a6245075-b59f-46cf-8b76-e8d95c378a22)
T1080 True Detection of Tainted Content Written to Shared Storage (x-mitre-detection-strategy--cdfe6166-43e9-434a-a961-139edd58ca0c)
T1090 True Detection of Proxy Infrastructure Setup and Traffic Bridging (x-mitre-detection-strategy--5c44619a-da36-4bbd-9730-efceacf2409f)
T1095 True Detection of Non-Application Layer Protocols for C2 (x-mitre-detection-strategy--2cb544af-ef54-4376-9608-b399ad67d3d6)
T1102 True Suspicious Use of Web Services for C2 (x-mitre-detection-strategy--769615c5-08d5-4f51-8f3b-7ac2f1febce8)
T1105 True Detect Ingress Tool Transfers via Behavioral Chain (x-mitre-detection-strategy--67677c4c-5778-49eb-ae74-1920645b8554)
T1129 True Behavior-chain, platform-aware detection strategy for T1129 Shared Modules (x-mitre-detection-strategy--928a6ce6-fca0-4d66-aba3-1121431b953e)
T1137 True Detect Office Startup-Based Persistence via Macros, Forms, and Registry Hooks (x-mitre-detection-strategy--71a8576b-c9ef-4485-b461-d706fd757a67)
T1143 False None returned
T1156 False None returned
T1189 True Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189) (x-mitre-detection-strategy--a070f9d2-3480-4362-99b3-8b36f5be0189)
T1190 True Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress) (x-mitre-detection-strategy--dd8477c8-2aad-4db3-b810-fe0d2f605fa8)
T1210 True Exploitation of Remote Services – multi-platform lateral movement detection (x-mitre-detection-strategy--ee73dd97-cf1a-4220-a7cf-52d864811bb4)
T1218 True Detection of Proxy Execution via Trusted Signed Binaries Across Platforms (x-mitre-detection-strategy--ce0b969a-1411-4b6f-a6aa-c31ef6fe6727)
T1399 False None returned
T1486 True Detection of Multi-Platform File Encryption for Impact (x-mitre-detection-strategy--d080a1b1-5ad1-45a1-8f7b-b736986c20d9)
T1490 True Behavioral Detection for T1490 - Inhibit System Recovery (x-mitre-detection-strategy--b13116ed-e9c0-4cd5-81f6-676074078477)
T1491 True Defacement via File and Web Content Modification Across Platforms (x-mitre-detection-strategy--2d5f2445-a395-4012-b378-c953f2df7353)
T1491.001 True Internal Website and System Content Defacement via UI or Messaging Modifications (x-mitre-detection-strategy--c8b4a2e4-386f-45b3-b32a-8ca4113e5592)
T1505.003 True Web Shell Detection via Server Behavior and File Execution Chains (x-mitre-detection-strategy--abb052c6-4edd-4592-9b9b-e53a55ac53b8)
T1539 True Detection of Web Session Cookie Theft via File, Memory, and Network Artifacts (x-mitre-detection-strategy--26fdbcb2-abc1-4844-8e5d-2c6039336cb7)
T1566 True Detection Strategy for Phishing across platforms. (x-mitre-detection-strategy--7ee73f2e-76b2-4f00-bcc0-7fb79d31d344)
T1567 True Detection Strategy for Exfiltration Over Web Service (x-mitre-detection-strategy--1753ab98-4530-4284-9bc3-5d4813abfb9e)
T1573 True Detection Strategy for Encrypted Channel across OS Platforms (x-mitre-detection-strategy--08861418-398c-4972-8850-5e11f2d32944)
T1583 True Detection of Acquire Infrastructure (x-mitre-detection-strategy--56752265-8647-4ce2-bc6c-c38c2e14685c)
T1584 True Detection of Compromise Infrastructure (x-mitre-detection-strategy--7f3e2c35-7394-4cc6-baef-73a830930953)
T1608 True Detection of Stage Capabilities (x-mitre-detection-strategy--5a1ada5b-5729-45d5-8b3d-f6fa7d2a3352)
Prior analysis Shared count Example observations
6e50c68f-5552-400c-9835-15867ddb022d 17 api.msn.com, client.wns.windows.com, dns.msftncsi.com, settings-win.data.microsoft.com, settingsfd-geo.trafficmanager.net
43bc93eb-d6db-4400-b983-b0dd404c8ca4 41 api.msn.com, checkappexec.microsoft.com, client.wns.windows.com, dns.msftncsi.com, imap.aol.com
6df36b51-4b44-4660-b534-2fa89705e807 20 api.msn.com, checkappexec.microsoft.com, client.wns.windows.com, dns.msftncsi.com, nexusrules.officeapps.live.com
29aa3ef8-47c9-4c47-b4cc-1ff3e0708142 11 api.msn.com, client.wns.windows.com, settings-win.data.microsoft.com, v10.events.data.microsoft.com, wns.notify.trafficmanager.net
b79032a8-d69e-4ac1-bdd4-542473fa8e3b 11 api.msn.com, client.wns.windows.com, settings-win.data.microsoft.com, v10.events.data.microsoft.com, wns.notify.trafficmanager.net
faf041c3-70e0-4a01-8780-10917e5e187c 10 api.msn.com, client.wns.windows.com, dns.msftncsi.com, settings-win.data.microsoft.com, v10.events.data.microsoft.com
08324647-35af-4af2-8d82-4387eec03918 13 api.msn.com, checkappexec.microsoft.com, client.wns.windows.com, dns.msftncsi.com, v10.events.data.microsoft.com
616a90fa-f15e-4fcb-8d56-7b8e0eff5785 3 settings-win.data.microsoft.com, v10.events.data.microsoft.com, www.bing.com
459e119d-191f-49e8-85ea-c78f9de41826 10 api.msn.com, client.wns.windows.com, settings-win.data.microsoft.com, v10.events.data.microsoft.com, wns.notify.trafficmanager.net
7a2cfe72-f48d-4894-8a2d-8889cb3b11b2 12 api.msn.com, client.wns.windows.com, settings-win.data.microsoft.com, v10.events.data.microsoft.com, wns.notify.trafficmanager.net
81373b30-6a59-49d1-89b0-bad73ed19eaa 12 api.msn.com, client.wns.windows.com, dns.msftncsi.com, settings-win.data.microsoft.com, v10.events.data.microsoft.com
38851ad7-b3a0-423d-ae89-3b7be4e4b908 12 api.msn.com, client.wns.windows.com, dns.msftncsi.com, settings-win.data.microsoft.com, v10.events.data.microsoft.com
bfccc426-aa9b-4007-8558-a66d37ecb90c 14 api.msn.com, checkappexec.microsoft.com, client.wns.windows.com, dns.msftncsi.com, settings-win.data.microsoft.com

Comparison with publisher answers and earlier runs

The following comparison is separate from native inference. It measures availability of selected facts, not 100% incident-diagnosis accuracy.

Publisher answer.

Identity and the listed infrastructure are packet-visible. Native family attribution, an infection-onset conclusion, and extraction/classification of 17 SMTP emails are not implemented. Publisher notes that the Emotet DLL cannot be exported from this capture. Do not interpret HTTP-export completeness as complete malware recovery.

Client Field Packet-verified expected value Live
10.12.3.66 ip 10.12.3.66 True
10.12.3.66 hostname DESKTOP-LUOABV1 True
10.12.3.66 account darin.figueroa True

Declared IOC subset available: 4/4. Not exhaustive recall.

Browser history/open, Markdown export and investigation transfer: True. Investigation ID: 40fe3cfe-82bb-402a-98a4-11b7a58a0b41. Investigation transfers preserve a bounded preview, total count, source-analysis URL and hashes. Complete evidence remains server-side. TTP-overlap leads are not inserted into actor associations. PDF export: HTTP 200, including an explicitly non-authoritative packet-evidence appendix. STIX export remains HTTP 409 until a human completes review/promotion; this is a successful safety check.

Follow-up priorities

Validate high/medium findings using frame/stream evidence; obtain process and endpoint telemetry for execution, persistence and credential-theft hypotheses. Provider data above is current-time external context, not historical execution evidence. Review shared-CDN matches for specificity. Do not execute exported objects or treat encrypted payload metadata as decrypted evidence.